Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

A Security Operations Center (SOC) analyst receives a high-priority alert from a Network Intrusion Detection System (NIDS) indicating suspicious outbound traffic from an internal enterprise workstation. Place the following analyst triage and incident response steps in the correct sequence, from initial alert evaluation to containment.

  1. 1Inspect the NIDS alert metadata in the SIEM dashboard to identify the alert signature, timestamp, and involved IP addresses.
  2. 2Query NetFlow and network packet capture (PCAP) records to analyze connection duration, volume, and payload characteristics.
  3. 3Cross-reference destination IP addresses and domain names against threat intelligence reputation feeds to assess malicious risk.
  4. 4Confirm the activity is a true positive Command and Control (C2) session and isolate the affected host network interface to prevent lateral movement.

Cevap

The correct sequence starts with inspecting the NIDS alert metadata in the SIEM, followed by querying NetFlow and PCAP telemetry records, cross-referencing destination indicators against threat intelligence feeds, and concluding with confirming the true positive alert and isolating the affected host.
Effective network security alert triage proceeds systematically from alert identification and SIEM evaluation, to telemetry deep-dive (NetFlow/PCAP analysis), threat intelligence enrichment, and finally root-cause confirmation leading to host containment.

Adım Adım Çözüm

1
Review initial SIEM alert details
Identified source workstation, destination IP, and specific NIDS signature.
Initial alert validation establishes baseline context before performing deeper queries.
2
Analyze supporting network telemetry (NetFlow/PCAP)
Detailed flow volume, session frequency, and packet characteristics gathered.
Telemetry logs confirm whether network traffic matched actual transmission patterns or was a false alarm.
3
Perform threat intelligence lookup
Destination IP confirmed to be associated with known botnet infrastructure.
Enriching local traffic data with global threat intelligence verifies malicious indicator severity.
4
Execute host containment
Workstation isolated from the network segment.
Immediate containment halts potential data exfiltration and lateral movement across the enterprise.

Anahtar Kavram

Network Security Monitoring Triage Workflow
Bu soruyu puanla