NASA6mo agoYou receive a SIEM alert for a suspicious login. What data sources will you use to confirm or disprove malicious activity.TechnicalSecurity Analyst
NASA6mo agoWrite a query that detects repeated authentication failures from the same IP within a 10-minute window. Then explain how you would determine whether the pattern indicates malicious activity or simple user error.TechnicalSecurity Analyst
NASA6mo agoThere are 3 classes of servers all with same critical vulnerability: public facing server, production databases with PII on it, and an office file share. Which one would you address first?TechnicalSecurity Analyst
NASA6mo agoTell me about a time you walked someone through removing malware from their device.TechnicalSecurity Analyst
Microsoft6mo agoWhere would you check in Windows to investigate a malicious process?TechnicalSecurity Engineer
NASA6mo agoImagine you are investigating an alert in Sentinel called EDR killer. What do you think that means and how would you investigate that?TechnicalSecurity Analyst