1
00:00:06,510 --> 00:00:10,020
- Welcome to Lesson 22: Deep Dive Quiz.

2
00:00:10,020 --> 00:00:12,060
In lesson 22 we talked about

3
00:00:12,060 --> 00:00:14,580
Given a Scenario, Using Data Sources

4
00:00:14,580 --> 00:00:16,380
to Support an Investigation

5
00:00:16,380 --> 00:00:19,020
and we only had one lesson, 22.1,

6
00:00:19,020 --> 00:00:21,330
which was all about data sources.

7
00:00:21,330 --> 00:00:23,670
So let's do five questions together.

8
00:00:23,670 --> 00:00:25,980
Make sure you've got your
pen, your pencil, your paper,

9
00:00:25,980 --> 00:00:27,750
put me on pause as often as you need to

10
00:00:27,750 --> 00:00:29,220
even if I don't even prompt you to

11
00:00:29,220 --> 00:00:30,240
and I forget to do that.

12
00:00:30,240 --> 00:00:32,100
Put me on, you know, don't
forget to put me on pause

13
00:00:32,100 --> 00:00:33,450
when you want to.

14
00:00:33,450 --> 00:00:34,293
Let's get going.

15
00:00:36,570 --> 00:00:38,910
Packet captures a process of intercepting

16
00:00:38,910 --> 00:00:41,370
and logging traffic for analysis.

17
00:00:41,370 --> 00:00:44,880
This packet capture mode
accepts any frame it captures,

18
00:00:44,880 --> 00:00:47,760
even if not the intended recipient.

19
00:00:47,760 --> 00:00:49,950
We had this question in
our three-second challenge,

20
00:00:49,950 --> 00:00:51,720
so I'm sure you're gonna get it.

21
00:00:51,720 --> 00:00:55,443
Is this normal, unfiltered,
promiscuous, or filtered?

22
00:00:56,460 --> 00:00:59,370
The packet capture mode
accepts any frame it captures,

23
00:00:59,370 --> 00:01:01,440
even if not the intended recipient.

24
00:01:01,440 --> 00:01:03,030
What's it gonna be?

25
00:01:03,030 --> 00:01:04,170
Yeah, for sure.

26
00:01:04,170 --> 00:01:05,310
It's promiscuous.

27
00:01:05,310 --> 00:01:07,050
Let's double check.

28
00:01:07,050 --> 00:01:08,133
And that's correct.

29
00:01:09,180 --> 00:01:10,800
The type of vulnerability scan

30
00:01:10,800 --> 00:01:13,470
that can identify rogue access points,

31
00:01:13,470 --> 00:01:17,310
SSID broadcasts, and weak protocols.

32
00:01:17,310 --> 00:01:22,083
Network, wireless,
application or host-base.

33
00:01:23,700 --> 00:01:24,750
What do you like?

34
00:01:24,750 --> 00:01:28,530
Rogue access points, SSID
broadcast, and weak protocols.

35
00:01:28,530 --> 00:01:30,120
That's gotta be what?

36
00:01:30,120 --> 00:01:32,250
Absolutely, that's wireless.

37
00:01:32,250 --> 00:01:33,720
Let's double check,

38
00:01:33,720 --> 00:01:35,670
and that's correct.

39
00:01:35,670 --> 00:01:37,290
All right, question three.

40
00:01:37,290 --> 00:01:41,040
You're investigating a DoS
attack, denial of service attack.

41
00:01:41,040 --> 00:01:43,440
It appears that traffic
is being redirected

42
00:01:43,440 --> 00:01:46,680
from other internet domains to your site.

43
00:01:46,680 --> 00:01:50,700
Which type of log would
likely be the most useful?

44
00:01:50,700 --> 00:01:52,350
An operating system log,

45
00:01:52,350 --> 00:01:53,730
a NetFlow log,

46
00:01:53,730 --> 00:01:55,290
a firewall log,

47
00:01:55,290 --> 00:01:56,643
or a DNS log?

48
00:01:57,870 --> 00:01:59,940
Traffic is being redirected

49
00:01:59,940 --> 00:02:03,390
from other internet domains to your site.

50
00:02:03,390 --> 00:02:05,823
So what type of log
might be the most useful?

51
00:02:07,140 --> 00:02:09,420
Operating system, NetFlow,

52
00:02:09,420 --> 00:02:11,553
firewall, or DNS?

53
00:02:12,750 --> 00:02:13,583
What do you think?

54
00:02:13,583 --> 00:02:15,390
You can put me on pause if you need to.

55
00:02:17,670 --> 00:02:20,220
I'm gonna go with DNS, right?

56
00:02:20,220 --> 00:02:23,400
My DNS log because that
should give me information

57
00:02:23,400 --> 00:02:28,400
about IP address to DNS
domain names mapping.

58
00:02:29,730 --> 00:02:31,320
So let's see what we got,

59
00:02:31,320 --> 00:02:32,463
if it's correct.

60
00:02:33,420 --> 00:02:34,713
And that is correct.

61
00:02:37,890 --> 00:02:39,330
All right, question four.

62
00:02:39,330 --> 00:02:42,300
Metadata that includes
comments, track changes,

63
00:02:42,300 --> 00:02:43,950
and speaker notes.

64
00:02:43,950 --> 00:02:47,160
Pseudo metadata, data packet metadata,

65
00:02:47,160 --> 00:02:51,090
file system metadata,
or application metadata.

66
00:02:51,090 --> 00:02:53,640
So this includes things
that a user created.

