Quiz 3 Question 9 of 20

A security analyst reviews a SIEM alert generated by the organization's UEBA platform. The alert indicates that a user account, typically active between 08:00 and 17:00 on weekdays, initiated a large data transfer to an external IP address at 02:00 on a Saturday. The analyst confirms the account credentials are valid and MFA was successfully completed. What is the most appropriate next step to determine if this activity is malicious?

Select an answer to reveal the explanation.

Motivation