XSIAM-ANALYST · Question #19
Based on the image below, which two additional steps should a SOC analyst take to secure the endpoint? (Choose two.)
The correct answer is A. Block 192.168.1.199. C. Isolate the affected workstation. Block 192.168.1.199: The image shows that the suspicious or malicious activity originated from this source IP address, making it a potential threat actor or compromised system on the network. Blocking this IP helps prevent further communication or lateral movement from the…
Question
Based on the image below, which two additional steps should a SOC analyst take to secure the endpoint? (Choose two.)
Exhibit
Options
- ABlock 192.168.1.199.
- BReboot the machine.
- CIsolate the affected workstation.
- DLive Terminal into the workstation to verify.
How the community answered
(48 responses)- A77% (37)
- B15% (7)
- D8% (4)
Explanation
Block 192.168.1.199: The image shows that the suspicious or malicious activity originated from this source IP address, making it a potential threat actor or compromised system on the network. Blocking this IP helps prevent further communication or lateral movement from the suspected Isolate the affected workstation: Since suspicious activities (like powershell_ise.exe running as an admin and launching splunkd.exe) are detected, isolating the workstation is a critical containment measure. This action disconnects the endpoint from the network, stopping any ongoing attack, lateral movement, or command-and-control activity, while allowing for forensic investigation. "Isolating an endpoint and blocking the source IP address are best practices for immediate containment in the event of detected compromise or suspicious activity."
Topics
Community Discussion
No community discussion yet for this question.
