A Security Operations Center (SOC) analyst reviewing network security monitoring (NSM) alerts identifies sustained IP protocol 47 (Generic Routing Encapsulation - GRE) traffic originating from an internal DMZ web server toward an unknown external IP address. NetFlow records confirm a high volume of asymmetric outbound data transfer. Which TWO of the following actions should the analyst take to address this network security incident?
- Isolate the compromised host from the network segment to halt active data exfiltration.Cevap
- Configure perimeter egress firewall rules to block unauthorized GRE traffic from leaving the network.Cevap
- CModify the web application code to enforce parameterized database queries.
- DReconfigure an internal honeypot sensor to inline mode to drop unauthorized packets.
Cevap
The analyst should isolate the compromised host from the network segment and configure perimeter egress firewall rules to block unauthorized GRE traffic.
Isolating the compromised server stops immediate outbound tunneling, while updating egress firewall rules prevents unauthorized GRE protocol traffic from crossing the enterprise boundary.
Adım Adım Çözüm
Anahtar Kavram
Network Traffic Anomaly Detection and Egress Containment
Tahmini Süre:1m 30s