A security analyst who works in the SOC receives a new requirement to monitor for indicators of compromise. Which of the following is the first action the analyst should take in this situation?
A.
Develop a dashboard to track the indicators of compromise.
B.
Develop a query to search for the indicators of compromise.
C.
Develop a new signature to alert on the indicators of compromise.
D.
Develop a new signature to block the indicators of compromise.
before you make a monitor, how do you know what to monitor? Thus, making query/knowing what to search will have to be first before you know what to monitor. Answer is B.
It should be in this order from start to finish:
B. Develop a query to search for the indicators of compromise.
C. Develop a new signature to alert on the indicators of compromise.
A. Develop a dashboard to track the indicators of compromise.
D. Develop a new signature to block the indicators of compromise.
You can't possibly make an alert on an IOC unless you have defined the relevant search terms to find them first. Answer B.
B and C match, i tend twards B. A queary search in all the system integrated in a SIEM (endhost, logs from netflow, from switches etc). a signature refers to an IPS or maybe a HIPS. I first want to know if I was breached. So Query first , signature later.
In the soc that's what we do with new IOCs. at least the first thing, run a query. with a query you can build a correlation rule... which can use different methods of alerting one of which can be a dashboard which needs constant monitoring...
@NerdAlert me either. However, I would probably develop new signature to alert about IoC activity. Why not block? As the question states: we must MONITOR the activity. When alert will come to our SIEM, we can then investigate the offense and check if this activity is FP or real threat.
I dont understand this one. Anyone who knows and can explain?
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CS0-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Chilaqui1es
1 year, 8 months agoSecurityGuyPP
1 year, 8 months agoSimonR2
1 year, 11 months agojustauser
2 years agokarpal
2 years agoCyberCEH
2 years, 1 month agoHershey2025
2 years, 1 month agoHershey2025
2 years, 1 month agokill_chain
1 year, 11 months agoZUL01
2 years, 1 month agoNerdAlert
2 years, 1 month ago