Google
PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #135
A SOC team notices repeated outbound HTTPS connections from a Compute Engine instance to an external IP every 60 seconds. CPU usage is normal and no malware signatures trigger. What is the BEST next…
The correct answer is C. Identify the process and service account generating the traffic. Understanding what is generating the traffic and under which identity is essential before
Incident Investigation and Response
Question
A SOC team notices repeated outbound HTTPS connections from a Compute Engine instance to an external IP every 60 seconds. CPU usage is normal and no malware signatures trigger. What is the BEST next analytical step?
Options
- ABlock the destination IP immediately
- BPower off the instance
- CIdentify the process and service account generating the traffic
- DNotify executive leadership
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C76% (16)
- D14% (3)
Explanation
Understanding what is generating the traffic and under which identity is essential before
Topics
#beaconing detection#C2 traffic analysis#incident investigation#process attribution
Community Discussion
No community discussion yet for this question.