nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #135

A SOC team notices repeated outbound HTTPS connections from a Compute Engine instance to an external IP every 60 seconds. CPU usage is normal and no malware signatures trigger. What is the BEST next…

The correct answer is C. Identify the process and service account generating the traffic. Understanding what is generating the traffic and under which identity is essential before

Incident Investigation and Response

Question

A SOC team notices repeated outbound HTTPS connections from a Compute Engine instance to an external IP every 60 seconds. CPU usage is normal and no malware signatures trigger. What is the BEST next analytical step?

Options

  • ABlock the destination IP immediately
  • BPower off the instance
  • CIdentify the process and service account generating the traffic
  • DNotify executive leadership

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    76% (16)
  • D
    14% (3)

Explanation

Understanding what is generating the traffic and under which identity is essential before

Topics

#beaconing detection#C2 traffic analysis#incident investigation#process attribution

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice