SECOPS-PRO · Question #62
During a post-incident review of a successful ransomware attack, the incident response team identifies that initial alerts were generated but deprioritized due to an 'Information' severity classificat
The correct answer is C. Develop correlation rules in the SIEM (e.g., Splunk, QRadar) or SOAR (e.g., XSOAR) to elevate. The core issue described is the failure to recognize a low-and-slow attack chain composed of individually low-fidelity events. Implementing correlation rules (Option C) in the SIEM or SOAR is the most effective solution. This allows the system to analyze multiple seemingly innocu
Question
During a post-incident review of a successful ransomware attack, the incident response team identifies that initial alerts were generated but deprioritized due to an 'Information' severity classification. Analysis reveals the alerts, while individually low-fidelity, collectively pointed to a reconnaissance phase followed by credential access on a critical server. What adjustment to the incident categorization and prioritization framework would be most effective in preventing similar oversights?
Options
- AImplement an automated system to escalate any 'Information' level alert to 'Low' severity after 24
- BMandate manual review of all 'Information' severity alerts by a Tier 1 SOC analyst within 1 hour of
- CDevelop correlation rules in the SIEM (e.g., Splunk, QRadar) or SOAR (e.g., XSOAR) to elevate
- DIncrease the threshold for all network-based alerts by 50% to reduce false positives and focus
- ECategorize all alerts related to critical servers as 'High' severity by default, irrespective of the
How the community answered
(35 responses)- A9% (3)
- C83% (29)
- D3% (1)
- E6% (2)
Explanation
The core issue described is the failure to recognize a low-and-slow attack chain composed of individually low-fidelity events. Implementing correlation rules (Option C) in the SIEM or SOAR is the most effective solution. This allows the system to analyze multiple seemingly innocuous events in sequence, identify patterns indicative of an attack (e.g., reconnaissance followed by credential access on a critical asset), and then automatically elevate the aggregated incident's severity and priority. Options A and B are inefficient or reactive. Option D risks missing legitimate threats. Option E would lead to significant alert fatigue and false positives, overwhelming analysts.
Topics
Community Discussion
No community discussion yet for this question.