Network Evidence and Incident Triage
- Explain baselines, logs, indicators, and containment
- Apply the idea to evidence from a realistic technology scenario
- Justify a decision using security, reliability, cost, and user impact
Network Evidence and Incident Triage
Network monitoring compares current activity with an expected baseline. Useful evidence includes source and destination addresses, ports, timestamps, DNS lookups, authentication events, and data volume. One unusual event is a clue; correlated events support a conclusion.
Decision lens
Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.
At 2:10 a.m., a staff workstation makes hundreds of DNS requests to random-looking domains and uploads gigabytes to a new external address.
- 1.The time, domain pattern, and volume differ from normal office use.
- 2.Correlate DNS, firewall, endpoint, and sign-in logs.
- 3.Isolate the workstation while preserving evidence.
- 4.Block confirmed malicious destinations and determine whether credentials or data were compromised.
What is the best first response to a strongly suspected compromised endpoint?
Which response best demonstrates complete reasoning about baselines, logs, indicators, and containment?
For a scenario about baselines, logs, indicators, and containment, identify the decisive evidence before naming a response. A defensible conclusion here is: The combined indicators justify containment and investigation; a single blocked request alone would be weaker evidence.
Answer the 2 checkpoints as you read.
Sign in to save your progress