Threat Detection & Prevention Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Detection & Prevention flashcards as text
Which MITRE ATT&CK tactic describes an adversary's efforts to avoid detection after gaining initial access?
Answer: Defense Evasion
Defense Evasion is the ATT&CK tactic covering techniques adversaries use to avoid detection and bypass security controls during an intrusion.
A security team wants to detect attackers performing internal reconnaissance after a breach. Which control is MOST effective?
Answer: Internal network traffic monitoring and east-west traffic analysis
Monitoring east-west (lateral) traffic within the network is critical for detecting internal reconnaissance since perimeter controls miss activity already inside.
What is the purpose of a Security Orchestration, Automation, and Response (SOAR) platform in threat prevention?
Answer: To automate repetitive investigation tasks and coordinate responses across security tools
SOAR platforms automate routine tasks like alert triage and tool coordination, freeing analysts to focus on complex investigations.
Which indicator would MOST strongly suggest a watering hole attack is in progress?
Answer: Multiple employees from the same organization infected after visiting a legitimate industry website
Watering hole attacks compromise websites frequently visited by a target group, so multiple victims from the same org infected via the same legitimate site is the telltale sign.
In threat detection, what does 'threat hunting' differ from automated monitoring in that it:
Answer: Is a proactive, hypothesis-driven search for hidden threats that evaded automated controls
Threat hunting is an active, analyst-led process starting from hypotheses about potential attacker behavior, not waiting for automated alerts.
A company deploys an allowlist (whitelist) application control policy. Which threat does this MOST effectively prevent?
Answer: Execution of unauthorized or malicious software on endpoints
Application allowlisting prevents unauthorized software from executing by only permitting explicitly approved applications to run on endpoints.
Which log source is MOST valuable for detecting pass-the-hash attacks in a Windows Active Directory environment?
Answer: Windows Security Event logs (Event IDs 4624, 4625, 4648)
Windows Security Event logs capture authentication events including logon type 3 with NTLM, which is characteristic of pass-the-hash lateral movement.