ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 363 - CAS-004 discussion

Report
Export

A company recently deployed a SIEM and began importing logs from a firewall, a file server, a domain controller a web server, and a laptop. A security analyst receives a series of SIEM alerts and prepares to respond. The following is the alert information:

Which of the following should the security analyst do FIRST?

A.
Disable Administrator on abc-uaa-fsl, the local account is compromised
Answers
A.
Disable Administrator on abc-uaa-fsl, the local account is compromised
B.
Shut down the abc-usa-fsl server, a plaintext credential is being used
Answers
B.
Shut down the abc-usa-fsl server, a plaintext credential is being used
C.
Disable the jdoe account, it is likely compromised
Answers
C.
Disable the jdoe account, it is likely compromised
D.
Shut down abc-usa-fw01; the remote access VPN vulnerability is exploited
Answers
D.
Shut down abc-usa-fw01; the remote access VPN vulnerability is exploited
Suggested answer: C

Explanation:

Based on the SIEM alerts, the security analyst should first disable the jdoe account, as it is likely compromised by an attacker. The alerts show that the jdoe account successfully logged on to the abcusa-fsl server, which is a file server, and then initiated SMB (445) traffic to the abc-web01 server, which is a web server. This indicates that the attacker may be trying to exfiltrate data from the file server to the web server. Disabling the jdoe account would help stop this unauthorized activity and prevent further damage.

Disabling Administrator on abc-usa-fsl, the local account is compromised, is not the first action to take, as it is not clear from the alerts if the local account is compromised or not. The alert shows that there was a successful logon event for Administrator on abc-usa-fsl, but it does not specify if it was a local or domain account, or if it was authorized or not. Moreover, disabling the local account would not stop the SMB traffic from jdoe to abc-web01.

Shutting down the abc-usa-fsl server, a plaintext credential is being used, is not the first action to take, as it is not clear from the alerts if a plaintext credential is being used or not. The alert shows

that there was RDP (3389) traffic from abc-admin1-logon to abc-usa-fsl, but it does not specify if the credential was encrypted or not. Moreover, shutting down the file server would disrupt its normal operations and affect other users.

Shutting down abc-usa-fw01; the remote access VPN vulnerability is exploited, is not the first action to take, as it is not clear from the alerts if the remote access VPN vulnerability is exploited or not. The alert shows that there was FTP (21) traffic from abc-usa-dcl to abc-web01, but it does not specify if it was related to the VPN or not. Moreover, shutting down the firewall would expose the network to other threats and affect other services. Reference: What is SIEM? | Microsoft Security, What is a SIEM Alert? | Cofense

asked 02/10/2024
KENEILWE DITHLAGE
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first