Skip to Content
CompTIA Advanced Security Practitioner (CASP+) CAS-004 Cert Guide, 3rd Edition
book

CompTIA Advanced Security Practitioner (CASP+) CAS-004 Cert Guide, 3rd Edition

by Robin Abernathy, Troy McMillan
July 2022
Intermediate to advanced
864 pages
20h 31m
English
Pearson IT Certification
Content preview from CompTIA Advanced Security Practitioner (CASP+) CAS-004 Cert Guide, 3rd Edition

Chapter 10

Analyzing Indicators of Compromise and Formulating an Appropriate Response

This chapter covers the following topics:

  • Indicators of compromise: This section covers packet capture (PCAP), network logs, vulnerability logs, operating system logs, access logs, NetFlow logs, notifications (including FIM alerts, SIEM alerts, DLP alerts, IDS/IPS alerts, and antivirus alerts), notification severity/priorities, and unusual process activity.

  • Response: This section describes firewall rules, IPS/IDS rules, ACL rules, signature rules, behavior rules, DLP rules, and scripts/regular expressions.

This chapter covers CAS-004 Objective 2.2 Given a scenario, analyze indicators of compromise and formulate an appropriate response.

Formulating an appropriate ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide, 2nd Edition

CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide, 2nd Edition

Omar Santos

Publisher Resources

ISBN: 9780137348947