CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 4: 300-220: Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity

Refer to the exhibit. A security engineer observes the Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service traffic with the Wireshark, which may spoof a source for name resolution to force communication with an adversary-controlled system, as well as perform an SMB Relay attack. After the security en…

Nội dung câu hỏi

Refer to the exhibit. A security engineer observes the Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service traffic with the Wireshark, which may spoof a source for name resolution to force communication with an adversary-controlled system, as well as perform an SMB Relay attack. After the security engineer identifies the traffic as malicious, they must determine the gaps in threat detection. Which gap would an analyst determine?

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Intercept network traffic for unusual ARP traffic. Gratuitous ARP replies may be suspicious.
  2. B. Revoke for API calls associated with polling to intercept keystrokes.
  3. C. Monitor for traffic on ports UDP 5355 and UDP 137 if LLMNR/NetBIOS. — đáp án hiện tại
  4. D. Augment Windows logs (ex: EIDs 1341, 1342, 1020, and 1063) for changes to DHCP settings.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề