Detection and Network Incident Response
- Explain network security evidence and response
- Apply the idea to evidence from a realistic technology scenario
- Justify a decision using security, reliability, cost, and user impact
Detection and Network Incident Response
Detection combines preventive controls with logs, alerts, and context. Incident response follows preparation, detection and analysis, containment, eradication, recovery, and lessons learned. Network evidence helps determine entry path, affected assets, lateral movement, and data transfer.
Decision lens
Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.
A server begins scanning internal subnets minutes after a successful login from an unfamiliar country.
- 1.Correlate identity, server, firewall, and endpoint records.
- 2.The login and scanning sequence suggests possible account compromise and discovery.
- 3.Contain the account and server while preserving evidence.
- 4.Reset credentials, remove persistence, close the entry path, recover, and monitor.
Which activity belongs in lessons learned?
Which response best demonstrates complete reasoning about network security evidence and response?
For a scenario about network security evidence and response, identify the decisive evidence before naming a response. A defensible conclusion here is: The correlated timeline supports rapid containment while a broader scope investigation continues.
Answer the 2 checkpoints as you read.
Sign in to save your progress