CS0-003 · Question #148
During a review of recent network traffic, an analyst realizes the team has seen this same traffic multiple times in the past three weeks, and it resulted in confirmed malware activity. The analyst…
The correct answer is C. Communicate the security incident to the threat team for further review and analysis. To improve future detection of known malicious traffic that currently lacks alerts, the analyst should engage the threat team for deeper review and analysis.
Question
During a review of recent network traffic, an analyst realizes the team has seen this same traffic multiple times in the past three weeks, and it resulted in confirmed malware activity. The analyst also notes there is no other alert in place for this traffic After resolving the security incident, which of the following would be the BEST action for the analyst to take to increase the chance of detecting this traffic in the future?
Options
- AShare details of the security incident with the organization's human resources management team
- BNote the security incident so other analysts are aware the traffic is malicious
- CCommunicate the security incident to the threat team for further review and analysis
- DReport the security incident to a manager for inclusion in the daily report
How the community answered
(30 responses)- A20% (6)
- B13% (4)
- C60% (18)
- D7% (2)
Why each option
To improve future detection of known malicious traffic that currently lacks alerts, the analyst should engage the threat team for deeper review and analysis.
Sharing details with the HR team is not an action to technically improve future detection of malicious network traffic.
Merely noting the incident for other analysts lacks an automated or systematic approach to ensure the traffic is detected reliably in the future.
If persistent malicious traffic is observed without existing alerts, it indicates a gap in the security detection mechanisms. The threat team or security engineering function is responsible for analyzing such incidents, developing new indicators of compromise (IOCs), signatures, or behavioral rules, and implementing them into security tools like SIEM or IDS/IPS to ensure future detection and prevention.
Reporting to a manager for daily reports is an administrative task and does not directly address the technical gap in detection capabilities.
Concept tested: Security incident response and improving detection
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.