nerdexam
Palo_Alto_Networks

XSIAM-ANALYST · Question #60

A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors state that the…

The correct answer is D. Remote Access. The Remote Access hunt collection surfaces tools and mechanisms (RATs, backdoors, remote services) attackers use to maintain persistence. Querying it will reveal where SystemBC or similar access channels were established across systems. Exam Questions, Study Guides, Practice…

Incident Investigation and Response

Question

A security analyst has been assigned a ticket from the help desk stating that users are experiencing errors when attempting to open files on a specific network share. These errors state that the file format cannot be opened. IT has verified that the file server is online and functioning, but that all files have unusual extensions attached to them. The security analyst reviews alerts within Cortex XSIAM and identifies malicious activity related to a possible ransomware attack on the file server. This incident is then escalated to the incident response team for further investigation. Upon reviewing the incident, the responders confirm that ransomware was successfully executed on the file server. Other details of the attack are noted below:

  • An unpatched vulnerability on an externally facing web server was

exploited for initial access

  • The attackers successfully used Mimikatz to dump sensitive

credentials that were used for privilege escalation

  • PowerShell was used on a Windows server for additional discovery, as

well as lateral movement to other systems

  • The attackers executed SystemBC RAT on multiple systems to maintain

remote access

  • Ransomware payload was downloaded on the file server via an external

site, "file.io" Refer to the scenario to answer this question:

Which hunt collection category in Cortex XSIAM should the incident responders use to identify all systems where the attackers established persistence during the attack?

Options

  • ANetwork Data
  • BProcess Execution
  • CCommand History
  • DRemote Access

How the community answered

(53 responses)
  • A
    28% (15)
  • B
    8% (4)
  • C
    15% (8)
  • D
    49% (26)

Explanation

The Remote Access hunt collection surfaces tools and mechanisms (RATs, backdoors, remote services) attackers use to maintain persistence. Querying it will reveal where SystemBC or similar access channels were established across systems. Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.

Topics

#ransomware#remote access investigation#file server#incident escalation

Community Discussion

No community discussion yet for this question.

Full XSIAM-ANALYST Practice