Cisco CyberOps Associate (CBROPS) 200-201 flashcards
179 free flashcards. Tap a card to flip it.
Policy vs. Procedure
Flip cardA security policy is a high-level statement of intent and rules (the 'what'), while a security procedure is a detailed, step-by-step guide on how to implement those rules (the 'how').
- Policies are strategic, procedures are tactical.
- Procedures ensure consistent implementation of policies.
- Both are essential for a comprehensive security program.
Memory trick: The blueprint (policy) needs clear instructions (procedure) to build.
Denial of Service (DoS)
Flip cardAn attack aimed at making a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.
- Can target network bandwidth, system resources, or application services.
- Caused by a single attacking source.
- Impacts availability and performance for legitimate users.
Memory trick: Availability attacks stop things from working when needed.
Remediation Tracking
Flip cardThe process of monitoring and managing the resolution of vulnerabilities, deficiencies, or findings identified during security assessments or audits.
- Ensures identified issues are addressed in a timely and effective manner.
- Involves assigning ownership, setting deadlines, and verifying completion.
- Crucial for continuous improvement of security posture.
Memory trick: Audits PLAN, EXECUTE, REPORT, and REMEDIATE.
Administrative Security Controls
Flip cardSecurity controls that involve policies, procedures, guidelines, and training to manage security risks.
- Focus on human behavior and organizational processes.
- Examples include security policies, incident response plans, and security awareness training.
- Often the first line of defense against human error.
Memory trick: Think PAT for controls: Physical, Administrative, Technical.
SQL Injection
Flip cardA code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution by the backend database.
- Can lead to data theft, data modification, or complete system compromise.
- Often uses payloads like 'UNION SELECT', 'OR 1=1--', or 'SLEEP()'.
- Prevention includes parameterized queries, input validation, and least privilege for database accounts.
Memory trick: Web attacks exploit weaknesses in how apps talk to users and databases.
Full TCP Connect Scan
Flip cardA full TCP connect scan attempts to establish a complete TCP three-way handshake with every target port. If the port is open, the handshake completes. If the port is closed, the target responds with a RST (reset) packet.
- Completes the TCP three-way handshake
- Easily detected by firewalls and IDS/IPS
- Closed ports respond with RST
- Slower than half-open scans but more reliable for some systems
Memory trick: Port scans are like 'Knocking on Doors' to see who's home.
Security Awareness Effectiveness
Flip cardThe degree to which security awareness training successfully changes employee behavior and knowledge to reduce human-related security risks.
- Requires clear communication and reinforcement.
- Measured by changes in employee actions and incident rates.
- Essential for proactive threat mitigation.
Memory trick: Humans are the first line of defense, if they know what to do.
Incident Containment
Flip cardThe incident response phase focused on limiting the scope and impact of a security incident to prevent further damage or spread.
- Involves actions like isolating systems, blocking IPs, or disabling accounts.
- Aims to stop the attack from progressing.
- Requires quick decision-making and precise execution.
Memory trick: PREDICT and C.E.R.P. for incidents: Preparation, Detection, Containment, Eradication, Recovery, Post-Incident.
HTTP C2 Communication
Flip cardHTTP Command and Control (C2) communication involves malware using standard HTTP/HTTPS protocols (GET, POST requests) to send and receive commands or exfiltrate data from a C2 server. This technique often employs obfuscated URLs, custom User-Agents, and non-standard HTTP headers to evade detection.
- Uses common HTTP/HTTPS ports (80, 443)
- Often seen with unusual URL patterns or query strings
- May use custom or spoofed User-Agent strings
- Aims to blend in with legitimate web traffic
Memory trick: C2 'Whispers' commands, often hiding in plain sight like a browser.
NIDS Passive Deployment
Flip cardA method of deploying a Network Intrusion Detection System (NIDS) where it monitors network traffic by receiving a copy of the data, rather than being placed directly in the data path, thus avoiding impact on network performance.
- Uses SPAN/mirror ports or network taps
- Zero latency or packet alteration
- Ideal for monitoring without intervention
Memory trick: NIDS: Span for Passive, Inline for Active.
Compliance Audit
Flip cardA systematic review to determine whether an organization is following external regulations, internal policies, and industry standards.
- Focuses on adherence to established rules and guidelines.
- Can involve reviewing documentation, interviewing personnel, and testing controls.
- Aims to identify gaps in compliance and areas for improvement.
Memory trick: Assessments VASTly improve security: Vulnerability, Audit, Simulation, Test.
Post-Incident Activity
Flip cardThe final phase of the incident response lifecycle, focusing on reviewing the incident, documenting lessons learned, and implementing improvements.
