SIEM & Threat Detection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 SIEM & Threat Detection flashcards as text
What is 'baselining' in the context of SIEM and anomaly detection?
Answer: Establishing normal behavior patterns to identify deviations that may indicate threats
Baselining involves collecting data over time to define what 'normal' looks like for users, systems, or networks, enabling detection of statistical deviations that may signal threats.
Which Windows Event ID should an analyst prioritize when investigating potential credential dumping via LSASS?
Answer: Event ID 10 in Sysmon (Process accessed)
Sysmon Event ID 10 logs when one process opens a handle to another, making it critical for detecting tools like Mimikatz accessing the LSASS process memory.
What does UEBA (User and Entity Behavior Analytics) add to traditional SIEM capabilities?
Answer: Machine learning-based profiling of user and device behavior to detect insider threats and compromised accounts
UEBA uses machine learning to build behavioral profiles of users and entities, detecting anomalies like unusual access times, data exfiltration patterns, or impossible travel scenarios.
A SOC analyst receives an alert for a PowerShell command with a Base64-encoded payload. What is the attacker most likely attempting?
Answer: Obfuscating malicious code to evade signature-based detection
Attackers commonly Base64-encode PowerShell payloads to bypass signature-based detection tools that scan for plaintext malicious strings.
Which network artifact is most useful for detecting Command-and-Control (C2) communications that use HTTP for cover?
Answer: User-Agent strings, request timing patterns, and beacon regularity in HTTP logs
C2 beaconing over HTTP often produces regular timing patterns, unusual User-Agent strings, and consistent request sizes that can be detected by analyzing web proxy logs.
What is the key difference between a signature-based IDS and a behavior-based IDS?
Answer: Signature-based IDS detects known attacks via pattern matching; behavior-based IDS detects anomalies from established baselines
Signature-based IDS matches traffic against known attack patterns (limited to known threats), while behavior-based IDS detects deviations from normal baselines (capable of detecting novel threats).
Which phase of incident response involves analyzing SIEM data to understand the full scope of a breach?
Answer: Detection and Analysis
The Detection and Analysis phase involves examining SIEM alerts, logs, and correlated events to confirm the incident, determine its scope, and understand the attack vector.