While investigating a security event, the Tier 1 SOC analyst will have a set of objectives or questions they should answer. Match each objective to its description.
- defines the threat actors location ==> who
- determines the type of malware that raised the alert ==> where
- defines the originating source of the attack ==> why
- describes the initial system intrusion methods and or infection vectors used by the malware ==> how
- defines the observed date and time the event occurred ==> when
- describes the basic functionality of the malware and or how it might be leveraged ==> what
Explanation & Hint:
To match each objective with its appropriate description in the context of a Tier 1 SOC analyst’s responsibilities:
These objectives help a SOC analyst to construct a comprehensive understanding of the security event, from identifying the nature of the threat to understanding its origins, purposes, and methods of execution. |