An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service area. What are the next steps the engineer must take?
A) Assign the issue to the incident handling provider because no suspicious activity has been observed during business hours.
B) Review the SIEM and FirePower logs, block all traffic, and document the results of calling the call center.
C) Define the access points using StealthWatch or SIEM logs, understand services being offered during the hours in question, and cross-correlate other source events.
D) Treat it as a false positive, and accept the SIEM issue as valid to avoid alerts from triggering on weekends.
Correct Answer:
Verified
Q66: A security architect in an automotive factory
Q67: Which bash command will print all lines
Q68: An organization suffered a security breach in
Q69: An organization had an incident with the
Q70: A logistic company must use an outdated
Q72: A SOC team receives multiple alerts by
Q73: An analyst received multiple alerts on the
Q74: Which action should be taken when the
Q75: A cloud engineer needs a solution to
Q76: Engineers are working to document, list, and
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents