Search Header Logo
Table Top Exercise

Table Top Exercise

Assessment

Presentation

•

Computers

•

12th Grade

•

Practice Problem

•

Medium

Created by

Krissy Wong

Used 5+ times

FREE Resource

45 Slides • 11 Questions

1

media
media

Week 7

CompTIA Security+:
Application of
Knowledge during
Incident Response

Table Top Exercises & Scenarios

2

media
media

Scenario 1

Phishing Email Compromise

3

media
media

Tabletop Exercise 1: Phishing Email Compromise

Scenario: Company XYZ's help desk receives multiple
reports from employees who claim to have received
suspicious emails. One of these emails contains a link
to a fake Office 365 login page. Several employees
have entered their credentials. The company’s
incident response team (IRT) is alerted, and you are
part of the team tasked with handling the situation.

4

Multiple Choice

After receiving multiple reports of suspicious emails, what should be your first step in responding to the potential phishing attack?

1

Notify law enforcement.

2

Investigate email headers and analyze the content.

3

Investigate email headers and analyze the content.

4

Immediately block all email access.

5

​ Investigating the email headers and content will help confirm the authenticity of the phishing emails and provide insight into how they were delivered.

6

media
media

Phishing Email Compromise: Scenario Overview

Phishing attacks remain one of the most common vectors for credential
theft and network breaches. Cybercriminals send fraudulent emails to trick
users into divulging sensitive information or clicking on malicious links.

In this scenario, employees at Company XYZ report suspicious emails resembling official Office 365
messages.

Scenario Details:

●A phishing campaign targets employees with a fake Office 365 login page.

●Multiple employees fall victim and enter their login credentials, potentially compromising their
accounts.

●The incident response team must respond quickly to contain the breach and limit damage.

Objectives:

●Identify the steps to respond to this phishing attack.

●Assess the potential impact on Company XYZ.

●Mitigate the threat and recommend long-term solutions to prevent similar incidents.

7

media
media

Scenario 1: Phishing Email Compromise

Incident Summary:

On Tuesday morning, several employees at Company XYZ reported receiving
suspicious emails that appeared to be from Microsoft Office 365. These emails
contained a link to a fraudulent login page, where multiple employees
inadvertently entered their credentials. The company’s SOC team immediately
launched an investigation to determine the extent of the compromise. It was
confirmed that the phishing attack successfully compromised the accounts of
seven employees, who had their credentials stolen.

The SOC team responded by disabling the affected accounts and conducting a
company-wide password reset. Multi-factor authentication (MFA) was enforced
across all user accounts to prevent unauthorized access. Further analysis of
email headers and phishing payloads revealed that the emails originated from a
compromised third-party service provider.

8

media
media

Exercise 1 Phishing Email Compromise: Objectives

Objectives:

1.Identify key steps for responding to phishing
incidents.

2.Assess the extent of the damage and how
many users were compromised.

3.Contain the incident by securing user
accounts and mitigating potential risks.

4.Recommend long-term preventative
measures, such as security awareness training
and technical controls like multi-factor
authentication (MFA).

Key Points:

●Indicators of Compromise (IOCs):
Suspicious login attempts,
unusual email forwarding rules.

●Incident Response: Lock
compromised accounts, force
password resets, and monitor
affected users.

●Prevention: Phishing simulations,
email filtering, and training on
email security hygiene.

9

media
media

Exercise 1: Phishing Email Compromise

Questions for the IR team:

1.

Detection: How would you confirm that this is a ransomware attack, and
what indicators of compromise (IOCs) would you look for?

2.

Containment: What immediate steps would you take to isolate the
ransomware and prevent further spread?

3.

Eradication: Would you attempt to decrypt the files or start restoring from
backups? How would you handle backups in the same network segment?

4.

Recovery: What actions would you take to restore operations, considering
the risk of re-infection?

5.

Prevention: How could the company improve its backup strategy and
ransomware defenses in the future?

10

Multiple Choice

Which of the following would be the most effective containment measure for a phishing attack where credentials have already been stolen?

1

Update antivirus definitions.

2

Conduct a company-wide password reset for all users.

3

Instruct employees to ignore phishing emails.

4

Disable compromised accounts and implement multi-factor authentication (MFA).

