Question 1
A Tier 2 SOC analyst at a financial services firm is investigating a high-magnitude offense related to 'Anomalous Database Activity'. The offense is triggered by a rule that correlates login events from a privileged user account with subsequent large data extractions from a production database. To distinguish between a legitimate administrative task and a potential insider threat, which investigative step should the analyst prioritize?
Answer and explanation
Correct answer: B
The most effective next step is to analyze the payload of the associated events. This will reveal the specific SQL queries run, which provides crucial context to differentiate between a routine backup/maintenance script (e.g., SELECT * FROM table_backup) and a malicious data exfiltration attempt (e.g., SELECT ssn, credit_card FROM customers). Escalating without this context is premature, reviewing past offenses is less direct, and checking asset profiles does not explain the specific action taken.