200-201 · Question #538
Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic. What should the engineer understand by examining the SNORT logs?
The correct answer is C. A remote threat performs an EternalBlue attack on several hosts and different ports. The SNORT alerts show EternalBlue (MS17-010) exploitation attempts coming from an internal host (192.168.200.10) targeting a Windows system (192.168.2.101) specifically on port 445, which is the SMB port exploited by EternalBlue.
Question
Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic. What should the engineer understand by examining the SNORT logs?
Exhibit
Options
- AA remote threat performs an EternalBlue attack on a Windows system on several ports.
- BAn inside threat performs an EternalBlue attack on hosts 192.168.2.101 and 192.168.200.10 on
- CA remote threat performs an EternalBlue attack on several hosts and different ports.
- DAn inside threat performs an EternalBlue attack on a Windows system on port 445.
How the community answered
(57 responses)- A5% (3)
- B19% (11)
- C68% (39)
- D7% (4)
Explanation
The SNORT alerts show EternalBlue (MS17-010) exploitation attempts coming from an internal host (192.168.200.10) targeting a Windows system (192.168.2.101) specifically on port 445, which is the SMB port exploited by EternalBlue.
Topics
Community Discussion
No community discussion yet for this question.
