220-1102 · Question #613
A technician has identified malicious traffic originating from a user's computer. Which of the following is the best way to identify the source of the attack?
The correct answer is A. Investigate the firewall logs. To identify the source of an attack generating malicious outbound traffic, investigating firewall logs is the most effective method as they record details about incoming and outgoing network connections.
Question
A technician has identified malicious traffic originating from a user's computer. Which of the following is the best way to identify the source of the attack?
Options
- AInvestigate the firewall logs.
- BIsolate the machine from the network.
- CInspect the Windows Event Viewer.
- DTake a physical inventory of the device.
How the community answered
(41 responses)- A76% (31)
- B15% (6)
- C2% (1)
- D7% (3)
Why each option
To identify the source of an attack generating malicious outbound traffic, investigating firewall logs is the most effective method as they record details about incoming and outgoing network connections.
Firewall logs provide detailed records of network traffic, including source and destination IP addresses, ports, protocols, and timestamps for both allowed and blocked connections. By analyzing these logs, a technician can trace the malicious outbound traffic to its ultimate external destination or identify unusual internal connection attempts, thus helping to pinpoint the source or target of the attack originating from the user's computer.
Isolating the machine is an important containment step to prevent further harm, but it does not help identify the source of the attack itself.
Inspecting the Windows Event Viewer can help identify internal system events, malware activity, or compromise indicators on the local machine, but it typically does not directly reveal the external source or destination of malicious network traffic.
Taking a physical inventory of the device is part of asset management and does not contribute to identifying the source of a network-based attack.
Concept tested: Network attack investigation and logging
Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/appendix-l-events-to-monitor
Topics
Community Discussion
No community discussion yet for this question.