SER Related
General/Troubleshooting
Best Practices
Compliance Related
NetScout
100

An SER is submitted to modify a user account in HTEN and SOMS, they only have a SOMS account. What needs to happen? (3x)

Do not approve the SER, they need 2x SERs. One to modify SOMS, one to create HTEN account. 

100

Who's responsibility is it to monitor the email inboxes?

Everyone, but the primarily Team1. 

100

All emails and alerts must be tracked in a ticket. True or False.

True. Either individual tickets, or bulk if a large amount is received. 

100

Case related account requests are to be completed within what time frame?

Turnaround time for these are to be completed by the end of the next business day.

100

A "Global" alert means that all of HTEN is targeted for an Arbor Alert. True or False

False, Global means that our internal Core infrastructure is feeling the impacts of the attack. 

200

A service account SER was submitted without an owner or description. Does this SER get approved?

No

200

Customer Portal troubleshooting can be done in what 3 main tools?

Account(AD), Authentication(PW/RSA), F5s

200

Remain logged into the phones in a ready state if you are at your desk and ready to receive a call to minimize RONAs. 

True. Log off/out if you are not ready. 

200

What are the 5 email addresses that are CC'd on reportable cases for MFN2?

  • Denise.Adkins@dms.fl.gov
  • MFN2DivtelEngineering@dms.fl.gov
  • Hank.Stephens@dms.fl.gov
  • SupportMFN2SOC
  • csoc@digital.fl.gov
200

What is the maximum attack size our Core Arbor TMS's can handle? What is the maximum attack size that Arbor Cloud mitigation service can handle?

TMS: 20 Gbps

Cloud: 15+ Tbps

300

Industrial Security approved the SER to create an MFN2 user account, this means that the person is cleared for MFN2. 

False. The SOC needs to confirm clearance prior to providing credentials to the user. (Process changing soon)

300

Will your team do physical work for 300 points? Y/N

15 Team pushups for 300 points.

300

What are the case requirements for each of Team1 and Team2?

Team1: 1 case per week

Team2: 5 HTEN & 1 SOMS case per week. (6 total).

300

Will your team do physical work for 300 points? Y/N

15 Team jumping jacks for 300 points.

300

How many routers across MFN2 route traffic to EITHER TMS or Arbor Cloud? Where are they located?

5 (2x TL2, 2x MI1, 1x DIA)

400
An SER can be modified at any time during the approval process. True or False

False, SERs can only be modified before the first approval. 

400

Team1 can process AND assign tickets to other members of the team if things are busy. 

True, as long as there is communication between team members about the work needing to be done and tie is spent efficiently. 

400

The SOC only uses the SIEM, Palo Alto devices, and IDS devices to generate case (reportable) material. True or False.

False, investigations can also start from emails and calls from customers, device alerts/alarms, and Arbor. 

400

What does the SLA timer icon look like in Remedy?

Stopwatch

400

When does the DDoS SLA timer start?

Customer confirms via email they are affected by an Arbor Alert and are requesting mitigation. 

500

You must properly investigate the request in the relative environments prior to approving them. 

True. Ensure the request matches what is reflected in the environments. 

500

SOC Front Monitor Displays are to be triaged as part of Morning Brief responsibilities. True or False.

True. (Morning Brief and SOC Display Wikis)

500

What is the responsibility of the MFN2 SOC in regards to addressing customer traffic threats?

Nothing. The SOC should only Recognize, investigate, report. Mitigation falls on the customer to complete. 

500

Case Remedy ticket file attachments should include the WHAT in the file name?

Case Number

500

Who can start Arbor manual mitigations if no SecEng is available or responding within the 45 minute time period?

Anyone

M
e
n
u