1
00:00:06,480 --> 00:00:07,980
- Welcome to lesson 17,

2
00:00:07,980 --> 00:00:09,510
deep dive quiz.

3
00:00:09,510 --> 00:00:12,780
Now, lesson 17 was all about
explaining security alerting

4
00:00:12,780 --> 00:00:15,140
and monitoring concepts and tools.

5
00:00:15,140 --> 00:00:16,470
In 17.1,

6
00:00:16,470 --> 00:00:18,390
we looked at logging and analysis.

7
00:00:18,390 --> 00:00:20,340
And then in 17.2,

8
00:00:20,340 --> 00:00:23,430
we took a really deep look at SNMP,

9
00:00:23,430 --> 00:00:24,390
NetFlow

10
00:00:24,390 --> 00:00:25,650
and SCAP.

11
00:00:25,650 --> 00:00:28,140
So now we're gonna do a
five question quiz together.

12
00:00:28,140 --> 00:00:30,510
Make sure you've got a pen or
pencil and some paper, right?

13
00:00:30,510 --> 00:00:32,610
Put me on pause as often as you need.

14
00:00:32,610 --> 00:00:34,740
I really want you to be
answering these questions.

15
00:00:34,740 --> 00:00:35,573
So you ready?

16
00:00:35,573 --> 00:00:36,423
Let's get started.

17
00:00:38,327 --> 00:00:42,690
We wanna determine if the
statements are true or false.

18
00:00:42,690 --> 00:00:45,180
Indicators of attack are artifacts

19
00:00:45,180 --> 00:00:48,090
about events that have already happened.

20
00:00:48,090 --> 00:00:51,060
Indicators of compromise
are observable behaviors

21
00:00:51,060 --> 00:00:52,083
or actions.

22
00:00:53,040 --> 00:00:54,810
Automation is the integration

23
00:00:54,810 --> 00:00:57,360
of disparate tools and platforms.

24
00:00:57,360 --> 00:01:01,080
Orchestration is the ability
to execute a series of tasks

25
00:01:01,080 --> 00:01:03,450
without human intervention.

26
00:01:03,450 --> 00:01:06,660
So we have four statements, right?

27
00:01:06,660 --> 00:01:09,360
We wanna decide each one
if they're true or false.

28
00:01:09,360 --> 00:01:10,320
Go ahead and put me on pause

29
00:01:10,320 --> 00:01:12,780
if you want while you think about it.

30
00:01:12,780 --> 00:01:15,030
And so indicators of
attack are about an event

31
00:01:15,030 --> 00:01:17,250
that has already happened.

32
00:01:17,250 --> 00:01:19,980
I'm gonna say that that is false.

33
00:01:19,980 --> 00:01:22,770
Indicators of an attack
are really telling us

34
00:01:22,770 --> 00:01:24,450
that something is happening

35
00:01:24,450 --> 00:01:26,400
or about to happen.

36
00:01:26,400 --> 00:01:29,250
Indicators of compromise
are observable behaviors

37
00:01:29,250 --> 00:01:30,390
or actions.

38
00:01:30,390 --> 00:01:32,370
That's really what an
indicator of an attack is.

39
00:01:32,370 --> 00:01:35,580
Matter of fact, indicator of
attack definition above, right,

40
00:01:35,580 --> 00:01:37,890
was really more indicator of compromise.

41
00:01:37,890 --> 00:01:40,320
It's about an event that
has already happened.

42
00:01:40,320 --> 00:01:42,633
So I'm gonna say that
one is false as well.

43
00:01:44,430 --> 00:01:46,350
Automation is the integration

44
00:01:46,350 --> 00:01:49,110
of disparate tools and platforms.

45
00:01:49,110 --> 00:01:50,373
Is that true or false?

46
00:01:51,840 --> 00:01:53,013
That is not true.

47
00:01:54,720 --> 00:01:55,980
So that's gonna be false.

48
00:01:55,980 --> 00:01:57,480
'Cause what is automation?

49
00:01:57,480 --> 00:01:59,190
Automation really is the ability

50
00:01:59,190 --> 00:02:01,230
to execute a series of tasks

51
00:02:01,230 --> 00:02:03,630
without human intervention.

