← Back to course

Network Evidence and Incident Triage

You’ll be able to

Network Evidence and Incident Triage

Network monitoring compares current activity with an expected baseline. Useful evidence includes source and destination addresses, ports, timestamps, DNS lookups, authentication events, and data volume. One unusual event is a clue; correlated events support a conclusion.

Decision lens

Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.

Worked example

At 2:10 a.m., a staff workstation makes hundreds of DNS requests to random-looking domains and uploads gigabytes to a new external address.

  1. 1.The time, domain pattern, and volume differ from normal office use.
  2. 2.Correlate DNS, firewall, endpoint, and sign-in logs.
  3. 3.Isolate the workstation while preserving evidence.
  4. 4.Block confirmed malicious destinations and determine whether credentials or data were compromised.
Answer: The combined indicators justify containment and investigation; a single blocked request alone would be weaker evidence.
Checkpoint

What is the best first response to a strongly suspected compromised endpoint?

Checkpoint

Which response best demonstrates complete reasoning about baselines, logs, indicators, and containment?

On the exam

For a scenario about baselines, logs, indicators, and containment, identify the decisive evidence before naming a response. A defensible conclusion here is: The combined indicators justify containment and investigation; a single blocked request alone would be weaker evidence.

Answer the 2 checkpoints as you read.

Sign in to save your progress