nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #19

Based on the image below, which two additional steps should a SOC analyst take to secure the endpoint? (Choose two.)

The correct answer is A. Block 192.168.1.199. C. Isolate the affected workstation. Block 192.168.1.199: The image shows that the suspicious or malicious activity originated from this source IP address, making it a potential threat actor or compromised system on the network. Blocking this IP helps prevent further communication or lateral movement from the…

Incident Investigation and Response

Question

Based on the image below, which two additional steps should a SOC analyst take to secure the endpoint? (Choose two.)

Exhibit

XSIAM-ANALYST question #19 exhibit

Options

  • ABlock 192.168.1.199.
  • BReboot the machine.
  • CIsolate the affected workstation.
  • DLive Terminal into the workstation to verify.

How the community answered

(48 responses)
  • A
    77% (37)
  • B
    15% (7)
  • D
    8% (4)

Explanation

Block 192.168.1.199: The image shows that the suspicious or malicious activity originated from this source IP address, making it a potential threat actor or compromised system on the network. Blocking this IP helps prevent further communication or lateral movement from the suspected Isolate the affected workstation: Since suspicious activities (like powershell_ise.exe running as an admin and launching splunkd.exe) are detected, isolating the workstation is a critical containment measure. This action disconnects the endpoint from the network, stopping any ongoing attack, lateral movement, or command-and-control activity, while allowing for forensic investigation. "Isolating an endpoint and blocking the source IP address are best practices for immediate containment in the event of detected compromise or suspicious activity."

Topics

#endpoint isolation#IP blocking#SOC response#incident containment

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice