Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium

A security operations center (SOC) receives an alert from its SIEM indicating multiple failed login attempts from an unknown IP address targeting a critical production server, followed by a successful login using a legitimate but rarely used administrative account. The SOC team immediately isolates the server, forces a password reset for the compromised account, and begins forensic analysis. Which security operation concept is the SOC team primarily demonstrating?

  1. AVulnerability Management
  2. BSecurity Metrics
  3. CThreat Intelligence
  4. DIncident Response
Show answer & explanation

Correct answer: D. Incident Response

The SOC team's actions—isolating the server, resetting passwords, and initiating forensic analysis—are direct responses to a detected security incident, which is the core of incident response.

Why the other options are wrong

  • A. Vulnerability management focuses on identifying and remediating weaknesses *before* they are exploited, not reacting to a successful exploit.
  • B. Security metrics are used to measure the effectiveness of security controls, not to manage an active incident.
  • C. Threat intelligence involves gathering and analyzing information about threats *before* an incident, not actively responding to one.

Incident Response

The organized approach to addressing and managing the aftermath of a security breach or cyber attack, aiming to contain, eradicate, and recover from the incident.

  • Follows a structured process (e.g., NIST SP 800-61).
  • Crucial for minimizing damage and recovery time.
  • Involves detection, analysis, containment, eradication, recovery, and post-incident activities.

Memory trick: When an alarm blares, Incident Response prepares!

More Security Concepts questions