GSEC COMPREHENSIVE QUESTIONS AND
ANSWERS SET A+
✔✔Incident handling phase 1 - ✔✔preparation; management support; policy; legal and
law enforcement, compliance, id team, communications
✔✔BCP - ✔✔Business continuity plan. last line of defense predict and plan for potential
outages of critical services or functions. includes DRP elements to return critical
BUSINESS functions to operation. BIA is under BCP and drives decisions to create
redundancies such as failover clusters or alternate sites.
✔✔BCP steps - ✔✔assess - threat id; damage (potential impact)
eval - cost benefit, risk assessment
prep - contingent operations, management of plan, testing of plan
mitigate - id preventive to reduce risks
respond - minimize impact
recover - return to normal ops
✔✔mobility disaster recovery kit - ✔✔unlocked phones
sim cards
charged batts
solar
✔✔chain of custody - ✔✔a written record of all people who have had possession of an
item of evidence
✔✔DFIR - ✔✔Digital Forensics and Investigation Response
✔✔Threat Hunting goals - ✔✔early and accurate detection
control and reduce impact
improve defenses
understand org weaknesses
,✔✔Threat hunting activities - ✔✔understand threats
know network
critical data and business processes
normal vs abnormal system behavior
threat intel
indicators of compromise
analysis
seek root cause
respond
correlation is critical
✔✔IoC - ✔✔Indicator of compromise - a data point that is extracted from security data
and can be used as high fidelity predictor of system compromise; attack signatures,
tampered logs; unauthZ access attempts
✔✔pivot point - ✔✔compromise in one element in system can lead to another; registry
keys in windows, start up files, running processes
✔✔lateral movement - ✔✔compromise one system, then another
✔✔Threat Intelligence - ✔✔The process of investigating and collecting information
about emerging threats and threat sources. Where to look? Visibility?
✔✔Threat hunting maturity model - ✔✔p 185
✔✔network threat hunting - ✔✔look for lateral movement; assume compromised; C2
(command and control)
✔✔C2 - ✔✔Command and control (by attacker)
✔✔Threat hunting metrics - ✔✔dwell time; lateral movement; reinfection
✔✔threat hunting plan - ✔✔limit scope
specific goals
document effort, outcomes
metrics
✔✔TTP - ✔✔tools, techniques, procedures
✔✔Risk Management - ✔✔using strategies to reduce the amount of risk to an
acceptable level
✔✔Risk Management goals - ✔✔identify measure control and minimize/eliminate the
likelihood of an attack, reduce risk to an acceptable level
, ✔✔risk - ✔✔risk = threat x vulnerability
✔✔SLE - ✔✔Single loss expectancy | $ measure the cost of a single occurrence of a
threat exploiting a vulnerability
✔✔AV - ✔✔value of an asset in dollars
✔✔EF - ✔✔Exposure Factor (0 - 100% asset loss)
✔✔ARO - ✔✔Annualized Rate of Occurrence | estimated frequency at which the threat
is expected to occur
✔✔ALE (Annual Loss Expectancy) - ✔✔Expected amount to lose annually from
resources failing.
Monetary measure of how much loss you can expect in a year.
ALE = SLE * ARO
✔✔quantitative analysis - ✔✔more powerful because based on metrics and typically
yields an objective numeric value (often $)
✔✔qualitative analysis - ✔✔easier and can identify high-risk areas and produces more
subjective results (low, medium, high)
✔✔Windows OS classes - ✔✔client server embedded
✔✔Windows Edition - ✔✔business, pro and enterprise have AD other (but only ent has
AppLocker)
✔✔Windows 10 Pro for workstations - ✔✔high end, 3D, video editing
✔✔Windows S - ✔✔only MS Store apps; can change to full, but not back
✔✔Windows on ARM - ✔✔ARM platform: medical devices, GPS, mobile, lower power,
less heat, more battery life)
✔✔Microsoft site license - ✔✔aka Software Assurance License
✔✔Microsoft patching - ✔✔must patch due to anti trust settlement
✔✔End of Sales - ✔✔product no longer sold to retailers or OEMs
✔✔End of mainstream support - ✔✔warranties expire for the product and it is no longer
improved only security patching
ANSWERS SET A+
✔✔Incident handling phase 1 - ✔✔preparation; management support; policy; legal and
law enforcement, compliance, id team, communications
✔✔BCP - ✔✔Business continuity plan. last line of defense predict and plan for potential
outages of critical services or functions. includes DRP elements to return critical
BUSINESS functions to operation. BIA is under BCP and drives decisions to create
redundancies such as failover clusters or alternate sites.
