CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 19: CS0-004: CompTIA CySA+ V4

A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the 10.213.4.27 file server. This file server is under investigation due to concerns about potential data exfiltration using Domain Name System (DNS) traffic. Which of the following commands should the analyst us…

Nội dung câu hỏi

A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the 10.213.4.27 file server. This file server is under investigation due to concerns about potential data exfiltration using Domain Name System (DNS) traffic. Which of the following commands should the analyst use to extract any potentially leaked data from the suspicious.pcap file?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. strings suspicious.pcap | grep 10.213.4.27
  2. B. zeek -r suspicious.pcap ; grep 10.213.4.27 file.log
  3. C. snort -r suspicious.pcap ; grep eve.log 10.213.4.27
  4. D. tcpdump -r suspicious.pcap port 53 and host 10.213.4.27 — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề