ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium

A security operations center (SOC) analyst observes a sudden and sustained increase in outbound network traffic from an internal server to an unknown external IP address. Further investigation reveals that the server is communicating over an unusual port and the traffic payload appears to be encrypted. Which of the following foundational security operations concepts is primarily being violated?

  1. AAnomaly Detection
  2. BDefense-in-Depth
  3. CLeast Privilege
  4. DSeparation of Duties
Show answer & explanation

Correct answer: A. Anomaly Detection

The scenario describes a deviation from baseline network behavior (sudden increase in traffic, unusual port, encrypted payload to unknown IP). Identifying such deviations is the core principle of anomaly detection.

Why the other options are wrong

  • B. Defense-in-Depth involves implementing multiple layers of security controls; while a breach might indicate a failure in one layer, the primary concept being applied to identify it is anomaly detection.
  • C. Least Privilege focuses on restricting user and process permissions to only what is necessary, which is not directly described as being violated here.
  • D. Separation of Duties prevents a single individual from controlling an entire critical process, and is not directly related to unusual network traffic patterns.

Anomaly Detection

Anomaly detection is a technique used to identify events or patterns that do not conform to expected behavior.

  • Identifies deviations from a baseline.
  • Can detect novel attacks or insider threats.
  • Often relies on statistical models, machine learning, or rule-based systems.

Memory trick: Anomalies are the 'odd ones out' in the security data crowd.

More Security Operations questions