Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

A security analyst receives a high-severity alert from an inline Network Intrusion Prevention System (NIPS) indicating potential encrypted command-and-control (C2) beaconing originating from an internal endpoint to an untrusted external IP address. In what sequence should the analyst execute the network security monitoring and initial containment workflow?

  1. 1Correlate the NIPS alert with SIEM event logs and host context to verify alert authenticity and rule out a false positive.
  2. 2Initiate network isolation of the affected endpoint to prevent lateral movement and further outbound communications.
  3. 3Query historical NetFlow logs and packet captures (PCAP) to analyze traffic patterns and quantify potential data exfiltration.
  4. 4Apply perimeter firewall blocks and DNS sinkholing for the identified external command-and-control IP address and domain.
  5. 5Perform host-based forensic investigation to identify and purge the malicious process establishing the network socket.

Cevap

The correct response workflow begins with alert correlation in the SIEM, followed by isolating the endpoint, querying NetFlow and packet captures to quantify damage, implementing perimeter blocks, and finally conducting host forensic remediation.
The workflow follows standard incident response procedures: validation (verifying SIEM/NIPS alert), containment (host network isolation), investigation/scoping (NetFlow/PCAP analysis), enterprise protection (perimeter block/sinkholing), and eradication/remediation (host forensics).

Adım Adım Çözüm

1
Validate the NIPS alert against SIEM log aggregations.
Confirms the alert is a true positive C2 beaconing attempt.
Prevents unnecessary containment procedures caused by false-positive alerts.
2
Isolate the compromised internal endpoint from the network.
Halts active C2 communication and blocks lateral movement within the network.
Immediate containment is required once a true positive C2 connection is confirmed.
3
Inspect historic NetFlow records and PCAP data.
Establishes a timeline of network activity and measures exfiltration metrics.
Deep monitoring telemetry analysis reveals the extent of compromised data.
4
Deploy perimeter block rules and DNS sinkholes for the malicious external indicators.
Protects the broader organization from connecting to the C2 infrastructure.
Defends remaining assets while investigation continues.
5
Execute detailed host-based forensic analysis and malware remediation.
Removes the root cause process and restores the system to a clean state.
Ensures complete eradication of the threat before returning the asset to service.

Anahtar Kavram

Incident Response Triage and Containment Workflow in Network Security Monitoring
Bu soruyu puanla