# Cybersecurity

- <span aria-hidden="true">Social media is a great way to connect to other security professionals in the <span style="color: rgb(224, 62, 45);">industry</span> 社交媒體是與業界其他安全專業人員聯繫的絕佳方式</span>
- <span aria-hidden="true">By <span style="color: rgb(224, 62, 45);">staying informed</span> about security trends, you can more effectively identify and <span style="color: rgb(224, 62, 45);">develop remediation strategies</span> to address a wide range of security challenges 藉由持續(隨時)瞭解安全趨勢，您可以更有效地辨識並制訂補救策略，以因應各種安全挑戰</span>
- <span aria-hidden="true">engaging with the <span style="color: rgb(224, 62, 45);">security community</span> through various <span style="color: rgb(224, 62, 45);">security organizations</span> and conferences is a great way to stay up-to-date on current <span style="color: rgb(224, 62, 45);">security news</span> 透過各種安全組織和會議與安全社群接觸，是掌握最新安全新聞的好方法</span>
- <span aria-hidden="true">You don't have to know everything. You have <span style="color: rgb(224, 62, 45);">teammates</span> and other people that can help you with <span style="color: rgb(224, 62, 45);">areas that you're weak</span> <span style="color: rgb(224, 62, 45);">in</span> 你不必什麼都懂。您有隊友和其他人可以幫助您解決您的弱點</span>
- <span aria-hidden="true">I <span style="color: rgb(224, 62, 45);">take courses</span>, try to <span style="color: rgb(224, 62, 45);">get certificates if I can along the way</span> 我參加了一些課程，並嘗試在有機會的情況下考取證書</span>
- <span aria-hidden="true">It's important to <span style="color: rgb(224, 62, 45);">continue to learn</span> in the field of cybersecurity because <span style="color: rgb(224, 62, 45);">things change all the time</span> 因為事物不斷在改變，持續學習對網路安全領域是重要的</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">always remember</span> not to click on <span style="color: rgb(224, 62, 45);">unexpected links</span> or attachments <span style="color: rgb(224, 62, 45);">sent from</span> unfamiliar users on social media. 切記不要點擊社交媒體上不熟悉的使用者所傳送的意外連結或附件</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Be aware of</span> social engineering 注意社交工程</span>
- <span aria-hidden="true">it’s also important to <span style="color: rgb(224, 62, 45);">be mindful</span> that hackers use social media to <span style="color: rgb(224, 62, 45);">trick</span> users <span style="color: rgb(224, 62, 45);">into</span> giving up private information 也要注意黑客會利用社交媒體誘騙使用者提供私人資訊</span>
- <span aria-hidden="true">Are you interested in <span style="color: rgb(224, 62, 45);">forensic security</span> or data logging 您是否對資安鑑識或資料記錄感興趣</span>
- <span aria-hidden="true">focus on <span style="color: rgb(224, 62, 45);">reacting to security incidents</span> or preventing them from happening 專注於安全事故應變或預防安全事故發生</span>
- <span aria-hidden="true">Security is a <span style="color: rgb(224, 62, 45);">constantly evolving</span> industry. As professionals in security, we must <span style="color: rgb(224, 62, 45);">evolve with</span> it by <span style="color: rgb(224, 62, 45);">seeking out</span> new information. （資訊)安全是一個不斷演進的產業。身為(資訊)安全的專業人員，我們必須透過尋找新的資訊來與時俱進。</span>
- <span aria-hidden="true">A few <span style="color: rgb(224, 62, 45);">well-known</span> security websites and blogs to get you started are 一些知名的安全網站與 blog 是</span>
- <span aria-hidden="true">will help you <span style="color: rgb(224, 62, 45);">stand out to hiring managers</span> and could give you an <span style="color: rgb(224, 62, 45);">extra edge over other candidates</span>（將可協助您在招募經理面前脫穎而出，並可讓您比其他應徵者更具優勢）</span>
- <span aria-hidden="true">What <span style="color: rgb(224, 62, 45);">excites me about</span> the <span style="color: rgb(224, 62, 45);">security profession</span> is（讓我對資安工作感到興奮的是）</span>
- <span aria-hidden="true">a few good resources for you to review <span style="color: rgb(224, 62, 45);">periodically</span>.（一些好的資源讓你定期檢視）</span>
- <span aria-hidden="true">As the industry <span style="color: rgb(224, 62, 45);">evolves</span>, it's <span style="color: rgb(224, 62, 45);">essential</span> to <span style="color: rgb(224, 62, 45);">stay up-to-date on</span> the latest <span style="color: rgb(224, 62, 45);">security trends and news</span>（隨著產業的演進，掌握最新的安全趨勢和新聞是非常重要的）</span>
- <span aria-hidden="true">As we <span style="color: rgb(224, 62, 45);">approach</span> the end of our program,（隨著/當我們的課程接近尾聲）</span>
- <span aria-hidden="true">we'll share some ways to <span style="color: rgb(224, 62, 45);">become involved with</span> the security community.（我們會分享一些參與安全社群的方法）</span>
- <span aria-hidden="true">we'll <span style="color: rgb(224, 62, 45);">identify</span> reliable security resources you can use to <span style="color: rgb(224, 62, 45);">stay up-to-date on</span> security news and trends.（我們會為您找出可靠的安全資源，讓您隨時掌握最新的安全新聞和趨勢。）</span>
- <span aria-hidden="true">how to <span style="color: rgb(224, 62, 45);">engage with</span> the security community, find jobs in the security field, create a resume, and <span style="color: rgb(224, 62, 45);">navigate</span> the interview process（接觸安全社群；掌握面試流程）</span>
- <span aria-hidden="true">other stakeholders will be more focused on how <span style="color: rgb(224, 62, 45);">policies</span> and <span style="color: rgb(224, 62, 45);">procedures</span> are <span style="color: rgb(224, 62, 45);">working to prevent</span> cyber attacks（其他利害關係人將更專注於政策與程序如何防止網路攻擊）</span>
- <span aria-hidden="true">Juliana decides to <span style="color: rgb(224, 62, 45);">put together</span> a <span style="color: rgb(224, 62, 45);">detailed document</span> with <span style="color: rgb(224, 62, 45);">timelines</span> that clearly explain <span style="color: rgb(224, 62, 45);">what happened</span>（決定整理出一份有時間軸的詳細文件，清楚說明所發生的事情）</span>
- <span aria-hidden="true">Juliana’s manager <span style="color: rgb(224, 62, 45);">has also been informed</span> that（還已經被告知...）</span>
- <span aria-hidden="true">Juliana's visual dashboard makes it easier for the <span style="color: rgb(224, 62, 45);">high-level stakeholders</span> to review incident #1 and determine <span style="color: rgb(224, 62, 45);">a course of action</span>（Juliana 的可視化儀表板讓高層級利害關係人更容易檢視事件 #1，並決定行動方案）</span>
- <span aria-hidden="true">Her dashboard will use charts and graphs <span style="color: rgb(224, 62, 45);">to relay</span> important information（她的儀表板會使用圖表來傳達重要資訊）</span>
- <span aria-hidden="true">she used her company’s <span style="color: rgb(224, 62, 45);">escalation</span> policy to <span style="color: rgb(224, 62, 45);">properly escalate</span> the two incidents（她運用公司的上報政策將兩起事件正確上報）</span>
- <span aria-hidden="true">escalation; escalate (上報/提升至上層處理/事件升級)</span>
- <span aria-hidden="true">allow <span style="color: rgb(224, 62, 45);">decision makers</span> to determine how to address security issues that <span style="color: rgb(224, 62, 45);">put the organization at risk</span>（讓決策者決定如何處理使組織陷入風險的安全問題）</span>
- <span aria-hidden="true">allow security team members to <span style="color: rgb(224, 62, 45);">convey</span> <span style="color: rgb(224, 62, 45);">essential information</span> to stakeholders（讓安全團隊成員向利害關係人傳達重要資訊）</span>
- <span aria-hidden="true">Those stakeholders and the security team can then work together to determine <span style="color: rgb(224, 62, 45);">how to address the issue</span>（然後，這些利害關係人和安全團隊可以共同合作，決定如何解決/處理問題）</span>
- <span aria-hidden="true" class=" css-4s48ix"><span style="color: rgb(224, 62, 45);">Based on</span> this information,（根據）</span>
- <div aria-label="play video from wants to know how many employees are often clicking on phishing emails." class="rc-Phrase css-13o25cb" data-cue="6" data-cue-index="5" role="button"><span aria-hidden="true" class=" css-4s48ix">wants to know how many employees are often clicking on phishing emails. </span></div><div aria-label="toggle video from current lecture segment" class="rc-Phrase active css-13o25cb" data-cue="7" data-cue-index="6" role="button" tabindex="0"><span aria-hidden="true" class=" css-4s48ix">The goal is to <span style="color: rgb(224, 62, 45);">identify which five departments</span> click on those emails <span style="color: rgb(224, 62, 45);">most often</span>.</span>（想要知道有多少員工經常點選釣魚電子郵件。目標是找出哪五個部門最常點選這些電子郵件。）</div>
- <span aria-hidden="true">The audit gathered data showing <span style="color: rgb(224, 62, 45);">how many phishing emails</span> each department clicked <span style="color: rgb(224, 62, 45);">over the last five months</span>（稽核收集的資料顯示每個部門在最近五個月內點選了多少封釣魚電子郵件）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Other times</span> you might want to include <span style="color: rgb(224, 62, 45);">a document attachment</span> that <span style="color: rgb(224, 62, 45);">further elaborates</span> on a specific topic.（其他時候，您可能想要包含一個文件附件，以進一步詳細說明特定主題）</span>
- <span aria-hidden="true">Security is often <span style="color: rgb(224, 62, 45);">a team effort</span>.（資訊安全通常是一項團隊工作。）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Visuals</span> help provide these <span style="color: rgb(224, 62, 45);">decision-makers</span> with <span style="color: rgb(224, 62, 45);">actionable information</span> that can help them <span style="color: rgb(224, 62, 45);">identify</span> potential risks to the organization's <span style="color: rgb(224, 62, 45);">security posture</span>.（可視化有助於為這些決策者提供可執行的資訊，幫助他們識別組織安全態勢的潛在風險）</span>
- <span aria-hidden="true">An entry-level analyst might <span style="color: rgb(224, 62, 45);">communicate directly or indirectly</span> with these individuals.（入門級的分析師可能會直接或間接與這些人溝通。）</span>
- <span aria-hidden="true">Create visual dashboards for <span style="color: rgb(224, 62, 45);">impactful</span> cybersecurity communications（建立具影響力的網路安全溝通視覺化儀表板）</span>
- <span aria-hidden="true">If you don't receive <span style="color: rgb(224, 62, 45);">a timely response</span> from a stakeholder, following up shows initiative.（如果您沒有收到利害關係人及時的回覆，追蹤展現您的主動性）</span>
- <span aria-hidden="true">It's important <span style="color: rgb(224, 62, 45);">to stand out</span> in the <span style="color: rgb(224, 62, 45);">security profession</span>, especially if you don't have previous experience in the industry.（在資安工作中，要表現突出很重要，特別是如果你沒有這個行業的先前經驗）</span>
- <span aria-hidden="true">It sounds simple, but a friendly call can often <span style="color: rgb(224, 62, 45);">prevent a major issue from occurring</span>（這聽起來很簡單，但一個友善的電話往往可以避免重大問題的發生。）</span>
- <span aria-hidden="true">When appropriate, <span style="color: rgb(224, 62, 45);">take the initiative to follow up with</span> a stakeholder if they haven't responded to an email <span style="color: rgb(224, 62, 45);">in a timely manner</span>.（如果利害關係人沒有及時回覆電子郵件，請在適當的時候要主動追蹤）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Direct communication</span> is often better than waiting days or weeks for an email response to an issue that requires immediate attention.（對於需要立即處理的問題，直接溝通往往比等待數天或數週的電子郵件回覆來得好）</span>
- <span aria-hidden="true">that sometimes a simple instant message or call <span style="color: rgb(224, 62, 45);">can help move a situation forward</span>.（有的時候一個簡單的即時訊息或電話就能推進一個情況）</span>
- <span aria-hidden="true">This means they may sometimes <span style="color: rgb(224, 62, 45);">miss an email</span>, or <span style="color: rgb(224, 62, 45);">fail to respond</span> in <span style="color: rgb(224, 62, 45);">a timely manner</span>.（這意味著他們有時候可能會錯過電子郵件，或者無法及時回應。）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Be sure to</span> follow the procedures <span style="color: rgb(224, 62, 45);">outlined in</span> your organization's playbooks（請務必遵循組織手冊中列出的程序）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Be mindful of</span> the sensitive information contained <span style="color: rgb(224, 62, 45);">in these types of communications</span>. 注意(留心)；在這些類型的溝通</span>
- <span aria-hidden="true">we'll focus on <span style="color: rgb(224, 62, 45);">various</span> <span style="color: rgb(224, 62, 45);">communication strategies</span> that can help you <span style="color: rgb(224, 62, 45);">engage with</span> and <span style="color: rgb(224, 62, 45);">convey key ideas</span> to stakeholders（各種溝通策略；接觸；傳達重要想法）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">The ability to</span> communicate threats, risks, vulnerabilities, or incidents and possible solutions is <span style="color: rgb(224, 62, 45);">a valuable skill</span> for security professionals.（溝通威脅、風險、弱點或事故以及可能的解決方案的能力是安全專業人員的寶貴技能。）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Senior-level stakeholders</span> might be more interested in the underlying risks, such as the potential financial burden of a security incident—<span style="color: rgb(224, 62, 45);">as opposed to</span> the details around logs（高層利害關係人；而不是）</span>
- <span aria-hidden="true">How do I explain the situation <span style="color: rgb(224, 62, 45);">in a nontechnical manner</span>?（以非技術性的方式說明情況）</span>
- <span aria-hidden="true">your <span style="color: rgb(224, 62, 45);">immediate supervisor</span>（直屬主管）</span>
- <span aria-hidden="true">how it impacts the organization, and <span style="color: rgb(224, 62, 45);">possible solutions to the issue</span>.（可能的解決方案）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">It's essential</span> that communications are specific and clear（...必須...）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Staying informed</span> about security issues helps stakeholders do their jobs <span style="color: rgb(224, 62, 45);">more effectively</span>.（隨時了解..., 更有效率的...）</span>
- <span aria-hidden="true">You <span style="color: rgb(224, 62, 45);">don't want them to have to</span> guess the reason for your email or why <span style="color: rgb(224, 62, 45);">it matters to them</span>.（不會讓他們要..., 對他們重要）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">keep</span> those top-level stakeholders <span style="color: rgb(224, 62, 45);">informed on</span> the security measures（讓...隨時了解/知道...）</span>
- <span aria-hidden="true">responsibilities; responsible for (職責;對...負責)</span>
- <span aria-hidden="true">there are <span style="color: rgb(224, 62, 45);">certain stakeholders</span> that the analyst will need to provide updates to (分析師需要向某些利害關係人提供最新資訊)</span>
- <span aria-hidden="true">the security <span style="color: rgb(224, 62, 45);">measures</span> and protocols <span style="color: rgb(224, 62, 45);">in place</span> (所採用的安全措施和協議)</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">A big part of what you’ll do</span> as a security analyst is report your findings to <span style="color: rgb(224, 62, 45);">various security stakeholders</span>. (身為資安分析師，您要做的一大部分工作就是向各個安全利害關係人報告您的發現。)</span>
- <span aria-hidden="true">the individuals who have <span style="color: rgb(224, 62, 45);">a significant interest</span> in those <span style="color: rgb(224, 62, 45);">business operations</span>: <span style="color: rgb(224, 62, 45);">stakeholders</span>. (與這些企業營運有重大利益關係的個人：利害關係人)</span>
- <span aria-hidden="true">They're also <span style="color: rgb(224, 62, 45);">tasked with</span> creating security and <span style="color: rgb(224, 62, 45);">business continuity plans</span>. (他們還負責制定資訊安全和營運持續計劃。)</span>
- <span aria-hidden="true">CISOs are <span style="color: rgb(224, 62, 45);">high-level executives</span> responsible for developing an organization's (高階主管)</span>
- <span aria-hidden="true">Another stakeholder <span style="color: rgb(224, 62, 45);">with an interest in security</span> is the Chief Information Security Officer, or <span style="color: rgb(224, 62, 45);">CISO</span> (有資安利害關係; 資安長)</span>
- <span aria-hidden="true">They are concerned about security from a <span style="color: rgb(224, 62, 45);">financial standpoint</span> because of the potential costs of an incident to the business.(財務觀點/立場)</span>
- <span aria-hidden="true">because the decisions made <span style="color: rgb(224, 62, 45);">on a day-to-day basis</span> by stakeholders will impact <span style="color: rgb(224, 62, 45);">how you do your job</span> (每天/日常;你的工作方式)</span>
- on a daily basis（在日常）
