CSOC Threat Detection and Incident Response 2 — Questions and Answers
Question 1: What is 'lateral movement' in the context of a cyber attack?
- The technique used by an attacker to progressively move through a compromised network to reach high-value targets (Correct answer)
- Moving malicious files across network segments to avoid detection
- The physical movement of a threat actor within a building to access a computer system
- Shifting attack traffic laterally between servers to avoid firewall detection
Correct answer: The technique used by an attacker to progressively move through a compromised network to reach high-value targets
Lateral movement describes how an attacker, after gaining initial access, navigates through a network to reach additional systems, escalate privileges, and access valuable assets. It is a key phase in many advanced persistent threat (APT) campaigns.
Question 2: What is the role of a 'playbook' in cybersecurity incident response?
- A predefined, documented set of steps for responding to specific types of security incidents consistently and efficiently (Correct answer)
- A log of all security incidents that have occurred over a defined period
- A training manual for new security operations centre staff
- A collection of threat intelligence reports from external cybersecurity agencies
Correct answer: A predefined, documented set of steps for responding to specific types of security incidents consistently and efficiently
An incident response playbook provides a standardised, step-by-step guide for responding to a specific type of incident such as ransomware, phishing, or DDoS. Playbooks reduce response time and ensure consistent handling of incidents.
Question 3: What does 'threat hunting' involve in a CSOC environment?
- Proactively searching through networks and systems for hidden threats that have evaded automated detection systems (Correct answer)
- Monitoring threat intelligence feeds for reports of new malware variants
- Responding to alerts generated by SIEM or IDS/IPS tools
- Conducting penetration tests to identify vulnerabilities before attackers do
Correct answer: Proactively searching through networks and systems for hidden threats that have evaded automated detection systems
Threat hunting is a proactive, human-driven process where analysts search for threats that may have bypassed automated detection tools. It involves hypothesis-based investigations, analysis of behavioural anomalies, and deep examination of system and network data.
Question 4: What is 'alert fatigue' in a CSOC and why is it a security risk?
- When analysts are overwhelmed by excessive security alerts, leading to desensitisation and missed real threats (Correct answer)
- When security systems fail due to processing too many alerts simultaneously
- When alerts are generated so rarely that analysts become unprepared for real incidents
- When automated systems flag all network traffic as suspicious, paralyzing operations
Correct answer: When analysts are overwhelmed by excessive security alerts, leading to desensitisation and missed real threats
Alert fatigue occurs when SOC analysts receive so many alerts that they begin to dismiss or overlook them, increasing the risk that genuine threats are missed. Reducing false positives and improving alert prioritisation are key strategies to address it.
Question 5: During a cybersecurity incident, why is it important to maintain a detailed incident timeline?
- A timeline establishes the sequence of events, supports forensic analysis, aids in containment decisions, and provides evidence for legal proceedings (Correct answer)
- A timeline is required only for incidents involving external attackers, not insider threats
- Maintaining a timeline is an administrative requirement that does not affect incident outcomes
- A timeline is created after the incident is fully resolved, not during the response
Correct answer: A timeline establishes the sequence of events, supports forensic analysis, aids in containment decisions, and provides evidence for legal proceedings
An incident timeline documents the chronological sequence of events, which is essential for understanding the attack's progression, making informed containment and eradication decisions, conducting forensic analysis, and supporting potential legal or regulatory proceedings.
Question 6: What is the significance of 'chain of custody' in cybersecurity incident response?
- It refers to the documented, unbroken record of how digital evidence has been handled, ensuring its integrity for potential legal proceedings (Correct answer)
- It is the sequence of command authority within the incident response team
- It describes how an attacker escalates privileges during an attack
- It is the process of handing over incident response responsibility between shifts in a CSOC
Correct answer: It refers to the documented, unbroken record of how digital evidence has been handled, ensuring its integrity for potential legal proceedings
Chain of custody ensures that digital evidence collected during an incident investigation is properly documented, preserved, and handled so that its integrity is maintained. This is essential if the evidence is to be used in legal or regulatory proceedings.
What is 'lateral movement' in the context of a cyber attack?