What is defensive security?
Defensive security is ongoing work to reduce the likelihood and impact of cyber incidents through prevention, detection, recovery, and response.
Study 7 Defensive Security Practices with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
What is defensive security?
Defensive security is ongoing work to reduce the likelihood and impact of cyber incidents through prevention, detection, recovery, and response.
What is a secure configuration?
A secure configuration is a reviewed set of system settings that supports required work while limiting unnecessary exposure.
What should precede setting configuration baselines?
Inventory devices, applications, cloud services, and their owners before establishing approved configuration baselines.
How can teams limit configuration drift?
Record and review configuration changes so systems do not drift from their approved baselines.
What does a patch do?
A patch corrects a software or firmware problem. Updates may also add improvements or support.
Which systems should receive high patch priority?
Prioritize actively exploited vulnerabilities and internet-facing systems, while tracking devices that cannot be updated and applying compensating protections.
What is an endpoint in security?
An endpoint is a device such as a laptop, desktop, server, or phone.
What can EDR do, and what does it not replace?
Endpoint detection and response (EDR) helps identify and investigate suspicious behavior, but does not replace secure configuration, least privilege, or timely updates.
What is a backup?
A backup is a separate copy of data or system information used to recover from loss, corruption, or attack.
How should backup copies be protected from compromised systems?
Protect backup accounts and copies from ordinary users and compromised systems; keep at least one copy offline or otherwise isolated from routine access.
Why test backup restoration?
Test restoration regularly; a completed backup alone does not prove that data can be recovered.
What makes monitoring more than just collecting logs?
Monitoring collects and reviews relevant activity to detect suspicious events and operational failures. Logs without review or response procedures provide limited protection.