Câu 16: 300-220: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
Refer to the exhibit. The security team at a company reviews the Intrusion Prevention System logs and detects a pass-the-hash attack on a domain controller. After further investigation, the team discovers that the attack originated from an endpoint running the Mimikatz tool. The team must improve the visibility of the…
Nội dung câu hỏi
Refer to the exhibit. The security team at a company reviews the Intrusion Prevention System logs and detects a pass-the-hash attack on a domain controller. After further investigation, the team discovers that the attack originated from an endpoint running the Mimikatz tool. The team must improve the visibility of the company’s endpoint actions and must add additional logging to detect similar attacks in the future. Which logs should the team leverage?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. extended audit logs from the domain controller for better visibility
- B. command logging on the domain controller to detect malicious processes
- C. endpoint antivirus logs to monitor the behavior of running processes
- D. sysmon logging from all the endpoints to monitor the access processes — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.