- <span aria-hidden="true">the supervisor indicates that a data breach has <span style="color: rgb(224, 62, 45);">occurred</span></span><span aria-hidden="true"> . This breach has <span style="color: rgb(224, 62, 45);">impacted</span> one of the <span style="color: rgb(224, 62, 45);">manufacturing sites</span> for the organization. </span><span aria-hidden="true">（主管表示已發生資料外洩事件。此外洩影響了該組織的其中一個製造據點。）</span>
- <span aria-hidden="true">the incident may be increased or decreased to a high or low <span style="color: rgb(224, 62, 45);">criticality level</span>.（嚴重等級）</span>
- <span aria-hidden="true"><span style="color: rgb(224, 62, 45);">Suddenly</span>, you <span style="color: rgb(224, 62, 45);">notice</span> there's been unusual log activity in an app that was recently banned from the organization.（突然間，您發現最近被組織禁用的應用程式出現不尋常的日誌活動。）</span>
- <span aria-hidden="true">The <span style="color: rgb(224, 62, 45);">internal compliance</span> of an organization’s data protection procedures. （內部規範）</span>
- <span aria-hidden="true">Malware infections can cause a system's network to <span style="color: rgb(224, 62, 45);">run an unusually low speeds</span>.（惡意軟體感染會導致系統的網路運行速度異常低）</span>
- <span aria-hidden="true">a few incident classification types to be aware of: <span style="color: rgb(224, 62, 45);">malware infection</span>, <span style="color: rgb(224, 62, 45);">unauthorized access</span>, and <span style="color: rgb(224, 62, 45);">improper usage</span> (應注意的幾種事件分類類型：惡意軟體感染、未授權存取和不當使用)</span>
- <span aria-hidden="true" class=" css-4s48ix"><span style="color: rgb(224, 62, 45);">Security incident escalation</span> is the process of identifying a potential security incident. (資安事故上報)</span>
- <span aria-hidden="true" class=" css-4s48ix">you’ll learn the importance of <span style="color: rgb(224, 62, 45);">escalating</span> security issues and the potential impact of <span style="color: rgb(224, 62, 45);">failing to</span> <span style="color: rgb(224, 62, 45);">escalate</span> an issue. (上報資安問題的重要性;未能上報問題的可能影響)</span>
- <span aria-hidden="true" class=" css-4s48ix">it has the potential to become a larger problem that <span style="color: rgb(224, 62, 45);">costs the company money</span>, <span style="color: rgb(224, 62, 45);">exposes sensitive customer data</span>, or <span style="color: rgb(224, 62, 45);">damages the company's reputation</span>. (它有可能成為一個更大的問題，使公司蒙受金錢損失、客戶敏感資料外洩或公司聲譽受損。)</span>
- <span aria-hidden="true" class=" css-4s48ix">From the <span style="color: rgb(224, 62, 45);">Chief Information Security Officer</span>, also known as the <span style="color: rgb(224, 62, 45);">CISO</span>, to the engineering team, <span style="color: rgb(224, 62, 45);">public relations</span> team, and even the <span style="color: rgb(224, 62, 45);">legal</span> team, every member of the security team matters. (資安長;工程團隊;公關團隊;法律團隊)</span>
- <span aria-hidden="true" class=" css-4s48ix">it's important that you know how to <span style="color: rgb(224, 62, 45);">evaluate</span> and <span style="color: rgb(224, 62, 45);">escalate</span> incidents <span style="color: rgb(224, 62, 45);">to</span> the </span><span aria-hidden="true">right individual</span><span aria-hidden="true" class=" css-4s48ix"> or team when necessary. (您必須知道如何評估事件，並在必要時將事件升級至對的人或團隊。)</span>
- <span aria-hidden="true" class=" css-4s48ix">I enabled debug logs in the service so I could <span style="color: rgb(224, 62, 45);">observe</span> what was going on (觀察/看到)</span>
- <span aria-hidden="true" class=" css-4s48ix">Penetration testing (pen test) (滲透測試)</span>
- <span aria-hidden="true" class=" css-4s48ix">security mindset, security awareness (資安思維; 資安意識)</span>
    - <span aria-hidden="true" class=" css-4s48ix">Your security mindset allows you to protect all levels of assets.</span>
    - <span aria-hidden="true" class=" css-4s48ix">So having a security mindset helps analysts defend against the constant pressure from attackers.</span>
    - <span aria-hidden="true" class=" css-4s48ix">Having a strong security mindset can help set you apart from other candidates as you prepare to enter the security profession. (資安工作)</span>
    - <span aria-hidden="true" class=" css-4s48ix">using fictitious emails to evaluate security awareness at the company.</span>
- <span aria-hidden="true" class=" css-4s48ix">should <span style="color: rgb(224, 62, 45);">be escalated to a supervisor</span>. (上報到主管)</span>
- <span aria-hidden="true" class=" css-4s48ix">how to <span style="color: rgb(224, 62, 45);">escalate incidents</span> to protect an organization's assets and data (升級事件)</span>
- <span aria-hidden="true" class=" css-4s48ix">happen</span>
    - <span aria-hidden="true" class=" css-4s48ix">after a security incident has taken place</span>
    - <span aria-hidden="true" class=" css-4s48ix">in case a security incident does occur</span>
- <span aria-hidden="true" class=" css-4s48ix">The role of a <span style="color: rgb(224, 62, 45);">security professiona</span>l is to ensure a company’s data and <span style="color: rgb(224, 62, 45);">assets</span> are protected from <span style="color: rgb(224, 62, 45);">threats, risks, and vulnerabilities</span>. (安全專業人員的角色是確保公司的資料和資產不受威脅、風險和弱點的影響。)</span>
- <span aria-hidden="true" class=" css-4s48ix">business continuity and disaster recovery plans (營運持續與災害復原計畫)</span>
- <span aria-hidden="true" class=" css-4s48ix">Conduct <span style="color: rgb(224, 62, 45);">training</span> for the business continuity team (進行...演練)</span>
