Q20Processes
A security analyst is investigating a whaling attack by correlating events from a SIEM, a detailed proxy-session log, and EDR logs. During the investigation, the analyst determines that several executive endpoints are connecting to C&C servers. The analyst reports the details to the incident response team and requests endpoint quarantine and suspicious email-domain blacklisting actions. According to NIST SP 800-61, at which incident-response step is the analyst?
← → navigate · a answer
Discussion · 0
No comments yet. Be the first.