A SOC analyst receives a high-priority alert: 'Lateral Movement Detected — SMB connection from workstation to domain controller using local admin credentials.' What is the most critical first investigative step?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the first step in any alert triage is validation — determining whether the activity is authorized (IT admins performing maintenance, backup agents, patch management systems) or malicious; escalating or taking disruptive action without validation wastes resources on false positives. A is wrong because reimaging without investigation destroys evidence and may cause unnecessary downtime if the activity was legitimate.
Full explanation below image
Full Explanation
B is correct because the first step in any alert triage is validation — determining whether the activity is authorized (IT admins performing maintenance, backup agents, patch management systems) or malicious; escalating or taking disruptive action without validation wastes resources on false positives. A is wrong because reimaging without investigation destroys evidence and may cause unnecessary downtime if the activity was legitimate. C is wrong because blocking all SMB enterprise-wide would disrupt file sharing, printing, and many critical services based on one alert. D is wrong because resetting the domain admin password based on a single unvalidated alert could disrupt IT operations and is premature.