Lesson 24: Security Operations, Investigations, Evidence, and Logging Foundations

Lesson 25/28 | Study Time: 15 Min

Lesson Twenty-Four

Security Operations, Investigations, Evidence, and Logging Foundations

SierraTec Secure CISSP Certification Preparation Course


Lesson Overview

Security operations is where security architecture, policy, identity, monitoring, incident handling, configuration management, recovery, and personnel procedures become day-to-day organizational practice.

A security program can have excellent:

  • policies;

  • firewalls;

  • identity systems;

  • encryption;

  • risk assessments;

and still fail if operational teams cannot:

  • detect suspicious activity;

  • preserve evidence;

  • investigate events;

  • distinguish normal activity from malicious behavior;

  • maintain trustworthy logs;

  • escalate incidents;

  • document what happened;

  • prove who performed administrative actions.

CISSP Domain 7 β€” Security Operations currently represents 13% of the CISSP examination.

The current Domain 7 outline contains fifteen objectives:

  1. Understand and comply with investigations.

  2. Conduct logging and monitoring activities.

  3. Perform Configuration Management.

  4. Apply foundational security operations concepts.

  5. Apply resource protection.

  6. Conduct incident management.

  7. Operate and maintain detection and preventive measures.

  8. Implement and support patch and vulnerability management.

  9. Understand and participate in change management.

  10. Implement recovery strategies.

  11. Implement Disaster Recovery processes.

  12. Test Disaster Recovery Plans.

  13. Participate in Business Continuity planning and exercises.

  14. Implement and manage physical security.

  15. Address personnel safety and security concerns.

Because Domain 7 is broad, SierraTec Secure divides it into several lessons.

Lesson Twenty-Four concentrates primarily on:

7.1 β€” Understand and comply with investigations

Including:

  • evidence collection and handling;

  • reporting and documentation;

  • investigative techniques;

  • digital forensic tools, tactics, and procedures;

  • artifacts involving data, computers, networks, and mobile devices.

7.2 β€” Conduct logging and monitoring activities

Including:

  • IDPS;

  • SIEM;

  • continuous monitoring and tuning;

  • egress monitoring;

  • log management;

  • threat intelligence;

  • threat hunting;

  • UEBA.

It also introduces parts of:

7.4 β€” Foundational Security Operations Concepts

Including:

  • need to know;

  • least privilege;

  • separation of duties;

  • privileged account management;

  • job rotation;

  • SLAs.

NIST SP 800-86 remains NIST's final dedicated guide for integrating digital forensic techniques into incident response. It emphasizes computer and network forensic activities and the use of data sources such as operating systems, files, applications, and network traffic.

NIST's current incident-response publication is SP 800-61 Rev. 3, finalized in April 2025. It superseded SP 800-61 Rev. 2 and integrates incident response into broader cybersecurity risk management using the NIST Cybersecurity Framework 2.0.

For logging, SP 800-92 remains the current final NIST publication, while SP 800-92 Rev. 1 remains an Initial Public Draft as of this lesson's August 2026 reference point.

The central Lesson Twenty-Four question is:

How should security professionals investigate suspicious activity, preserve trustworthy evidence, and use logging, monitoring, threat intelligence, and behavioral analysis to understand security events without compromising evidence integrity, operational reliability, privacy, or organizational obligations?


CISSP Exam Objective Alignment

Lesson TopicPrimary Alignment
Investigations7.1
Evidence collection7.1
Evidence handling7.1
Evidence integrity7.1
Chain of custody7.1
Reporting7.1
Documentation7.1
Investigative techniques7.1
Digital forensics7.1
Data artifacts7.1
Computer artifacts7.1
Network artifacts7.1
Mobile artifacts7.1
Volatile evidence7.1
Memory acquisition7.1 supporting concept
Forensic imaging7.1 supporting concept
Hash verification7.1 supporting concept
Logging7.2
Log management7.2
Centralized logging7.2
SIEM7.2
IDS7.2
IPS7.2
Continuous monitoring7.2
Tuning7.2
Egress monitoring7.2
Threat intelligence7.2
Threat feeds7.2
Threat hunting7.2
UEBA7.2
Need to know7.4
Least privilege7.4
Separation of duties7.4
Privileged-account management7.4
Job rotation7.4
SLA7.4

Learning Objectives

After completing this lesson, you should be able to:

  1. Explain the purpose of a security investigation.

  2. Distinguish an event from an incident.

  3. Explain why authorization matters during investigations.

  4. Identify common investigation categories.

  5. Explain the importance of legal and management coordination.

  6. Define evidence.

  7. Explain evidence relevance.

  8. Explain evidence reliability.

  9. Explain evidence integrity.

  10. Explain chain of custody.

  11. Explain why documentation begins immediately.

  12. Explain preservation.

  13. Explain acquisition.

  14. Explain examination.

  15. Explain analysis.

  16. Explain forensic reporting.

  17. Explain volatile versus nonvolatile evidence.

  18. Explain order-of-volatility reasoning.

  19. Explain live acquisition.

  20. Explain dead/static acquisition.

  21. Explain memory evidence.

  22. Explain disk imaging conceptually.

  23. Explain forensic write protection.

  24. Explain hashing in forensic evidence.

  25. Explain forensic working copies.

  26. Explain timeline reconstruction.

  27. Explain timestamp challenges.

  28. Explain why time synchronization matters.

  29. Identify computer artifacts.

  30. Identify network artifacts.

  31. Identify mobile-device artifacts.

  32. Identify application and cloud artifacts.

  33. Define a security log.

  34. Explain the log-management lifecycle.

  35. Identify important log sources.

  36. Explain centralized log collection.

  37. Explain log normalization.

  38. Explain log correlation.

  39. Explain SIEM.

  40. Explain SIEM use cases.

  41. Explain tuning.

  42. Explain alert fatigue.

  43. Explain IDS.

  44. Explain IPS.

  45. Compare network- and host-based detection.

  46. Explain signature-based detection.

  47. Explain anomaly/behavior-based detection.

  48. Explain continuous monitoring.

  49. Explain egress monitoring.

  50. Explain log retention.

  51. Explain log integrity.

  52. Explain threat intelligence.

  53. Distinguish data, information, and intelligence.

  54. Explain Indicators of Compromise.

  55. Explain adversary TTPs conceptually.

  56. Explain threat feeds.

  57. Explain threat-intelligence relevance.

  58. Explain threat hunting.

  59. Explain hypothesis-driven hunting.

  60. Explain UEBA.

  61. Explain behavioral baselines.

  62. Explain false positives in behavioral systems.

  63. Explain least privilege in security operations.

  64. Explain separation of duties.

  65. Explain privileged-account monitoring.

  66. Explain job rotation.

  67. Explain SLA relevance to security operations.

  68. Apply CISSP FIRST/BEST/MOST reasoning to investigation scenarios.


Part I β€” Security Operations

1. Security Operations

Security operations applies security requirements during normal organizational activity.

It includes:

PEOPLE
+
PROCESS
+
TECHNOLOGY
+
MONITORING
+
RESPONSE

2. Operational Security Is Continuous

Security architecture might define:

what should happen.

Security operations must ensure:

it continues happening.


3. Operational Examples

Security operations may involve:

  • monitoring alerts;

  • reviewing logs;

  • administering privileged access;

  • responding to suspicious activity;

  • maintaining protective systems;

  • preserving investigation evidence.


Part II β€” Event Versus Incident

4. Security Event

An event is an observable occurrence.

Examples:

  • failed login;

  • firewall block;

  • service restart;

  • account creation.

Not every event is malicious.


5. Security Incident

An incident involves circumstances that jeopardize or may jeopardize security objectives or require coordinated response.

Example:

EVENT
One failed login

versus

INCIDENT
Thousands of authentication attempts
+
successful account takeover
+
data access

6. Avoid Premature Conclusions

A security analyst should not immediately assume:

unusual = malicious.

Investigation establishes context.


Part III β€” Investigation Purpose

7. Investigation

A security investigation attempts to determine:

  • what happened;

  • when;

  • how;

  • which systems were affected;

  • which identities were involved;

  • what evidence supports the conclusion;

  • what response is required.


8. Investigation Flow

TRIGGER
β”‚
β–Ό
AUTHORIZE
β”‚
β–Ό
PRESERVE
β”‚
β–Ό
COLLECT
β”‚
β–Ό
EXAMINE
β”‚
β–Ό
ANALYZE
β”‚
β–Ό
CONCLUDE
β”‚
β–Ό
REPORT

Part IV β€” Investigation Types

9. Different Investigations Have Different Requirements

Possible contexts include:

  • administrative;

  • civil;

  • criminal;

  • regulatory;

  • contractual/industry;

  • incident-response investigations.


10. Administrative Investigation

May involve:

  • policy violation;

  • employee misuse;

  • inappropriate access;

  • internal misconduct.


11. Criminal Investigation

May involve suspected violation of criminal law.

The security professional should:

follow organizational procedures and involve appropriate legal/law-enforcement authorities where required.


12. Civil Investigation

May arise from:

  • lawsuits;

  • contractual disputes;

  • damages;

  • negligence claims.


13. Regulatory Investigation

May involve:

  • privacy obligations;

  • sector regulation;

  • breach-reporting obligations;

  • supervisory authority.


14. Investigation Type Matters

The applicable process can affect:

  • evidence handling;

  • privilege/confidentiality;

  • reporting;

  • external notification.

CISSP candidates should avoid assuming one universal legal procedure applies worldwide.


Part V β€” Authorization to Investigate

15. Investigation Authority

Investigators should operate under appropriate:

  • organizational authority;

  • policy;

  • legal direction;

  • incident-response procedures.


16. Why Authority Matters

Unauthorized investigation techniques may create:

  • privacy issues;

  • employment-law issues;

  • contractual problems;

  • evidence concerns;

  • operational disruption.


Part VI β€” Legal Coordination

17. Security Professionals Are Not Automatically Legal Decision Makers

When legal questions arise, involve appropriate:

  • legal counsel;

  • privacy personnel;

  • compliance;

  • management.

NIST SP 800-86 specifically cautions that forensic guidance should be applied with management and legal consultation concerning applicable laws and regulations.


Part VII β€” Evidence

18. Evidence

Evidence is information used to support or refute a conclusion.

Examples:

  • logs;

  • memory artifacts;

  • files;

  • packet captures;

  • access records;

  • device images.


19. Evidence Must Answer a Question

For example:

Question:

Did Administrator Alice disable the firewall?

Evidence might include:

  • authentication logs;

  • privileged-session records;

  • firewall configuration history;

  • change ticket.


Part VIII β€” Evidence Characteristics

20. Relevant

Evidence should relate to the matter being investigated.


21. Reliable

Investigators should understand:

  • where evidence came from;

  • how it was collected;

  • whether the source can be trusted.


22. Integrity

Investigators should be able to demonstrate that evidence has not been improperly altered.


23. Complete Enough for the Purpose

One log entry may not tell the entire story.

Corroborating evidence can be valuable.


Part IX β€” Evidence Integrity

24. Preserve the Original State

Whenever practical and appropriate:

minimize unnecessary modification of original evidence.


25. Evidence Integrity Model

IDENTIFY
↓
PRESERVE
↓
COLLECT
↓
PROTECT
↓
ANALYZE COPY
↓
DOCUMENT

Part X β€” Chain of Custody

26. Chain of Custody

Chain of custody documents:

who controlled evidence, when, where, and what happened to it.


27. Example

09:10
Drive collected by Analyst A
β”‚
β–Ό
09:25
Placed in evidence container
β”‚
β–Ό
10:15
Transferred to Forensic Analyst B
β”‚
β–Ό
10:30
Image created

28. Chain-of-Custody Purpose

It helps support confidence that:

the evidence examined is the evidence originally collected.


Part XI β€” Documentation

29. Document Immediately

Do not wait until the end of a long investigation to reconstruct:

  • times;

  • actions;

  • people;

  • commands;

  • evidence locations.


30. Investigator Notes

Useful notes may record:

  • date/time;

  • investigator;

  • action performed;

  • system;

  • reason;

  • result.


Part XII β€” Forensic Process

31. A Useful High-Level Model

IDENTIFY
↓
PRESERVE
↓
COLLECT
↓
EXAMINE
↓
ANALYZE
↓
REPORT

NIST SP 800-86 provides practical guidance for performing forensic activities in support of incident response and troubleshooting.


Part XIII β€” Identify

32. Identification

Determine:

  • what evidence may exist;

  • where it exists;

  • which systems are involved.


Part XIV β€” Preserve

33. Preservation

Protect relevant information from:

  • modification;

  • deletion;

  • overwrite;

  • unauthorized access.


Part XV β€” Collection / Acquisition

34. Collection

Obtain evidence using methods appropriate to:

  • system;

  • volatility;

  • investigation;

  • authority.


Part XVI β€” Examination

35. Examination

Extract potentially relevant artifacts.

Examples:

  • files;

  • process listings;

  • logs;

  • browser artifacts;

  • network sessions.


Part XVII β€” Analysis

36. Analysis

Determine relationships among artifacts.

Example:

AUTHENTICATION
β”‚
β–Ό
PROCESS EXECUTION
β”‚
β–Ό
NETWORK CONNECTION
β”‚
β–Ό
FILE ACCESS

Part XVIII β€” Reporting

37. Investigation Report

A report should distinguish:

  • observed evidence;

  • analysis;

  • conclusion;

  • limitations.


Part XIX β€” Volatile Evidence

38. Volatile Evidence

Volatile data may disappear when:

  • system shuts down;

  • process exits;

  • network connection terminates.

Examples:

  • RAM;

  • running processes;

  • active connections.


39. Nonvolatile Evidence

Examples:

  • disk files;

  • retained logs;

  • archived data.


Part XX β€” Order of Volatility

40. Principle

When collection is appropriate, investigators often prioritize evidence that is likely to disappear first.

Conceptually:

VERY VOLATILE
RAM / active processes / connections
β”‚
β–Ό
LESS VOLATILE
local persistent storage
β”‚
β–Ό
ARCHIVED / BACKUP DATA

41. Not an Absolute Mechanical Rule

Collection decisions must consider:

  • evidence value;

  • system safety;

  • investigative procedure;

  • legal requirements.


Part XXI β€” Live Acquisition

42. Live System

Live acquisition collects evidence while the system is running.

Advantages:

  • volatile memory available;

  • active connections visible;

  • running processes visible.


43. Live Acquisition Tradeoff

Any interaction with a live system:

changes system state.

Therefore the investigator should:

  • minimize unnecessary actions;

  • document actions.


Part XXII β€” Static / Dead Acquisition

44. Static Acquisition

Evidence is acquired from a system that is no longer actively running.

Advantages may include:

  • reduced ongoing system-state change;

  • controlled disk acquisition.


45. Tradeoff

Powering off may destroy:

volatile information.

This is why collection strategy matters.


Part XXIII β€” Memory Forensics

46. RAM Can Contain

Depending on the system:

  • running processes;

  • network information;

  • loaded code;

  • credentials or key material;

  • malware artifacts.


47. Memory Is Volatile

Once power is removed:

RAM evidence is generally lost.


Part XXIV β€” Disk Imaging

48. Forensic Image

A forensic image attempts to create a reliable copy of digital storage for analysis.


49. Analyze the Copy

Conceptually:

ORIGINAL MEDIA
β”‚
β–Ό
FORENSIC IMAGE
β”‚
β–Ό
WORKING COPY
β”‚
β–Ό
ANALYSIS

This helps preserve the original.


Part XXV β€” Write Protection

50. Write Blocker

A forensic write-blocking mechanism can help prevent examination activity from modifying source media during acquisition or analysis.


51. Objective

Protect the integrity of original evidence.


Part XXVI β€” Hashing Evidence

52. Cryptographic Hash

A hash can help verify that collected data has not changed.

EVIDENCE
β”‚
β–Ό
HASH
β”‚
β–Ό
DIGEST A

LATER COPY
β”‚
β–Ό
HASH
β”‚
β–Ό
DIGEST B

A = B?

53. Important Exam Trap

A matching hash supports:

data integrity.

It does not by itself establish:

  • who collected the evidence;

  • why it is relevant;

  • proper chain of custody.


Part XXVII β€” Working Copy

54. Protect Originals

Where practical:

analyze verified copies rather than repeatedly manipulating original evidence.


Part XXVIII β€” Timeline Analysis

55. Timeline

Investigators may correlate:

  • login time;

  • process start;

  • file modification;

  • network connection;

  • alert generation.


56. Example

02:14 Login
02:16 PowerShell starts
02:18 External connection
02:20 Credential access alert
02:25 Large outbound transfer

Part XXIX β€” Timestamp Problems

57. Timestamps Can Differ

Systems may use:

  • UTC;

  • local time;

  • different time zones;

  • unsynchronized clocks.


58. Daylight Saving Time

Time conversion can further complicate timelines.

Document:

  • source timezone;

  • normalization method.


Part XXX β€” Time Synchronization

59. Why Synchronization Matters

Consider:

FIREWALL: 13:05
SERVER: 13:12
SIEM: 13:08

Correlation becomes difficult.


60. Operational Principle

Security infrastructure should maintain sufficiently reliable time synchronization for:

  • investigations;

  • correlation;

  • auditing.


Part XXXI β€” Artifact

61. Digital Artifact

An artifact is data that may provide evidence about:

  • actions;

  • system state;

  • communications;

  • identity behavior.

The current CISSP outline explicitly identifies data, computer, network, and mobile-device artifacts.


Part XXXII β€” Computer Artifacts

62. Examples

Depending on platform:

  • files;

  • registry/configuration artifacts;

  • process history;

  • browser data;

  • event logs;

  • installed software.


Part XXXIII β€” Network Artifacts

63. Examples

  • firewall logs;

  • DNS records;

  • proxy logs;

  • packet captures;

  • NetFlow/flow records;

  • VPN logs.


Part XXXIV β€” Mobile Artifacts

64. Examples

Depending on device and authorization:

  • application data;

  • call/message metadata;

  • location artifacts;

  • browser history;

  • authentication records.


Part XXXV β€” Application Artifacts

65. Examples

  • authentication logs;

  • application transactions;

  • API logs;

  • database activity.


Part XXXVI β€” Cloud Artifacts

66. Modern Investigation Context

Cloud environments can contain:

  • identity-provider logs;

  • API activity;

  • cloud audit trails;

  • object-access logs;

  • administrative events.

Cloud evidence may be controlled partly by:

the provider.


Part XXXVII β€” Artifact Correlation

67. One Artifact Rarely Tells Everything

Example:

VPN LOG
Alice logged in

ENDPOINT LOG
PowerShell executed

DNS LOG
Unknown domain queried

PROXY LOG
Large upload occurred

Together they create a richer picture.


