A security team's AI-powered network anomaly detection system generates an alert: 'Unusual outbound data transfer to an external IP, 2.3 GB in 15 minutes, outside business hours, from a workstation normally handling no outbound transfers.' An analyst examines the alert. What contextual questions are essential before classifying this as a security incident?
- A.The alert should be immediately escalated as a high-severity data exfiltration incident based on the volume and timing alone
- B.Is the destination IP a known cloud backup or software update service? Did the workstation recently have a backup agent installed? Is the user on approved overtime? Was a large software update scheduled for that time window? - all of which are legitimate explanations that must be checked before escalating
- C.Check only whether the destination IP is on a threat intelligence blocklist; if not, close the alert