CS0-003 · Question #464
A SOC analyst observes reconnaissance activity from an IP address. The activity follows a pattern of short bursts toward a low number of targets. An open-source review shows that the IP has a bad repu
The correct answer is A. Add the IP address to the EDR deny list.. Blocking the IP address at the EDR (Endpoint Detection and Response) level provides an immediate, targeted response to the detected reconnaissance activity, preventing further interaction with the high-value assets. EDR tools are designed to detect and block malicious IPs across
Question
A SOC analyst observes reconnaissance activity from an IP address. The activity follows a pattern of short bursts toward a low number of targets. An open-source review shows that the IP has a bad reputation. The perimeter firewall logs indicate the inbound traffic was allowed. The destination hosts are high-value assets with EDR agents installed. Which of the following is the best action for the SOC to take to protect against any further activity from the source IP?
Options
- AAdd the IP address to the EDR deny list.
- BCreate a SIEM signature to trigger on any activity from the source IP subnet detected by the web
- CImplement a prevention policy for the IP on the WAF.
- DActivate the scan signatures for the IP on the NGFWs.
How the community answered
(42 responses)- A81% (34)
- B12% (5)
- C5% (2)
- D2% (1)
Explanation
Blocking the IP address at the EDR (Endpoint Detection and Response) level provides an immediate, targeted response to the detected reconnaissance activity, preventing further interaction with the high-value assets. EDR tools are designed to detect and block malicious IPs across endpoints.
Topics
Community Discussion
No community discussion yet for this question.