โ† All CCP Flashcard Decks

SIEM & Threat Detection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 SIEM & Threat Detection flashcards as text
  1. What is 'log normalization' and why is it critical for SIEM effectiveness?

    Answer: Converting logs from various formats into a consistent schema so correlation rules can work across all sources

    Log normalization converts heterogeneous log formats into a standard schema, enabling correlation rules to reference consistent field names regardless of the originating source.

  2. An organization's SIEM detects an internal host communicating with a known Tor exit node. What is the most likely security concern?

    Answer: Data exfiltration or C2 communication being tunneled through Tor to evade detection

    Internal systems communicating with Tor exit nodes most commonly indicate malware using Tor for anonymous C2 communications or an insider exfiltrating data through an anonymization network.

  3. What is the purpose of the 'kill chain' model in threat detection?

    Answer: To map adversary attack stages so defenders can detect and disrupt attacks at multiple points

    The cyber kill chain model maps adversary progression from reconnaissance to exfiltration, enabling defenders to identify detection opportunities at each stage before objectives are achieved.

  4. Which SIEM tuning approach reduces false positives without increasing false negatives?

    Answer: Whitelisting known-good activity while refining detection logic based on environmental context

    Whitelisting verified legitimate activity (like scheduled maintenance scripts or known admin accounts) reduces false positives while preserving detection capability for genuine threats.

  5. What does the MITRE ATT&CK technique T1055 (Process Injection) help an attacker achieve?

    Answer: Evading defenses and escalating privileges by running code within the context of another process

    Process injection allows attackers to execute malicious code within the memory space of a legitimate process, inheriting its privileges and evading process-based security controls.

  6. Which log source is essential for detecting DNS-based data exfiltration?

    Answer: DNS query and response logs showing unusually large TXT record queries or high-entropy subdomains

    DNS exfiltration encodes data in DNS queries (often as long, high-entropy subdomains or TXT record lookups), making DNS server query logs the primary detection source.

  7. What is 'threat hunting' and how does it differ from reactive SIEM alerting?

    Answer: Threat hunting is a proactive, hypothesis-driven search for hidden threats; SIEM alerting is reactive and triggered by predefined rules

    Threat hunting proactively searches for stealthy adversaries that evade automated detection by forming hypotheses and manually querying data; SIEM alerts reactively fire on pre-defined conditions.