QuestionQ96
Incident ResponseYou are a SOC analyst on duty during a high-severity incident involving a DDoS attack against your organization’s e-commerce platform. The attack is disrupting online transactions, and the incident-response team has assigned you to analyze live network traffic using the SOC’s SIEM tools and packet-capture systems. After identifying unusual traffic patterns and dissecting communication protocols, you trace the activity to several command-and-control (C2) servers directing a botnet. Your goal is to recommend an eradication strategy that will sever the attackers’ control over the infected devices and stop the attack. Based on this scenario, which of the following strategies will your team implement?
- A Rate Limiting
- B Blocking Potential Attacks
- C Neutralizing Handlers
- D Disabling Botnets
Community Discussion