Question 1
A SOC analyst at a financial institution is investigating a high-severity incident involving a compromised domain controller. The analyst needs to understand the full sequence of events, from initial access on a user's workstation to the final actions on the server. The analyst finds that the Causality Chain view for the incident seems to terminate after a svchost.exe process, failing to show the subsequent lateral movement. Which of the following is the most likely reason for this incomplete visualization?
Answer and explanation
Correct answer: D
The Causality Chain relies on tracking parent-child process relationships and other instrumented events. If an attacker uses a technique that breaks this chain, such as scheduling a task on a remote machine or using WMI for execution, the visualization can be broken. While other options are plausible security issues, the most direct cause for an incomplete Causality Chain is a break in the instrumented event lineage, which is common when attackers leverage legitimate system tools for lateral movement in ways that obscure their origin.