A SOC team is responding to an incident where an attacker exfiltrated 50GB of data over three weeks. The team's incident response policy requires notifying stakeholders within 24 hours of incident confirmation. When does the 24-hour notification clock typically start?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because notification SLAs are typically triggered by the confirmation and declaration of an incident, not by the historical start of attacker activity which may be unknown at the time of discovery; the team must work to identify the timeline during the investigation while meeting notification requirements from the confirmation point. A is wrong because the exfiltration start date was three weeks ago and was not known; notification is triggered by confirmed discovery, not retroactive attacker activity start.
Full explanation below image
Full Explanation
B is correct because notification SLAs are typically triggered by the confirmation and declaration of an incident, not by the historical start of attacker activity which may be unknown at the time of discovery; the team must work to identify the timeline during the investigation while meeting notification requirements from the confirmation point. A is wrong because the exfiltration start date was three weeks ago and was not known; notification is triggered by confirmed discovery, not retroactive attacker activity start. C is wrong because the end of exfiltration is also in the past and doesn't trigger future notification obligations. D is wrong because SIEM alerts require analyst triage and confirmation before an incident is declared; an unreviewed alert is not a confirmed incident.