QuestionQ28

Security Operations

A SOC analyst identifies reconnaissance activity originating from an IP address. The activity follows a pattern of brief bursts directed at a small number of targets. An open-source review indicates that the IP has a poor reputation. Perimeter firewall logs show that the inbound traffic was permitted. The destination hosts are high-value assets with EDR agents installed. Which of the following is the best action for the SOC to take to protect against further activity from the source IP?

Explanation

An EDR deny-list entry can enforce a targeted block of a known-bad external IP on the protected high-value endpoints, preventing additional connections from that source. EDR platforms support custom IP indicators and blocking actions based on organization-provided threat intelligence. SIEM alerting does not prevent traffic, and a WAF would protect only applicable web traffic rather than all endpoint-directed activity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!