11

​Disabling compromised accounts and implementing MFA helps prevent attackers from using the stolen credentials while enhancing security moving forward.

12

media
media

Scenario 1: Phishing Email Compromise

Stakeholders:

1.Affected Employees: The individuals whose accounts were compromised by the phishing attack.
They are directly impacted and may need to take additional actions, such as resetting passwords
and completing security training.

2.IT and SOC Teams: The technical staff responsible for investigating, containing, and mitigating the
phishing attack. They also play a role in providing guidance on how to prevent future incidents.

3.Company Executives and Leadership: Management, including the Chief Information Officer (CIO)
and Chief Information Security Officer (CISO), who are responsible for overseeing the organization’s
response and ensuring that company data remains secure. They may also be responsible for
communicating with external stakeholders.

4.Legal and Compliance Teams: They may need to assess whether any regulations or data
protection laws (e.g., GDPR, HIPAA) were violated due to the phishing attack, particularly if sensitive
information was compromised.

5.Third-party Vendors: Any external service providers whose systems may have been implicated in
the phishing attack, especially if the phishing emails appeared to originate from them.

6.All Employees: The phishing campaign affects the broader employee base, as additional training
and security measures, such as multi-factor authentication, may be rolled out across the company.

13

media
media

Lessons Learned: In response to
this incident, Company XYZ
implemented phishing awareness
training for all employees and
enhanced email filtering to detect
and block future phishing
attempts. The SOC team also
improved monitoring for abnormal
login patterns.

14

Multiple Choice

What long-term action can help prevent similar phishing attacks in the future?

1

Restrict all external emails from entering the company network.

2

Set up stronger firewalls.

3

Encrypt all internal emails.

4

Conduct regular phishing awareness training and simulate phishing attacks.

15

​Regular training and simulations can help employees recognize phishing attempts and reduce the likelihood of falling victim to such attacks.

16

media
media

Preventive Controls: Phishing Email Compromise

1.Security Awareness Training:

○Regular training to educate employees about phishing threats, how to recognize suspicious emails, and safe email
practices.

○Simulated phishing tests to keep employees vigilant.

2.Email Filtering and Anti-Phishing Tools:

○Deploy advanced email filtering solutions that scan incoming emails for malicious links, attachments, and patterns
associated with phishing attacks.

○Use anti-phishing tools that flag and quarantine potentially harmful emails before they reach employees.

3.Multi-Factor Authentication (MFA):

○Require MFA for all user accounts, making it harder for attackers to use stolen credentials from phishing attempts.

4.Email Header and Link Analysis:

○Implement systems that automatically analyze email headers and embedded links for indicators of phishing attempts
before allowing them into the network.

5.Incident Response Plan:

○Ensure the company has a robust incident response plan that includes specific steps for responding to phishing attacks
and credential compromise.

6.Domain-Based Message Authentication, Reporting & Conformance (DMARC):

○Use DMARC to authenticate legitimate emails from your domain and block emails that may be spoofing your company.

17

media
media

Scenario 2

Ransomware Attack on Critical Servers

18

media
media

Tabletop Exercise 2: Ransomware Attack

Scenario: Company XYZ is hit by ransomware that
encrypts files on its critical file servers. The attackers
demand a large ransom in Bitcoin. The company's
backups are available but are stored in the same
network segment as the affected servers. The SOC
team is tasked with responding to this incident.

19

Multiple Choice

Your company’s file servers have been encrypted by ransomware. What should be your first action?

1

Shut down the affected systems.

2

Disconnect the infected systems from the network to prevent further spread.

3

Attempt to decrypt the files using antivirus software.

4

Pay the ransom to avoid downtime

20

​Disconnecting infected systems prevents the ransomware from spreading to other parts of the network, which is critical in containing the attack.

21

media
media

Ransomware Attack on Critical Servers: Scenario Overview

Ransomware attacks encrypt vital company data and demand payment for the
decryption key. These attacks can cause massive operational disruption, data loss,
and financial damage.

In this scenario, Company XYZ is hit by ransomware targeting critical file servers.

Scenario Details:

●Attackers demand Bitcoin in exchange for decrypting the data.

●The company’s backup data is located on the same network segment as the encrypted
servers, leaving the organization vulnerable.

Objectives:

●Analyze how to respond to the ransomware incident.

