CS0-003 · Question #105
A security analyst at example.com receives SIEM alert for an IDS signature and reviews the associated packet capture and TCP stream: Packet capture: TCP stream: Which of the following actions should t
The correct answer is B. Contact the application owner for connect.example.local for additional information.. Anytime we receive alerts/offenses that appears to be a potential scan (interna/external), we already verify with the app owner/client if this was expected activity. We never close a ticket without confirmation, even its from an approved source.
Question
A security analyst at example.com receives SIEM alert for an IDS signature and reviews the associated packet capture and TCP stream:
Packet capture:
TCP stream:
Which of the following actions should the security analyst take NEXT?
Exhibits
Options
- AReview the known Apache vulnerabilities to determine if a compromise actually occurred
- BContact the application owner for connect.example.local for additional information.
- CMark the alert as a false positive scan coming from an approved source.
- DRaise a request to the firewall team to block 203.0.113.15.
How the community answered
(21 responses)- B86% (18)
- C5% (1)
- D10% (2)
Explanation
Anytime we receive alerts/offenses that appears to be a potential scan (interna/external), we already verify with the app owner/client if this was expected activity. We never close a ticket without confirmation, even its from an approved source.
Topics
Community Discussion
No community discussion yet for this question.

