Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

The SOC team has detected and confirmed an incident with the following events been initially correlated: a suspicious out-of-office-hours activity (incl. external flash drive attached)

The SOC team has detected and confirmed an incident with the following events been initially

correlated: a suspicious out-of-office-hours activity (incl. external flash drive attached) on a

workstation connected to gateway 10; opening of a large number of files on a file server connected to

gateway 9; and a large volume of traffic between the workstation and a DB server connected to

gateway 5. Based on the advice you provided in Question 1 which of the data that has been collected

will be relevant to this case, and what evidence do you expect to derive from there?

This is an ongoing incident and as part of the Incident Response you have been asked to provide

advice on whether they need to start collecting any additional data, if so what type and from where

(both network-based as well as from end-points) - this is in addition to the advice you provided in

Question 1. The approach you advise should be forensically sound so that any evidence collected can

be used in court.

image

workstation workstation 8 workstation 5 ((41) 15 printer 9 workstation workstation workstation 1 2 printer printer workstation 12 ((41)) 14 10 workstation workstation workstation 13 7 4 workstation workstation printer, 11 workstation workstation workstation workstation workstation workstation workstation workstation workstation

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Financial Management for Public Health and Not for Profit Organizations

Authors: Steven A. Finkler, Thad Calabrese

4th edition

133060411, 132805669, 9780133060416, 978-0132805667

More Books

Students also viewed these Computer Network questions

Question

What is the effect of word war second?

Answered: 1 week ago

Question

Distinguish between cash basis and accrual basis accounting.

Answered: 1 week ago