โ† All CCP Flashcard Decks

SIEM & Threat Detection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 SIEM & Threat Detection flashcards as text
  1. Which SIEM component is responsible for normalizing log data from disparate sources into a common format?

    Answer: Data normalization parser

    Data normalization parsers translate raw logs from different formats (syslog, Windows Event Log, JSON) into a unified schema for consistent analysis.

  2. An analyst notices thousands of failed SSH login attempts from a single IP, followed by one successful login. What attack stage does this most likely represent?

    Answer: Brute force attack culminating in successful authentication

    Many failed logins followed by one success is the classic signature of a brute force attack where the attacker eventually guesses the correct password.

  3. What is the purpose of a SIEM use case library?

    Answer: To define pre-built detection rules and alert logic for known attack patterns

    A use case library contains pre-built detection logic, correlation rules, and alert thresholds mapped to known attack techniques, accelerating threat detection.

  4. Which metric measures the percentage of actual threats correctly identified by a detection system?

    Answer: Recall (sensitivity)

    Recall (sensitivity) measures the ratio of true positives to all actual positive cases, indicating how many real threats the system successfully detects.

  5. A SIEM rule triggers an alert every time a user accesses more than 50 files within 5 minutes. What type of detection logic is this?

    Answer: Anomaly threshold detection

    Triggering on a fixed count threshold (50 files in 5 minutes) is anomaly threshold detection, which flags activity exceeding defined limits.

  6. What does 'event enrichment' mean in the context of SIEM?

    Answer: Adding contextual information (e.g., geolocation, asset criticality) to raw events

    Event enrichment adds contextual metadata such as user identity, asset ownership, geolocation, or threat intelligence data to raw log events, improving analyst decision-making.

  7. Which MITRE ATT&CK tactic involves adversaries trying to steal credentials to gain further access?

    Answer: Credential Access

    The Credential Access tactic in MITRE ATT&CK covers techniques adversaries use to steal account names and passwords, such as keylogging or credential dumping.