← All CSS Flashcard Decks

Threat Detection & Prevention Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Detection & Prevention flashcards as text
  1. Which network anomaly detection approach establishes normal traffic patterns first and then alerts on deviations?

    Answer: Baseline behavioral analytics

    Baseline behavioral analytics profiles normal activity over time and generates alerts when observed behavior significantly deviates from the established baseline.

  2. An attacker uses Living-off-the-Land (LotL) techniques. Which detection approach is MOST effective against this?

    Answer: Behavioral monitoring of legitimate system tools like PowerShell and WMI

    LotL attacks abuse built-in OS tools, so behavioral monitoring of how those tools are used (unusual parent processes, encoded commands) is more effective than signature scanning.

  3. What is the primary advantage of using threat intelligence feeds in a prevention strategy?

    Answer: They provide context and indicators of compromise to proactively block known malicious infrastructure

    Threat intelligence feeds supply actionable IOCs (IPs, domains, hashes) and context that enable proactive blocking before attacks reach the organization.

  4. During incident triage, an analyst finds an outbound connection to an IP on a threat intelligence blacklist. Before blocking, what should the analyst verify?

    Answer: Whether the IP could be a shared hosting or CDN address used by legitimate services

    Blacklisted IPs are sometimes shared infrastructure used by both malicious and legitimate services, so blindly blocking can cause unintended outages.

  5. Which technique is used to detect command-and-control traffic that blends into normal HTTPS traffic?

    Answer: TLS/SSL traffic analysis using JA3 fingerprinting and certificate anomaly detection

    JA3 fingerprinting creates a hash of TLS handshake parameters to identify malicious clients even when traffic is encrypted, without decrypting the payload.

  6. A SIEM correlation rule fires when five failed logins are followed by a successful login within 10 minutes from the same source IP. What attack is this rule designed to detect?

    Answer: Brute force or password spraying leading to account compromise

    This pattern — multiple failures then a success — is the classic signature of a brute force or credential stuffing attack that eventually guesses the correct password.

  7. Which prevention control MOST effectively reduces the risk from zero-day exploits targeting browser vulnerabilities?

    Answer: Using browser isolation technology that renders web content in a sandboxed remote environment

    Browser isolation executes web content in a remote sandbox, so zero-day exploits cannot reach the endpoint even if the browser is compromised.