Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security operations center (SOC) analyst receives an alert from the SIEM indicating 'Multiple failed login attempts' for a critical administrative account on a domain controller. This alert is immediately followed by 'Successful login' from an unknown external IP address. What is the most appropriate immediate action for the analyst to take?

  1. AReset the password for the compromised administrative account.
  2. BReview firewall logs for the external IP address.
  3. CIsolate the domain controller from the network.
  4. DRun a full vulnerability scan on the domain controller.
Show answer & explanation

Correct answer: C. Isolate the domain controller from the network.

Given the 'Successful login' from an unknown external IP after failed attempts, it strongly indicates a compromise. The most critical immediate action is to isolate the affected system to prevent further compromise or lateral movement within the network, then investigate.

Why the other options are wrong

  • A. Resetting the password is important, but without isolating the system first, the attacker might still have active sessions or other persistence mechanisms.
  • B. Reviewing firewall logs is part of the investigation, but isolating the system takes precedence to contain the threat.
  • D. A vulnerability scan is a proactive measure; it's too late for detection and response to an active compromise.

Incident Response - Containment

The phase in incident response aimed at stopping the spread of an incident, preventing further damage, and isolating affected systems.

  • Immediate action after detection and analysis.
  • Goal is to limit the scope and impact of the breach.
  • Methods include network segmentation, system shutdown, or service disabling.

Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Learn – that’s the IR journey!

More Security Monitoring questions