Threat Detection & Prevention Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Detection & Prevention flashcards as text
What distinguishes a UEBA (User and Entity Behavior Analytics) system from a traditional SIEM?
Answer: UEBA applies machine learning to detect anomalous behavior patterns, while traditional SIEM relies on predefined correlation rules
UEBA uses machine learning to build behavioral baselines and detect deviations, going beyond the static rule-based approach of traditional SIEM systems.
An organization detects that an attacker performed a successful SQL injection, extracted a database, and then deleted all logs. Which control would have BEST prevented log deletion?
Answer: Forwarding logs to an immutable, centralized SIEM in real time
Streaming logs to an external, append-only SIEM ensures attackers who compromise the source system cannot retroactively destroy the audit trail.
Which technique allows an attacker to bypass network-based intrusion detection by splitting a TCP packet payload across multiple fragments?
Answer: IP fragmentation evasion
Splitting a malicious payload across fragmented packets can evade IDS/IPS systems that do not properly reassemble TCP streams before inspecting content.
A threat detection engineer wants to reduce alert fatigue without missing real threats. Which approach is MOST appropriate?
Answer: Tuning detection rules using historical false positive data and adding risk scoring to prioritize high-confidence alerts
Systematic rule tuning based on false positive history combined with risk-based prioritization reduces noise while preserving detection of genuine threats.
Which indicator in endpoint telemetry MOST strongly suggests process injection has occurred?
Answer: A legitimate system process (e.g., svchost.exe) spawning unusual network connections or child processes
Process injection hijacks trusted processes, so suspicious network behavior or unusual child processes spawned by normally benign system processes is a strong indicator.
What is the purpose of 'threat modeling' in a prevention-focused security program?
Answer: To systematically identify, prioritize, and mitigate potential threats before they are exploited
Threat modeling is a proactive process that maps assets, identifies potential attack vectors, and drives preventive controls before an incident happens.
A security team implements egress filtering on the perimeter firewall. Which threat does this PRIMARILY help prevent?
Answer: Unauthorized outbound data exfiltration and C2 communications from compromised internal hosts
Egress filtering controls outbound traffic, limiting what compromised internal systems can communicate with externally, which disrupts exfiltration and C2 channels.