Question 1
Q1A SOC analyst at an e-commerce company receives a high-severity alert from their Cisco Secure Firewall. The alert indicates a successful SQL injection attack against a public-facing web server, originating from an IP address in a foreign country. The application team has confirmed they cannot patch the vulnerability for at least 24 hours. Which mitigation technique should the analyst recommend as the most immediate and effective measure?
Show answer & explanation
Correct answer: C
Deploying a virtual patch on the IPS is the best immediate action. This technique uses the IPS to inspect traffic and block the specific malicious pattern (the SQL injection attempt) before it reaches the vulnerable server. This mitigates the risk without taking the server offline (which causes business impact) or only blocking a single source IP (which the attacker can easily change). Shutting down the database is a last resort and highly disruptive.