CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 4: NSE7_SOC_AR-7.6: Fortinet NSE 7 - Security Operations 7.6 Architect

Review the incident report. Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT paylo…

Nội dung câu hỏi

Review the incident report. Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files. Which two MITRE ATT&CK techniques best describe this activity? (Choose two.)

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Exploitation of Remote Services
  2. B. Non-Standard Port — đáp án hiện tại
  3. C. Exfiltration Over Alternative Protocol — đáp án hiện tại
  4. D. Hide Artifacts

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề