Incident Response

There are a few very important processes that function at a foundational level to the Windows operating system and have well-documented behavior. It is important to understand how these processes operate normally in order to recognize abnormalities. Research at least four processes on a network that is used to recognize abnormalities.

Active Directory accounts are used on many networks to log on to Windows workstations, servers, and other infrastructure systems, using a single sign-on (SSO). Security teams should monitor authentication and authorization systems because they provide valuable insight regarding access controls in the environment. Research at least three common Indicators of Compromise (IoC) associated with account usage.

The primary response must be at least 300 words in length and fully address the topic, demonstrating critical thinking and understanding.

Requirements: No plagiarism and no AI   |   .doc file

WRITE MY PAPER