展示を参照してください。 疑わしい IP アドレスは、Threat Intelligence によってブルート フォース試行のソースとしてタグ付けされます。攻撃者は、失敗したログイン エントリを多数生成した後、アカウントを侵害します。インシデント対応の検出ステップを担当するのはどの関係者ですか?
正解:C
In the context of incident response, the detection step involves identifying potential security incidents. The Security Operation Center (SOC) Analyst, which in this case is Employee 4, is typically responsible for monitoring and analyzing security alerts to detect suspicious activities such as brute-force attempts. Therefore, Employee 4 would be the stakeholder responsible for the incident response detection step. Reference: The role of a SOC Analyst in incident response is outlined in cybersecurity frameworks and best practices, which describe the responsibilities of various stakeholders in detecting and responding to security incidents.