ISECTION A - 20 Marks
QUESTION 1
10 marks
Your company's firewall has been breached and a malware has infected several systems. Describe
how machine learning can assist in detecting and countering this malware in future.
(10 marks]
QUESTION 2
10 marks
With increasing reports of insider threats, how would you use accessanalytics to mitigate such risks?
(10 marks]
(
J SECTION B - 50 Marks
QUESTION 3
25 marks
You have been given a dataset from a Security Information and Event Management {SIEM)system
showing multiple high-volume traffic spikes to a particular server within the organization. The traffic
is from different IP addresses but follows a consistent pattern: high traffic for 10 minutes, then silence,
repeated hourly.
(a) Interpret what kind of threat or activity this pattern might indicate.
l5 marks]
(
(b) Detail an analytic approach you would use to further investigate this pattern, including
specific data points you would analyse and any additional tools you would employ.
[10 marks]
(c) Recommend at least three specific countermeasures to mitigate this potential threat.
[5 marks]
(d) How would you ensure long-term monitoring and response to similar patterns in the future?
[S marks]
Page 2