/
Technical Questions
Save to my account
Sign up
Technical Questions
View
Tekrar Notlari.pdf Flashcards
Study
1
Question
What is the CIA triangle in cybersecurity?
Answer
It stands for confidentiality, integrity, and availability, which are three pillars of cybersecurity.
2
Question
Define Confidentiality in cybersecurity.
Answer
Confidentiality ensures that sensitive data is accessed only by authorized users, often achieved through encryption methods.
3
Question
Explain Integrity in cybersecurity.
Answer
Integrity ensures that data has not been changed, modified, or corrupted while in transit, commonly protected using hashing techniques.
4
Question
Describe Availability in cybersecurity.
Answer
Availability ensures that data is available when needed, often maintained through backups to protect against DDoS attacks.
5
Question
What is a Sniffing Attack in cybersecurity?
Answer
A Sniffing Attack involves attackers capturing data using tools like Wireshark to intercept and read it in clear text, posing a serious security threat.
6
Question
Define Man in the Middle Attack in cybersecurity.
Answer
A Man in the Middle Attack occurs when an attacker sits between devices to intercept and manipulate data during transmission.
7
Question
Explain the difference between DoS and DDoS attacks.
Answer
DoS disrupts services from a single attacker, while DDoS uses multiple computers to attack a single target, both aimed at compromising availability.
8
Question
What is a Denial of Service (DoS) attack?
Answer
A DoS attack disrupts services by overwhelming a system, similar to one person blocking the entrance to a store.
9
Question
What is a Distributed Denial of Service (DDoS) attack?
Answer
A DDoS attack uses multiple sources to overwhelm a target, like a large group of people blocking a store entrance from different sides.
10
Question
Explain the concept of Encoding in cybersecurity.
Answer
Encoding is a simple algorithm that transforms data into another format, reversible using tools like link sanitizer and cyberchef, aiding in data transformation and protection.
11
Question
Define Encryption in cybersecurity.
Answer
Encryption is a two-way function used to maintain confidentiality, with algorithms like RSA, AES, and 3DES commonly employed for data security.
12
Question
What is Hashing in cybersecurity?
Answer
Hashing is a one-way algorithm that validates data integrity, with common algorithms like MD5, SHA-1, and SHA-2 used to generate unique hash values for data verification.
13
Question
Explain the difference between Encryption and Hashing.
Answer
Encryption hides data for confidentiality and is reversible, while hashing verifies data integrity in a one-way function.
14
Question
What is a digital signature in cybersecurity?
Answer
A digital signature is a cryptographic technique using private and public keys to verify the authenticity and integrity of digital documents or messages, ensuring data integrity and sender authentication.
15
Question
What is a three-way handshake in networking?
Answer
A three-way handshake is a process to establish a connection between a client and a server, involving three steps: SYN, SYNACK, and ACK packets exchanged to initiate communication.
16
Question
Differentiate between TCP and UDP protocols.
Answer
TCP (Transmission Control Protocol) is connection-oriented and reliable, ensuring data delivery, while UDP (User Datagram Protocol) is connectionless and faster, suitable for real-time applications but with no reliability guarantees.
17
Question
What is a three-way handshake in networking?
Answer
A process used to create a connection between a client and a server involving three steps: SYN packet from client, SYNACK packet from server, and ACK packet from client.
18
Question
What are the main differences between TCP and UDP protocols?
Answer
TCP is connection-based, reliable, and slower for large data transfers. UDP is connectionless, less reliable, and faster, making it suitable for voice or video calls.
19
Question
Why is UDP preferred for video conferences and live streams despite not providing receipts?
Answer
Sometimes, connection speed is more important than reliability, making UDP the preferred protocol for applications where speed is crucial.
20
Question
Explain the TCP flags: SYN, ACK, FIN, RES, PSH, URG.
Answer
SYN - synchronization for connection establishment, ACK - acknowledgment of packets received, FIN - gracefully terminate the connection, RES - reset to stop the connection, PSH - immediately pushes out data, URG - informs to prioritize certain data.
21
Question
What are some examples of cybersecurity frameworks used by professionals and organizations?
Answer
Examples include MITRE ATT&CK Framework, Cyber Kill Chain, NIST Cybersecurity Framework, SANS, and ISO, each serving different purposes in cybersecurity management and defense.
22
Question
What is the NIST framework used for?
Answer
The NIST framework helps organizations manage and reduce cybersecurity risks.
23
Question
How many steps are there in the NIST framework?
Answer
The NIST framework has four steps: preparation, detection and monitoring, eradication, containment and recovery, and post-incident activity.
