CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 16: 300-220: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity

Refer to the exhibit. The security team at a company reviews the Intrusion Prevention System logs and detects a pass-the-hash attack on a domain controller. After further investigation, the team discovers that the attack originated from an endpoint running the Mimikatz tool. The team must improve the visibility of the…

Nội dung câu hỏi

Refer to the exhibit. The security team at a company reviews the Intrusion Prevention System logs and detects a pass-the-hash attack on a domain controller. After further investigation, the team discovers that the attack originated from an endpoint running the Mimikatz tool. The team must improve the visibility of the company’s endpoint actions and must add additional logging to detect similar attacks in the future. Which logs should the team leverage?

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. extended audit logs from the domain controller for better visibility
  2. B. command logging on the domain controller to detect malicious processes
  3. C. endpoint antivirus logs to monitor the behavior of running processes
  4. D. sysmon logging from all the endpoints to monitor the access processes — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề