Question: Course Capstone Analyze SIEM Alerts: Alert # 4 : Account status change User was added to a different group, removed from a group, or added
Course Capstone Analyze SIEM Alerts: Alert #: Account status change User was added to a different group, removed from a group, or added to the security group by user ITUserAdmin Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert. a Alert #: Device login A user account logged into a desktop computer Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert. a Alert #: Service change Antimalware service stopped on a host Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert. a Alert #: LogonLogoff pattern User login outside of normal pattern Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert. a Alert #: File integrity Evidence log files were deleted or tampered with Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert. a Alert #: Geographic login disparity A user attempted to log in from places that are geographically separated by a long distance in a short amount of time. Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert. a Alert #: Logonlogoff pattern Excessive login attempts for a user Question: Should this issue be escalated? Answer: If you answered Yes: Briefly describe the potential impact of the issue, including its potential impact to CI.A a Describe any recommended immediate action to address the event. a Provide your recommendation for a security control to mitigate risk moving forward. a If you answered No: Provide your reason for dismissing the alert
a
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