- Occurs after an incident is resolved and systems are recovered.
- Aims to prevent similar incidents and improve future response.
- Includes activities like reporting, evidence retention, and plan updates.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-mortem.
Procedure Development
Flip cardThe process of creating detailed, step-by-step instructions that guide individuals or systems in performing a specific task or process in a consistent and secure manner.
- Translates high-level policies into actionable steps.
- Ensures consistency and reduces errors.
- Requires technical expertise for implementation details.
Memory trick: Policy is the goal, procedure is the map to get there.
Malware Beaconing
Flip cardA technique used by malware where a compromised host periodically sends small, often encrypted, communication packets to its command and control (C2) server.
- Indicates the host is still active and connected to the C2.
- Characterized by regular, fixed intervals and low data volume.
- Often uses common ports (e.g., 80, 443) or DNS to blend in.
Memory trick: Malware calls home like a robot checking in.
Domain Generation Algorithm (DGA)
Flip cardA technique used by malware to algorithmically generate a large number of new domain names, which can be used as potential command and control (C2) servers, making it difficult for defenders to block all C2 communication paths.
- Generates new domains on the fly
- Used for C2 resilience
- Challenges traditional blacklisting approaches
Memory trick: C2 Evasion: DGA for Domains, DNS for Tunnels.
Nmap SYN Scan (-sS)
Flip cardA stealthy port scanning technique that sends SYN packets to target ports and analyzes the responses without completing the full TCP three-way handshake, making it harder to detect by traditional firewalls.
- Also known as 'half-open' scan
- Identifies open, closed, or filtered ports
- Does not establish a full connection
Memory trick: Network Mapper Scans: Stealthy, TCP, UDP, Ping.
Preventative Security Control
Flip cardA security control designed to prevent unauthorized or undesirable actions from occurring.
- Aims to stop incidents before they start.
- Examples include firewalls, access controls, encryption.
- Effectiveness depends on proper implementation and enforcement.
Memory trick: Prevent, Detect, Correct, Deter, Compensate.
PSH Flag Abuse (C2)
Flip cardMalware can abuse the TCP PSH (Push) flag to force immediate delivery of small data segments to a command-and-control (C2) server, bypassing buffering delays. This allows for rapid, low-latency communication, which can be harder to detect than larger, more sustained data transfers.
- TCP PSH flag forces immediate data delivery
- Abused by malware for rapid C2 communication
- Often seen with small payloads to C2 servers
- Helps malware minimize connection duration and evade detection
Memory trick: TCP Flags are like 'Traffic Signals', and malware often runs a red light (PSH) to speed past.
Security Procedure
Flip cardA detailed, step-by-step instruction set for performing specific security-related tasks or actions.
- Explains 'how' to implement policies and standards.
- Highly specific and often role-based.
- Ensures consistency and repeatability of security operations.
Memory trick: Policies are high, Procedures are low, Standards are in between, Guidelines just flow.
Security Awareness Program Effectiveness Metrics
Flip cardQuantifiable measures used to evaluate how well a security awareness program achieves its goals, particularly in changing employee behavior.
- Focus on behavioral changes, not just knowledge acquisition.
- Examples include phishing click rates, incident reporting rates, policy compliance.
- Baseline measurements are crucial for demonstrating improvement.
Memory trick: Measure Behavior, Not Just Knowledge.
Effective Security Procedure
Flip cardA detailed, step-by-step instruction set designed to ensure consistent and correct execution of security tasks, directly supporting security policies.
- Must be clear, concise, and easy to follow.
- Should be specific, measurable, and actionable.
- Helps achieve compliance and reduce human error.
Memory trick: Effective procedures are like clear recipes: precise and easy to follow.
HTTP Command and Control (C2)
Flip cardA method of command and control where malware communicates with its C2 server using standard HTTP or HTTPS requests and responses, often mimicking legitimate web browser traffic.
- Blends with normal web traffic, making detection difficult.
- Often uses common ports (80, 443) and legitimate-looking User-Agent strings.
- Commands and data are typically encoded or embedded within HTTP headers, cookies, or POST data.
Memory trick: Malware C2 uses different languages to talk to its master.
Post-Incident Activities
Flip cardActions taken after an incident has been contained, eradicated, and recovered from, including documentation, lessons learned, and mandatory notifications.
- Crucial for continuous improvement and compliance.
- Involves detailed reporting and analysis.
- Often includes legal and regulatory obligations.
Memory trick: PREPARE, DETECT, CONTAIN, ERADICATE, RECOVER, POST-MORTEM.
