CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 35: 350-201: Performing CyberOps Using Core Security Technologies (CBRCOR)

An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is associated with Duqu malware. Which tactics, techniques, and procedures align with this analysis?

Nội dung câu hỏi

An analyst is alerted for a malicious file hash. After analysis, the analyst determined that an internal workstation is communicating over port 80 with an external server and that the file hash is associated with Duqu malware. Which tactics, techniques, and procedures align with this analysis?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Command and Control, Application Layer Protocol, Duqu — đáp án hiện tại
  2. B. Discovery, Remote Services: SMB/Windows Admin Shares, Duqu
  3. C. Lateral Movement, Remote Services: SMB/Windows Admin Shares, Duqu
  4. D. Discovery, System Network Configuration Discovery, Duqu

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề