Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A security operations center (SOC) receives an alert from its SIEM indicating multiple failed login attempts from an unknown IP address targeting a critical production server, followed by a successful login using a legitimate but rarely used administrative account. The SOC team immediately isolates the server, forces a password reset for the compromised account, and begins forensic analysis. Which security operation concept is the SOC team primarily demonstrating?
- AVulnerability Management
- BSecurity Metrics
- CThreat Intelligence
- DIncident Response
Show answer & explanationAnswer & explanation
Correct answer: D. Incident Response
The SOC team's actions—isolating the server, resetting passwords, and initiating forensic analysis—are direct responses to a detected security incident, which is the core of incident response.
Why the other options are wrong
- A. Vulnerability management focuses on identifying and remediating weaknesses *before* they are exploited, not reacting to a successful exploit.
- B. Security metrics are used to measure the effectiveness of security controls, not to manage an active incident.
- C. Threat intelligence involves gathering and analyzing information about threats *before* an incident, not actively responding to one.
Incident Response
The organized approach to addressing and managing the aftermath of a security breach or cyber attack, aiming to contain, eradicate, and recover from the incident.
- Follows a structured process (e.g., NIST SP 800-61).
- Crucial for minimizing damage and recovery time.
- Involves detection, analysis, containment, eradication, recovery, and post-incident activities.
Memory trick: When an alarm blares, Incident Response prepares!