●Prioritize recovery efforts and minimize data loss.

●Discuss strategies to enhance ransomware defenses moving forward.

●

22

media
media

Scenario 2: Ransomware Attack on Critical Servers

Incident Summary:

On Wednesday evening, Company XYZ detected a ransomware attack that
targeted the organization's critical file servers. The ransomware encrypted the
majority of the company’s data and demanded payment in Bitcoin for the
decryption key. Upon investigation, it was found that backups were also at risk,
as they were stored on the same network segment as the infected servers.

The SOC team quickly isolated the affected servers from the network to prevent
the ransomware from spreading further. After analyzing the situation, the team
opted to restore from backups that were fortunately unencrypted. The
restoration process was successful, and business operations were brought back
online within 48 hours.

23

Multiple Choice

If the company’s backups are stored on the same network segment as the encrypted servers, what risk does this pose?

1

The company may need to restore from local copies instead of cloud backups.

2

The backups might not be up-to-date.

3

The backups may also be encrypted or compromised.

4

The attackers could demand a higher ransom.

24

​ Storing backups on the same network segment as infected systems can lead to the backups being encrypted or compromised by the ransomware.

25

media
media

Exercise 2: Ransomware Attack on Critical Servers

Questions for the IR team:

1.

Detection: How would you confirm that this is a ransomware attack, and
what indicators of compromise (IOCs) would you look for?

2.

Containment: What immediate steps would you take to isolate the
ransomware and prevent further spread?

3.

Eradication: Would you attempt to decrypt the files or start restoring from
backups? How would you handle backups in the same network segment?

4.

Recovery: What actions would you take to restore operations, considering
the risk of re-infection?

5.

Prevention: How could the company improve its backup strategy and
ransomware defenses in the future?

26

media
media

Scenario 2: Ransomware Attack on Critical Servers

Stakeholders:

1.Business Unit Leaders: The managers responsible for the departments affected by the ransomware,
especially if critical business operations are disrupted (e.g., finance, HR, production). They need to be
informed of the status of operations and potential downtime.

2.IT and SOC Teams: The team leading the investigation, containment, and recovery efforts to bring systems
back online. Their quick response is essential for limiting the damage.

3.Company Executives (CISO, CIO, CEO): Senior leadership, particularly the CISO and CIO, are
responsible for overseeing the incident and ensuring the organization's strategic interests are protected. In
case of a major disruption, the CEO may also be involved in decision-making.

4.Legal and Compliance Teams: They need to assess whether reporting obligations apply under data
protection laws or industry regulations, and whether ransom payment considerations comply with legal
guidelines.

5.Customers and Clients: If the ransomware attack impacts critical data or customer information, clients
need to be notified and assured that steps are being taken to resolve the issue.

6.Backup and Recovery Providers: If the company relies on third-party providers for backup solutions, they
need to assist in the restoration process and ensure that backups are secure and available.

7.Public Relations Team: If the ransomware attack becomes public, the PR team will need to manage
communications to protect the company’s reputation and provide accurate information to stakeholders.

8.

27

Multiple Choice

Which of the following is the best long-term strategy to prevent future ransomware incidents?

1

Purchase ransomware insurance.

2

Train all employees to detect phishing emails.

3

Make daily full backups of all systems and store them on the same network.

4

Implement robust endpoint detection and response (EDR) tools.

28

​EDR tools are proactive in identifying and containing threats at the endpoint level, making them crucial for preventing ransomware infections.

29

media
media

Lessons Learned: Following this
incident, Company XYZ enhanced
its backup strategy by
implementing offline and offsite
backups, along with network
segmentation to protect critical
data. They also deployed endpoint
detection and response (EDR)
solutions to detect and mitigate
future ransomware threats.

30

media
media

Preventive Controls: Ransomware Attack on Critical Servers

Regular Backups and Offsite Storage:

●Maintain up-to-date, encrypted backups of critical data stored in secure, offsite or cloud locations that are not directly
connected to the network.

●Implement the "3-2-1" backup strategy: 3 copies of data, 2 on different media, and 1 offsite.

Endpoint Detection and Response (EDR):

●Deploy EDR solutions that continuously monitor endpoints for suspicious behavior, such as file encryption by unknown
processes, and isolate affected systems in real-time.

Network Segmentation:

●Separate critical systems and sensitive data from the general corporate network. Limit lateral movement to prevent
ransomware from spreading.

User Access Controls:

●Implement least-privilege access, where users only have access to the data and systems necessary for their role. Reduce
the likelihood of ransomware infecting high-value targets.

Patch Management:

●Regularly update and patch operating systems, software, and firmware to reduce vulnerabilities that ransomware might
exploit.

Email and Web Gateway Protections:

●Block or filter suspicious attachments, executables, and websites that are common delivery methods for ransomware
payloads.

Incident Response Plan with Ransomware-Specific Playbooks:

●Develop a playbook for responding to ransomware incidents, including network isolation, recovery, and communication
strategies.

31

media
media

Scenario 3

Data Exfiltration via Insider Threat

32

media
media

Tabletop Exercise 3: Data Exfiltration from Internal Threat

Scenario: A malicious insider at Company XYZ has
been slowly exfiltrating sensitive customer data to an
external server. The activity has been detected
through network traffic analysis. The SOC team must
respond immediately to prevent further data loss
and mitigate the damage caused by the breach.

33

Multiple Choice

You have detected suspicious outbound network traffic indicating that sensitive data is being exfiltrated. What is the first step in responding to this insider threat?

1

Fire the employee involved.

2

Block the suspicious outbound traffic and preserve logs for investigation.

3

Disconnect the network entirely.

4

Notify all users of a data breach

34

​Blocking the traffic limits further data loss, and preserving logs allows you to analyze the scope of the breach and take appropriate actions.

35

media
media

Data Exfiltration Via Insider Threat: Scenario Overview

Insider threats are security risks that come from within an organization,
often in the form of disgruntled employees or those with malicious
intent. They can result in data breaches, intellectual property theft, and
financial loss.

In this scenario, a malicious insider at Company XYZ is slowly
exfiltrating sensitive customer data to an external location.
Scenario Details:

●
The insider has been identified through suspicious network traffic.

●
The data exfiltration has gone unnoticed for several weeks, potentially exposing
sensitive customer information.

Objectives:

●Develop a plan to identify the extent of the insider threat.

●Recommend a course of action to contain the breach.

●Implement long-term solutions to monitor insider activity and prevent future breaches.

●

36

media
media

Scenario 3: Data Exfiltration from Insider Threat

Incident Summary:

Over the course of several weeks, Company XYZ’s network monitoring tools
flagged unusual outbound data transfers from an employee’s workstation. Upon
further investigation, it was discovered that the employee had been exfiltrating
sensitive customer data to an external server. The insider had managed to avoid
detection for weeks, slowly transferring data under the guise of normal
operations.

Once the SOC team confirmed the data exfiltration, they immediately blocked
the employee’s network access, preserved evidence for further legal action, and
initiated an internal investigation. The data exfiltration was halted, and all
affected customers were notified of the breach.

37

media
media

Exercise 3 Data Exfiltration from Insider Threat: Objectives

Objectives:

1.Identify the scope of the data breach and the
individual responsible for the malicious
activity.

2.Contain the threat to prevent further data
leakage.

3.Recommend strategies for monitoring and
preventing future insider threats.

Key Points:

●Tools: Use Data Loss Prevention

(DLP), Network Intrusion Detection
Systems (NIDS), and logs to track the
data flow.

●Containment: Isolate the employee’s

system, block further access, and
preserve evidence for legal action.

●Prevention: Implement stricter access

controls, monitor user behavior (User
Behavior Analytics - UBA), and
enforce data encryption policies.

38

media
media

Exercise 3: Data Exfiltration from Internal Threat

Questions for the IR team:

1.

Detection: How would you investigate and verify the exfiltration activity, and what tools
would you use (e.g., SIEM, DLP solutions)?

2.

Containment: What steps would you take to prevent further data exfiltration and secure
sensitive information?

3.

Eradication: How would you handle the insider and prevent further breaches (e.g.,
employee termination, disabling accounts)?

4.

Recovery: What actions would you take to ensure the company recovers from the
breach and customers are notified?

5.

Prevention: What long-term security measures (e.g., insider threat detection programs,
user activity monitoring) would you implement to prevent future insider attacks?

39

Multiple Choice

Which of the following monitoring tools is most effective in identifying insider threats through data exfiltration?

1

Data Loss Prevention (DLP) systems.

2

Intrusion Prevention System (IPS).

3

Web Application Firewall (WAF).

4

Antivirus software

40

​DLP systems are specifically designed to monitor and prevent unauthorized data exfiltration, making them an essential tool for detecting insider threats.

41

media
media

Scenario 2: Ransomware Attack on Critical Servers

Stakeholders:

1.Affected Customers/Clients: The individuals or organizations whose sensitive data was exfiltrated. They need to be
informed of the breach and reassured that corrective actions are being taken.

2.HR Department: The employee responsible for the data exfiltration will need to be dealt with according to company
policies, potentially resulting in termination or legal action. HR must manage the disciplinary or legal process.

3.IT and SOC Teams: The technical teams responsible for identifying, investigating, and stopping the insider threat. They
also need to assess whether additional preventive measures, such as monitoring and access control, should be
implemented.

4.Company Executives (CIO, CISO): Senior management responsible for overseeing the response to the insider threat
and managing the impact on the company’s reputation and operations. They will also need to inform relevant external
stakeholders.

5.Legal and Compliance Teams: This group assesses the legal implications of the insider threat, particularly in terms of
data protection laws and potential litigation. They may also need to work with law enforcement if criminal charges are
pursued.

6.Data Privacy Officers (DPO): If the company has a dedicated DPO, they will be responsible for ensuring that the
company complies with data protection regulations, such as GDPR, and managing breach notifications.

7.Security Awareness Trainers: Following the incident, training programs may be revised or strengthened to prevent
future insider threats and enhance the security culture within the company.

8.Board of Directors: In the case of significant data breaches, the board may need to be informed to ensure appropriate
risk management and governance.

42

media
media

Lessons Learned: Company XYZ
reinforced its insider threat detection
program by implementing stricter
access controls and deploying Data
Loss Prevention (DLP) tools to
monitor and restrict the unauthorized
movement of sensitive data. The
company also instituted regular
audits of user activity to proactively
identify risky behaviors.

43

Multiple Choice

What should be the primary focus of long-term prevention strategies for insider threats?

1

Restricting all employees’ access to the internet.

2

Implementing zero-trust architecture and regular monitoring of user activity.

3

Running monthly vulnerability scans.

4

Encrypting all internal data.

44

​Zero-trust architecture ensures that users are only given the minimum necessary access, while regular monitoring helps identify suspicious behavior early.

45

media
media

Preventive Controls: Data Exfiltration from Insider Threat

Data Loss Prevention (DLP):

●Implement DLP systems to monitor, detect, and block unauthorized attempts to move sensitive data outside the organization.
This includes setting thresholds for abnormal data transfers.

User Activity Monitoring (UAM):

●Monitor and log user activities, especially for privileged accounts, to detect unusual patterns of behavior that may indicate insider
threats.

●Use AI and behavioral analytics to identify anomalies in user behavior, such as accessing data outside their normal duties.

Access Control Policies:

●Enforce strict role-based access control (RBAC) to ensure that employees only have access to the data necessary for their job
role. Regularly review and adjust these permissions.

Zero Trust Architecture:

●Adopt a zero-trust model, where every user, device, and network is continuously authenticated and authorized before access to
any resources is granted.

Network Segmentation and Encryption:

●Encrypt sensitive data both in transit and at rest to prevent unauthorized access to readable data. Ensure that sensitive data is
segregated from less sensitive areas of the network.

Exit Protocols and Offboarding:

●Establish strong exit protocols, including disabling user accounts, retrieving company-owned devices, and monitoring access
during an employee’s notice period to prevent exfiltration.

Regular Audits and Access Reviews:

●Perform regular audits of user access logs and conduct periodic access reviews to identify whether users have unnecessary
privileges or unauthorized access to sensitive data.

46

media
media

Solutions

47

Multiple Choice

During incident response, which phase involves taking steps to prevent similar incidents from happening in the future?

1

Detection.

2

Lessons Learned.

3

Recovery.

4

Eradication.

48

Multiple Choice

Which of the following is a critical component of any effective incident response plan?

1

Implementing company-wide password changes every week.

2

Encrypting all emails.

3

Relying solely on automated tools for threat detection.

