350-201(NEW-127Q) · Question #47
An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations…
The correct answer is D. Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in question, and cross-correlate other source events. Option D is correct because when anomalous network activity is detected, the first step is investigation, not action - you must identify what is happening before responding. Using StealthWatch or SIEM logs to map access points, understand which services are active during the…
Question
Options
- AAssign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
- BReview the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
- CTreat it as a false-positive, and accept the SIEM issue as valid to avoid alerts from triggering on weekends.
- DDefine the access points using StealthWatch or SIEM logs, understand services being offered during the hours in question, and cross-correlate other source events.
How the community answered
(14 responses)- A36% (5)
- B14% (2)
- C7% (1)
- D43% (6)
Explanation
Option D is correct because when anomalous network activity is detected, the first step is investigation, not action - you must identify what is happening before responding. Using StealthWatch or SIEM logs to map access points, understand which services are active during the suspicious window, and cross-correlate other events gives the engineer a complete picture needed to determine whether this is an attack, misconfigured service, or legitimate scheduled job.
Why the distractors fail:
- A is wrong because unusual global traffic outside business hours is suspicious activity - deferring to an incident handler without investigation skips the engineer's core responsibility.
- B is wrong because immediately blocking all traffic is a premature, disruptive action taken before understanding the scope or nature of the activity; documentation of a call center call is also irrelevant here.
- C is wrong because dismissing recurring, geographically anomalous traffic as a false-positive without evidence is negligent - it could be exfiltration, C2 beaconing, or DDoS participation.
Memory tip: Think of the engineer as a doctor - you don't prescribe treatment (block traffic) or discharge the patient (false-positive) before running diagnostics (logs + correlation). The Sunday-night pattern is a classic indicator of scheduled malicious activity like data exfiltration or botnet callbacks, making thorough log analysis essential.
Topics
Community Discussion
No community discussion yet for this question.