Scenario Based SOC Analyst Interview Questions and Answers | Part 1 | Security Analysts | SOC| Cyber

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 มิ.ย. 2024
  • SOC Interview Q&A: • SOC Analyst Interview ...
    Scenario Based SOC Interview Q&A Part 2: • Scenario Based SOC Ana...
    CyberSecurity Interview Question and Answer Playlist: • CyberSecurity Intervie...
    Incident Response Lifecycle : • Incident Response Life...
    EDR Interview: • EDR Interview Question...
    Subscribe here: / @cyberplatter8980
    CyberPlatter Discord Channel: / discord

ความคิดเห็น • 22

  • @sachin-tr4nc
    @sachin-tr4nc 9 หลายเดือนก่อน +10

    Finally started, Thanks for starting this session, It will help alot, please include Real time SIEM Scenario questions & answer with use cases, Thanks in Advance & Have a great year ahead 🙂

  • @a.r.bentley61
    @a.r.bentley61 25 วันที่ผ่านมา

    This is good information. it does leave out one critical part in the beginning: whether the employee took action on the email. If the employee simply opened the email, and realized it was spam/phishing/etc, they could simply just report it, mark it as spam/phishing, allow a cyber review of the email, and then delete once in the clear. If they do take action shes giving good steps to take.

  • @AI-InfoSec
    @AI-InfoSec 5 หลายเดือนก่อน +4

    How to start career as SOC what are the basic tools and knowledge to have while appearing for SOC Analyst

  • @sachin-tr4nc
    @sachin-tr4nc 9 หลายเดือนก่อน +7

    Hi Mam,
    Can you make videos on below mentioned Topic, as in whole youtube No one has done till now,
    So i request to please make
    "How to create use cases & How to Develop use cases with correlation Rules for All SIEM"
    Thanks in Advance Have a Great year ahead.

  • @sayoadeyemi5359
    @sayoadeyemi5359 หลายเดือนก่อน +1

    Very informative

  • @alis518
    @alis518 หลายเดือนก่อน

    Informative video

  • @ishwaryanarayan1010
    @ishwaryanarayan1010 7 หลายเดือนก่อน +2

    Thanks . Very informative videos

  • @Aryan-ij3bx
    @Aryan-ij3bx 3 หลายเดือนก่อน +2

    Thanks for your help ❤

  • @maruthikumar9171
    @maruthikumar9171 6 หลายเดือนก่อน +2

    thank you help a lot of information sharing.

  • @claudiamanta1943
    @claudiamanta1943 2 หลายเดือนก่อน

    Thank you. I am not an IT specialist, and all this is fascinating.
    I have a question. If that employee (who actually paid attention to the IT security training) had not opened that suspicious email, do you need to take all those steps that are hugely disruptive? Can you not contain the suspicious email and analyse it?
    I think it is more likely that you need to worry about the others in the organisation because the phishing attack might have been deployed at a larger scale and not all employees are as careful as the one who reported it. What would you do? Scan all network for that (and similar) email, isolate it, see on what devices it was open and quarantine those?
    PS- I love your Eastern European accent (is it Romanian? Hungarian?).
    Many thanks.

  • @aejazinamdar6226
    @aejazinamdar6226 7 หลายเดือนก่อน +2

    Hello madam, this video is really awesome. I have a question. If email is opened then it is fine. If user has accessed any attachment or links then it should be necessary to isolate. Pls confirm

  • @ale.9479
    @ale.9479 6 หลายเดือนก่อน +1

    Do you guys offer classes?

  • @user-iy6tf2uk5h
    @user-iy6tf2uk5h 6 หลายเดือนก่อน +3

    These questions are relevant for which level..? L1 , L2 or L3.....

    • @pavankalyan8489
      @pavankalyan8489 4 หลายเดือนก่อน

      All positions mainly L1 and some l2

  • @user-cz7fx9py3y
    @user-cz7fx9py3y 7 หลายเดือนก่อน

    Can we get pdf of these questions?

  • @priyadharshini4519
    @priyadharshini4519 8 หลายเดือนก่อน +2

    Ma'am, If the user has not opened/accessed any contents of the email in the first question. Is it still necessary to perform the device isolation, disabling the user from AD.?

    • @cyberplatter8980
      @cyberplatter8980  7 หลายเดือนก่อน +1

      Hi, Priya, the user is the one who is reporting the email (so they have at least opened the email) and the analyst is sure is a malicious one in this scenario. So, the immediate action is isolation. But if the user has not opened the email at all, you don't have to consider this.

    • @user-ln3kg4oj2q
      @user-ln3kg4oj2q 6 หลายเดือนก่อน +1

      Opening email and opening attachments... Any different process for these two scenarios??

    • @abdulrameez1265
      @abdulrameez1265 4 หลายเดือนก่อน

      Hi Ma'am, I have googled this. "If you open an email from a scammer without interacting with it, it won’t infect your machine, but the scammer will be able to gather data to use for targeted cyber attacks. For example, the scammer may be able to gather your IP address, the Operating System (OS) that you use and your location"