Below are network packet captures of malicious activity discovered on the network. Packets are captured when IDS/IPS or firewalls detect suspicious activity and then record the traffic. Depending on your configuration it may proactively block the traffic but it will ultimately end up as an alert for the SOC to investigate. The packet capture goes beyond the log files and provides a full picture of traffic on the network. In this lab you will be investigating and triaging a number of alerts as if you were a SOC analyst on call. It will be important to provide a technical understanding of the incidents but also put into context the impact to the business and identify the remediation steps. 2. The Business Implications Of These Results Explain how these detections impact the business, what are the short term and long-term risks presented?
Computer Science
Below are network packet captures of malicious activity discovered on the network. Packets are captured when IDS/IPS or firewalls detect suspicious activity and then record the traffic. Depending on your configuration it may proactively block the traffic but it will ultimately end up as an alert for the SOC to investigate. The packet capture goes beyond the log files and provides a full picture of traffic on the network. In this lab you will be investigating and triaging a number of alerts as if you were a SOC analyst on call. It will be important to provide a technical understanding of the incidents but also put into context the impact to the business and identify the remediation steps.
2. The Business Implications Of These Results
Explain how these detections impact the business, what are the short term and long-term risks presented?
Trending now
This is a popular solution!
Step by step
Solved in 2 steps