🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)50 / 147
Question 50 of 147
A SOC analyst receives an automated SIEM alert indicating multiple failed logins followed by a successful login on a domain controller. Before escalating or taking any containment action, the analyst reviews correlated logs, verifies the source IP reputation, and confirms whether the activity represents genuine malicious behavior. According to the incident response workflow, which phase is the analyst currently performing?
Reviewed for accuracy · Report an issueNext question