100-160 exam dumps

100-160 practice question 234 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 234

Select 3

A cybersecurity analyst is monitoring a Security Information and Event Management (SIEM) system and notices an alert indicating multiple failed login attempts on a critical server within a short timeframe. The analyst uses the SIEM to review the event logs and then leverages a Security Orchestration, Automation, and Response (SOAR) platform to address the issue. What actions should the analyst take to investigate and respond to this incident?

  1. A

    Analyze the event logs within the SIEM to identify the source IP address of the failed login attempts.

  2. B

    Use the SOAR platform to automatically block the suspicious IP address at the firewall.

  3. C

    Ignore the alert, as failed logins alone are not necessarily indicative of malicious activity.

  4. D

    Perform a packet capture to analyze the network traffic coming from the suspicious IP address for signs of malicious behavior.

  5. E

    Manually contact the user whose account is experiencing failed login attempts to verify if they are aware of the activity.

Show answer and explanation

Correct answers: A, B, D

Explanation

The SIEM system helps detect and monitor security incidents by analyzing event logs, while the SOAR platform can automate response actions. In this scenario, identifying the source of the failed login attempts using SIEM, automating a block using SOAR, and conducting an advanced investigation with packet captures are appropriate actions for incident investigation and response. Ignoring the alert or relying solely on user communication does not adequately address the potential threat.

  • A. Correct.

    Analyzing the event logs in the SIEM is a critical first step to investigate and identify the source of the suspicious activity, such as the IP address involved.

  • B. Correct.

    Using the SOAR platform to automate the blocking of the suspicious IP address is a valid response to prevent further potential unauthorized access attempts.

  • C. Incorrect.

    Ignoring the alert is not a recommended course of action, as multiple failed login attempts can be an indicator of a brute-force attack or other malicious activity.

  • D. Correct.

    Performing a packet capture allows for deeper investigation into the network traffic, which can help identify signs of malicious behavior, such as unusual data patterns or command-and-control communication.

  • E. Incorrect.

    While contacting the user might provide additional information, it is not the most immediate or effective action to investigate and respond to this incident.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam