A Suricata alert fires with the message 'ET POLICY Outbound DNS Query for TOR Exit Node.' The alert appears on a workstation used by a financial analyst. What should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because correlating the Suricata alert with Zeek dns.log and http.log provides context about what domain was queried, whether traffic followed, and whether other hosts are affected before taking action. A is wrong because reimaging without investigation destroys forensic evidence and may not address the root cause.
Full explanation below image
Full Explanation
B is correct because correlating the Suricata alert with Zeek dns.log and http.log provides context about what domain was queried, whether traffic followed, and whether other hosts are affected before taking action. A is wrong because reimaging without investigation destroys forensic evidence and may not address the root cause. C is wrong because blocking all DNS disrupts the entire organization based on a single alert. D is wrong because financial analysts have no legitimate business reason to query TOR exit node domains, and assuming benign intent is poor security practice.