4

Having a clear chain of command and communication process.

49

media
media

General Solutions (Applicable to All Scenarios):

Incident Response Plan:

●Resilient Incident Response Platform (IBM): A dedicated incident response management tool to help
organizations plan and execute responses to cyber incidents.

●Splunk Phantom: A security orchestration and response (SOAR) platform that automates incident response
workflows and integrates with SIEM solutions.

Security Information and Event Management (SIEM):

●Splunk Enterprise Security: A powerful SIEM platform for monitoring, detecting, and responding to security
threats in real-time.

●QRadar (IBM Security): Provides real-time threat detection and response capabilities, helping organizations
manage large-scale incident responses.

Third-Party Vendor Management:

●OneTrust Vendor Risk Management: Automates the management and assessment of third-party vendors
to ensure they meet security standards.

●BitSight: Provides continuous monitoring of third-party vendor security to ensure compliance and reduce risk
exposure.

50

media
media

Phishing Email Compromise

Security Awareness Training:

●KnowBe4: A popular security awareness training platform that offers phishing simulations and training programs to
educate employees on recognizing threats.

●Cofense PhishMe: Provides real-world phishing simulations and targeted training based on the types of phishing
attacks employees encounter.

Email Filtering and Anti-Phishing Tools:

●Microsoft Defender for Office 365: Offers advanced phishing and malware protection, including safe links, safe
attachments, and email filtering.

●Proofpoint Email Protection: Provides email filtering for spam, phishing, and other malicious content with advanced
threat protection capabilities.

Multi-Factor Authentication (MFA):

●Google Authenticator: A widely-used MFA solution for mobile devices to enhance account security.

●Duo Security (Cisco): A cloud-based MFA solution that integrates with many applications, ensuring secure access
through multiple layers of verification.

Email Header and Link Analysis:

●Mimecast: Provides deep email analysis for phishing, including scanning links and attachments for malicious
behavior.

●Barracuda Email Protection: Analyzes email headers and body content to block or quarantine potentially malicious
emails.

Domain-Based Message Authentication, Reporting & Conformance (DMARC):

●Valimail: Offers DMARC services to prevent email spoofing and enforce email authentication policies.

●EasyDMARC: A platform to simplify DMARC, DKIM, and SPF configurations and protect against email-based attacks.

51

media
media

Ransomware Attack on Critical Servers

Regular Backups and Offsite Storage:

●Veeam Backup & Replication: Provides reliable backups, offsite storage, and recovery options for physical, virtual, and cloud
environments.

●Acronis Cyber Backup: Offers advanced backup and disaster recovery features with encryption and protection from ransomware.

Endpoint Detection and Response (EDR):

●CrowdStrike Falcon: A leading EDR solution that continuously monitors endpoints for signs of compromise, enabling swift detection
and response to ransomware and other threats.

●Carbon Black (VMware): Provides EDR services to detect and respond to ransomware attacks through behavior analytics and
endpoint protection.

Network Segmentation:

●Cisco TrustSec: Provides software-defined network segmentation to isolate sensitive systems and limit ransomware propagation.

●Fortinet Security Fabric: Uses network segmentation to compartmentalize sensitive data and restrict access.

User Access Controls:

●Okta Identity Cloud: A user identity management solution that enforces role-based access controls, ensuring users only have access
to the systems they need.

●Microsoft Active Directory: Allows for detailed control of user permissions, group policies, and access control lists to enforce least
privilege.

Patch Management:

●Ivanti Patch Management: Automates the patching process across operating systems, third-party applications, and endpoint devices.

●Microsoft WSUS (Windows Server Update Services): Centralizes the patch management process for Microsoft products and
third-party applications in a Windows environment.

Email and Web Gateway Protections:

●Symantec Email Security Cloud: Offers protection against email-based ransomware attacks by blocking suspicious attachments and
links.

●Zscaler Web Security: Protects users from ransomware by scanning web traffic and blocking access to malicious sites and payloads.

52

media
media

Data Exfiltration from Insider Threat

Data Loss Prevention (DLP):

●Symantec DLP: Monitors data transfers across endpoints, email, and cloud services to prevent unauthorized data exfiltration.

●Forcepoint DLP: Detects and blocks attempts to move sensitive data out of the organization, both on-premises and in the cloud.