Regulatory Compliance Management
Flip cardThe systematic process of ensuring an organization meets and adheres to applicable laws, regulations, industry standards, and internal policies.
- Involves continuous monitoring and adaptation.
- Crucial for avoiding legal penalties and reputational damage.
- Often requires specific processes for data handling, privacy, and reporting.
Memory trick: Governance is about guiding the ship through legal waters.
ICMP Tunneling
Flip cardA technique that encapsulates IP traffic, or other data, within the data section of ICMP echo request and reply packets to create a covert communication channel.
- Often used for command and control (C2) or data exfiltration.
- Can bypass some firewall rules that permit ICMP traffic.
- Characterized by unusually large or non-standard data in ICMP packets.
Memory trick: Covert channels are like ghosts, hard to see but leave strange traces.
Adherence to Security Procedures
Flip cardThe degree to which an organization consistently follows its documented security processes and guidelines.
- Crucial for maintaining a consistent security posture.
- Often assessed during security audits and compliance reviews.
- Deviation can indicate weaknesses in controls or training.
Memory trick: Audits CHECK for compliance, gaps, and effectiveness.
Incident Response Life Cycle
Flip cardA structured approach to handling and managing the aftermath of a security breach or cyberattack. It aims to minimize damage and recovery time.
- Typically involves several phases.
- Ensures a systematic and efficient response.
- Helps organizations recover quickly and learn from incidents.
Memory trick: Prepare, find, fix, recover, learn, repeat.
Acceptable Use Policy (AUP)
Flip cardA document that outlines the rules and guidelines for how employees or users are permitted to use an organization's IT assets and resources.
- Defines appropriate and inappropriate system usage.
- Helps protect organizational assets from misuse.
- Often includes guidelines for internet and email use.
Memory trick: Guiding behavior is about setting clear rules for action.
Tshark
Flip cardThe command-line network protocol analyzer that is part of the Wireshark suite, used for capturing, displaying, and analyzing packet data from live networks or saved PCAP files.
- Command-line version of Wireshark
- Supports stream reassembly
- Powerful filtering and export capabilities
Memory trick: PCAP Analysis: Tshark for CLI, Wireshark for GUI.
Sysmon Process Create (Event ID 1)
Flip cardSysmon's Event ID 1 logs every process creation, providing extensive details including the executable path, parent process, user, and full command-line arguments.
- Crucial for detecting suspicious process execution.
- Captures full command-line arguments.
- Requires Sysmon to be installed and configured.
Memory trick: Sysmon sees every single system process starting.
Kernel-Level Rootkit Detection
Flip cardDetecting rootkits that modify the operating system kernel, making them extremely difficult to find with standard user-mode tools by comparing the live kernel state to a trusted baseline.
- Rootkits hide their presence from user-mode tools.
- Requires out-of-band or trusted environment analysis.
- Memory analysis and trusted baseline comparisons are key.
Memory trick: Rootkits hide, memory reveals.
Memory Acquisition Forensic Soundness
Flip cardEnsuring that memory acquisition is performed in a way that preserves the integrity and authenticity of the collected digital evidence, making it reliable for forensic investigation.
- Minimize changes to the live system.
- Document every step.
- Verify integrity of acquired data.
Memory trick: Evidence integrity is key for legal certainty.
Linux File Deletion Forensics
Flip cardInvestigating deleted files on Linux by examining file system metadata structures like inode tables and the journal, which can retain information about deleted files even if their data blocks are marked as free.
- Deletion marks blocks as free, doesn't erase data.
- Inode tables store file metadata.
- File system journals record metadata changes.
Memory trick: Deleted files leave behind journal clues and inode identities.
Linux Package Integrity Check
Flip cardUtilities (`rpm -Va`, `dpkg --verify`) used on Linux systems to verify the integrity of installed packages and their constituent files against official package manifests.
- Detects unauthorized modifications to system binaries.
- Compares file attributes, checksums, and permissions.
- Crucial for detecting rootkits and backdoors.
Memory trick: When a Linux system feels 'off', check 'packages', 'connections', or 'permissions', not just a file 'list'.
Auditd Command Logging
Flip cardUsing the Linux Auditing System (auditd) to log specific system calls, such as 'execve', to capture detailed information about command execution, including full command-line arguments, for forensic purposes.
- Captures system calls, not just shell commands.
- Resilient to 'bash_history' clearing.
- Requires specific rules for 'execve' logging.
Memory trick: Auditd logs all commands, even when history is gone.
Linux Audit Logs
Flip cardSystem-level logs on Linux, typically managed by `auditd`, that record detailed information about system calls, file access, and process activity.
- Provides granular forensic data.
