DCOM 212 MidTerm Review ACTUAL UPDATED QUESTIONS AND CORRECT
ANSWERS
Outlier detection data analysis conducted by response teams and digital forensics investigators
anomaly detection makes use of profiles used to describe the services & resources each authorized
user or group normally accesses
Anomaly Detection triggers alarms based on False
characteristic signatures of external attacks
Ad hoc network consists of laptops, tablets, and other True
devices connected via Wi-Fi are not subject to NSM
when they talk directly to each other
Whitelist is a list that inherently denies all listings not documented on it.
Blacklist is a list that inherently permits all listings not documented on it
Heuristic detection utilizes algorithms detecting certain types of attacks to detect suspicious traffic.
Tap is dedicated hardware installed for accessing network traffic
Continuous monitoring (CM) is vulnerability-centric True
NSM involves preventing intrusions because prevention False
eventually fails
Data collection tools aggregate data in passive real-time for live analysis or post-mortem analysis
attack protocol is a logical sequence of steps or processes used by an attacker to launch an
attack against a target system or network
scanning tools typically are used to collect information that an attacker needs to launch a
successful attack
Packet sniffers captures copies of packets from network and analyzes them
passive actions security appliance takes no direct action against a data packet
port scanners are used by both attackers and defenders to identify/fingerprint computers active
on a network and other useful information
, data presentation tools expose Network Security Monitoring appliance information to analysts
Packet analysis tools read network traffic
Data Delivery Tools Agent software shuttle data from the collection tools to the presentation software
active actions security appliance takes direct action against a data packet
When using trap-and-trace, the trace usually consists of a False
honeypot or padded cell and an alarm
Entrapment is the action of luring an individual into committing a crime to get a conviction.
In regards to Data Inspection a False Negative would be illegitimate traffic being identified as legitimate traffic
defined as
Honeypots are decoy systems designed to lure potential attackers away from critical systems.
Honeynet When a collection of honeypots connects several honeypot systems on a subnet
In regards to Data Inspection a False Positive would be legitimate traffic being identified as illegitimate traffic
defined as:
padded cell is a honey pot that has been protected so that it cannot be easily compromised.
In regards to Data Inspection a True Positive would be illegitimate traffic being identified as illegitimate traffic
defined as:
In regards to Data Inspection a True Negative would be legitimate traffic being identified as legitimate traffic
defined as
Enticement is the process of attracting attention to a system by placing tantalizing bits of
information in key locations.
The full-fledged implementation of any operating system True
(OS) over the production network is known as a Pure
Honeypot
Honeynet is a collection of similar Honeypot types & configuration
Honeyfarm is a deployment of various honeypot types across the production network
ANSWERS
Outlier detection data analysis conducted by response teams and digital forensics investigators
anomaly detection makes use of profiles used to describe the services & resources each authorized
user or group normally accesses
Anomaly Detection triggers alarms based on False
characteristic signatures of external attacks
Ad hoc network consists of laptops, tablets, and other True
devices connected via Wi-Fi are not subject to NSM
when they talk directly to each other
Whitelist is a list that inherently denies all listings not documented on it.
Blacklist is a list that inherently permits all listings not documented on it
Heuristic detection utilizes algorithms detecting certain types of attacks to detect suspicious traffic.
Tap is dedicated hardware installed for accessing network traffic
Continuous monitoring (CM) is vulnerability-centric True
NSM involves preventing intrusions because prevention False
eventually fails
Data collection tools aggregate data in passive real-time for live analysis or post-mortem analysis
attack protocol is a logical sequence of steps or processes used by an attacker to launch an
attack against a target system or network
scanning tools typically are used to collect information that an attacker needs to launch a
successful attack
Packet sniffers captures copies of packets from network and analyzes them
passive actions security appliance takes no direct action against a data packet
port scanners are used by both attackers and defenders to identify/fingerprint computers active
on a network and other useful information
, data presentation tools expose Network Security Monitoring appliance information to analysts
Packet analysis tools read network traffic
Data Delivery Tools Agent software shuttle data from the collection tools to the presentation software
active actions security appliance takes direct action against a data packet
When using trap-and-trace, the trace usually consists of a False
honeypot or padded cell and an alarm
Entrapment is the action of luring an individual into committing a crime to get a conviction.
In regards to Data Inspection a False Negative would be illegitimate traffic being identified as legitimate traffic
defined as
Honeypots are decoy systems designed to lure potential attackers away from critical systems.
Honeynet When a collection of honeypots connects several honeypot systems on a subnet
In regards to Data Inspection a False Positive would be legitimate traffic being identified as illegitimate traffic
defined as:
padded cell is a honey pot that has been protected so that it cannot be easily compromised.
In regards to Data Inspection a True Positive would be illegitimate traffic being identified as illegitimate traffic
defined as:
In regards to Data Inspection a True Negative would be legitimate traffic being identified as legitimate traffic
defined as
Enticement is the process of attracting attention to a system by placing tantalizing bits of
information in key locations.
The full-fledged implementation of any operating system True
(OS) over the production network is known as a Pure
Honeypot
Honeynet is a collection of similar Honeypot types & configuration
Honeyfarm is a deployment of various honeypot types across the production network