QuestionQ96

Incident Response

You are a SOC analyst on duty during a high-severity incident involving a DDoS attack against your organization’s e-commerce platform. The attack is disrupting online transactions, and the incident-response team has assigned you to analyze live network traffic using the SOC’s SIEM tools and packet-capture systems. After identifying unusual traffic patterns and dissecting communication protocols, you trace the activity to several command-and-control (C2) servers directing a botnet. Your goal is to recommend an eradication strategy that will sever the attackers’ control over the infected devices and stop the attack. Based on this scenario, which of the following strategies will your team implement?

  • A Rate Limiting
  • B Blocking Potential Attacks
  • C Neutralizing Handlers
  • D Disabling Botnets
Explanation

Neutralizing C2 handlers disrupts the infrastructure that issues commands to the botnet’s infected devices, severing their connection to the attackers and halting coordinated DDoS activity. CISA describes botnet-disruption operations that severed victim computers’ connections to C2 servers.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!