Threat Detection & Prevention Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Detection & Prevention flashcards as text
Which behavioral indicator is MOST characteristic of a slow-and-low attack designed to evade detection thresholds?
Answer: Distributed low-frequency requests spread over days or weeks
Slow-and-low attacks deliberately spread malicious activity over extended time periods to stay below detection thresholds and avoid triggering alerts.
A security analyst notices DNS queries to randomly generated domain names at regular intervals from a workstation. This pattern MOST likely indicates:
Answer: Domain Generation Algorithm (DGA) malware communicating with a C2 server
DGA malware generates pseudo-random domain names to locate C2 servers, making it harder to block by blacklisting static domains.
Which prevention control BEST addresses the risk of credential stuffing attacks against web applications?
Answer: Implementing rate limiting combined with CAPTCHA and breached-password detection
Combining rate limiting, CAPTCHA, and checking credentials against known breach databases directly counters automated credential stuffing.
What does the 'dwell time' metric measure in the context of threat detection?
Answer: Duration between initial compromise and detection of an attacker
Dwell time measures how long an attacker remains undetected in an environment after initial compromise, a key indicator of detection effectiveness.
An IDS generates an alert for a known exploit signature, but investigation reveals no actual attack occurred. This is classified as a:
Answer: False positive
A false positive occurs when a detection system triggers an alert for benign activity that matches a malicious pattern, wasting analyst time.
Which technique does a next-generation firewall (NGFW) use that a traditional stateful firewall does NOT?
Answer: Application-layer deep packet inspection and user identity awareness
NGFWs add application-layer (Layer 7) inspection and can enforce policies based on application type and user identity, beyond what stateful firewalls provide.
When deploying honeypots for threat detection, what is the PRIMARY security concern to address?
Answer: Attackers could pivot from the honeypot to compromise production systems
Poorly isolated honeypots can be used as launch pads by attackers to reach production systems, so strict network segmentation is essential.