nerdexam
CompTIA

220-1102 · Question #613

A technician has identified malicious traffic originating from a user's computer. Which of the following is the best way to identify the source of the attack?

The correct answer is A. Investigate the firewall logs. To identify the source of an attack generating malicious outbound traffic, investigating firewall logs is the most effective method as they record details about incoming and outgoing network connections.

Security

Question

A technician has identified malicious traffic originating from a user's computer. Which of the following is the best way to identify the source of the attack?

Options

  • AInvestigate the firewall logs.
  • BIsolate the machine from the network.
  • CInspect the Windows Event Viewer.
  • DTake a physical inventory of the device.

How the community answered

(41 responses)
  • A
    76% (31)
  • B
    15% (6)
  • C
    2% (1)
  • D
    7% (3)

Why each option

To identify the source of an attack generating malicious outbound traffic, investigating firewall logs is the most effective method as they record details about incoming and outgoing network connections.

AInvestigate the firewall logs.Correct

Firewall logs provide detailed records of network traffic, including source and destination IP addresses, ports, protocols, and timestamps for both allowed and blocked connections. By analyzing these logs, a technician can trace the malicious outbound traffic to its ultimate external destination or identify unusual internal connection attempts, thus helping to pinpoint the source or target of the attack originating from the user's computer.

BIsolate the machine from the network.

Isolating the machine is an important containment step to prevent further harm, but it does not help identify the source of the attack itself.

CInspect the Windows Event Viewer.

Inspecting the Windows Event Viewer can help identify internal system events, malware activity, or compromise indicators on the local machine, but it typically does not directly reveal the external source or destination of malicious network traffic.

DTake a physical inventory of the device.

Taking a physical inventory of the device is part of asset management and does not contribute to identifying the source of a network-based attack.

Concept tested: Network attack investigation and logging

Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/appendix-l-events-to-monitor

Topics

#Security#Network Monitoring#Incident Response#Firewall Logs

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice