Soru

Zorluk: ZorNetwork Security Monitoring and Alerting

A security analyst receives a high-priority alert from a perimeter Network Intrusion Detection System (NIDS) indicating anomalous, high-frequency outbound HTTPS connections from an internal host to an unrated external IP address. Place the operational monitoring and initial response steps in the correct chronological order from alert reception to formal escalation.

  1. 1Analyze raw network telemetry and packet captures (PCAP) to validate the alert signature and rule out a sensor false positive.
  2. 2Cross-examine SIEM and host-level endpoint detection logs to confirm whether malicious process execution occurred on the source host.
  3. 3Apply network isolation controls to the affected endpoint to contain potential command-and-control (C2) communication.
  4. 4Document verified indicators of compromise (IoCs) and formally escalate the case to the Incident Response team.

Cevap

The correct chronological order begins with validating raw network telemetry and packet captures to rule out false positives, followed by correlating network activity with host-level SIEM logs to verify compromise. Once verified, network isolation controls are applied to contain the threat, and finally, gathered IoCs are documented and escalated to the Incident Response team.
The triage workflow follows a logical progression: packet validation (confirming the network anomaly), host correlation (verifying execution and impact), endpoint containment (mitigating active threat risk), and incident escalation (handing over complete IoC artifacts).

Adım Adım Çözüm

1
Inspect packet captures and NIDS telemetry associated with the alert.
Alert authenticity is confirmed and false positive possibilities are eliminated.
Initial triage must always verify that an alert reflects genuine anomalous behavior before initiating invasive containment actions.
2
Correlate network alerts with host process logs and EDR events in the SIEM.
Scope of host execution and impact is determined.
Network monitoring alerts provide transport-layer visibility, but host correlation is required to assess whether malicious execution took place.
3
Initiate network containment by isolating the endpoint.
Active outbound C2 sessions and potential lateral movement vectors are severed.
Containment limits damage once threat activity or active compromise is verified.
4
Compile forensic findings and escalate the incident ticket.
Incident response personnel receive complete contextual data for remediation.
Escalation occurs after immediate containment and initial documentation are finalized.

Anahtar Kavram

Network Security Monitoring Triage and Incident Containment Lifecycle
Bu soruyu puanla