Security Operations & Administration Flashcards
9 cards from real SSCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Security Operations & Administration flashcards as text
Which of the following is a key responsibility of a security operations center (SOC)?
Answer: Incident detection and response
A Security Operations Center (SOC) is a centralized unit responsible for continuously monitoring and improving an organization's security posture. Its primary function is incident detection and response, which involves identifying, analyzing, and mitigating cybersecurity threats and breaches promptly.
What is the purpose of a security baseline?
Answer: To ensure consistent security configuration
The purpose of a security baseline is to define a minimum set of security configurations and practices that must be applied to systems and applications. This ensures consistent security configuration across an organization's IT environment, establishing a secure starting point and reducing vulnerabilities.
Which process involves reviewing and analyzing logs for unusual or suspicious activity?
Answer: Log review
Log review is the process of systematically examining system-generated records for unusual or suspicious activity. This proactive measure helps identify potential security breaches, policy violations, or operational issues that might otherwise go unnoticed, allowing for timely investigation and remediation.
Which principle is emphasized by regular system updates and patching?
Answer: Vulnerability management
Regular system updates and patching are fundamental to vulnerability management. This process involves identifying, assessing, and remediating security weaknesses in software and systems to protect against known exploits and maintain a strong security posture, thereby reducing the risk of successful attacks.
Which document outlines the procedures for responding to cybersecurity incidents?
Answer: Incident response plan
An incident response plan (IRP) is a crucial document that provides a structured approach for an organization to prepare for, detect, contain, eradicate, recover from, and learn from cybersecurity incidents. It outlines specific roles, responsibilities, communication protocols, and technical procedures to minimize damage and restore normal operations efficiently. Without a well-defined IRP, an organization may react chaotically, leading to greater losses during a security breach.
What is the primary goal of a change management process in security operations?
Answer: To control system updates and minimize risk
The primary goal of a change management process in security operations is to ensure that all modifications to systems, applications, or configurations are performed in a controlled, documented, and tested manner. This structured approach helps prevent unintended security vulnerabilities, system downtime, or operational disruptions that could arise from poorly managed changes. By minimizing these risks, change management maintains system stability and security posture.
Which of the following tools helps detect unauthorized system changes?
Answer: File integrity monitoring
File integrity monitoring (FIM) tools are designed to detect unauthorized or unexpected changes to critical system files, configuration files, and content files. By creating a baseline of known good states and continuously comparing current states against it, FIM can alert administrators to potential tampering, malware infections, or misconfigurations. This helps maintain system security and compliance.
What is a common outcome of failing to rotate logs regularly?
Answer: Loss of critical security data
Failing to rotate logs regularly can lead to log files growing excessively large, potentially overwriting older, critical security data. This loss of historical data can severely hinder incident investigations, forensic analysis, and compliance auditing, making it difficult to understand past events or detect persistent threats. Proper log rotation ensures that valuable security information is retained and accessible.
Why are standard operating procedures (SOPs) important in security operations?
Answer: They enable consistent and effective responses
Standard Operating Procedures (SOPs) are vital in security operations because they provide clear, step-by-step instructions for performing routine tasks and responding to incidents. This standardization ensures that all personnel follow the same best practices, leading to consistent, efficient, and effective actions regardless of who is performing the task. SOPs reduce errors, improve training, and enhance overall security posture.