✔✔BCP steps - ✔✔assess - threat id; damage (potential impact)
eval - cost benefit, risk assessment
prep - contingent operations, management of plan, testing of plan
mitigate - id preventive to reduce risks
respond - minimize impact
recover - return to normal ops
✔✔mobility disaster recovery kit - ✔✔unlocked phones
sim cards
charged batts
solar
✔✔chain of custody - ✔✔a written record of all people who have had possession of an
item of evidence
✔✔DFIR - ✔✔Digital Forensics and Investigation Response
✔✔Threat Hunting goals - ✔✔early and accurate detection
control and reduce impact
improve defenses
understand org weaknesses
,✔✔Threat hunting activities - ✔✔understand threats
know network
critical data and business processes
normal vs abnormal system behavior
threat intel
indicators of compromise
analysis
seek root cause
respond
correlation is critical
✔✔IoC - ✔✔Indicator of compromise - a data point that is extracted from security data
and can be used as high fidelity predictor of system compromise; attack signatures,
tampered logs; unauthZ access attempts
✔✔pivot point - ✔✔compromise in one element in system can lead to another; registry
keys in windows, start up files, running processes
✔✔lateral movement - ✔✔compromise one system, then another
✔✔Threat Intelligence - ✔✔The process of investigating and collecting information
about emerging threats and threat sources. Where to look? Visibility?
✔✔Threat hunting maturity model - ✔✔p 185
✔✔network threat hunting - ✔✔look for lateral movement; assume compromised; C2
(command and control)
✔✔C2 - ✔✔Command and control (by attacker)
✔✔Threat hunting metrics - ✔✔dwell time; lateral movement; reinfection
✔✔threat hunting plan - ✔✔limit scope
specific goals
document effort, outcomes
metrics
✔✔TTP - ✔✔tools, techniques, procedures
✔✔Risk Management - ✔✔using strategies to reduce the amount of risk to an
acceptable level
✔✔Risk Management goals - ✔✔identify measure control and minimize/eliminate the
likelihood of an attack, reduce risk to an acceptable level
, ✔✔risk - ✔✔risk = threat x vulnerability
✔✔SLE - ✔✔Single loss expectancy | $ measure the cost of a single occurrence of a
threat exploiting a vulnerability
✔✔AV - ✔✔value of an asset in dollars
✔✔EF - ✔✔Exposure Factor (0 - 100% asset loss)
✔✔ARO - ✔✔Annualized Rate of Occurrence | estimated frequency at which the threat
is expected to occur
✔✔ALE (Annual Loss Expectancy) - ✔✔Expected amount to lose annually from
resources failing.
Monetary measure of how much loss you can expect in a year.
ALE = SLE * ARO
✔✔quantitative analysis - ✔✔more powerful because based on metrics and typically
yields an objective numeric value (often $)
✔✔qualitative analysis - ✔✔easier and can identify high-risk areas and produces more
subjective results (low, medium, high)
✔✔Windows OS classes - ✔✔client server embedded
✔✔Windows Edition - ✔✔business, pro and enterprise have AD other (but only ent has
AppLocker)
✔✔Windows 10 Pro for workstations - ✔✔high end, 3D, video editing
✔✔Windows S - ✔✔only MS Store apps; can change to full, but not back
✔✔Windows on ARM - ✔✔ARM platform: medical devices, GPS, mobile, lower power,
less heat, more battery life)
✔✔Microsoft site license - ✔✔aka Software Assurance License
✔✔Microsoft patching - ✔✔must patch due to anti trust settlement
✔✔End of Sales - ✔✔product no longer sold to retailers or OEMs
✔✔End of mainstream support - ✔✔warranties expire for the product and it is no longer
improved only security patching