Part XXXVIII β€” Log Defined

68. Log

A log is a record of events occurring within computing systems, services, or networks.

The draft NIST SP 800-92 Rev. 1 describes logs as records of events involving physical/virtual platforms, networks, services, and cloud environments.


Part XXXIX β€” Why Log

69. Logging Supports

  • detection;

  • investigation;

  • accountability;

  • operations;

  • compliance;

  • troubleshooting.


Part XL β€” Log Management

70. Lifecycle

NIST describes log management as including:

  • generation;

  • transmission;

  • storage;

  • access;

  • disposal.


71. Log Lifecycle Diagram

GENERATE
↓
COLLECT
↓
TRANSMIT
↓
STORE
↓
ANALYZE
↓
RETAIN
↓
DISPOSE

Part XLI β€” Log Sources

72. Operating Systems

May record:

  • logon;

  • privilege use;

  • process/service events;

  • system errors.


73. Applications

May record:

  • user actions;

  • authentication;

  • transactions;

  • errors.


74. Network Devices

May record:

  • allowed/blocked connections;

  • configuration changes;

  • routing/security events.


75. Identity Systems

May record:

  • login;

  • MFA events;

  • privilege changes;

  • federation events.


76. Cloud Services

May record:

  • administrative actions;

  • resource changes;

  • authentication;

  • API activity.


Part XLII β€” What Should Be Logged?

77. Requirement Driven

Logging should reflect:

  • risk;

  • system function;

  • investigation need;

  • privacy/legal obligations;

  • monitoring objectives.


78. Avoid Two Extremes

Too little:

no evidence.

Too much without strategy:

enormous cost and unusable noise.


Part XLIII β€” Centralized Logging

79. Central Collection

SERVER LOGS ──┐
FIREWALLS ─────
ENDPOINTS ────┼──► CENTRAL LOG PLATFORM
CLOUD ─────────
IDENTITY β”€β”€β”€β”€β”€β”˜

80. Advantages

  • cross-system correlation;

  • centralized retention;

  • easier investigation;

  • reduced reliance on compromised endpoints.


Part XLIV β€” Log Forwarding

81. Local Logs Can Be Attacked

An attacker with administrator access may attempt to:

  • delete;

  • alter;

  • disable local logging.

Forwarding important records centrally can improve resilience.


Part XLV β€” Log Integrity

82. Protect Logs

Security controls may include:

  • access restrictions;

  • integrity protections;

  • centralized storage;

  • immutable/WORM-style storage where appropriate.


83. Why?

An attacker who can alter evidence may conceal:

unauthorized activity.


Part XLVI β€” Log Confidentiality

84. Logs May Contain Sensitive Information

Examples:

  • usernames;

  • IP addresses;

  • URLs;

  • system details;

  • personal information.

Protect logs according to sensitivity.


Part XLVII β€” Log Retention

85. Retention Should Be Defined

Factors may include:

  • investigation needs;

  • regulation;

  • business requirements;

  • storage cost;

  • privacy.


86. CISSP Trap

There is no universal:

β€œKeep every log for X years.”

Retention is requirement driven.


Part XLVIII β€” SIEM

87. Security Information and Event Management

A SIEM centralizes and analyzes security information from multiple sources.


88. Simplified SIEM Architecture

LOG SOURCES
β”‚
β–Ό
COLLECT
β”‚
β–Ό
NORMALIZE
β”‚
β–Ό
CORRELATE
β”‚
β–Ό
DETECT
β”‚
β–Ό
ALERT
β”‚
β–Ό
ANALYST

Part XLIX β€” Normalization

89. Different Formats

Firewall:

source=10.1.1.4

Application:

client_ip=10.1.1.4

Normalization maps fields into a consistent representation.


Part L β€” Correlation

90. Correlation

Correlation identifies relationships among multiple events.

Example:

FAILED LOGINS
+
SUCCESSFUL LOGIN
+
NEW ADMIN ROLE
+
LARGE DOWNLOAD
=
HIGH-PRIORITY ALERT

Part LI β€” SIEM Is Not Magic

91. A SIEM Requires

  • reliable data;

  • good use cases;

  • tuning;

  • analyst processes.


92. Garbage In, Garbage Out

If the system does not receive:

identity logs,

it cannot reliably detect identity events dependent on those logs.


Part LII β€” Detection Rule

93. Detection Use Case

A rule may identify:

five failed logins followed by successful privileged authentication from a new location.


Part LIII β€” Tuning

94. Tuning

Tuning adjusts detection logic to improve:

  • relevance;

  • accuracy;

  • operational usefulness.

Continuous monitoring and tuning are specifically included in current CISSP Objective 7.2.


Part LIV β€” False Positive

95. Detection False Positive

Alert says:

malicious activity.

Reality:

legitimate activity.


Part LV β€” False Negative

96. Detection False Negative

Malicious activity occurs.

Detection system:

produces no useful alert.

This can be particularly dangerous.


Part LVI β€” Alert Fatigue

97. Too Many Low-Value Alerts

Analysts can become overwhelmed.

Result:

  • important alerts missed;

  • slow response;

  • poor morale.


98. CISSP Principle

The objective is not:

maximum alerts.

It is:

useful detection and response.


Part LVII β€” IDS

99. Intrusion Detection System

IDS identifies potentially malicious or policy-violating activity.

Primary function:

detect and alert.


Part LVIII β€” IPS

100. Intrusion Prevention System

IPS can detect and actively:

  • block;

  • drop;

  • prevent

selected activity.


Part LIX β€” IDS vs IPS

101.

IDSIPS
DetectsDetects + can prevent
Often passive/out-of-bandOften inline
Lower direct disruption riskIncorrect blocking can affect availability

Part LX β€” Network-Based IDPS

102. Network-Based

Monitors network communications.

Strengths:

  • broad network visibility.

Limitations:

  • encrypted payload visibility;

  • host-local activity may be missed.


Part LXI β€” Host-Based Detection

103. Host-Based

Monitors activity on endpoints/servers.

Can observe:

  • processes;

  • files;

  • local events;

  • endpoint behavior.


Part LXII β€” Signature Detection

104. Signature-Based

Matches activity against known patterns.

Strength:

reliable recognition of known patterns.

Weakness:

may miss new/unrecognized techniques.


Part LXIII β€” Anomaly Detection

105. Anomaly-Based

Identifies deviation from expected behavior.

Strength:

can detect unusual activity not represented by a known signature.

Weakness:

normal unusual activity may create false positives.


Part LXIV β€” Detection in Depth

106. Combine Methods

SIGNATURE
+
BEHAVIOR
+
ENDPOINT
+
NETWORK
+
IDENTITY
=
BETTER DETECTION CONTEXT

Part LXV β€” Continuous Monitoring

107. Continuous Does Not Mean Human Watching Every Screen

Continuous monitoring means ongoing collection and evaluation appropriate to:

  • risk;

  • control objectives;

  • organizational capabilities.


Part LXVI β€” Monitoring Objectives

108. Examples

  • detect unauthorized privilege changes;

  • monitor critical configuration;

  • identify malware;

  • detect unusual outbound traffic.


Part LXVII β€” Tuning Is Continuous

109. Environments Change

New:

  • applications;

  • users;

  • business processes;

  • attacks

can make yesterday's detection rules less effective.


Part LXVIII β€” Egress Monitoring

110. Egress

Egress monitoring examines traffic:

leaving the organization or protected environment.

It is explicitly included in current Objective 7.2.


Part LXIX β€” Why Egress Matters

111. Many Controls Focus on Incoming Traffic

But compromised systems may communicate:

outward.


112. Egress Examples

Monitor for:

  • unusual destinations;

  • large transfers;

  • command-and-control traffic;

  • unauthorized protocols.


Part LXX β€” Exfiltration Detection

113. Example

WORKSTATION
β”‚
β–Ό
10 GB outbound transfer
β”‚
β–Ό
UNKNOWN EXTERNAL HOST

Could indicate:

  • legitimate backup;

  • cloud sync;

  • exfiltration.

Investigation determines context.


Part LXXI β€” Threat Data

114. Raw Threat Data

Examples:

  • IP address;

  • malware hash;

  • suspicious domain;

  • CVE.

Raw data alone is not necessarily intelligence.


Part LXXII β€” Threat Information

115. Information

Data becomes more useful when contextualized.

Example:

Domain X is associated with a current phishing campaign targeting financial institutions.


Part LXXIII β€” Threat Intelligence

116. Intelligence

Threat intelligence is analyzed and contextualized information useful for security decisions.


117. Intelligence Question

What does this threat information mean for our organization?


Part LXXIV β€” Threat Intelligence Lifecycle

118. Useful Model

REQUIREMENTS
↓
COLLECTION
↓
PROCESSING
↓
ANALYSIS
↓
DISSEMINATION
↓
FEEDBACK

Part LXXV β€” Intelligence Requirements

119. Start With Organizational Needs

Poor approach:

Subscribe to 200 feeds.

Better:

Determine what threats matter to our assets, sector, geography, and mission.


Part LXXVI β€” Indicator of Compromise

120. IOC

An Indicator of Compromise may be an observable associated with malicious activity.

Examples:

  • malicious IP;

  • file hash;

  • suspicious domain.


Part LXXVII β€” IOC Limitation

121. Indicators Can Change

Attackers can quickly change:

  • IP addresses;

  • domains;

  • file hashes.

