Help desk tells the SOC the city was breached because an IDS signature fired toward the elections file server. Which CIM field should the analyst check first before escalating?
Select an answer to reveal the explanation.
Short Explanation
An IDS fire can be a smoke alarm that already went off in a locked vault. Check action first: allowed versus blocked. Do not call a breach until you know the control actually let the session through.
Full Explanation
On Network_Traffic and Intrusion_Detection models, the CIM action field records whether the control allowed or blocked the traffic. That is the first check before escalating a we-were-breached call from an IDS signature. User-agent, mail identity, and file-hash fields answer other questions and are not on DHCP leases or Authentication for this purpose. Use action to see whether the control already denied the session.