1
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

【TryHackMe】SOC Fundamentals:Walkthrough

Posted at

概要

TryHackMe「SOC Fundamentals」のWalkthroughです。

Task1

Q1.What does the term SOC stand for?

A.Security Operations Center

Task2

Q1.The SOC team discovers an unauthorized user is trying to log in to an account. Which capability of SOC is this?

image.png

A.Detection

Q2.What are the three pillars of a SOC?

image.png

A.People, Process, Technology

Task3

Q1.Alert triage and reporting is the responsibility of?

Hint.Choose the relevant role from the list in the task.

image.png

A.SOC Analyst (Level 1)

Q2.Which role in the SOC team allows you to work dedicatedly on establishing rules for alerting security solutions?

image.png

A.Detection Engineer

Task4

Q1.At the end of the investigation, the SOC team found that John had attempted to steal the system's data. Which 'W' from the 5 Ws does this answer?

image.png

A.Who

Q2.The SOC team detected a large amount of data exfiltration. Which 'W' from the 5 Ws does this answer?

image.png

A.What

Task5

Q1.Which security solution monitors the incoming and outgoing traffic of the network?

image.png

A.Firewall

Q2.Do SIEM solutions primarily focus on detecting and alerting about security incidents? (yea/nay)

image.png

A.yea

Task6

Q1.What: Activity that triggered the alert?

ポートスキャンのアクティビティが検知されました。

image.png

A.Port Scan

Q2.When: Time of the activity?

A.June 12, 2024 17:24

Q3.Where: Destination host IP?

SIEM Solutionの画面からDestination host ipが確認できます。

image.png

A.10.0.0.3

Q4.Who: Source host name?

Source Host Nameを確認できます。

image.png

A.Nessus

Q5.Why: Reason for the activity? Intended/Malicious

A.Intended

Q6.Additional Investigation Notes: Has any response been sent back to the port scanner IP? (yea/nay)

A.yea

Q7.What is the flag found after closing the alert?

プライベートIPレンジからのポートスキャンなので誤検知になります。
解答に正解するとフラグが表示されます。

image.png

A.THM{000_INTRO_TO_SOC}

1
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
1
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?