Câu 4: NSE7_SOC_AR-7.6: Fortinet NSE 7 - Security Operations 7.6 Architect
Review the incident report. Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT paylo…
Nội dung câu hỏi
Review the incident report. Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files. Which two MITRE ATT&CK techniques best describe this activity? (Choose two.)
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Exploitation of Remote Services
- B. Non-Standard Port — đáp án hiện tại
- C. Exfiltration Over Alternative Protocol — đáp án hiện tại
- D. Hide Artifacts
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.