Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security operations center (SOC) analyst receives an alert from the SIEM indicating 'Multiple failed login attempts' for a critical administrative account on a domain controller. This alert is immediately followed by 'Successful login' from an unknown external IP address. What is the most appropriate immediate action for the analyst to take?
- AReset the password for the compromised administrative account.
- BReview firewall logs for the external IP address.
- CIsolate the domain controller from the network.
- DRun a full vulnerability scan on the domain controller.
Show answer & explanationAnswer & explanation
Correct answer: C. Isolate the domain controller from the network.
Given the 'Successful login' from an unknown external IP after failed attempts, it strongly indicates a compromise. The most critical immediate action is to isolate the affected system to prevent further compromise or lateral movement within the network, then investigate.
Why the other options are wrong
- A. Resetting the password is important, but without isolating the system first, the attacker might still have active sessions or other persistence mechanisms.
- B. Reviewing firewall logs is part of the investigation, but isolating the system takes precedence to contain the threat.
- D. A vulnerability scan is a proactive measure; it's too late for detection and response to an active compromise.
Incident Response - Containment
The phase in incident response aimed at stopping the spread of an incident, preventing further damage, and isolating affected systems.
- Immediate action after detection and analysis.
- Goal is to limit the scope and impact of the breach.
- Methods include network segmentation, system shutdown, or service disabling.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Learn – that’s the IR journey!