Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

A Security Operations Center (SOC) analyst receives a high-priority alert from a Network Intrusion Detection System (NIDS) indicating anomalous outbound TCP traffic on port 443 with a mismatched Server Name Indication (SNI) header. In what order should the analyst execute the following triage and response steps to effectively investigate and mitigate the network threat?

  1. 1Review the NIDS alert metadata to establish the source IP, destination IP, and triggered signature details.
  2. 2Query NetFlow record telemetry to evaluate total session duration and traffic volume transferred between endpoints.
  3. 3Correlate network telemetry with endpoint detection logs to identify the specific host process driving the connection.
  4. 4Implement perimeter firewall block rules and isolate the affected endpoint from the internal network.

Cevap

The correct sequence begins with examining the initial NIDS alert metadata, querying NetFlow data to measure session impact, correlating network events with host endpoint logs, and ending with executing containment and network block rules.
The analyst must follow standard network security monitoring procedure: start by reviewing NIDS metadata for baseline context, examine NetFlow records for session metrics, cross-reference endpoint logs to determine the initiating process, and finally enforce containment once malicious activity is confirmed.

Adım Adım Çözüm

1
Analyze NIDS alert metadata
Identified source internal host IP and remote destination IP address
Initial triage requires verifying basic alert properties before conducting deeper analysis.
2
Evaluate NetFlow telemetry
Quantified session duration and total byte counts sent over the network
Flow statistics help assess potential impact and determine if large data transfers occurred.
3
Correlate with host endpoint logs
Identified the specific process and user account creating the socket connection
Linking network alerts to endpoint activity isolates the root cause software or script.
4
Execute containment and mitigation controls
Blocked outbound connection attempt and isolated compromised system
Active containment is performed after identifying and verifying the threat vector to prevent further damage.

Anahtar Kavram

Network Security Monitoring Triage Workflow
Tahmini Süre:1m 30s
Bu soruyu puanla