- <span aria-hidden="true" class=" css-4s48ix">If you're <span style="color: rgb(224, 62, 45);">not sure of</span> the potential impact of an incident, <span style="color: rgb(224, 62, 45);">it's always best to</span> be cautious and report events to <span style="color: rgb(224, 62, 45);">the appropriate team members</span>. (不確定...; 最好; 適當的團隊成員)</span>
- <div aria-label="play video from When a security event results in a data breach," class="rc-Phrase css-13o25cb" data-cue="47" data-cue-index="46" role="button"><span aria-hidden="true" class=" css-4s48ix">When a security event results in a <span style="color: rgb(224, 62, 45);">data breach</span>, </span><span aria-hidden="true" class=" css-4s48ix">it is categorized as a <span style="color: rgb(224, 62, 45);">security incident</span>. (資料外洩; 資安事故)</span></div>
- if it was <span style="color: rgb(224, 62, 45);">compromised</span> (如果受到入侵/危害)
- Intellectual property (智財)
- They can have a <span style="color: rgb(224, 62, 45);">significantly negative impact</span> on an organization if <span style="color: rgb(224, 62, 45);">leaked publicly</span>. (嚴重的負面影響;公開洩漏)
- Examples of confidential data include <span style="color: rgb(224, 62, 45);">proprietary information</span> such as <span style="color: rgb(224, 62, 45);">trade secrets</span>, <span style="color: rgb(224, 62, 45);">financial records</span>, and sensitive government data. (專利資訊;商業秘密;財務紀錄)
- Access to confidential data sometimes involves the signing of non-disclosure agreements (NDAs)
- This data classification type is important for an organization’s <span style="color: rgb(224, 62, 45);">ongoing business operations</span> (持續營運)
- <span style="color: rgb(224, 62, 45);">Unauthorized access</span> to sensitive data can cause <span style="color: rgb(224, 62, 45);">significant damage</span> to an organization’s finances and <span style="color: rgb(224, 62, 45);">reputation</span>. (未授權存取;重大損害;聲譽)
- personally identifiable information (PII), sensitive personally identifiable information (SPII), and protected health information (PHI)
- Public data, Private data, Sensitive data, Confidential data
- If <span style="color: rgb(224, 62, 45);">an individual</span> gains <span style="color: rgb(224, 62, 45);">unauthorized access</span> to private data(個人;未經授權存取)
- Private data is information that should <span style="color: rgb(224, 62, 45);">be kept from the public</span>. (不可公開)
- threats, risks, and vulnerabilities that are <span style="color: rgb(224, 62, 45);">posed by</span> <span style="color: rgb(224, 62, 45);">social engineering</span> attacks, such as phishing (由社交工程造成的...)
- such as <span style="color: rgb(224, 62, 45);">intellectual property, trade secrets</span>, PII, and even <span style="color: rgb(224, 62, 45);">financial information</span> (智慧財產;商業機密;財務資訊)
- helps you <span style="color: rgb(224, 62, 45);">prepare for</span> the <span style="color: rgb(224, 62, 45);">worst-case scenario</span>, even if it doesn't happen(對...做準備；最糟情況)
- cybersecurity profession（網路安全工作）
- cybersecurity professionals（網路安全專家）
- cybersecurity field（網路安全領域）
- <span style="color: rgb(224, 62, 45);">refine</span> your understanding of key security concepts（精進/改進）
- Writing code that assigns<span style="color: rgb(224, 62, 45);"> security incident</span> tickets to the <span style="color: rgb(224, 62, 45);">appropriate</span> cybersecurity team based on its priority level. (寫程式依據優先等級分派資安事故單給合適的資安小組)
- This <span style="color: rgb(224, 62, 45);">results in</span> DNS resolvers sending large responses to (導致)
- which can <span style="color: rgb(224, 62, 45);">lead to</span> <span style="color: rgb(224, 62, 45);">significant issues</span> like <span style="color: rgb(224, 62, 45);">unplanned downtime</span> (導致; 重大問題; 意外停機)
- can access <span style="color: rgb(224, 62, 45);">restricted</span> information (限制性的)
- Security professionals <span style="color: rgb(224, 62, 45);">are often tasked</span> with reviewing log files(被要求/要負責/通常的任務)
- Automate cybersecurity tasks with Python
- removing usernames that match <span style="color: rgb(224, 62, 45);">specific criteria</span> from an access list.（特定標準）
- Make sure your browser <span style="color: rgb(224, 62, 45);">is up to date with the latest version</span>(確認瀏覽器是最新的版本)
- it might be used to determine <span style="color: rgb(224, 62, 45);">whether or not to lock an account</span>. (是否鎖定帳戶)
- checks whether someone is allowed to <span style="color: rgb(224, 62, 45);">access a particular</span> file (是否...; 存取特定檔案)
- improve <span style="color: rgb(224, 62, 45);">efficiency</span>; allow it to work <span style="color: rgb(224, 62, 45);">effectively</span> (提高效率; 有效運作)
- use Python code to reduce the <span style="color: rgb(224, 62, 45);">manual effort</span> needed to manage an access control list(人工作業; )
- <span style="color: rgb(224, 62, 45);">Throughout</span> this certificate you will use Qwiklabs and Jupyter Notebooks to complete <span style="color: rgb(224, 62, 45);">hands-on</span> activities（整個認證課程中；實作）
- Security analysts can access Python through <span style="color: rgb(224, 62, 45);">a variety of environments</span>（各種環境）
- The fast.log file is used for basic logging and alerting and <span style="color: rgb(224, 62, 45);">is considered</span> a <span style="color: rgb(224, 62, 45);">legacy</span> file format（視為...；傳統）
