Below are network packet captures of malicious activity discovered on the network. Packets are captured when IDS/IPS or firewalls detect suspicious activity and then record the traffic. Depending on your configuration it may proactively block the traffic but it will ultimately end up as an alert for the SOC to investigate. The packet capture goes beyond the log files and provides a full picture of traffic on the network. In this lab you will be investigating and triaging a number of alerts as if you were a SOC analyst on call. It will be important to provide a technical understanding of the incidents but also put into context the impact to the business and identify the remediation steps. 2. The Business Implications Of These Results Explain how these detections impact the business, what are the short term and long-term risks presented?

Management Of Information Security
6th Edition
ISBN:9781337405713
Author:WHITMAN, Michael.
Publisher:WHITMAN, Michael.
Chapter12: Protection Mechanisms
Section: Chapter Questions
Problem 5RQ
icon
Related questions
Question

Computer Science

Below are network packet captures of malicious activity discovered on the network. Packets are captured when IDS/IPS or firewalls detect suspicious activity and then record the traffic. Depending on your configuration it may proactively block the traffic but it will ultimately end up as an alert for the SOC to investigate. The packet capture goes beyond the log files and provides a full picture of traffic on the network. In this lab you will be investigating and triaging a number of alerts as if you were a SOC analyst on call. It will be important to provide a technical understanding of the incidents but also put into context the impact to the business and identify the remediation steps.

2. The Business Implications Of These Results

Explain how these detections impact the business, what are the short term and long-term risks presented?

Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 2 steps

Blurred answer
Similar questions
  • SEE MORE QUESTIONS
Recommended textbooks for you
Management Of Information Security
Management Of Information Security
Computer Science
ISBN:
9781337405713
Author:
WHITMAN, Michael.
Publisher:
Cengage Learning,
Systems Architecture
Systems Architecture
Computer Science
ISBN:
9781305080195
Author:
Stephen D. Burd
Publisher:
Cengage Learning
A+ Guide to Hardware (Standalone Book) (MindTap C…
A+ Guide to Hardware (Standalone Book) (MindTap C…
Computer Science
ISBN:
9781305266452
Author:
Jean Andrews
Publisher:
Cengage Learning