GCIH · Question #402
A SOC analyst is reviewing event logs from several network devices across the enterprise and notices that there are an abnormally high number of logon attempts across the desktop systems for several…
The correct answer is D. An event ticket should be created and escalated to the security team to investigate the attempts. The front line team in the SOC should have the authority to escalate any events that meet the criteria of a security issue to the responsive team. By issuing a ticket to the security team, they are logging the events, collecting the information and applying a service level…
Question
A SOC analyst is reviewing event logs from several network devices across the enterprise and notices that there are an abnormally high number of logon attempts across the desktop systems for several user IDs. What should the analyst do next?
Options
- AThe desktop teams should be notified to suspend the accounts of the users and reissue new
- BAn IDS signature should be deployed to monitor the user's logon attempts and alert the SOC of
- CEach device should be examined for any successful logon attempts within the past 24 hours.
- DAn event ticket should be created and escalated to the security team to investigate the attempts.
How the community answered
(24 responses)- A4% (1)
- B13% (3)
- C4% (1)
- D79% (19)
Explanation
The front line team in the SOC should have the authority to escalate any events that meet the criteria of a security issue to the responsive team. By issuing a ticket to the security team, they are logging the events, collecting the information and applying a service level agreement to the primary business group to handle. Failed logon attempts across multiple desktop systems for several users could indicate a manual or automated (virus/worm) attempt to probe common or collected usernames with a dictionary of pass phrases.
Topics
Community Discussion
No community discussion yet for this question.