- The Network-based IDS application <span style="color: rgb(224, 62, 45);">inspects</span> network traffic from different devices on the network（檢查/審視）
- When <span style="color: rgb(224, 62, 45);">suspicious</span> or <span style="color: rgb(224, 62, 45);">unusual</span> network activity is detected（可疑的；不尋常的）
- IDS (Intrusion Detection System) is an application that monitors activity and <span style="color: rgb(224, 62, 45);">alerts on possible intrusions</span>.（監視活動；可能入侵的告警）
- Detection requires data, and this data can come from <span style="color: rgb(224, 62, 45);">various</span> data sources.（各種的）
- It’s important to know how to read and <span style="color: rgb(224, 62, 45);">interpret</span> different log formats so that you can <span style="color: rgb(224, 62, 45);">uncover</span> the key details surrounding an event and <span style="color: rgb(224, 62, 45);">identify</span> <span style="color: rgb(224, 62, 45);">unusual</span> or malicious activity.（解讀；發掘；查明；不尋常）
- logs provide key details about activities that <span style="color: rgb(224, 62, 45);">occurred</span> across an organization（發生）
- logs record events that <span style="color: rgb(224, 62, 45);">happen</span> on a network, or system.（發生）
- intrusion detection systems; intrusion prevent systems (IDS;IPS)
- investigating an alert involving a possible <span style="color: rgb(224, 62, 45);">network intrusion</span>（網路入侵）
- When <span style="color: rgb(224, 62, 45);">an outage occurs</span> due to a <span style="color: rgb(224, 62, 45);">security incident</span>（發生資安事件的停機）
- Business Continuity Plan（BCP 營運持續計畫）
- the three letters in the <span style="color: rgb(224, 62, 45);">CIA</span> triad stand for <span style="color: rgb(224, 62, 45);">confidentiality</span>, <span style="color: rgb(224, 62, 45);">integrity</span>, and <span style="color: rgb(224, 62, 45);">availability</span>（資安鐵三角；機密性；完整性；可用性）
- ensure that you complete a <span style="color: rgb(224, 62, 45);">thorough analysis</span> so that you have enough information to <span style="color: rgb(224, 62, 45);">make an informed decision</span> about your <span style="color: rgb(224, 62, 45);">findings</span>.（徹底分析；做出明智的決定；發現）
- you'll receive and <span style="color: rgb(224, 62, 45);">assess</span> the alert to <span style="color: rgb(224, 62, 45);">determine</span> if it's <span style="color: rgb(224, 62, 45);">a false positive</span>（評估；確定/決定；誤警報）
- which prioritizes incidents according to their level of <span style="color: rgb(224, 62, 45);">importance</span> or <span style="color: rgb(224, 62, 45);">urgency</span>.（重要等級或緊急程度）
- <span style="color: rgb(224, 62, 45);">Having previously investigated</span> the file hash, it is confirmed to be a known malicious file.（之前調查過檔案雜湊值，證實這是已知的惡意檔案）
- The email body and subject line contained <span style="color: rgb(224, 62, 45);">grammatical errors</span>.（語法錯誤）
- <span style="color: rgb(224, 62, 45);">Tedious, error-prone, or time-consuming tasks</span> can be automated, while analysts can <span style="color: rgb(224, 62, 45);">prioritize their time with</span> other tasks.（繁瑣，容易出錯或耗時工作；優先處理...）
- It is an example of a <span style="color: rgb(224, 62, 45);">non-automated playbook</span>, which requires <span style="color: rgb(224, 62, 45);">step-by-step</span> actions performed by an analyst.（非自動的手冊；一步一步動作）
- This depicts the process for detecting a DDoS and <span style="color: rgb(224, 62, 45);">begins with</span> determining <span style="color: rgb(224, 62, 45);">the indicators of compromise</span>, like unknown incoming traffic.（首先確定入侵指標；）
- Documentation must be <span style="color: rgb(224, 62, 45);">regularly</span> reviewed and updated to <span style="color: rgb(224, 62, 45);">keep up with</span> the evolving threat landscape. (文件必須定期審閱與更新，以跟上不斷演變的威脅形勢)
- Incident response plans standardize an organization’s response process by outlining procedures <span style="color: rgb(224, 62, 45);">in advance of an incident</span>. (事件發生前)
- If a malicious actor compromised a system, evidence must be available to determine their actions so that <span style="color: rgb(224, 62, 45);">appropriate legal action can be taken</span>. (採取適當的法律行動)
- You <span style="color: rgb(224, 62, 45);">observe</span> a known user successfully authenticate a new device using two-factor (觀察到; 注意到)
- Security terms 
    - malicious actors (惡意行為者)
    - malicious activity (惡意活動)
    - attackers (攻擊者)
    - security incidents（資安事件;安全事件）
    - security analysts（資安分析師; 安全分析師）
    - security professionals（資安專家; 安全專家）
    - security profession（資安工作）
    - security field（資安領域）
    - the <span style="color: rgb(224, 62, 45);">suspicious</span> IP address (可疑的)
    - <span style="color: rgb(224, 62, 45);">unusual</span> processes (不尋常的)
- IoCs may be the result of <span style="color: rgb(224, 62, 45);">human error</span>, <span style="color: rgb(224, 62, 45);">system malfunctions</span>, and other reasons not related to security. (人為錯誤; 系統故障)
- <span style="color: rgb(224, 62, 45);">baselines</span> help establish a standard of expected or normal behavior for systems, devices, and networks. (基線)
- A <span style="color: rgb(224, 62, 45);">baseline</span> is <span style="color: rgb(224, 62, 45);">a reference point</span> that’s used for comparison. (baseline 是...)