Therefore IOCs may become stale.


Part LXXVIII β€” Tactics, Techniques, and Procedures

122. TTPs

Higher-level adversary behavior can sometimes remain useful longer than specific IOCs.

Think:

How does the adversary operate?

rather than only:

Which IP did they use yesterday?


Part LXXIX β€” Threat Feeds

123. Threat Feed

A feed can provide:

  • indicators;

  • vulnerabilities;

  • reputation data;

  • campaign information.


124. More Feeds β‰  Better Intelligence

Evaluate:

  • accuracy;

  • timeliness;

  • relevance;

  • duplication.


Part LXXX β€” Threat Intelligence Use

125. Examples

Threat intelligence can help:

  • prioritize vulnerability remediation;

  • enrich SIEM alerts;

  • block known malicious infrastructure;

  • guide hunting.


Part LXXXI β€” Threat Hunting

126. Threat Hunting

Threat hunting proactively searches for potentially malicious activity that existing automated controls may not have identified.

Threat hunting is explicitly included under threat intelligence in current CISSP Objective 7.2.


Part LXXXII β€” Hunting Is Not Random Searching

127. Hypothesis

Example:

If an attacker obtained administrative credentials, we may observe privileged authentication from unusual endpoints followed by remote administration.


Part LXXXIII β€” Hunt Flow

128.

HYPOTHESIS
β”‚
β–Ό
IDENTIFY DATA
β”‚
β–Ό
QUERY
β”‚
β–Ό
ANALYZE
β”‚
β–Ό
FINDINGS
β”‚
β”Œβ”€β”΄β”€β”€β”
NONE SUSPICIOUS
β”‚
β–Ό
INVESTIGATE

Part LXXXIV β€” Hunting Outcomes

129. Even a Hunt That Finds No Attack Can Provide Value

It may reveal:

  • missing telemetry;

  • weak detection coverage;

  • poor logging.


Part LXXXV β€” Detection Engineering Feedback

130. Hunt-to-Detection

HUNT FINDS PATTERN
β”‚
β–Ό
CREATE DETECTION
β”‚
β–Ό
AUTOMATE MONITORING

This turns manual learning into repeatable protection.


Part LXXXVI β€” UEBA

131. User and Entity Behavior Analytics

UEBA analyzes behavior associated with:

  • users;

  • devices;

  • services;

  • other entities.

UEBA is explicitly listed in CISSP Objective 7.2.


Part LXXXVII β€” Behavioral Baseline

132. Example

Normal user:

  • logs in 08:00–17:00;

  • downloads 20 files/day;

  • uses US office.

Suddenly:

  • logs in 03:00;

  • accesses 10,000 records;

  • uses new device.

UEBA may increase:

risk or anomaly score.


Part LXXXVIII β€” UEBA Does Not Prove Malice

133. Anomaly β‰  Attack

User may be:

  • traveling;

  • working emergency shift;

  • performing legitimate project work.

Behavioral systems provide:

investigative signals.


Part LXXXIX β€” Baseline Challenge

134. Normal Behavior Changes

Organizations constantly change.

Therefore behavioral models require:

  • tuning;

  • updated baselines;

  • analyst judgment.


Part XC β€” Entity Behavior

135. Not Only Humans

UEBA may detect unusual behavior by:

  • service accounts;

  • servers;

  • applications.


Part XCI β€” Example Service Identity

136.

Normal:

service account accesses Database A only.

New behavior:

service account authenticates interactively to ten servers.

This may warrant investigation.


Part XCII β€” Operational Accountability

137. Domain 7.4 Foundation

The current outline includes:

  • need to know;

  • least privilege;

  • separation of duties;

  • privileged-account management;

  • job rotation;

  • SLAs.

These principles matter directly to investigation and monitoring.


Part XCIII β€” Need to Know

138. Investigators May See Sensitive Data

Investigation access should be limited to:

information necessary for the assigned responsibility.


Part XCIV β€” Least Privilege

139. Monitoring Tools Are Powerful

A SIEM administrator may access:

  • sensitive logs;

  • security alerts;

  • identity activity.

Grant only necessary privilege.


Part XCV β€” Separation of Duties

140. Example

An administrator should not always have unchecked ability to:

  • make sensitive changes;

  • delete audit evidence;

  • approve their own activity.


Part XCVI β€” Security Operations SoD

141.

SYSTEM ADMIN
Changes system

SECURITY MONITOR
Observes security events

AUDITOR
Reviews evidence

The exact structure depends on organizational size and risk.


Part XCVII β€” Privileged Account Management

142. High-Value Activity

Privileged accounts should be:

  • individually attributable where practical;

  • strongly authenticated;

  • monitored;

  • reviewed.


Part XCVIII β€” Privileged Event

143. Example

Creation of:

a new domain administrator

should be considered a high-value security event.


Part XCIX β€” Job Rotation

144. Job Rotation

Job rotation can:

  • reduce dependence on one person;

  • expose hidden irregularities;

  • support cross-training.


145. Fraud Detection Context

If one employee controls a sensitive function indefinitely:

misconduct may remain hidden.

Rotation can introduce independent observation.


Part C β€” Mandatory Vacation Concept

146. Related Principle

In some high-risk financial or operational contexts, requiring personnel to be absent for a period may reveal fraud dependent on continuous concealment.

Treat this as:

risk-based organizational practice,

not a universal requirement.


Part CI β€” Service-Level Agreement

147. SLA

An SLA establishes measurable service commitments.

Operational security examples:

  • incident-response time;

  • monitoring availability;

  • provider notification.


Part CII β€” SLA Is Not an Incident Plan

148. Important Distinction

An SLA tells you:

expected service performance.

An incident-response plan tells you:

what the organization does when security events occur.


Part CIII β€” Detection Pipeline

149. End-to-End Monitoring

EVENT OCCURS
β”‚
β–Ό
LOG CREATED
β”‚
β–Ό
LOG FORWARDED
β”‚
β–Ό
SIEM INGESTS
β”‚
β–Ό
DETECTION FIRES
β”‚
β–Ό
ANALYST REVIEWS
β”‚
β–Ό
INVESTIGATION

Part CIV β€” Pipeline Failure

150. Failure Can Occur Anywhere

  • logging disabled;

  • forwarding fails;

  • parser fails;

  • detection absent;

  • alert ignored.


Part CV β€” Control Testing

151. Security Operations Should Test the Pipeline

Example:

Generate an authorized synthetic suspicious event and verify it reaches the analyst.

This connects Domain 6 testing with Domain 7 operations.


Part CVI β€” Logging Failure Scenario

152.

Endpoint creates alert.

SIEM does not receive it.

Question:

Is endpoint detection the problem?

Not necessarily.

The failure may be:

collection or transmission.


Part CVII β€” Corroboration

153. Strong Investigation

IDENTITY LOG
+
ENDPOINT LOG
+
NETWORK LOG
+
APPLICATION LOG
=
CORROBORATED TIMELINE

Part CVIII β€” Evidence From Security Tools

154. Security Tool Output Is Evidence, Not Absolute Truth

An EDR alert can contain:

  • detection logic;

  • false positives;

  • missing context.

Validate appropriately.


Part CIX β€” Evidence Preservation During Response

155. Operational Tension

Security may need to:

stop an active attack immediately.

Forensics may want to:

preserve evidence.


156. CISSP Mindset

The organization's primary duty may include protecting:

  • people;

  • mission;

  • critical operations.

Do not allow evidence collection to create unacceptable additional harm.


Part CX β€” Evidence vs Containment

157. Example

Malware is actively destroying production data.

Do not wait indefinitely for perfect forensic preservation while:

business-critical information is being destroyed.

Use authorized procedures balancing:

  • containment;

  • evidence needs;

  • business impact.


Part CXI β€” Investigation Privacy

158. Monitoring Can Expose Personal Information

Security investigations may reveal:

  • communications;

  • locations;

  • browsing;

  • employee activity.

Follow:

  • policy;

  • law;

  • legitimate purpose;

  • access restrictions.


Part CXII β€” Minimum Necessary Evidence

159. Investigators Should Avoid Unnecessary Collection

More evidence is not automatically better if collection creates:

  • privacy risk;

  • storage risk;

  • scope violations.


Part CXIII β€” SIEM Retention

160. Storage Tradeoff

Long retention provides:

  • historical investigation capability.

But increases:

  • storage;

  • privacy;

  • protection obligations.


Part CXIV β€” Detection Latency

161. Time Matters

Useful metrics include:

  • time to detect;

  • time to triage;

  • time to escalate.

Detailed incident-response metrics will be covered later.


Part CXV β€” SOC Prioritization

162. Not Every Alert Is Equal

A SOC may prioritize using:

  • asset criticality;

  • confidence;

  • severity;

  • threat intelligence;

  • user privilege.


Part CXVI β€” High-Privilege Identity

163. Example

An unusual login by:

cafeteria kiosk account

and an unusual login by:

domain administrator

should not necessarily receive identical priority.


Part CXVII β€” Context-Enriched Alert

164.

ALERT
+
ASSET CRITICALITY
+
IDENTITY PRIVILEGE
+
THREAT INTELLIGENCE
+
BEHAVIOR
=
BETTER TRIAGE

Part CXVIII β€” Automation

165. Automation Can Assist

Examples:

  • enrichment;

  • deduplication;

  • initial prioritization;

  • containment workflows.


