312-49V11 · Question #171
During an investigation, a forensics analyst discovers an unusual increase in outbound network traffic, network traffic traversing on non-standard ports, and multiple failed login attempts on a host…
The correct answer is B. Examining the logs for repeated requests for the same file, indicating a possible exploit attempt. A practical immediate containment-oriented next step is to identify whether an exploit is being actively leveraged. Repeated requests for the same resource/file often indicate scanning or exploitation attempts (e.g., repeated hits to vulnerable endpoints). This helps quickly…
Question
During an investigation, a forensics analyst discovers an unusual increase in outbound network traffic, network traffic traversing on non-standard ports, and multiple failed login attempts on a host system. The analyst also found that certain programs were using these unusual ports, appearing to be legitimate. If these are the primary Indicators of Compromise, what should be the next immediate step in the investigation to contain the intrusion effectively?
Options
- AEnforcing stringent password policies and re-authenticating all users to prevent further login
- BExamining the logs for repeated requests for the same file, indicating a possible exploit attempt
- CAnalyzing Uniform Resource Locators for any signs of phishing or spamming activities
- DConducting a deep dive into user-agent strings to determine if there is any spoofing of device OS
How the community answered
(34 responses)- A9% (3)
- B76% (26)
- C3% (1)
- D12% (4)
Explanation
A practical immediate containment-oriented next step is to identify whether an exploit is being actively leveraged. Repeated requests for the same resource/file often indicate scanning or exploitation attempts (e.g., repeated hits to vulnerable endpoints). This helps quickly pinpoint the entry vector and supports rapid blocking/containment actions.
Topics
Community Discussion
No community discussion yet for this question.