- Once <span style="color: rgb(224, 62, 45);">something unusual or suspicious</span> is detected (不尋常或可疑的東西)
- How could the company <span style="color: rgb(224, 62, 45);">prevent</span> an <span style="color: rgb(224, 62, 45);">incident</span> like this <span style="color: rgb(224, 62, 45);">from occurring</span> again?（如何防範這類的事件再發生）
- the stages of <span style="color: rgb(224, 62, 45);">incident detection</span>, investigation, analysis, and response（事故偵測；調查；分析；回應）
- analyze the contents of <span style="color: rgb(224, 62, 45);">captured packets</span>（擷取的封包）
- The app should be <span style="color: rgb(224, 62, 45);">in compliance with</span> PCI-DSS.（符合/遵守）
- developers <span style="color: rgb(224, 62, 45);">tend to</span> focus on <span style="color: rgb(224, 62, 45);">making</span> their applications <span style="color: rgb(224, 62, 45);">work correctly</span> <span style="color: rgb(224, 62, 45);">rather than</span> protecting their products from injection.（往往更；讓...正常運作；而不是）
- Malware（惡意軟體） 
    - Virus（病毒）
    - Worm（蠕蟲）
    - Trojan（木馬）
    - Ransomware（勒索軟體）
    - Spyware（間諜軟體）
- analyzing the <span style="color: rgb(224, 62, 45);">suspicious</span> message（可疑的）
- the group managed to <span style="color: rgb(224, 62, 45);">gain access to</span> the organization’s network and internal tools.（群體；成功取得...的存取）
- <span style="color: rgb(224, 62, 45);">Threat actors</span> use many different <span style="color: rgb(224, 62, 45);">tactics</span> to <span style="color: rgb(224, 62, 45);">carry out</span> their attacks.（威脅行動者；手法；執行）
- <span style="color: rgb(224, 62, 45);">unauthorized access</span> to <span style="color: rgb(224, 62, 45);">restricted systems</span>.（未經授權存取; 受限系統）
- specific type of attacks that <span style="color: rgb(224, 62, 45);">cybercriminals</span> commonly use. (網路犯罪)
- using fictitious emails to evaluate <span style="color: rgb(224, 62, 45);">security awareness</span> at the company. (安全意識)
- <span style="color: rgb(224, 62, 45);">Keeping</span> software <span style="color: rgb(224, 62, 45);">updated</span> requires <span style="color: rgb(224, 62, 45);">effort</span>. (軟體保持更新需要付出努力)
- Vulnerability scanners <span style="color: rgb(224, 62, 45);">are meant to</span> be <span style="color: rgb(224, 62, 45);">non-intrusive</span>. (應該; 非侵入性)
- Examples of <span style="color: rgb(224, 62, 45);">remediation</span> steps might include things like enforcing (矯正)
- We'll explore this step <span style="color: rgb(224, 62, 45);">in more details</span> (更多細節)
- An employee reports that they <span style="color: rgb(224, 62, 45);">cannot log into</span> the payroll system with their <span style="color: rgb(224, 62, 45);">access credentials</span>. (無法登入; 存取帳密)
- <span style="color: rgb(224, 62, 45);">Symmetric</span> and <span style="color: rgb(224, 62, 45);">asymmetric</span> encryption (對稱與非對稱加密)
- keep private; keep safe (保持私密; 保持安全)
- you'll review <span style="color: rgb(224, 62, 45);">the controls in place</span> to prevent data leaks. (現有的控制)
- <span style="color: rgb(224, 62, 45);">Periodically</span> auditing those accounts is a key part of <span style="color: rgb(224, 62, 45);">keeping</span> your company’s systems <span style="color: rgb(224, 62, 45);">secure</span>.（定期; 保持...安全）
- Score risks based on their <span style="color: rgb(224, 62, 45);">severity</span> (嚴重性)
- So much of the global marketplace has <span style="color: rgb(224, 62, 45);">shifted to</span> cloud-based services. (轉移至)
- <span style="color: rgb(224, 62, 45);">As</span> the environment continues to transform, (當...時候)
- Don't <span style="color: rgb(224, 62, 45);">get discouraged</span> now; Don't let anyone <span style="color: rgb(224, 62, 45);">discourage</span> you from cybersecurity. (不要灰心)
- <span style="color: rgb(224, 62, 45);">Suppose</span> you wanted to know what department the employee using ...（假設）
- The <span style="color: rgb(224, 62, 45);">principle of least privilege</span> is the concept of granting only the minimal access and authorization required to complete a task or function. （最小權限原則）
- we use u to <span style="color: rgb(224, 62, 45);">represent</span> the user, g to represent the group（表示; 代表）
- its output <span style="color: rgb(224, 62, 45);">indicates</span> that the working directory is logs （顯示; 指示）
- Although it <span style="color: rgb(224, 62, 45);">took some practice and time to get used to</span>, it has been one of the biggest tools ...（需要一些練習與時間來習慣）
