Câu 24: CAS-005: CompTIA SecurityX
A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbound traffic from any infected machines. Which of the following is the most appropriate action for the systems administr…
Nội dung câu hỏi
A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbound traffic from any infected machines. Which of the following is the most appropriate action for the systems administrator to take?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Monitor for IoCs associated with C&C communications.
- B. Tune alerts to Identify changes to administrative groups.
- C. Review NetFlow logs for unexpected increases in egress traffic. — đáp án hiện tại
- D. Perform binary hash comparisons to identify infected devices.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.