24
Question
Which step of the NIST framework involves detection and monitoring?
Answer
Step two of the NIST framework involves detection and monitoring.
25
Question
What is the NIST Incident Response Framework for?
Answer
The NIST Incident Response Framework is a guide for developing, implementing, and maintaining incident response capabilities within an organization.
26
Question
What is the most important incident response step according to the text?
Answer
The most important incident response step according to the text is preparation, as it allows organizations to respond quickly and efficiently to incidents.
27
Question
How many layers are there in the OSI model?
Answer
The OSI model consists of seven layers, each serving a specific function in network communication.
28
Question
What is the purpose of the OSI model?
Answer
The purpose of the OSI model is to enable communication between different systems over a network.
29
Question
Application Layer
Answer
User interface or Human Computer interaction layer where applications can access the network services (HTTP, FTP, SMTP, DNS) and are vulnerable to attacks such as phishing, malware, and social engineering.
30
Question
Presentation Layer
Answer
Encryption and decryption occur (SSL, SSH) to protect against attacks like buffer overflow and code injection.
Tekrar Notlari.pdf Flashcards
Study
1
Question
What is SQL injection and how to prevent it?
Answer
SQL injection is a type of attack that allows attackers to execute malicious SQL statements. To prevent it, implement secure coding practices and input validation to block unauthorized database access.
2
Question
What are private IP addresses and public IP addresses?
Answer
Private IP addresses are used within a local network and are not accessible from the internet. Common ranges include 10.0.0.0 to 10.255.255.255, 172.16.0.0 to 172.31.255.255, and 192.168.0.0 to 192.168.255.255. Public IP addresses are unique addresses used to communicate over the internet.
3
Question
What is Mimikatz and how is it used?
Answer
Mimikatz is a tool created by Benjamin Delpy in 2007 for extracting important information like passwords from Windows systems. Despite antivirus software blocking it, attackers still use it to gain unauthorized access to networks or systems.
4
Question
What is a DDoS attack and how can it be prevented?
Answer
A DDoS attack occurs when multiple computers overwhelm a single target to disrupt its services. To prevent it, set up firewalls, intrusion prevention systems (IPS), use load balancing, and limit requests from certain IPs.
5
Question
What is a man-in-the-middle attack and how can it be prevented?
Answer
A man-in-the-middle attack involves intercepting and manipulating data between devices. To prevent it, use Static ARP to prevent ARP poisoning, encryption to secure data, and IPS systems to detect network anomalies.
6
Question
What is the difference between Telnet and Secure Shell (SSH)?
Answer
Telnet and SSH are protocols for remote access to computers. The key difference is security - Telnet sends data in plain text, while SSH encrypts all data for secure communication.
7
Question
What are Nessus, NMAP, Qualys, and TCP Dump used for in cybersecurity?
Answer
Nessus is a vulnerability scanning tool, NMAP is a network mapping tool, Qualys is used for security assessments, and TCP Dump is for packet analysis in cybersecurity.
8
Question
What is Nessus used for in the field of cybersecurity?
Answer
Nessus is a widely used vulnerability scanning tool that helps identify vulnerabilities, misconfigurations, and security issues in networks, systems, and applications. It provides detailed reports and recommendations for remediation.
9
Question
What is Nmap Network Mapper used for in cybersecurity?
Answer
Nmap is a powerful network scanning tool used for discovering hosts and services on a network, identifying open ports, operating systems, and potential vulnerabilities. It is often used for reconnaissance and network mapping.
10
Question
What is Qualys known for in cybersecurity?
Answer
Qualys is a cloud-based security and compliance platform that offers services including vulnerability management, web application scanning, and compliance monitoring. It helps organizations identify and prioritize security risks across their IT infrastructure.
11
Question
What is TCP Dump used for in cybersecurity?
Answer
TCP Dump is a command-line packet analyzer that captures and displays network packets in real-time. It is commonly used for troubleshooting network issues, monitoring network traffic, and analyzing network protocols.
12
Question
What is remote code execution (RCE) and how can attackers use it?
Answer
Remote code execution allows attackers to remotely execute malicious code on a computer by exploiting code vulnerabilities. Examples of attacks using RCE include SQL injection, Blind SQL injection, and Cross-Site Scripting (XSS) attacks.
13
Question
Explain Brute Force attack and provide mitigation techniques.
Answer
Brute Force is a password guessing attack where various combinations of usernames and passwords are tried repeatedly until successful entry. Mitigation techniques include encouraging complex passwords, locking out accounts after attempts, using Captcha, and implementing multifactor authentication.