166. But Automation Needs Governance

Automated false decisions can:

  • block legitimate users;

  • isolate critical systems;

  • create outages.


Part CXIX β€” AI/ML in Security Operations

167. Supporting Technology

Modern security tools may use machine-learning or AI-based methods for:

  • anomaly detection;

  • alert correlation;

  • prioritization.

The CISSP outline also explicitly lists machine-learning and AI-based tools under Domain 7.7's detection/prevention measures, which will be covered in a later lesson.


168. AI Output Requires Validation

AI-generated:

  • summary;

  • alert;

  • investigation hypothesis

should not automatically be treated as:

verified evidence.


Part CXX β€” SierraTec Secure TRACE Model

169. TRACE Framework

Use TRACE for investigation and evidence questions.

T β€” Trigger and Authority

Why is the investigation occurring, and who authorized it?

R β€” Retain and Protect Evidence

Preserve volatile and persistent evidence appropriately.

A β€” Analyze Correlated Artifacts

Use multiple trustworthy sources.

C β€” Chronicle Custody and Actions

Document who did what, when, and why.

E β€” Explain Findings and Limitations

Report evidence-supported conclusions without overstatement.


Part CXXI β€” TRACE Diagram

170.

T
TRIGGER / AUTHORITY
β”‚
β–Ό
R
RETAIN EVIDENCE
β”‚
β–Ό
A
ANALYZE ARTIFACTS
β”‚
β–Ό
C
CHRONICLE CUSTODY
β”‚
β–Ό
E
EXPLAIN FINDINGS

Part CXXII β€” SierraTec Secure SIGNAL Model

171. SIGNAL Framework

Use SIGNAL for logging and monitoring questions.

S β€” Select Important Events

Determine what needs to be logged.

I β€” Integrate Sources

Centralize relevant telemetry.

G β€” Guard Integrity

Protect logs from unauthorized modification.

N β€” Normalize and Correlate

Create meaningful context.

A β€” Alert and Analyze

Tune detection for actionable outcomes.

L β€” Learn and Improve

Feed incidents and hunts back into better monitoring.


Part CXXIII β€” SIGNAL Diagram

172.

S
SELECT EVENTS
β”‚
β–Ό
I
INTEGRATE SOURCES
β”‚
β–Ό
G
GUARD INTEGRITY
β”‚
β–Ό
N
NORMALIZE / CORRELATE
β”‚
β–Ό
A
ALERT / ANALYZE
β”‚
β–Ό
L
LEARN / IMPROVE

Part CXXIV β€” Worked Scenario 1: Evidence

173.

An administrator suspects malware on a live server. Memory may contain evidence that will disappear when the system is powered off.

What should the investigator consider?

A. Appropriately collecting volatile evidence before shutdown when authorized and operationally safe.

B. Always power off immediately regardless of investigation requirements.

C. Delete all logs.

D. Reinstall before documentation.

Correct Answer

A


Part CXXV β€” Scenario 2: Chain of Custody

174.

A forensic drive passes through several analysts, but nobody documented the transfers.

What is the PRIMARY concern?

A. Weak chain-of-custody documentation.

B. Excessive encryption.

C. Too much logging.

D. Network latency.

Correct Answer

A


Part CXXVI β€” Scenario 3: Hash

175.

An investigator hashes a disk image immediately after acquisition and again before analysis. The values match.

What does this MOST directly support?

A. Evidence integrity.

B. Proof that the suspect committed the act.

C. Authorization to investigate.

D. Chain of custody by itself.

Correct Answer

A


Part CXXVII β€” Scenario 4: Time

176.

Firewall timestamps and server timestamps differ by 12 minutes, making reconstruction difficult.

What control would have MOST directly reduced this problem?

A. Consistent time synchronization.

B. Disk encryption.

C. Data classification.

D. Increased bandwidth.

Correct Answer

A


Part CXXVIII β€” Scenario 5: SIEM

177.

Security wants to correlate authentication, firewall, endpoint, and cloud events centrally.

Which technology is MOST appropriate?

A. SIEM.

B. UPS.

C. RAID.

D. VLAN.

Correct Answer

A


Part CXXIX β€” Scenario 6: False Positives

178.

A SIEM produces thousands of alerts for legitimate scheduled administration every evening.

What is the BEST response?

A. Tune the detection while preserving ability to identify genuinely suspicious activity.

B. Disable all monitoring.

C. Ignore every evening alert permanently without analysis.

D. Remove administrative logs.

Correct Answer

A


Part CXXX β€” Scenario 7: IDS vs IPS

179.

An organization wants a control to detect suspicious traffic but not automatically block production connections.

Which technology mode BEST fits?

A. IDS.

B. Inline IPS configured to block.

C. Data-destruction tool.

D. Backup appliance.

Correct Answer

A


Part CXXXI β€” Scenario 8: Egress

180.

A workstation transfers 40 GB to an unfamiliar external host at 03:00.

Which monitoring activity is MOST relevant?

A. Egress monitoring.

B. Physical visitor logging only.

C. Printer monitoring.

D. UPS monitoring.

Correct Answer

A


Part CXXXII β€” Scenario 9: Threat Intelligence

181.

A threat feed contains 100,000 IP addresses, most unrelated to the organization's sector or assets.

What should the security team do?

A. Prioritize relevant, reliable, timely intelligence rather than assuming more indicators always provide more value.

B. Block the entire Internet.

C. Treat every indicator as equally important forever.

D. Disable threat intelligence.

Correct Answer

A


Part CXXXIII β€” Scenario 10: Threat Hunt

182.

Analysts suspect attackers may be using legitimate remote-administration tools to move laterally but no alert has fired.

What activity BEST fits?

A. Hypothesis-driven threat hunting.

B. Backup restoration.

C. Physical inventory only.

D. Risk acceptance.

Correct Answer

A


Part CXXXIV β€” Scenario 11: UEBA

183.

A service account that normally accesses one database begins authenticating interactively to twenty workstations.

Which technology may be especially useful for identifying this deviation?

A. UEBA.

B. RAID.

C. HVAC.

D. DNSSEC only.

Correct Answer

A


Part CXXXV β€” Scenario 12: Anomaly

184.

UEBA flags a user's overseas login as anomalous, but investigation confirms the employee is traveling for approved business.

What is this BEST viewed as?

A. An anomalous signal requiring context, not automatic proof of compromise.

B. Confirmed malware.

C. Proof that UEBA is useless.

D. Chain-of-custody failure.

Correct Answer

A


Part CXXXVI β€” Scenario 13: Log Integrity

185.

Attackers compromise a server with local administrator access and delete local event logs.

Which design would have BEST improved evidence resilience?

A. Forwarding important logs to appropriately protected centralized storage.

B. Keeping all logs only on the compromised server.

C. Disabling central logging.

D. Sharing the log-administrator password.

Correct Answer

A


Part CXXXVII β€” Scenario 14: Evidence vs Operations

186.

Malware is actively encrypting a hospital's critical production systems. An analyst wants to delay containment for several hours to collect perfect forensic evidence.

What is the BEST CISSP response?

A. Follow authorized incident procedures and balance evidence preservation against protection of critical operations and safety.

B. Always preserve evidence regardless of operational harm.

C. Ignore the malware.

D. Delete all evidence.

Correct Answer

A


Part CXXXVIII β€” Scenario 15: Least Privilege

187.

Every SOC analyst has unrestricted ability to delete SIEM data.

What principle is MOST clearly violated?

A. Least privilege.

B. Availability planning.

C. Data classification only.

D. Encryption.

Correct Answer

A


Part CXXXIX β€” Scenario 16: Separation of Duties

188.

One administrator can modify critical security settings, erase audit logs, and approve the change afterward.

What is the PRIMARY concern?

A. Inadequate separation of duties.

B. Too much threat intelligence.

C. Strong chain of custody.

D. Excessive backup frequency.

Correct Answer

A


Part CXL β€” Scenario 17: Logging

189.

A security application produces excellent alerts locally, but its logs are never forwarded to the SOC.

What is the PRIMARY problem?

A. Monitoring visibility/collection gap.

B. The local security control necessarily failed.

C. Encryption is too strong.

D. The asset is automatically secure.

Correct Answer

A


Part CXLI β€” Scenario 18: Investigation Report

190.

An investigator believes an employee exfiltrated files but has only circumstantial network data.

What is the BEST reporting approach?

A. Clearly distinguish observed evidence, analytical inference, and limitations.

B. Present suspicion as proven fact.

C. Delete conflicting evidence.

D. Avoid documenting limitations.

Correct Answer

A


Part CXLII β€” Common CISSP Exam Traps

191. Trap β€” Every Security Event Is an Incident

No.

Events require:

context.


192. Trap β€” Investigator Should Immediately Collect Everything

No.

Collection should be:

  • authorized;

  • relevant;

  • appropriately scoped.


193. Trap β€” Chain of Custody Is Only for Criminal Cases

CISSP candidates should understand chain-of-custody documentation as valuable whenever evidence integrity and handling accountability matter.


194. Trap β€” Hash Proves Who Committed the Attack

No.

Hashing supports evidence integrity.


195. Trap β€” Always Shut Down a Suspected System First

No.

Shutdown may destroy volatile evidence.

But operational risk may still require rapid isolation or shutdown.

Use authorized procedures and judgment.


196. Trap β€” Never Touch a Live System

Impossible in many investigations.

Live collection changes state, so:

document and minimize changes.


197. Trap β€” Forensics Always Takes Priority Over Business Operations

No.

Protecting:

  • life;

  • safety;

  • mission;

  • critical assets

may take priority.


198. Trap β€” Local Logs Are Always Trustworthy

A compromised administrator may alter local records.

Corroborate and centralize where appropriate.


199. Trap β€” More Logs Always Means Better Security

No.

Logging must be:

  • purposeful;

  • manageable;

  • protected.


200. Trap β€” SIEM Automatically Detects Everything

No.

SIEM depends on:

  • data;

  • parsers;

  • detection rules;

  • tuning;

  • analysts.


201. Trap β€” IDS Blocks Threats

IDS primarily detects.

IPS can actively prevent/block.


202. Trap β€” Signature Detection Finds Every Attack

No.

It may miss unknown or modified behavior.


203. Trap β€” Anomaly Detection Proves Malicious Activity

No.

Anomaly means:

deviation from baseline.

Investigate context.


204. Trap β€” Threat Feed Equals Threat Intelligence

Raw indicators become intelligence only after:

context and analysis.


205. Trap β€” More Threat Feeds Are Always Better

No.

Quality and relevance matter.


206. Trap β€” Threat Hunting Is Random Log Searching

Good hunting is generally:

hypothesis and intelligence driven.


207. Trap β€” UEBA Applies Only to Human Users

No.

It may evaluate:

  • users;

  • systems;

  • service accounts;

  • other entities.


208. Trap β€” Log Retention Has One CISSP-Approved Duration

No.

Retention depends on:

  • legal;

  • regulatory;

  • business;

  • investigative requirements.


209. Trap β€” Investigators Decide Legal Admissibility Alone

No.

Legal standards vary, and counsel/appropriate authorities should be involved when required.


Part CXLIII β€” Knowledge Check

210. Question 1

What is the PRIMARY purpose of chain-of-custody documentation?

A. Track possession and handling of evidence.

B. Encrypt all evidence.

C. Determine guilt automatically.

D. Replace investigation notes.

Correct Answer

A


211. Question 2

Which evidence type is generally most likely to disappear when power is removed?

A. RAM contents.

B. Archived backup tape.

C. Printed report.

D. Retained disk image.

Correct Answer

A


212. Question 3

What is the primary purpose of hashing forensic evidence?

A. Support verification of integrity.

B. Prove identity of attacker.

C. Provide physical access.

D. Replace chain of custody.

Correct Answer

A


213. Question 4

Why should investigators document live-system actions?

A. The actions can change system state.

B. Documentation automatically prevents malware.

C. Live systems contain no evidence.

D. Hashing is impossible.

Correct Answer

A


214. Question 5

Which system commonly centralizes and correlates security events?

A. SIEM.

B. UPS.

C. RAID.

D. HVAC.

Correct Answer

A


215. Question 6

What does normalization do?

A. Maps different event formats into more consistent fields/structures.

B. Deletes logs.

C. Encrypts every event.

D. Creates user identities.

Correct Answer

A


216. Question 7

What does correlation do?

A. Identifies meaningful relationships among events.

B. Replaces authentication.

C. Eliminates incidents.

D. Creates backup media.

Correct Answer

A


217. Question 8

Which technology primarily detects suspicious network activity without necessarily blocking it?

A. IDS.

B. IPS in blocking mode.

C. RAID.

D. UPS.

Correct Answer

A


218. Question 9

What does an IPS add beyond basic detection capability?

A. Ability to actively block/prevent selected traffic.

B. Physical access.

C. Data classification.

D. Backup restoration.

Correct Answer

A


219. Question 10

What is egress monitoring primarily concerned with?

A. Outbound traffic.

B. Building entry.

C. Incoming mail.

D. Backup storage only.

Correct Answer

A


220. Question 11

What is threat intelligence?

A. Analyzed and contextualized threat information useful for decisions.

B. Every raw IP address.

C. A firewall rule only.

D. A backup schedule.

Correct Answer

A


221. Question 12

What is an IOC?

A. Observable potentially associated with malicious activity.

B. Business-impact analysis.

C. Authentication factor.

D. Security policy.

Correct Answer

A


222. Question 13

What is threat hunting?

A. Proactive searching for potentially malicious activity not necessarily identified by automated controls.

B. Random deletion of alerts.

C. Backup verification.

D. Security awareness training.

Correct Answer

A


223. Question 14

What is UEBA designed to analyze?

A. Behavioral patterns involving users and entities.

B. Only physical locks.

C. Only encryption algorithms.

D. Only backups.

Correct Answer

A


224. Question 15

What does an anomaly indicate?

A. Behavior differs from expected baseline.

B. Malicious activity is conclusively proven.

C. Evidence is inadmissible.

D. Logs are encrypted.

Correct Answer

A


225. Question 16

Why centralize logs?

A. Support correlation, monitoring, retention, and evidence resilience.

B. Eliminate access control.

C. Prevent every attack.

D. Remove time synchronization.

Correct Answer

A


226. Question 17

Why protect log integrity?

A. Prevent unauthorized alteration of security evidence.

B. Increase network bandwidth.

C. Shorten passwords.

D. Eliminate auditing.

Correct Answer

A


227. Question 18

What is the primary operational risk of excessive false-positive alerts?

A. Alert fatigue can obscure important events.

B. Increased cryptographic strength.

C. Improved availability.

D. Better chain of custody.

Correct Answer

A


228. Question 19

What does separation of duties reduce?

A. Concentration of sensitive authority.

B. Logging coverage.

C. Authentication assurance.

D. Backup integrity.

Correct Answer

A


229. Question 20

What is the BEST description of security investigation reporting?

A. Evidence-supported conclusions with clear documentation and limitations.

B. Investigator opinion without evidence.

C. Only raw logs.

D. Unverified allegations.

Correct Answer

A


Part CXLIV β€” Original CISSP-Style Practice Questions

230. Practice Question 1

A server suspected of compromise contains encryption keys only in memory. Operations plans an immediate power-off.

What should the incident team consider FIRST?

A. Whether authorized volatile-memory collection is necessary and operationally appropriate before shutdown.

B. Always power off before thinking about evidence.

C. Delete memory.

D. Reformat the server.

Correct Answer

A


231. Practice Question 2

A forensic analyst receives a drive but cannot determine who handled it during the previous six hours.

Which evidence-control process failed?

A. Chain of custody.

B. Vulnerability management.

C. Change management.

D. Business continuity.

Correct Answer

A


232. Practice Question 3

An investigator creates a forensic image, validates its hash, and performs all analysis using a working copy.

What principle is BEST demonstrated?

A. Preservation of original evidence integrity.

B. Elimination of documentation.

C. Risk acceptance.

D. Privileged escalation.

Correct Answer

A


233. Practice Question 4

A company receives 25 million security events per day, but the SOC has no defined detection use cases.

What is the BEST improvement?

A. Define risk-based monitoring objectives and detection use cases before simply increasing log volume.

B. Collect 50 million events instead.

C. Disable the SIEM.

D. Delete all identity logs.

Correct Answer

A


234. Practice Question 5

A detection rule identifies known malware accurately but fails to identify new variants with different signatures.

What limitation is MOST clearly demonstrated?

A. Signature-based detection may miss unknown or changed patterns.

B. Anomaly detection is impossible.

C. SIEM cannot use signatures.

D. Malware cannot change.

Correct Answer

A


235. Practice Question 6

A UEBA platform flags an employee who downloads 5,000 files, but the employee is performing an authorized migration.

What is the BEST analyst response?

A. Investigate and contextualize the anomaly rather than automatically declaring compromise.

B. Terminate the employee immediately.

C. Disable all behavioral monitoring.

D. Delete the alert without review.

Correct Answer

A


236. Practice Question 7

A SOC subscribes to dozens of intelligence feeds but cannot identify which indicators are relevant to its industry or assets.

What should security management improve?

A. Threat-intelligence requirements, relevance analysis, and prioritization.

B. Number of feeds only.

C. Password rotation.

D. Backup storage.

Correct Answer

A


237. Practice Question 8

A hunt discovers repeated remote administration from unusual endpoints but the SIEM has no detection for this behavior.

What is the BEST next step after investigation?

A. Use the hunting insight to improve a repeatable detection use case where appropriate.

B. Keep the knowledge only with the hunter.

C. Delete the hunt evidence.

D. Disable remote access entirely without analysis.

Correct Answer

A


238. Practice Question 9

An attacker gains local administrator privileges on a workstation and deletes its logs. The centralized log server retains prior forwarded records.

Which design principle helped most?

A. Centralized protected log collection.

B. Local-only logging.

C. Shared administrator credentials.

D. Disabling audit trails.

Correct Answer

A


239. Practice Question 10

A SOC rule produces 10,000 alerts per day, and analysts investigate fewer than 2%.

Which action is BEST?

A. Review detection quality, prioritize high-risk use cases, and tune noise while preserving meaningful coverage.

B. Generate more alerts.

C. Ignore all alerts.

D. Disable monitoring permanently.

Correct Answer

A


240. Practice Question 11

A forensic investigation reveals an employee's personal data unrelated to the investigation.

What should the investigator do?

A. Follow scope, need-to-know, privacy, and evidence-handling requirements.

B. Share the unrelated data with the entire team.

C. Publish it.

D. Automatically use it for unrelated disciplinary purposes.

Correct Answer

A


241. Practice Question 12

An administrator can disable security controls, delete logs, and approve their own changes.

Which operational control should management strengthen?

