ExamGecko
Question list
Search
Search

Related questions











Question 266 - 200-201 discussion

Report
Export

A SOC analyst detected connections to known C&C and port scanning activity to main HR database servers from one of the HR endpoints via Cisco StealthWatch. What are the two next steps of the SOC team according to the NISTSP800-61 incident handling process? (Choose two)

A.

Isolate affected endpoints and take disk images for analysis

Answers
A.

Isolate affected endpoints and take disk images for analysis

B.

Provide security awareness training to HR managers and employees

Answers
B.

Provide security awareness training to HR managers and employees

C.

Block connection to this C&C server on the perimeter next-generation firewall

Answers
C.

Block connection to this C&C server on the perimeter next-generation firewall

D.

Update antivirus signature databases on affected endpoints to block connections to C&C

Answers
D.

Update antivirus signature databases on affected endpoints to block connections to C&C

E.

Detect the attack vector and analyze C&C connections

Answers
E.

Detect the attack vector and analyze C&C connections

Suggested answer: A, C

Explanation:

According to the NIST SP 800-61 incident handling process, the SOC team should first isolate the affected endpoints to prevent further spread of the attack and take disk images for analysis (A). This helps in preserving evidence for a thorough investigation.The next step would be to block the connection to the C&C server on the perimeter next-generation firewall , which helps to cut off the communication between the compromised endpoint and the attacker's server, thereby mitigating the threat123.

asked 07/10/2024
Mahdi Far
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first