Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

A network intrusion detection system (NIDS) generates an alert showing unexpected SMB connection attempts originating from an internal workstation (192.168.10.45) directed toward an unassigned internal IP address (10.0.99.50) hosting a decoy server. Security policy dictates that no operational systems should ever communicate with this target address. Which of the following conclusions correctly interprets this network security monitoring alert?

  1. The alert indicates unauthorized internal lateral movement or reconnaissance detected by a deception monitoring control.Cevap
  2. B
    The deception asset failed to inline-drop the SMB packets before the connection request reached the listening service.
  3. C
    The target asset is functioning as a preventive control designed to remediate host configuration vulnerabilities automatically.
  4. D
    The security analyst must deploy perimeter Web Application Firewall rules to block the internal SMB connection attempts.

Cevap

The alert indicates unauthorized internal lateral movement or reconnaissance detected by a deception monitoring control.
Because honeypots are decoy assets with no legitimate operational role, any network traffic directed toward them serves as a high-fidelity indicator of unauthorized reconnaissance or lateral movement from a compromised host.

Adım Adım Çözüm

1
Analyze the alert telemetry, identifying the source IP, destination IP, and target protocol.
Identified internal host 192.168.10.45 initiating SMB connections to target host 10.0.99.50.
Determining the flow and nature of traffic is necessary to evaluate the security context of the alert.
2
Evaluate the functional role of the target asset in network operations.
Recognized 10.0.99.50 as a decoy/honeypot asset with zero legitimate production traffic.
Because honeypots serve no active business purpose, any connection attempt represents high-fidelity evidence of scanning or unauthorized lateral movement.
3
Select the option that accurately reflects the alert significance and security control classification.
Concluded that the event captures internal threat activity via a detective deception control.
Honeypots serve a detective function rather than acting as inline traffic firewalls or automated remediation utilities.

Anahtar Kavram

Deception Technology and Network Incident Alerting
Bu soruyu puanla