Quick Revision

GK One-Line Question & Answer

15541+ short questions with short answers, covering every category and sub-category on the site — no long articles to scroll through. Good for a fast recap before an exam, or a few minutes of daily practice.

Computer Networks → Introduction to Computer Networks 39

What is attack vector
Path or method used by attacker to gain access
click to copy
What is vulnerability vs threat vs risk
Vulnerability is weakness threat exploits it risk is probability x impact
click to copy
What is qualitative risk assessment
Ranking risks as high medium low without exact numbers
click to copy
What is quantitative risk assessment
Calculating risk in monetary terms (ALE ARO SLE)
click to copy
What is ALE (Annual Loss Expectancy)
ARO times SLE = expected annual cost of risk
click to copy
What is SLE (Single Loss Expectancy)
Asset value times exposure factor for single incident
click to copy
What is ARO (Annual Rate of Occurrence)
Expected frequency of threat occurring per year
click to copy
What is AV in risk formula
Asset Value - cost of asset
click to copy
What is EF (Exposure Factor)
Percentage of asset value lost in single incident
click to copy
What is risk acceptance
Deciding to live with risk without additional controls
click to copy
What is risk transference
Shifting risk to another party like insurance
click to copy
What is risk mitigation
Implementing controls to reduce risk
click to copy
What is risk avoidance
Eliminating activity that causes the risk
click to copy
What is security audit
Formal examination of security controls against standards
click to copy
What is penetration test report
Document detailing vulnerabilities found and recommendations
click to copy
What is red team vs penetration test
Red team emulates full adversary pen test focuses on specific systems
click to copy
What is purple team
Red and blue teams working together to improve defenses
click to copy
What is threat emulation
Simulating specific threat actor TTPs to test defenses
click to copy
What is breach and attack simulation (BAS)
Automated continuous testing of security controls
click to copy
What is tabletop exercise
Discussion-based incident response practice
click to copy
What is SANS incident response cycle
Preparation Identification Containment Eradication Recovery Lessons Learned
click to copy
What is containment in incident response
Limiting spread and impact of security incident
click to copy
What is eradication in incident response
Removing cause of incident from environment
click to copy
What is forensic imaging in incident response
Creating exact bit-for-bit copy of storage for analysis
click to copy
What is chain of custody in forensics
Documentation tracking evidence handling for legal admissibility
click to copy
What is network forensics
Capturing and analyzing network traffic for investigation
click to copy
What is memory forensics
Analyzing RAM dump for malware artifacts and evidence
click to copy
What is log analysis in incident response
Examining system and network logs to reconstruct events
click to copy
What is SIEM correlation rule
Logic combining events to detect attack patterns
click to copy
What is alert fatigue
Analysts ignoring alerts due to excessive volume
click to copy
What is false positive in security
Alert triggered when no actual threat exists
click to copy
What is false negative in security
Actual threat not detected by security system
click to copy
What is SOAR playbook
Automated workflow responding to specific security alerts
click to copy
What is threat hunting hypothesis
Assumption about attacker behavior guiding hunt activity
click to copy
What is SOC tier 1 analyst
Alert triaging and initial investigation
click to copy
What is SOC tier 2 analyst
Deeper investigation and threat hunting
click to copy
What is SOC tier 3 analyst
Expert malware analysis threat intelligence and research
click to copy
What is MSSP (Managed Security Services Provider)
Outsourced security monitoring and management services
click to copy
What is MDR (Managed Detection and Response)
Managed service including active threat hunting and response
click to copy

Computer Networks → Types of Networks 1

What is incident response plan (IRP)
Documented procedures for responding to security incidents
click to copy