- Records user and process actions.
- Configurable to monitor specific events (e.g., file reads, writes, executions).
Memory trick: When a penguin's files go missing, check the 'audit' trail, not just the general 'sys' talk.
Windows Run Keys
Flip cardRegistry keys (`...\CurrentVersion\Run` and `...\CurrentVersion\RunOnce`) that Windows checks during startup or user logon to automatically execute specified programs.
- Common malware persistence mechanism.
- HKLM affects all users, HKCU affects the current user.
- `RunOnce` keys execute only once and are then deleted.
Memory trick: To auto-run, malware goes to the 'Run' keys, either for 'all' or just the 'current' user.
Process Creation Events (EDR)
Flip cardDetailed logs captured by EDR solutions that record when a new process is created, including its parent process, command-line arguments, and user context.
- Crucial for identifying suspicious execution chains.
- Enables detection of living-off-the-land techniques.
- Often includes process hash, user, and execution path.
Memory trick: An EDR needs to 'see' every 'process', 'file', and 'network' move to understand the whole story.
Rootkit Detection Tools
Flip cardSpecialized utilities designed to identify the presence of rootkits on a system by looking for anomalies in system calls, hidden files, processes, or network connections.
- Bypasses standard OS tools.
- Checks for kernel-level manipulations.
- Examples: `chkrootkit`, `rkhunter`.
Memory trick: To find a hidden rootkit, you need a special 'checker', not just the 'standard' process or file views.
Kernel-Mode Rootkit Detection
Flip cardThe process of identifying malicious software operating at the operating system's kernel level, which can hide its presence from user-mode tools.
- Undetectable by user-mode tools
- Manipulates kernel data structures
- Best detected via full memory dump analysis
Memory trick: Kernel ghosts hide deep; only memory's eye can see.
Winlogon Notify Persistence
Flip cardA Windows persistence technique where attackers register a malicious DLL under the Winlogon\Notify Registry key, causing it to be loaded and executed during the logon process.
- Abuses legitimate Winlogon functionality.
- Malicious DLLs loaded upon user logon.
- Provides high-privilege execution.
Memory trick: Registry keys help malware persist and notify Winlogon.
Scheduled Task Persistence
Flip cardA malware persistence technique where malicious code is configured to execute automatically at specific intervals or times using legitimate operating system scheduling features.
- Utilizes Windows Task Scheduler or Linux Cron Jobs.
- Ensures malicious code runs even after reboots.
- Can be used for command and control, data exfiltration, or further infection.
Memory trick: To stay hidden, malware can 'schedule' its reappearance, 'hijack' a path, or 'hide' in plain sight.
Kernel-Mode Rootkit Detection (Memory Forensics)
Flip cardUtilizing memory forensics to analyze a full memory dump for anomalies in kernel structures, loaded modules, and process lists, which can reveal the presence of kernel-mode rootkits.
- Rootkits hide from user-mode tools.
- Memory dumps capture kernel state.
- Volatility Framework is a key analysis tool.
Memory trick: Kernel rootkits hide, but memory reveals all.
Memory Acquisition Tools
Flip cardSoftware used to extract a copy of the contents of a computer's volatile memory (RAM) for forensic analysis.
- Captures live system state.
- Essential for detecting in-memory malware or credential dumps.
- Examples include FTK Imager, DumpIt, WinPMEM.
Memory trick: To catch a digital ghost, you need specific tools: one for 'memory', one for 'network', one for 'scanning'.
dpkg --verify
Flip cardA command on Debian-based Linux systems used to check the integrity of installed packages by comparing files against their known good state.
- Compares file checksums
- Identifies unauthorized modifications
- Specific to Debian/Ubuntu systems
Memory trick: Debian's dpkg verifies package purity.
File Integrity Monitoring (FIM)
Flip cardA security control that monitors critical system and application files for unauthorized changes by comparing their current state (e.g., hashes) to a known good baseline.
- Detects tampering with executables, configurations.
- Uses cryptographic hashes for integrity checks.
- Alerts on deviations from a baseline.
Memory trick: Integrity monitoring keeps files as they should be.
LOLBIN Command Line Analysis
Flip cardAnalyzing the command-line arguments of legitimate system binaries (LOLBINs) to detect malicious usage, often facilitated by detailed process creation logs like Sysmon Event ID 1.
- LOLBINs are legitimate tools used maliciously.
- Command-line arguments reveal their specific malicious function.
- Sysmon Event ID 1 is ideal for capturing this detail.
Memory trick: LOLBINs hide in plain sight, command lines tell the tale.