14
Question
What is a salted hash and how does it enhance security?
Answer
A salted hash is a security measure used to protect passwords and sensitive data by turning them into long scrambled codes with added random characters (salt). This makes it harder for attackers to crack the code and reveal the original password, enhancing security.
15
Question
Define SIEM and provide 3 examples of SIEM systems.
Answer
SIEM stands for Security Information and Event Management. It is a system that collects and organizes logs from various sources to help identify suspicious activity. Examples of SIEM systems are Splunk Enterprise Security, IBM QRadar, and LogRhythm McAfee Enterprise Security Manager.
16
Question
How can organizations prevent zero-day attacks?
Answer
Preventing zero-day attacks involves proactive security measures such as keeping systems and software up to date with patches, using network segmentation to limit attack surfaces, implementing intrusion detection systems, and conducting regular security audits.
17
Question
What is a SIEM system used for?
Answer
A SIEM system is used to collect and organize logs from different sources to identify suspicious activity and enhance online security.
18
Question
Name some popular SIEM systems.
Answer
Some popular SIEM systems include Splunk Enterprise Security, IBM QRadar, and LogRhythm McAfee Enterprise Security Manager.
19
Question
How can you prevent a zero-day attack?
Answer
To prevent a zero-day attack, update your apps as soon as patches are available, use a web application firewall (WAF) to block unnecessary transactions, and minimize the use of non-essential apps.
20
Question
What are the key indicators of a phishing email?
Answer
Key indicators of a phishing email include inconsistencies in sender information, grammar mistakes, urgency tactics, unexpected links or attachments, and overall suspicious content.
21
Question
Define spam, scam, and phishing emails.
Answer
- Spam Emails: Unwanted emails sent in bulk, usually for advertising. - Scam Emails: Deceptive emails with dishonest plans to obtain money or personal information. - Phishing Emails: Fake emails that trick recipients into sharing sensitive information by posing as legitimate sources.
22
Question
Define threat, vulnerability, and risk in cybersecurity.
Answer
- Threat: Someone or something with the potential to harm a system or organization. - Vulnerability: A weakness in a system that can be exploited by a hacker. - Risk: The potential for loss or damage when a threat exploits a vulnerability.
23
Question
What is Qualys vulnerability management?
Answer
Qualys vulnerability management is a cloud-based service that helps companies defend against vulnerabilities, prioritize risks based on CVSS scores, and identify zero-day vulnerabilities. It provides a comprehensive solution for finding and fixing vulnerabilities in systems.
24
Question
What is Qualys Vulnerability Management?
Answer
Qualys Vulnerability Management is a cloud-based service that helps companies defend against the latest vulnerabilities. It prioritizes risks based on CVSS scores ranging from 0 to 10, with scores of 8, 9, or 10 indicating high or critical vulnerabilities requiring immediate patching.
25
Question
What is VMDR in Qualys and how is it described?
Answer
VMDR in Qualys is described as a superhero for cybersecurity. It is a single tool that finds vulnerabilities in systems and fixes them in one place. It automatically tracks all devices and software, prioritizes serious problems, and helps in fast resolution. It is easy to use and cost-effective.
26
Question
What is the difference between vulnerability scanning and penetration testing?
Answer
Vulnerability scanning is an automated checkup for systems, while penetration testing involves real people digging into systems to identify vulnerabilities. Scanning highlights problems, while penetration testing delves deeper to understand how issues could lead to security breaches or data leaks.
27
Question
Explain the difference between static and dynamic malware analysis.
Answer
Static malware analysis involves examining a suspicious file without running it to gather information, while dynamic analysis runs the malware in a safe environment (sandbox) to observe its behavior.
28
Question
What is the difference between HTTP and HTTPS?
Answer
HTTP (Hypertext Transfer Protocol) uses port 80 and sends data without encryption, while HTTPS (Hypertext Transfer Protocol Secure) uses port 443 and encrypts data over TLS (Transport Layer Security).
29
Question
What is lateral movement and how can it be prevented?
Answer
Lateral movement is the process by which an attacker moves through a network after gaining initial access. Segmentation, a security best practice, can help prevent lateral movement by securing the entire network.
30
Question
What are the 5 suspicious behaviors observed in malware analysis for potential compromise?
Answer
1. Behavior based on workflow and SOP at Solvent. 2. Check if the malware is hidden but functional. 3. Execute based on the workflow at Solvent. 4. Look for five suspicious behaviors before escalating to the IR Team. 5. Consider threats under outbound traffic.
