QuestionQ49

Threat Hunting Processes

The Security Operations Center receives two security information and event management alerts about two distinct possible attacks. The first alert involves brute-force attempts against a domain controller, and the second concerns network flooding. After an initial investigation, the team validates both alerts and starts a detailed investigation.

According to the CAPEC model, which vulnerability criterion should the team prioritize during the investigation?

Explanation

CAPEC identifies password brute forcing as having High typical severity and flooding as having Medium typical severity. Prioritizing the attack with the highest typical severity focuses the investigation on the incident with the greater expected impact.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!