A. Separation of duties and privileged-account oversight.

B. Network bandwidth.

C. Backup compression.

D. Data classification labels only.

Correct Answer

A


Part CXLV β€” Investigation Memory Table

PhaseCore Question
TriggerWhy are we investigating?
AuthorityAre we authorized?
PreserveWhat could be lost or altered?
CollectWhat evidence is needed?
ExamineWhat artifacts are present?
AnalyzeWhat relationships explain events?
ReportWhat does evidence support?

Part CXLVI β€” Evidence Memory Table

ConceptMeaning
RelevanceEvidence relates to issue
ReliabilityEvidence source/method is trustworthy
IntegrityEvidence remains unaltered
Chain of custodyTracks possession/handling
HashSupports integrity verification
Volatile evidenceDisappears quickly
Working copyUsed for analysis instead of original

Part CXLVII β€” Forensic Artifact Table

Artifact CategoryExamples
ComputerFiles, processes, OS events
NetworkFirewall, DNS, proxy, packet/flow data
MobileApp data, metadata, device records
ApplicationTransactions, authentication, API logs
CloudIdentity events, API activity, audit trails
MemoryProcesses, connections, volatile artifacts

Part CXLVIII β€” Detection Comparison Table

TechniqueStrengthLimitation
SignatureKnown patternsMay miss new variants
AnomalyDetect unusual behaviorFalse positives
Network IDSBroad network viewEncryption/host visibility
Host detectionDeep endpoint viewRequires endpoint deployment
SIEM correlationCross-source contextDepends on telemetry/tuning
UEBABehavioral anomaliesAnomaly does not prove attack

Part CXLIX β€” IDS and IPS Memory Table

IDSIPS
DetectDetect + prevent
Often passiveOften inline
Lower blocking riskCan disrupt legitimate traffic
Alerts analystsCan automatically block

Part CL β€” Threat Intelligence Memory Table

ConceptThink
Raw dataIndicator without context
Threat informationContextualized data
IntelligenceDecision-relevant analysis
IOCObservable indicator
TTPAdversary behavior
FeedSource of threat data/information
HuntProactive investigation

Part CLI β€” Logging Memory Table

StageSecurity Question
GenerateWhat should be recorded?
CollectDid we receive it?
TransmitIs transfer reliable/protected?
StoreIs it protected?
AnalyzeCan we detect meaningful behavior?
RetainHow long is it needed?
DisposeCan it be securely removed?

Part CLII β€” SIEM Memory Table

LOG SOURCES
↓
COLLECT
↓
NORMALIZE
↓
CORRELATE
↓
DETECT
↓
ALERT
↓
INVESTIGATE
↓
IMPROVE

Part CLIII β€” Key Terms

Security Event

Observable occurrence within an information environment.

Security Incident

Security-related occurrence requiring coordinated investigation or response.

Investigation

Structured effort to determine facts surrounding suspicious or significant activity.

Evidence

Information supporting or refuting an investigative conclusion.

Chain of Custody

Documented history of evidence possession and handling.

Evidence Integrity

Confidence that evidence has not been improperly changed.

Volatile Evidence

Information likely to disappear when system state changes or power is removed.

Live Acquisition

Collection performed while a system remains operational.

Forensic Image

Reliable copy of digital storage created for forensic examination.

Write Blocker

Mechanism designed to prevent writes to source media during forensic acquisition.

Hash

Cryptographic digest used to help verify data integrity.

Artifact

Digital information that may reveal system or user activity.

Timeline Analysis

Correlation of events according to time.

Log

Record of events occurring within systems, networks, applications, or services.

Log Management

Processes for generating, transmitting, storing, accessing, analyzing, retaining, and disposing of logs.

SIEM

Security Information and Event Management.

Normalization

Mapping heterogeneous event data into a common representation.

Correlation

Identifying relationships among events.

IDS

Intrusion Detection System.

IPS

Intrusion Prevention System.

IDPS

Intrusion Detection and Prevention System.

Signature-Based Detection

Detection based on known patterns.

Anomaly-Based Detection

Detection based on deviation from expected behavior.

Egress Monitoring

Monitoring outbound communications.

Threat Intelligence

Analyzed threat information supporting security decisions.

IOC

Indicator of Compromise.

TTP

Tactic, Technique, or Procedure describing adversary behavior.

Threat Feed

Source supplying threat-related data or information.

Threat Hunting

Proactive search for potentially malicious activity.

UEBA

User and Entity Behavior Analytics.

Behavioral Baseline

Representation of expected normal behavior.

Alert Fatigue

Reduced analyst effectiveness caused by excessive low-value alert volume.

Least Privilege

Granting only access required for legitimate duties.

Separation of Duties

Dividing sensitive responsibilities among multiple roles or individuals.

Job Rotation

Periodic reassignment of responsibilities that can improve resilience and expose irregularities.

SLA

Service-Level Agreement.


CISSP Exam Focus

For investigation questions, think:

WHAT HAPPENED?
↓
ARE WE AUTHORIZED?
↓
WHAT EVIDENCE MAY DISAPPEAR?
↓
HOW DO WE PRESERVE IT?
↓
WHO HANDLED IT?
↓
WHAT DO MULTIPLE ARTIFACTS SHOW?
↓
WHAT DOES THE EVIDENCE ACTUALLY SUPPORT?

For logging questions:

WHAT MUST BE DETECTED?
↓
WHICH LOG SOURCE SHOWS IT?
↓
IS THE LOG GENERATED?
↓
IS IT COLLECTED?
↓
IS IT PROTECTED?
↓
CAN IT BE CORRELATED?
↓
IS THE ALERT ACTIONABLE?

Remember:

  • Domain 7 currently represents 13% of the CISSP examination.

  • Current Objective 7.1 covers evidence collection/handling, reporting, investigative techniques, digital forensics, and artifacts.

  • Current Objective 7.2 covers IDPS, SIEM, continuous monitoring/tuning, egress monitoring, log management, threat intelligence/hunting, and UEBA.

  • Obtain and respect appropriate investigative authority.

  • Investigation procedures may differ according to legal, regulatory, administrative, and contractual context.

  • Consult appropriate legal/management authorities when required.

  • Preserve evidence integrity.

  • Document chain of custody.

  • Volatile evidence may require collection before nonvolatile evidence where authorized and appropriate.

  • Live acquisition changes system state; document actions.

  • Hashing supports evidence-integrity verification.

  • A hash does not replace chain-of-custody documentation.

  • Analyze verified copies where appropriate rather than unnecessarily modifying originals.

  • Correlate multiple artifacts.

  • Time synchronization greatly assists incident reconstruction.

  • NIST SP 800-86 remains final guidance for integrating forensic techniques with incident response, though it is an older 2006 publication.

  • NIST SP 800-61 Rev. 3, finalized April 2025, is the current NIST incident-response publication and integrates incident response with broader cybersecurity risk management.

  • NIST SP 800-92 remains the final log-management guide from 2006; SP 800-92 Rev. 1 remains a draft as of August 2026.

  • Centralized logging improves correlation and can improve evidence resilience.

  • Protect logs for confidentiality and integrity.

  • Retention periods are requirement driven.

  • SIEM effectiveness depends on data quality, detection logic, tuning, and analyst processes.

  • IDS primarily detects.

  • IPS can detect and actively prevent.

  • Signature detection is strong for recognized patterns.

  • Anomaly detection may discover novel behavior but can generate false positives.

  • Continuous monitoring requires continual tuning.

  • Egress monitoring can detect suspicious outbound activity.

  • Raw threat feeds are not automatically intelligence.

  • Threat intelligence must be relevant, timely, and contextual.

  • Threat hunting is proactive and hypothesis driven.

  • UEBA detects behavioral anomalies, not guaranteed malicious activity.

  • Need-to-know and least privilege apply to investigators and SOC personnel.

  • Separation of duties protects the integrity of operational security processes.

  • Privileged security operations should be attributable and monitored.

  • Do not sacrifice human safety or critical mission operations solely to obtain perfect forensic evidence.

  • Investigation reports should clearly separate evidence, analysis, conclusions, and limitations.


Lesson Summary

Lesson Twenty-Four began CISSP Domain 7 β€” Security Operations.

Security operations transforms security design into continuous operational activity.

The investigation process can be remembered as:

TRIGGER
↓
AUTHORITY
↓
PRESERVE
↓
COLLECT
↓
EXAMINE
↓
ANALYZE
↓
REPORT

The SierraTec Secure TRACE model summarizes this:

T β€” Trigger and Authority
R β€” Retain and Protect Evidence
A β€” Analyze Correlated Artifacts
C β€” Chronicle Custody and Actions
E β€” Explain Findings and Limitations

You learned that digital evidence may exist in:

MEMORY
COMPUTERS
NETWORKS
APPLICATIONS
MOBILE DEVICES
CLOUD SERVICES

NIST SP 800-86 remains a useful final NIST reference for integrating computer and network forensic techniques with incident response and emphasizes forensic examination of files, operating systems, network traffic, and applications.

You studied evidence preservation:

ORIGINAL
↓
PRESERVE
↓
ACQUIRE
↓
HASH / VERIFY
↓
WORKING COPY
↓
ANALYSIS

You then moved into logging and monitoring.

