200-201 · Question #304
A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch. What are the two next steps of the SOC team
The correct answer is B. Isolate affected endpoints and take disk images for analysis. E. Detect the attack vector and analyze C&C connections.. Isolate affected endpoints and take disk images for analysis: Isolating affected endpoints helps prevent further potential damage or spread of the attack. Taking disk images enables a thorough forensic analysis of the affected endpoints to understand the extent of the compromise
Question
A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints, via Cisco StealthWatch. What are the two next steps of the SOC team according to the NIST.SP800-61 incident handling process? (Choose two.)
Options
- AUpdate antivirus signature databases on affected endpoints to block connections to C&C.
- BIsolate affected endpoints and take disk images for analysis.
- CBlock connection to this C&C server on the perimeter next-generation firewall.
- DProvide security awareness training to HR managers and employees
- EDetect the attack vector and analyze C&C connections.
How the community answered
(52 responses)- A13% (7)
- B56% (29)
- C25% (13)
- D6% (3)
Explanation
Isolate affected endpoints and take disk images for analysis: Isolating affected endpoints helps prevent further potential damage or spread of the attack. Taking disk images enables a thorough forensic analysis of the affected endpoints to understand the extent of the compromise and gather evidence for further investigation. Detect the attack vector and analyze C&C connections: Analyzing the attack vector helps in understanding how the attack occurred and identifying potential vulnerabilities or weaknesses in the network or systems. Analyzing Command and Control (C&C) connections provides insights into the attacker's methods, tactics, and the scope of the compromise, aiding in the response
Topics
Community Discussion
No community discussion yet for this question.