An analyst reviews EDR, email gateway, and firewall logs for a suspected intrusion: email delivery to user at 09:02, macro-enabled attachment executed at 09:15, outbound TLS beacon to rare domain at 09:21, SMB admin shares accessed from workstation at 09:36. Which sequence best supports identification and scoping?
Select an answer to reveal the explanation.
Short Explanation
Think of the timeline like a story: the email arrives, the user runs it, the malware phones home, then the attacker moves sideways. If you put lateral movement before C2, you're guessing where the attacker learned to go. Get the order right first, then scope the blast radius.
Full Explanation
Building an incident timeline means arranging observed events in the order they actually occurred so the analyst can identify the initial access vector and scope the affected systems. In a phishing intrusion, the earliest relevant artifact is usually the message delivery, followed by user execution of a malicious attachment or link. Once code runs, it commonly establishes command and control, and only after that does the attacker have remote tasking to move laterally. A sequence that places lateral movement before command and control is weak because lateral movement normally requires attacker-controlled instructions or credentials obtained through prior execution. A sequence that puts execution before delivery ignores the phishing delivery as the initial access event, making scoping harder because the entry point is unclear. A sequence that puts command and control before execution is also incorrect, since a beacon generally cannot occur before the payload has run on the endpoint. Exam caveat: CompTIA often tests the logical order of evidence from the incident response process, not every possible attacker variant, so use the artifacts shown in the scenario rather than assuming unusual tradecraft. Operational check: normalize timestamps from email gateway, endpoint detection logs, and network proxy or firewall, then sort them ascending before annotating affected hosts and accounts.