Question: The Operations team has received intelligence from a credible internal source there may be an insider threat at Deepship. In your role as a Security
The Operations team has received intelligence from a credible internal source there may be an insider threat at Deepship. In your role as a Security Operations Center analyst you've been given the task of identifying a policy violation that may indicate the presence of an insider threat. Follow the steps below then select the correct indicators of compromise from the succeeding list.
Log into your Security Onion SIEM as you have done in previous weeks.
From the pane on the left of the screen under "Tools" click "Kibana"
Set the data picker range to Jun @ :: Aug @ ::
In the filter text box in the upper left of the screen, add the filter for event.dataset.keyword: rdp see the image for details
Kibana
Select correct answers
Question options:
Destination port
Destination IP
Destination IP
Destination IP
Source IP
Source IP
First connection July
First connection July
First connection July
Last connection July
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
