SEARCH
You are in browse mode. You must login to use MEMORY

   Log in to start


From course:

ICE CONSULTING PRODUCTS & SERVICES

» Start this Course
(Practice similar questions for free)
Question:

ALERT & REPSONSE

Author: James Williams



Answer:

1. Create a ticket to track the event 2. Update the ticket with any enrichment data available. Identify Friend or Foe Add network information about the source Internal? Or External? Check blacklist information (AbuseIPDB, Zeus Tracker…) and add to ticket Identify the user logged into the system at time of event (if internal) 3. Classify the ticket Internal / External Recon, Exploit, Data Exfil,Malware, Unknown


0 / 5  (0 ratings)

1 answer(s) in total