A Zeek analyst notices entries in notice.log with the note type Scan::Port_Scan pointing to an internal IP address as the scanner. What does this indicate and what is the appropriate investigative action?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because an internal host generating port scan notices in Zeek indicates either a compromised host performing lateral movement reconnaissance or an unauthorized scanning tool; either scenario requires immediate investigation of the scanning host. A is wrong because the scanner is internal, not external; blocking at the perimeter firewall does not address the internal threat.
Full explanation below image
Full Explanation
B is correct because an internal host generating port scan notices in Zeek indicates either a compromised host performing lateral movement reconnaissance or an unauthorized scanning tool; either scenario requires immediate investigation of the scanning host. A is wrong because the scanner is internal, not external; blocking at the perimeter firewall does not address the internal threat. C is wrong because assuming routine IT activity without verification is poor security practice; legitimate IT scanning should be documented and excluded from detection. D is wrong because Zeek's Scan::Port_Scan notice has well-defined thresholds; while tuning may be needed, the first action is investigation, not dismissal.