User Activity Monitoring (UAM):

●Teramind: Provides comprehensive user activity monitoring and behavioral analytics to detect and respond to insider threats.

●ObserveIT (Proofpoint): Tracks user behavior to prevent insider threats and data exfiltration through behavioral analysis.

Access Control Policies:

●BeyondTrust Privileged Access Management (PAM): Manages and monitors privileged accounts, ensuring users have the minimum
access necessary to perform their tasks.

●CyberArk: Enforces least privilege access and monitors privileged account usage to prevent insider misuse.

Zero Trust Architecture:

●Zscaler Zero Trust Exchange: Implements zero trust by verifying every user and device before granting access to network resources.

●Palo Alto Networks Prisma Access: Enforces zero trust network access by securing users and devices, regardless of location.

Network Segmentation and Encryption:

●Check Point Security Gateways: Offers network segmentation with built-in encryption to protect sensitive data from insider threats.

●Fortinet FortiGate: Provides network segmentation and encryption capabilities to isolate sensitive systems and data.

Exit Protocols and Offboarding:

●Workday HCM: Ensures smooth offboarding by automating the process of disabling accounts and retrieving assets.

●BambooHR: Offers a structured offboarding process to ensure former employees' access is terminated and company assets are
recovered.

Regular Audits and Access Reviews:

●Netwrix Auditor: Helps track user access and permissions, providing detailed audits to ensure compliance and detect unauthorized
access to sensitive data.

●SolarWinds Access Rights Manager: Reviews and manages user permissions, ensuring they align with company policies.

53

media
media

Real
World

Case Studies in Cyber Attacks

54

media
media

Real-World Example:
Ubiquiti Networks (2021)

●Incident: Ubiquiti Networks, a global provider of networking technology, fell victim to a
phishing attack that led to a massive data breach. Attackers sent phishing emails to
employees and gained access to privileged credentials, which allowed them to
exfiltrate sensitive information from the company's cloud environment. Ubiquiti initially
downplayed the severity of the breach but later revealed that it had compromised
sensitive customer data.

●Impact: The breach affected a significant portion of Ubiquiti's customer base, exposing
personal information and leading to a hit on the company’s reputation. Employees and
customers were urged to change their passwords and enable two-factor authentication.

Takeaway: This mirrors the phishing email compromise scenario where attackers trick
employees into divulging credentials, which are then used for unauthorized access. The
importance of MFA, email filtering, and user training is highlighted.

55

media
media

Real-World Example:
Colonial Pipeline (2021)

●Incident: Colonial Pipeline, which supplies nearly half of the East Coast's fuel, was hit
by a ransomware attack by the DarkSide group. The attackers gained access to the
company’s IT systems and deployed ransomware, forcing the pipeline's operators to
shut down operations for days. Colonial Pipeline ultimately paid a ransom of $4.4
million in Bitcoin to regain access to their systems.

●Impact: The shutdown caused fuel shortages and panic-buying along the East Coast,
leading to significant economic disruption. The attack raised awareness of the
vulnerability of critical infrastructure and prompted government action to improve
cybersecurity defenses.

Takeaway: This event mirrors the ransomware attack scenario where critical systems are
compromised, leading to a shutdown of operations. Effective incident response planning,
regular backups, and network segmentation could have mitigated the impact.

56

media
media

Real-World Example:
Tesla Insider Data Leak (2020)

●Incident: Tesla thwarted an insider plot where a Russian hacker attempted
to recruit a Tesla employee to introduce malware into the company’s
systems. The plan was to use the employee to plant ransomware that
would exfiltrate data and demand a ransom from Tesla. The employee
reported the offer to Tesla and the FBI, who arrested the hacker.

●Impact: Although the plot was prevented, the case highlighted the growing
threat of insider involvement in cyberattacks. This insider threat could have
led to severe data exfiltration and operational disruptions.

Takeaway: This mirrors the insider threat scenario, where an employee is used
(or attempts to act) maliciously. Strong insider threat monitoring, access controls,
and awareness training are critical to preventing similar incidents.

pattern-tertiary
media
media

Week 7

CompTIA Security+:
Application of
Knowledge during
Incident Response

Table Top Exercises & Scenarios

Show answer

Auto Play

Slide 1 / 56

SLIDE