67
00:02:53,640 --> 00:02:56,730
Comments, track changes, speaker notes,

68
00:02:56,730 --> 00:02:59,700
could be embedded audio or visual video.

69
00:02:59,700 --> 00:03:02,940
So pseudo metadata, data packet metadata,

70
00:03:02,940 --> 00:03:06,183
file system metadata,
or application metadata.

71
00:03:07,680 --> 00:03:08,610
Well, let's see.

72
00:03:08,610 --> 00:03:09,840
Let's start at the bottom.

73
00:03:09,840 --> 00:03:12,780
Application metadata will be things like

74
00:03:12,780 --> 00:03:15,930
how long you're using the application for,

75
00:03:15,930 --> 00:03:18,360
if there's been any modifications for it.

76
00:03:18,360 --> 00:03:20,700
Changes in name, changes in version,

77
00:03:20,700 --> 00:03:22,290
so that doesn't work.

78
00:03:22,290 --> 00:03:25,530
File system metadata is all
about changes in file size,

79
00:03:25,530 --> 00:03:28,050
in time, in file attributes.

80
00:03:28,050 --> 00:03:30,250
Anything has to do
specifically with a file.

81
00:03:31,590 --> 00:03:34,800
Data packet metadata, it's
all about the attributes

82
00:03:34,800 --> 00:03:37,830
of the particular data packet itself.

83
00:03:37,830 --> 00:03:41,040
Pseudo metadata is gonna
be the best answer here.

84
00:03:41,040 --> 00:03:41,873
You're gonna choose it?

85
00:03:41,873 --> 00:03:42,706
You like it?

86
00:03:42,706 --> 00:03:43,680
Let's check,

87
00:03:43,680 --> 00:03:44,913
and that is correct.

88
00:03:45,960 --> 00:03:49,080
All right, we are going to do a matching

89
00:03:49,080 --> 00:03:50,880
and we only have three choices here.

90
00:03:50,880 --> 00:03:54,093
A port mirror, a network
TAP, and a sniffer.

91
00:03:55,200 --> 00:03:56,670
We've got on the right-hand side,

92
00:03:56,670 --> 00:03:58,590
a dedicated passive hardware device

93
00:03:58,590 --> 00:04:01,833
that copies and forwards
network packets for analysis;

94
00:04:06,780 --> 00:04:08,910
captures network traffic from a switch

95
00:04:08,910 --> 00:04:10,710
and forwards a copy of the traffic

96
00:04:10,710 --> 00:04:12,483
to an analysis device;

97
00:04:14,760 --> 00:04:17,493
or used to capture and analyze packets.

98
00:04:18,990 --> 00:04:19,890
What do you think?

99
00:04:21,060 --> 00:04:22,380
You wanna put me on pause?

100
00:04:22,380 --> 00:04:23,580
Well, let's try it.

101
00:04:23,580 --> 00:04:25,710
Well, right here, a
sniffer's already there.

102
00:04:25,710 --> 00:04:29,490
A sniffer is used to capture
and analyze network packets.

103
00:04:29,490 --> 00:04:33,300
Then we either have a dedicated
passive hardware device

104
00:04:33,300 --> 00:04:36,400
that copies and forwards network traffic

105
00:04:37,410 --> 00:04:40,560
or network packets for analysis,

106
00:04:40,560 --> 00:04:43,740
or we have captures network
traffic from a switch

107
00:04:43,740 --> 00:04:47,733
and forwards a copy of that
traffic to an analysis device.

108
00:04:48,570 --> 00:04:50,400
Well, a network TAP is going to be

109
00:04:50,400 --> 00:04:52,410
a passive hardware device,

110
00:04:52,410 --> 00:04:53,820
so let's choose that.

111
00:04:53,820 --> 00:04:56,310
And a port mirror, well that just mirrors

112
00:04:56,310 --> 00:04:57,300
various ports, right?

113
00:04:57,300 --> 00:04:58,470
Like on a switch.

114
00:04:58,470 --> 00:05:00,570
Captured network traffic from a switch

115
00:05:00,570 --> 00:05:05,570
and forwards a copy of the
traffic to an analysis device.

116
00:05:05,790 --> 00:05:06,780
That's our port mirror.

117
00:05:06,780 --> 00:05:09,690
The dedicated passive
hardware device that copies

118
00:05:09,690 --> 00:05:12,060
and forwards network packet information

119
00:05:12,060 --> 00:05:13,770
is gonna be our network TAP,

120
00:05:13,770 --> 00:05:15,990
and use to capture and analyze packets,

121
00:05:15,990 --> 00:05:17,550
well that's gonna be our sniffer.

122
00:05:17,550 --> 00:05:18,750
You agree?

123
00:05:18,750 --> 00:05:20,283
All right, let's check it out.

124
00:05:21,150 --> 00:05:22,170
And that is correct.

125
00:05:22,170 --> 00:05:23,370
Great work.

126
00:05:23,370 --> 00:05:24,840
All right, what's up next?

127
00:05:24,840 --> 00:05:26,970
we're gonna move into module five.

128
00:05:26,970 --> 00:05:28,380
Module five is all about

129
00:05:28,380 --> 00:05:31,020
Security Program Management and Oversight.

130
00:05:31,020 --> 00:05:33,480
And we're gonna start up with lesson 23,

131
00:05:33,480 --> 00:05:37,230
which is Summarize Effective
Security Governance.

132
00:05:37,230 --> 00:05:38,880
Look forward to seeing you there.
