ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 429 - CAS-004 discussion

Report
Export

A SOC analyst received an alert about a potential compromise and is reviewing the following SIEM logs:

Which of the following is the most appropriate action for the SOC analyst to recommend?

A.
Disabling account JDoe to prevent further lateral movement
Answers
A.
Disabling account JDoe to prevent further lateral movement
B.
Isolating laptop314 from the network
Answers
B.
Isolating laptop314 from the network
C.
Alerting JDoe about the potential account compromise
Answers
C.
Alerting JDoe about the potential account compromise
D.
Creating HIPS and NIPS rules to prevent logins
Answers
D.
Creating HIPS and NIPS rules to prevent logins
Suggested answer: B

Explanation:

The SIEM logs indicate suspicious behavior that could be a sign of a compromise, such as the launching of cmd.exe after Outlook.exe, which is atypical user behavior and could indicate that a machine has been compromised to perform lateral movement within the network. Isolating laptop314 from the network would contain the threat and prevent any potential spread to other systems while further investigation takes place.

asked 02/10/2024
chengbin lin
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first