nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #40

An alert fires indicating lateral movement between endpoints. It was triggered after evaluating multiple unrelated activities, such as credential access and abnormal port scanning. What are likely…

The correct answer is B. Behaviorally inferred by a correlation rule D. Likely caused by a multi-stage correlation rule. Lateral movement isn't a single, observable event - it's a behavioral conclusion drawn from multiple suspicious activities observed over time. When a SIEM correlates credential access and abnormal port scanning to infer an attacker moving between systems, that inference is the…

Threat Detection and Analytics

Question

An alert fires indicating lateral movement between endpoints. It was triggered after evaluating multiple unrelated activities, such as credential access and abnormal port scanning. What are likely characteristics of this alert? (Choose two)

Options

  • ATriggered by an IOC match
  • BBehaviorally inferred by a correlation rule
  • CSuggests a pre-configured playbook was executed
  • DLikely caused by a multi-stage correlation rule

How the community answered

(29 responses)
  • A
    28% (8)
  • B
    59% (17)
  • C
    14% (4)

Explanation

Lateral movement isn't a single, observable event - it's a behavioral conclusion drawn from multiple suspicious activities observed over time. When a SIEM correlates credential access and abnormal port scanning to infer an attacker moving between systems, that inference is the definition of behavioral detection (B). Because the rule requires multiple distinct, unrelated event types to all be present before firing, it is by definition a multi-stage correlation rule (D) - one that chains together several detection stages rather than matching a single condition.

Why A is wrong: IOC (Indicator of Compromise) matches are atomic - a known malicious IP, file hash, or domain triggers the alert alone. This alert fired on behavioral patterns, not a known-bad indicator.

Why C is wrong: A playbook is a response workflow triggered after an alert fires. It describes remediation steps, not how the alert itself was generated.

Memory tip: Think of it as a recipe vs. an ingredient. An IOC match is one bad ingredient (A). A correlation rule is a recipe (D) that requires multiple ingredients - and when those ingredients describe behavior rather than known-bad signatures, the result is a behavioral inference (B). Multi-activity alert = multi-stage behavioral correlation.

Topics

#Lateral Movement#Correlation Rules#Behavioral Detection#Multi-stage Detection

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice