Monitoring and Logging (SIEM)
Security Operations involves continuously monitoring systems and networks. Logs from firewalls, servers, and applications are collected to spot anomalies (e.g., repeated failed logins or unusual traffic patterns). A SIEM (Security Information and Event Management) tool aggregates logs and uses rules or analytics to alert on suspicious activity. For example, a SIEM can flag if a user suddenly downloads a large amount of data late at night. Regular log review and automated alerts help catch incidents early, before they escalate.
Incident Response Process
When a security incident occurs, following a structured Incident Response (IR) plan is crucial. Common phases are: Preparation (establishing policies and tools), Identification (detecting and confirming an incident), Containment (isolating affected systems), Eradication (removing the threat, such as deleting malware), Recovery (restoring systems to normal operation, e.g., from backups), and Lessons Learned (reviewing what happened and improving processes). For example, in a malware outbreak, containment might involve disconnecting infected machines from the network. In answers, list each phase clearly; exam questions often ask you to outline these steps.
Digital Forensics and Evidence Handling
ProReviewer — locked
Drills, code labs, and full solutions.
Business Continuity and Disaster Recovery
ProReviewer — locked
Drills, code labs, and full solutions.
Practice & Exam Drills — Lesson 6
ProReviewer — locked
Drills, code labs, and full solutions.