Tekrar Notlari.pdf Flashcards
Study
1
Question
Anomalies In Privileged User Account Activity
Answer
Unusual activity in privileged user account activity
2
Question
DNS Request Anomalies
Answer
Suspicious behaviors in DNS request activities
3
Question
Unusual log in activity
Answer
Unusual patterns in login activities
4
Question
Web traffic with inhuman behavior
Answer
Web traffic exhibiting abnormal behavior
5
Question
Large Number of Requests for the Same File
Answer
Abnormal high volume of requests for a single file
6
Question
Unusual activity in outbound network traffic
Answer
Suspicious behavior in outbound network traffic
7
Question
Unusual HTML response sizes
Answer
Abnormal sizes of HTML responses observed
8
Question
Changes in mobile device profiles
Answer
Unusual alterations in mobile device configurations
9
Question
Unusual changes in registry and/or system files
Answer
Suspicious modifications in registry or system files
10
Question
Where can we spot 5 suspicious behaviors
Answer
Dell XDR, MITRE Attack Framework, Anyrun
11
Question
What is a macro
Answer
A small program used in software like Microsoft Excel to automate tasks
12
Question
How can macros be misused
Answer
By embedding harmful code to execute malicious actions on a computer
13
Question
What is Emotet ransomware
Answer
A type of harmful software spread through fake emails with dangerous links or attachments
14
Question
Ways to stay safe from Emotet and Ransomware
Answer
Keep computer updated, Avoid suspicious attachments or links, Educate others on bad emails, Use strong passwords, Limit access, Back up files
15
Question
How to analyze pcap files for malware analysis
Answer
Open pcap file, Analyze traffic for suspicious patterns, Identify infected hosts, Look for Indicators of Compromise (IOCs)
16
Question
What are the steps to analyze pcap files for malware?
Answer
1. Open pcap File 2. Use a network traffic analysis tool like Wireshark to open the pcap file 3. Analyze Traffic 4. Identify Infected Hosts 5. Identify Indicators of Compromise (IOCs) 6. Generate Executive Summary Report 7. Response Code Analysis 8. Take Action
17
Question
What is segmentation in cybersecurity?
Answer
Segmentation is like dividing a big area into smaller sections. Each section has its own rules and protections to prevent problems from spreading and keep different parts safe from each other.
18
Question
How can you identify a password spraying attack?
Answer
You can identify a password spraying attack by noticing lots of fast login tries, sudden failed logins from real users, or logins from accounts that shouldn't exist. It's about detecting unusual login patterns that indicate lateral movement.
19
Question
What is Secureworks Dell Taegis XDR?
Answer
Secureworks Dell Taegis XDR is a cybersecurity platform that helps organizations detect and respond to cyber threats using advanced technology to quickly find and stop security incidents across IT systems.
20
Question
What experience does the individual have with EDR tools?
Answer
The individual is familiar with Microsoft Defender XDR, Trend Vision One, Palo Alto Networks Cortex XDR, Cisco AMP EDR, and Dell Taegis XDR. They access customers' dashboards to investigate alerts, look at event timelines, and take actions like blocking or quarantining compromised endpoints.
21
Question
What experience does the individual have with Cloud services?
Answer
The individual uses Cisco AMP Cloud services, Cisco Umbrella Investigation, and Cisco Threat Grid for further investigation. They are also familiar with Azure Cloud Environment, Azure Sentinel Microsoft SIEM Solution, and have experience with installing VM boxes and Kali Linux in a Cloud environment.
22
Question
What should you do if the threat is spreading to the network and compromising endpoints?
Answer
Either block or quarantine the compromised endpoint.
23
Question
What steps can you take to prevent identity theft?
Answer
Use strong and unique passwords, avoid sharing confidential information, keep browsers and software updated, have antivirus software installed, and change passwords if attacked.
24
Question
What is Bro, now known as Zeek?
Answer
A free network security tool that watches network traffic to find potential security issues.
25
Question
Why do attackers send something encoded?
Answer
To hide the payload, especially the injection part, in the payload.
26
Question
Where are the PCAP files coming from that you analyze with Wireshark?
Answer
Integrated with Cisco Magnet to download PCAP files based on our work environment.
27
Question
What are some open source rules you know in cybersecurity?
Answer
Snort rules, Surikata rules, Yara rules for malware analysis.
28
Question
How do you keep yourself updated in cybersecurity?
Answer
Subscribed to TryHackme, PortSwigger, and HacktheBox for practice, watch walkthroughs, and follow industry updates.
29
Question
What cloud environment are you familiar with?
Answer
Azure Cloud Environment
30
Question
What Microsoft SIEM solution are you familiar with?
Answer
Azure Sentinel