Process Memory Dump
Flip cardA snapshot of the memory space used by a specific running process at a given time, essential for detailed malware analysis and forensic investigations.
- Captures injected code and hidden modules
- Analyzed offline with specialized tools
- Tools: Process Explorer, procdump
Memory trick: To see inside, dump the process mind.
PowerShell Operational Log
Flip cardA specific Windows Event Log channel (`Microsoft-Windows-PowerShell/Operational`) that records detailed activities of the PowerShell engine, including script block logging.
- Records full script content and arguments.
- Crucial for detecting and analyzing PowerShell-based attacks.
- Requires specific configuration for full script block logging.
Memory trick: When PowerShell goes rogue, look directly at its 'operational' journal, not just the general 'security' or 'system' diaries.
Behavioral Analysis (Endpoint Security)
Flip cardAn endpoint security technique that monitors the actions and patterns of processes and users on a host, looking for deviations from normal behavior to detect unknown or zero-day threats.
- Effective against zero-day and fileless malware.
- Uses heuristics, machine learning, or AI.
- Focuses on 'how' a program acts, not 'what' it is.
Memory trick: To protect an endpoint, you need to 'scan' for known threats, 'control' traffic, and 'watch' for weird behavior.
Dynamic Malware Analysis
Flip cardThe process of executing suspicious code in a controlled environment (sandbox) to observe its behavior and understand its functionality.
- Observes real-time execution.
- Identifies network communication, file system changes, registry modifications.
- Performed in an isolated environment to prevent infection.
Memory trick: To catch a sneaky bug, you either dissect it still or watch it run free (but safely!).
LOLBIN Command Line Auditing
Flip cardThe practice of configuring endpoint logging to capture the full command-line arguments of executed processes to detect the malicious use of legitimate system binaries (LOLBINs).
- Crucial for detecting LOLBIN misuse
- Requires 'Audit Process Creation' (Event ID 4688)
- Captures full command-line arguments
Memory trick: To catch the LOLBIN, you must read its full command line story.
Windows Service Persistence
Flip cardMalware can achieve persistence on a Windows system by creating or modifying service entries in the Registry, ensuring its execution upon system startup.
- Services automatically start with the system.
- Registry key HKLM\SYSTEM\CurrentControlSet\Services stores service configurations.
- Unusual service entries can indicate malware.
Memory trick: Many malware make systems start services.
LD_PRELOAD Abuse Detection
Flip cardDetecting malicious use of LD_PRELOAD, which forces a process to load a specified shared library before any others, often used by attackers for rootkit-like functionality or privilege escalation.
- LD_PRELOAD can be global or per-process.
- Allows interception of system calls.
- Revealed by examining a process's loaded libraries.
Memory trick: Libraries can be preloaded; 'lsof' shows the load.
Sysinternals Process Explorer
Flip cardA free utility from Microsoft that provides advanced process management and analysis capabilities for Windows operating systems.
- Displays hierarchical process tree
- Shows loaded DLLs and handles
- Can identify hidden or injected code
Memory trick: Process Explorer is your magnifying glass for Windows processes.
File Hash Integrity Check
Flip cardThe process of comparing the cryptographic hash of a file to a known good hash value to detect unauthorized modifications or corruption.
- Essential for detecting tampering and malware.
- Often performed by File Integrity Monitoring (FIM) systems.
- Any mismatch indicates a change to the file.
Memory trick: A HIDS screams if a 'file' changes, a 'process' acts weird, or a 'log' looks fishy.
Live System Analysis (Linux)
Flip cardExamining a running Linux system to gather real-time data about processes, network connections, and open files without stopping or altering critical system functions.
- Focuses on volatile data.
- Uses commands like 'ps', 'netstat', 'lsof', 'ss'.
- Aims to understand current system state and ongoing activities.
Memory trick: Linux live investigations look for active system states.
Certutil.exe Misuse
Flip cardThe malicious use of the legitimate Windows `certutil.exe` utility, typically for downloading files from the internet or encoding/decoding data, as a 'living off the land' technique.
- Bypasses traditional security controls.
- Used for file download, base64 encoding/decoding.
- Relies on specific command-line arguments.
Memory trick: Attackers use Windows' own 'utilities' like 'Certutil', 'PowerShell', or 'WMIC' to do their dirty work.
UDP Flood Attack
Flip cardA denial-of-service (DoS) attack that overwhelms a target system by flooding it with a large volume of User Datagram Protocol (UDP) packets.
- Uses connectionless UDP protocol.
- Often targets random ports to exhaust resources generating ICMP responses.
- Can be amplified using reflection techniques.
Memory trick: Many types of floods, but only UDP brings the 'unreachable' tide.