NASA6mo agoYou receive a SIEM alert for a suspicious login. What data sources will you use to confirm or disprove malicious activity.TechnicalSecurity Analyst
NASA6mo agoWrite a query that detects repeated authentication failures from the same IP within a 10-minute window. Then explain how you would determine whether the pattern indicates malicious activity or simple user error.TechnicalSecurity Analyst
NASA6mo agoThere are 3 classes of servers all with same critical vulnerability: public facing server, production databases with PII on it, and an office file share. Which one would you address first?TechnicalSecurity Analyst