- you'll <span style="color: rgb(224, 62, 45);">become much more familiar</span> with（變得更加熟悉）
- it <span style="color: rgb(224, 62, 45);">might happen</span> because we don't have the <span style="color: rgb(224, 62, 45);">appropriate</span> permissions to perform a command. (適合的)
- I <span style="color: rgb(224, 62, 45);">misspelled</span> the command（拼錯）
- the bash shell is <span style="color: rgb(224, 62, 45);">the most commonly used</span> shell in the ...（最常使用的）
- You might <span style="color: rgb(224, 62, 45);">examine</span> different types of logs to <span style="color: rgb(224, 62, 45);">identify what's going on in the system</span>. (檢查; 查明系統發生了什麼事)
- Almost everyone <span style="color: rgb(224, 62, 45);">learned on their own</span> <span style="color: rgb(224, 62, 45);">by experimenting</span> (透過實驗自學)
- These <span style="color: rgb(224, 62, 45);">individuals</span> will <span style="color: rgb(224, 62, 45);">likely</span> already have experience using GUIs (這些人; 可能)
- security analysts <span style="color: rgb(224, 62, 45);">commonly</span> use a CLI <span style="color: rgb(224, 62, 45);">in their everyday work</span> (通常; 日常工作中)
- using a GUI <span style="color: rgb(224, 62, 45);">is more like</span> ordering food from a restaurant. (更像)
- Using virtual machines <span style="color: rgb(224, 62, 45);">can also be an efficient</span> and convenient <span style="color: rgb(224, 62, 45);">way</span> to perform security tasks. (也可以是有效率且方便的方式)
- One more <span style="color: rgb(224, 62, 45);">aspect</span> to consider is that (還有一個考慮的方向是)
- The OS <span style="color: rgb(224, 62, 45);">is responsible for</span> ensuring that <span style="color: rgb(224, 62, 45);">each </span>program<span style="color: rgb(224, 62, 45);"> is</span> allocating and <span style="color: rgb(224, 62, 45);">de-allocating</span> resources. (負責; 釋放)
- <span style="color: rgb(224, 62, 45);">A variety of</span> programs, tasks, and processes <span style="color: rgb(224, 62, 45);">are</span> ... (各式各樣)
- The OS handles resource and memory management to ensure the <span style="color: rgb(224, 62, 45);">limited capacity of the computer system</span> is used <span style="color: rgb(224, 62, 45);">where it's needed most</span>. (電腦系統的有限容量; 最需要的地方)
- make sure all the resources of the computer are used <span style="color: rgb(224, 62, 45);">efficiently</span>. (有效地)
- Security analysts <span style="color: rgb(224, 62, 45);">should be aware of</span> vulnerabilities that <span style="color: rgb(224, 62, 45);">affect</span> operating systems. (應該要了解; 影響)
- They run multiple applications <span style="color: rgb(224, 62, 45);">at once</span> (一次)
- will be <span style="color: rgb(224, 62, 45);">an essential part of your job</span> as a security analyst. (基本部分工作)
- The <span style="color: rgb(224, 62, 45);">shared responsibility</span> model <span style="color: rgb(224, 62, 45);">states</span> that the CSP must take responsibility for... (共同職責模式；規定)
- <span style="color: rgb(224, 62, 45);">Brute force</span> attacks are a <span style="color: rgb(224, 62, 45);">trial-and-error</span> process of guessing passwords. (暴力破解; 反覆試驗)
- up-to-date; out-of-date (最新; 過期)
- security hardening <span style="color: rgb(224, 62, 45);">involves</span> minimizing the <span style="color: rgb(224, 62, 45);">attack surface</span> or <span style="color: rgb(224, 62, 45);">potential vulnerabilities</span> and <span style="color: rgb(224, 62, 45);">keeping a network as secure as possible</span>. (安全強化; 涉及/包括; 攻擊表面; 潛在漏洞; 盡可能保持網路安全
- refer to; referred to as (是指...; 這被稱為...) 
    - Software as a service, <span style="color: rgb(224, 62, 45);">refers to</span> software suites operated by the CSP that a company can use remotely without hosting the software.
    - it is <span style="color: rgb(224, 62, 45);">referred to as</span> a hybrid cloud environment.
- Open-source tools and <span style="color: rgb(224, 62, 45);">proprietary</span> tools (專有/私有工具)
- <span style="color: rgb(224, 62, 45);">Analyst; Analysis; Analyze; Analytic</span>
    - like machine learning or data analytics
    - As a security analyst
    - Splunk is a data analysis platform
    - Splunk Enterprise is a self-hosted tool used to retain, analyze and search the log data to provide security information and alert in real-time
- <span style="color: rgb(224, 62, 45);">From there</span> I <span style="color: rgb(224, 62, 45);">managed</span> to get myself into a security vendor and learn security (從那時開始, 我成功進入一家網路安全供應商學習網路安全)