A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates that an attacker has installed a remote access tool on a user's laptop while traveling. The attacker has the user's credentials and is attempting to connect to the network.
What is the next step in handling the incident?
A. Block the source IP from the firewall
B. Perform an antivirus scan on the laptop
C. Identify systems or services at risk
D. Identify lateral movement
A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
A SIEM tool fires an alert about a VPN connection attempt from an unusual location. The incident response team validates
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!