52
00:02:03,630 --> 00:02:06,240
So that really should help
us out on our last one.

53
00:02:06,240 --> 00:02:07,350
Orchestration is the ability

54
00:02:07,350 --> 00:02:08,730
to execute a series of tasks

55
00:02:08,730 --> 00:02:10,530
without human intervention.

56
00:02:10,530 --> 00:02:11,970
That's gonna be false

57
00:02:11,970 --> 00:02:13,740
because orchestration

58
00:02:13,740 --> 00:02:18,030
is the integration of
disparate tools and platforms.

59
00:02:18,030 --> 00:02:19,410
So in both cases,

60
00:02:19,410 --> 00:02:21,270
on our indicators of attack and compromise

61
00:02:21,270 --> 00:02:23,340
we swap the definitions.

62
00:02:23,340 --> 00:02:25,050
And in automation and orchestration,

63
00:02:25,050 --> 00:02:27,870
we would need to swap
the definitions as well.

64
00:02:27,870 --> 00:02:30,480
You agree that they're
all false statements?

65
00:02:30,480 --> 00:02:31,383
Let's check.

66
00:02:32,310 --> 00:02:33,610
And that would be correct.

67
00:02:36,330 --> 00:02:38,430
All right, logs are a
critical data source.

68
00:02:38,430 --> 00:02:40,110
What we're gonna do here in question two

69
00:02:40,110 --> 00:02:43,020
is we're gonna match the
log analysis technique.

70
00:02:43,020 --> 00:02:45,840
So down the left hand
side, we have normalization

71
00:02:45,840 --> 00:02:47,220
deduplication,

72
00:02:47,220 --> 00:02:48,480
correlation,

73
00:02:48,480 --> 00:02:50,400
and aggregation.

74
00:02:50,400 --> 00:02:51,570
On the right hand side,

75
00:02:51,570 --> 00:02:53,100
we really have the description right,

76
00:02:53,100 --> 00:02:54,960
relating log entries,

77
00:02:54,960 --> 00:02:56,850
consolidating log entries,

78
00:02:56,850 --> 00:02:58,980
removing duplicate entries

79
00:02:58,980 --> 00:03:01,470
or standardizing log details.

80
00:03:01,470 --> 00:03:04,370
Put me on pause, you can take
a moment and match these up.

81
00:03:05,550 --> 00:03:08,070
All right, well, starting
with normalization.

82
00:03:08,070 --> 00:03:11,040
Normalization is when
we standardize, right?

83
00:03:11,040 --> 00:03:13,233
So it's standardizing our log details.

84
00:03:14,400 --> 00:03:15,600
Deduplication.

85
00:03:15,600 --> 00:03:17,700
Well, that's gonna be
getting rid of duplicates

86
00:03:17,700 --> 00:03:20,073
or removing duplicate entries.

87
00:03:20,910 --> 00:03:21,840
Correlation.

88
00:03:21,840 --> 00:03:23,310
Well, when we correlate something

89
00:03:23,310 --> 00:03:25,380
whether it's logs or anything else, right?

90
00:03:25,380 --> 00:03:27,390
We're relating some to things.

91
00:03:27,390 --> 00:03:31,350
So correlation would be
relating our log entries

92
00:03:31,350 --> 00:03:34,110
and aggregation is when we
put things together, right?

93
00:03:34,110 --> 00:03:37,110
So that would be
consolidating our log entries.

94
00:03:37,110 --> 00:03:38,220
So normalization,

95
00:03:38,220 --> 00:03:40,020
standardizing log details.

96
00:03:40,020 --> 00:03:43,080
Deduplication, removing duplicate entries.

97
00:03:43,080 --> 00:03:44,340
Correlation,

98
00:03:44,340 --> 00:03:46,050
relating log entries

99
00:03:46,050 --> 00:03:48,990
and aggregation,
consolidating log entries.

100
00:03:48,990 --> 00:03:50,460
Do you like it? You agree?

101
00:03:50,460 --> 00:03:51,840
We'll check.

102
00:03:51,840 --> 00:03:53,460
And that is correct.

103
00:03:53,460 --> 00:03:54,840
All right, let's go to question three.

104
00:03:54,840 --> 00:03:56,640
Another matching.

105
00:03:56,640 --> 00:03:58,710
This time we're gonna
match the automation tool

106
00:03:58,710 --> 00:04:00,330
and its description.

107
00:04:00,330 --> 00:04:01,260
On the left hand

108
00:04:01,260 --> 00:04:02,790
we have SIEM,

109
00:04:02,790 --> 00:04:03,690
TIP,

110
00:04:03,690 --> 00:04:05,010
UEBA

111
00:04:05,010 --> 00:04:06,780
and SOAR.

112
00:04:06,780 --> 00:04:07,860
On the right hand side,

113
00:04:07,860 --> 00:04:10,650
combines multiple threat
intelligence feeds,

114
00:04:10,650 --> 00:04:13,770
models the behavior of
humans and machines,

115
00:04:13,770 --> 00:04:16,320
real-time data capture and analysis

116
00:04:16,320 --> 00:04:19,500
or responds to alerts and takes action.

117
00:04:19,500 --> 00:04:20,760
Yeah, let's change it up a little bit.

118
00:04:20,760 --> 00:04:23,310
We'll start on the right
hand side this time.

119
00:04:23,310 --> 00:04:26,163
Combines multiple threat
intelligence feeds.

120
00:04:27,900 --> 00:04:29,163
Well, I like,

121
00:04:30,480 --> 00:04:32,220
TIP, right?

122
00:04:32,220 --> 00:04:33,053
Why TIP?

123
00:04:33,053 --> 00:04:35,403
TIP is our threat intelligence platform.

124
00:04:36,870 --> 00:04:38,490
Next up, we have up on top now,

125
00:04:38,490 --> 00:04:41,853
models the behavior of
humans and machines.

126
00:04:43,050 --> 00:04:45,720
I'm gonna choose UEBA.

127
00:04:45,720 --> 00:04:48,720
User and Entity Behavioral Analytics.

128
00:04:48,720 --> 00:04:49,830
Okay, up on top now,

129
00:04:49,830 --> 00:04:52,410
we have realtime data
capture and analysis.

130
00:04:52,410 --> 00:04:54,763
Well, that's gonna be
our SIEM or our SIEM.

131
00:04:55,980 --> 00:04:58,470
And down at the bottom we
have response to alerts

132
00:04:58,470 --> 00:04:59,820
and takes actions.

133
00:04:59,820 --> 00:05:01,383
That's gonna be our SOAR.

134
00:05:03,000 --> 00:05:03,930
So I didn't really pause

135
00:05:03,930 --> 00:05:05,040
and give you time to pause

136
00:05:05,040 --> 00:05:05,970
but I hope that you did

137
00:05:05,970 --> 00:05:07,590
and so you could match this.

138
00:05:07,590 --> 00:05:08,460
But let's go through these,

139
00:05:08,460 --> 00:05:11,820
SIEM, real-time data capture and analysis.

140
00:05:11,820 --> 00:05:14,760
A TIP combines multiple
threat intelligence feeds.

141
00:05:14,760 --> 00:05:16,950
UEBA models the behavior of humans

142
00:05:16,950 --> 00:05:17,850
and machines

143
00:05:17,850 --> 00:05:21,660
and SOAR responds to
alerts and takes action.

144
00:05:21,660 --> 00:05:22,493
Agree?

145
00:05:22,493 --> 00:05:23,343
Let's check.

146
00:05:24,240 --> 00:05:25,533
And we are correct.

147
00:05:27,450 --> 00:05:30,240
Blank is a suite of open standards

148
00:05:30,240 --> 00:05:32,670
for communicating security flaws

149
00:05:32,670 --> 00:05:35,220
and configuration information.

150
00:05:35,220 --> 00:05:37,200
Is this a CVE,

151
00:05:37,200 --> 00:05:38,640
ISCM,

152
00:05:38,640 --> 00:05:39,780
SCAP

153
00:05:39,780 --> 00:05:44,010
or DOD 5220.22M?

154
00:05:44,010 --> 00:05:46,020
This is a suite of open standards

155
00:05:46,020 --> 00:05:48,240
for communicating security flaws

156
00:05:48,240 --> 00:05:50,193
and configuration information.

157
00:05:51,870 --> 00:05:53,970
Go ahead and make your choice.

158
00:05:53,970 --> 00:05:56,243
Put me on pause if you
need to think about it.

159
00:05:57,300 --> 00:05:59,670
Well, I'm gonna choose SCAP.

160
00:05:59,670 --> 00:06:02,820
SCAP is going to be my
suite of open standards

161
00:06:02,820 --> 00:06:03,690
or my protocols

162
00:06:03,690 --> 00:06:05,670
for communicating security flaws

163
00:06:05,670 --> 00:06:08,610
and configuration information.

164
00:06:08,610 --> 00:06:09,450
CVE.

165
00:06:09,450 --> 00:06:11,580
Remember, that's a common
vulnerability and exposure.

166
00:06:11,580 --> 00:06:13,230
So that would be very specific.

167
00:06:13,230 --> 00:06:15,100
ISCM actually stands for

168
00:06:16,290 --> 00:06:19,351
Information Security Continuous Monitoring

169
00:06:19,351 --> 00:06:21,570
and DOD 5220.22M.

170
00:06:21,570 --> 00:06:22,920
Where do we see that?

171
00:06:22,920 --> 00:06:24,270
We saw that one when we were looking

172
00:06:24,270 --> 00:06:26,583
at disc wiping and sanitation.

173
00:06:27,750 --> 00:06:29,520
So I'm gonna go with SCAP.

174
00:06:29,520 --> 00:06:31,080
You like it?

175
00:06:31,080 --> 00:06:33,360
Let's see, and that is correct.

176
00:06:33,360 --> 00:06:34,923
All right, our last question.

177
00:06:35,880 --> 00:06:39,210
Your organization has been
experiencing internet access

178
00:06:39,210 --> 00:06:41,730
bottlenecks and latency.

179
00:06:41,730 --> 00:06:44,733
Which set of troubleshooting
tools would you choose?

180
00:06:45,870 --> 00:06:48,390
SNMP and SCAP.

181
00:06:48,390 --> 00:06:50,400
NetFlow and SCAP.

182
00:06:50,400 --> 00:06:52,530
NetFlow and SNMP.

183
00:06:52,530 --> 00:06:54,363
Or SOAR and SIM.

184
00:06:55,230 --> 00:06:59,220
So we've got internet access
bottlenecks and latency.

185
00:06:59,220 --> 00:07:02,280
So which two tools was
gonna make the most sense,

186
00:07:02,280 --> 00:07:04,410
SNMP and SCAP,

187
00:07:04,410 --> 00:07:05,997
NetFlow and SCAP,

188
00:07:05,997 --> 00:07:07,830
NetFlow and SNMP,

189
00:07:07,830 --> 00:07:10,050
or SOAR and SIM?

190
00:07:10,050 --> 00:07:12,450
You put me on pause while
you think about these.

191
00:07:14,430 --> 00:07:16,590
Well, because the issue
really is bottlenecks

192
00:07:16,590 --> 00:07:18,180
and latency, right?

193
00:07:18,180 --> 00:07:21,540
The flow of data and how
devices are operating.

194
00:07:21,540 --> 00:07:24,903
I'm gonna choose NetFlow and SNMP.

195
00:07:25,950 --> 00:07:26,850
You like that one?

196
00:07:26,850 --> 00:07:28,560
Let's check.

197
00:07:28,560 --> 00:07:30,090
And that's correct.

198
00:07:30,090 --> 00:07:31,260
Well, congratulations.

199
00:07:31,260 --> 00:07:32,850
Another great job.

200
00:07:32,850 --> 00:07:33,990
So what's up next?

201
00:07:33,990 --> 00:07:35,850
We're gonna go into lesson 18.

202
00:07:35,850 --> 00:07:37,290
Given a scenario,

203
00:07:37,290 --> 00:07:41,070
modify enterprise capabilities
to enhance security.

204
00:07:41,070 --> 00:07:42,020
I'll see you there.
