CAS-003 · Question #550
A security analyst is reviewing logs and discovers that a company-owned computer issued to an employee is generating many alerts and warnings. The analyst continues to review the log events and…
The correct answer is D. The analyst is blue team. An analyst monitoring SIEM alerts and logs to detect and report security events is performing a defensive role, which defines the blue team in a security exercise or ongoing security operations.
Question
A security analyst is reviewing logs and discovers that a company-owned computer issued to an employee is generating many alerts and warnings. The analyst continues to review the log events and discovers that a non-company-owned device from a different, unknown IP address is generating the same events. The analyst informs the manager of these findings, and the manager explains that these activities are already known and part of an ongoing events. Given this scenario, which of the following roles are the analyst, the employee, and the manager filling?
Options
- AThe analyst is red team
- BThe analyst is white team
- CThe analyst is red team
- DThe analyst is blue team
How the community answered
(57 responses)- A11% (6)
- B19% (11)
- C5% (3)
- D65% (37)
Why each option
An analyst monitoring SIEM alerts and logs to detect and report security events is performing a defensive role, which defines the blue team in a security exercise or ongoing security operations.
The red team performs offensive simulated attacks against systems; log review and alert monitoring are defensive activities incompatible with a red team role.
The white team administers and referees security exercises, setting rules and judging outcomes, rather than performing active SIEM monitoring and reporting.
This choice duplicates option A; the red team conducts offensive operations and does not perform defensive log analysis.
The blue team is responsible for defensive security operations including real-time monitoring, detection of anomalous activity, and escalating findings to management. An analyst reviewing SIEM logs, identifying unusual events across multiple devices, and reporting to a manager is performing the core functions of blue team operations. The manager's awareness of the activity as an ongoing event is consistent with an authorized security exercise in which the analyst's defensive monitoring role is the blue team.
Concept tested: Security team roles - blue team defensive monitoring
Source: https://csrc.nist.gov/glossary/term/blue_team
Topics
Community Discussion
No community discussion yet for this question.