The security-monitoring pipeline is:

EVENT
↓
LOG
↓
COLLECT
↓
NORMALIZE
↓
CORRELATE
↓
DETECT
↓
ALERT
↓
INVESTIGATE

The SierraTec Secure SIGNAL model summarizes effective logging:

S β€” Select Important Events
I β€” Integrate Sources
G β€” Guard Integrity
N β€” Normalize and Correlate
A β€” Alert and Analyze
L β€” Learn and Improve

You studied:

  • centralized logging;

  • SIEM;

  • IDS;

  • IPS;

  • signature detection;

  • anomaly detection;

  • egress monitoring;

  • continuous monitoring;

  • tuning.

The current CISSP outline explicitly includes all of these concepts under Objective 7.2.

You then examined threat intelligence:

RAW DATA
↓
CONTEXT
↓
ANALYSIS
↓
INTELLIGENCE
↓
SECURITY DECISION

and threat hunting:

HYPOTHESIS
↓
QUERY
↓
ANALYZE
↓
INVESTIGATE
↓
IMPROVE DETECTION

Finally, you examined UEBA and operational accountability.

LEAST PRIVILEGE
+
NEED TO KNOW
+
SEPARATION OF DUTIES
+
PRIVILEGED ACCOUNTABILITY
=
TRUSTWORTHY OPERATIONS

The central Lesson Twenty-Four principle is:

Effective security operations depend on trustworthy evidence and trustworthy visibility. Investigations must be authorized, evidence must be preserved and documented, logs must be reliable and protected, monitoring must be tuned to meaningful risk, and analytical conclusions must remain grounded in corroborated evidence rather than assumptions.


Exam Readiness Check

Before moving to Lesson Twenty-Five, make sure you can explain without reviewing:

  • What Security Operations means.

  • Why Domain 7 is operationally different from security design.

  • Event versus incident.

  • Why investigations require appropriate authorization.

  • Administrative, civil, criminal, regulatory, and incident investigation contexts.

  • Why legal coordination may be necessary.

  • What evidence is.

  • Relevance, reliability, and integrity.

  • What chain of custody is.

  • Why documentation should begin immediately.

  • The purpose of evidence preservation.

  • Identification, preservation, collection, examination, analysis, and reporting.

  • Volatile versus nonvolatile evidence.

  • Why RAM may need early collection.

  • Why order of volatility is a principle rather than an inflexible rule.

  • Live versus static acquisition.

  • Why live collection changes system state.

  • What memory forensics examines conceptually.

  • What forensic imaging means.

  • What a write blocker is.

  • Why hashes are used.

  • Why a hash does not replace chain of custody.

  • Why investigators often analyze working copies.

  • What timeline analysis is.

  • Why time-zone handling matters.

  • Why system time synchronization matters.

  • Computer artifacts.

  • Network artifacts.

  • Mobile artifacts.

  • Application artifacts.

  • Cloud artifacts.

  • Why corroborating artifacts strengthens analysis.

  • What a security log is.

  • What log management means.

  • Generation, collection, transmission, storage, analysis, retention, and disposal.

  • Major log sources.

  • Why centralized logging helps.

  • Why log integrity matters.

  • Why logs may require confidentiality.

  • Why no universal log-retention period exists.

  • What SIEM means.

  • Collection, normalization, correlation, detection, alerting, and investigation.

  • Why SIEM is not automatically effective.

  • What tuning means.

  • False positives versus false negatives.

  • What alert fatigue means.

  • IDS versus IPS.

  • Network-based versus host-based monitoring.

  • Signature versus anomaly detection.

  • What continuous monitoring means.

  • Why continuous monitoring requires tuning.

  • What egress monitoring means.

  • Why outbound traffic can reveal compromise.

  • Raw threat data versus threat intelligence.

  • What an IOC is.

  • Why IOCs can become stale.

  • What TTPs represent conceptually.

  • Why threat-feed quantity is not the same as intelligence quality.

  • What threat hunting means.

  • What a hunting hypothesis is.

  • Why hunts can improve detection even when no attacker is found.

  • What UEBA means.

  • Why anomalous behavior does not prove malicious behavior.

  • Why UEBA applies to service accounts and devices as well as people.

  • How least privilege applies to SOC and forensic personnel.

  • Why separation of duties matters in logging and administration.

  • Why privileged-account events deserve monitoring.

  • How job rotation can support operational resilience and fraud detection.

  • What an SLA means in operational security.

  • Why evidence preservation must be balanced against human safety and critical mission operations.


Coming Next

Lesson Twenty-Five: Configuration Management, Resource Protection, Patch Management, and Change Control

Lesson Twenty-Five will continue CISSP Domain 7 and focus primarily on:

7.3 β€” Configuration Management

Including:

  • provisioning;

  • baselining;

  • automation.

7.5 β€” Resource Protection

Including:

  • media management;

  • media protection;

  • data at rest;

  • data in transit.

7.8 β€” Patch and Vulnerability Management

7.9 β€” Change Management

It will cover:

  • secure baselines;

  • configuration items;

  • CMDB concepts;

  • configuration drift;

  • gold images;

  • hardened templates;

  • infrastructure as code;

  • automated configuration;

  • configuration monitoring;

  • unauthorized change;

  • provisioning;

  • secure deprovisioning;

  • media inventory;

  • removable media;

  • media labeling;

  • storage;

  • transport;

  • sanitization;

  • encryption;

  • data-at-rest protection;

  • data-in-transit protection;

  • patch lifecycle;

  • vulnerability-to-patch workflow;

  • emergency patching;

  • patch testing;

  • rollback;

  • End of Life;

  • End of Support;

  • compensating controls;

  • change requests;

  • change advisory processes;

  • standard changes;

  • normal changes;

  • emergency changes;

  • segregation of duties;

  • impact assessment;

  • authorization;

  • maintenance windows;

  • post-implementation review;

  • configuration verification;

  • unauthorized-change detection;

  • original SierraTec frameworks;

  • CISSP exam traps;

  • knowledge checks;

  • scenario questions.

The central Lesson Twenty-Five question will be:

How should organizations maintain secure, known system states while protecting media and information, applying patches, and controlling operational changes without introducing unacceptable security or availability risk?


Publication and Independence Notice

This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.

CISSP is administered by ISC2. SierraTec Secure's program is independent CISSP certification-preparation material and should not be represented as official ISC2 training unless separately authorized.

Current Domain 7 scope and its 13% weighting were verified against the official ISC2 CISSP Certification Exam Outline. Current Objectives 7.1 and 7.2 cover investigations, evidence handling, forensic artifacts, IDPS, SIEM, continuous monitoring, egress monitoring, log management, threat intelligence, threat hunting, and UEBA.

Digital-forensics concepts were supplemented by NIST SP 800-86, which remains NIST's final dedicated publication on integrating forensic techniques into incident response.

Current incident-response context was aligned with NIST SP 800-61 Rev. 3, finalized in April 2025 and superseding SP 800-61 Rev. 2.

Log-management concepts were aligned with NIST SP 800-92, the current final publication. NIST's planned Revision 1, Cybersecurity Log Management Planning Guide, remains an Initial Public Draft as of August 2026.

The SierraTec Secure TRACE and SIGNAL frameworks, diagrams, scenarios, knowledge checks, comparison tables, and practice questions are original educational material and are not actual, recalled, leaked, or official CISSP examination questions.

Sallieu Kanu

Sallieu Kanu

Product Designer
0
Best Seller
Faithful User
Expert Vendor
King Seller

Class Sessions

1- Introduction to CISSP 2- Thinking Like a CISSP: Security Principles, Risk, and Professional Decision-Making 3- Lesson 1 4- Lesson 3 5- Lesson 4: Risk Management, Risk Assessment, and Risk Treatment 6- Lesson 5: Threat Modeling, Supply-Chain Risk, and Third-Party Risk 7- Lesson 6: Legal, Regulatory, Privacy, Compliance, and Investigation Foundations 8- Lesson 7: Asset Security and Information Lifecycle Management 9- Lesson 8: Security Architecture Foundations and Protection Mechanisms 10- Lesson 9: Security Models, Trusted Systems, and Secure Design 11- Lesson 10: Cryptography and Cryptographic Solutions 12- Lesson 11: Cryptographic Attacks and Public Key Infrastructure 13- Lesson 12: Physical and Facility Security Architecture 14- Lesson 13: Information System Lifecycle and Secure Engineering 15- Lesson 14: Communication and Network Security Foundations 16- Lesson 15: Secure Network Components and Infrastructure Protection 17- Lesson 16: Secure Communication Channels, Remote Access, and Third-Party Connectivity 18- Lesson 17: Identity and Access Management Foundations 19- Lesson 18: Authentication Systems, Federation, SSO, and Identity Protocols 20- Lesson 19: Authorization Models and Access-Control Enforcement 21- Lesson 20: Identity Provisioning, Access Reviews, Privileged Access, and Account Lifecycle 22- Lesson 21: Security Assessment and Testing Foundations 23- Lesson 22: Advanced Security Control Testing and Vulnerability Management 24- Lesson 23: Security Metrics, Test Analysis, Reporting, and Audit Assurance 25- Lesson 24: Security Operations, Investigations, Evidence, and Logging Foundations 26- Lesson 25: Configuration Management, Resource Protection, Patch Management, and Change Control 27- Lesson 26: Incident Management and Operational Detection and Prevention 28- Lesson 27: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Join Us Today

We'll send the best deals and offers to your email. No spam, ever.

GDPR

When you visit any of our websites, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and manage your preferences. Please note, that blocking some types of cookies may impact your experience of the site and the services we are able to offer.