CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 2: Google Cloud Professional Security Operations Engineer

You are responsible for identifying suspicious activity and security events at your organization. You have been asked to search in Google Security Operations (SecOps) for network traffic associated with an active HTTP backdoor that runs on TCP port 5555. You want to use the most effective approach to identify traffic…

Nội dung câu hỏi

You are responsible for identifying suspicious activity and security events at your organization. You have been asked to search in Google Security Operations (SecOps) for network traffic associated with an active HTTP backdoor that runs on TCP port 5555. You want to use the most effective approach to identify traffic originating from the server that is running the backdoor. What should you do?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Detect on events where network.ApplicationProtocol is HTTP.
  2. B. Detect on events where target.port is 5555.
  3. C. Detect on events where principal.port is 5555. — đáp án hiện tại
  4. D. Detect on events where network.ip_protocol is TCP.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề