CISSP · Domain 7
Security Operations
About 13% of the exam
Foundational operations concepts
- Need to know
- access only what the task requires
- Least privilege
- minimum rights, minimum time
- Separation of duties
- no one completes a critical task alone
- Two-person control
- both present to act
- Job rotation
- detect fraud, spread knowledge
- Mandatory vacation
- someone else runs the desk
- SLA
- agreed service levels with penalties
- Privileged account management
- vault, monitor, rotate
Logging, monitoring, detection
- SIEM correlates, SOAR automates the response
- Tune rules: exclude known-good automation
- UEBA spots behavior drift
- Threat intel feeds indicators of compromise
- Threat hunting starts from a hypothesis
- LOLBins: legitimate tools used maliciously
- Egress monitoring and DLP catch exfiltration
- TLS inspection trades privacy for visibility
- Protect logs: integrity, retention, time sync
Incident management lifecycle
CBK steps
- Preparation builds the capability
- Detection: notice and confirm the event
- Response: triage, activate the team
- Mitigation: contain the damage
- Reporting to stakeholders and regulators
- Recovery: restore normal service
- Remediation: fix the root cause
- Lessons learned feed back into preparation
NIST SP 800-61
- Preparation: people, tools, playbooks
- Detection and analysis
- Containment, eradication, recovery
- Post-incident activity and lessons
Rules of the road
- Contain first, then investigate
- Preserve evidence while containing
- Severity 1: immediate, executive notification
- Report only through approved channels
- Rebuild persistent compromises all at once
- Ransomware: isolate, assess, restore from clean backups
Preparation is the phase where everything else gets built; the exam calls the first live phase Detection
Investigations and evidence
Investigation types
- Criminal
- beyond a reasonable doubt
- Civil
- preponderance of evidence
- Administrative
- internal policy, lowest bar
- Regulatory
- agency enforces a law
Evidence types
- Direct
- proves the fact by itself
- Real
- physical objects, the drive
- Documentary
- records, logs, printouts
- Demonstrative
- charts that explain
- Hearsay
- second hand, usually excluded
- Best evidence rule
- original beats a copy
Admissibility
- Relevant, material, competent
- Chain of custody unbroken
- Hash before and after imaging
- Work on copies, never originals
- Enticement legal, entrapment not
- Interview witnesses, interrogate suspects
Digital forensics
- Identify
- Preserve
- Collect
- Examine
- Analyze
- Present
- Order of volatility
- registers, RAM, swap, disk, logs, archive
- Memory first
- capture RAM before power off
- Write blocker
- read the drive, change nothing
- Live forensics
- running system, accept changes
- eDiscovery
- find, hold, produce records
Vulnerability and patch management
- Inventory
- Assess
- Test
- Approve
- Deploy
- Verify
- Asset inventory first or you miss hosts
- Prioritize by exposure, not CVSS alone
- Test in staging before production
- Virtual patch: IPS or WAF rule blocks exploit
- Verify with a rescan
- Legacy unpatchable: isolate and monitor
Change and configuration management
- Request
- Impact review
- Approve (CAB)
- Test
- Schedule
- Implement
- Document
- Review
- Emergency change
- act now, document and review after
- Baseline
- approved known-good configuration
- CMDB
- items and their relationships
- Version control
- who changed what, roll back
- Immutable infrastructure
- replace servers, never edit live
- Drift
- live differs from baseline
Preventive and detective measures
- Signature IDS
- known patterns, misses new
- Anomaly IDS
- learned baseline, more false positives
- IPS
- inline, blocks, can block good traffic
- Allowlisting
- only approved software runs
- Sandbox
- detonate unknowns safely
- Honeypot
- decoy to watch attackers
- EDR, XDR
- endpoint telemetry, cross-source
- Anti-malware
- signatures plus behavior
- Firewall, WAF
- network and web filtering
IDS detects and alerts; IPS sits in the path and stops it
Backups
- Full
- everything, every run
- Incremental
- since last any backup, clears bit
- Differential
- since last full, keeps bit
- Restore incremental
- full plus every incremental
- Restore differential
- full plus latest differential
- 3-2-1
- three copies, two media, one offsite
- Electronic vaulting
- batch copy to remote site
- Remote journaling
- transaction log shipped live
- Remote mirroring
- live duplicate, near zero RPO
- Sanitize media
- before disposal or reuse
Recovery sites
- Hot
- mirrored, hours, most expensive
- Warm
- hardware ready, load data, days
- Cold
- empty space, weeks, cheapest
- Mobile
- trailer or container, deploy anywhere
- Reciprocal
- mutual aid, rarely enforceable
- Cloud, multi-region
- failover, mind DNS TTLs
- Return order
- least critical goes back first
Hot site buys time with money; cold site buys money with time
DR and BC execution
- BIA sets priorities, MTD per process
- DRP restores IT, BCP keeps the business running
- RTO: time to restore service
- RPO: data loss you can tolerate
- WRT: verify and reload after restore
- Call tree and notification first
- Pandemic plans: remote capacity, endpoints
- Exercise plans, then maintain them
- Update after every change and test
Physical and personnel safety
- Life safety comes before assets
- Guards decide, cameras record, lights deter
- Badges, visitor logs, escorts
- Mantrap and turnstile against tailgating
- Duress codes and panic buttons
- Travel security and executive protection
- Emergency management and evacuation drills
- Insider threat program and awareness
Rapid recall: attack frameworks
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and control
- Actions on objectives
- Kill chain: break any link
- MITRE ATT&CK: tactics and techniques catalog
- Diamond model: adversary, capability, infrastructure, victim
- Indicators of compromise feed detection
Key formulas
- Availability = MTBF / (MTBF + MTTR)
- Lower MTTR raises availability
- RTO + WRT must fit inside MTD
- RPO drives backup frequency
- Hourly RPO needs hourly backups or journaling
- SLE = AV x EF
- ALE = SLE x ARO
RTO is how long you are down; RPO is how much you lost; MTD is how long the business survives
Reference strip: frameworks, terms, malware
Frameworks
- NIST SP 800-61 incident handling
- NIST SP 800-86 forensic integration
- NIST SP 800-34 contingency planning
- ISO 27035 incidents, ISO 22301 continuity
- ITIL change and configuration practices
Evidence words
- Chain of custody, hash verification
- Relevant, material, competent
- Best evidence, parol evidence
- Exigent circumstances, search warrant
- Legal hold, eDiscovery
Continuity terms
- BIA, MTD, RTO, RPO, WRT
- Hot, warm, cold, mobile, reciprocal
- Vaulting, journaling, mirroring
- Checklist, walkthrough, simulation, parallel, full
Malware to name
- Virus needs a host, worm self-propagates
- Trojan disguised, ransomware extorts
- Rootkit hides, logic bomb waits
- Fileless lives in memory
- Botnet, C2, beaconing
Detection technology
- SIEM, SOAR, UEBA, EDR, XDR, NDR
- IDS, IPS, honeypot, honeynet
- Protocol analyzer shows the traffic
- Threat intel platform, STIX, TAXII
Quick exam traps
- Trap: Emergency changes skip documentation
- Trap: Enticement and entrapment are the same thing
- Trap: Return the most critical systems to the primary site first
- Trap: Differential backups clear the archive bit
- Trap: Image the disk before capturing memory
- Trap: A hot site is the cheapest option
- Trap: An IDS blocks the attack
- Trap: RTO measures acceptable data loss
cybercertprep.com · original revision sheet written from the public body of knowledge