nerdexam
CompTIA

SY0-701 · Question #1084

A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports. Which of the following data sources should the analyst use…

The correct answer is D. Packet captures. Packet captures allow the analyst to examine traffic characteristics such as destination IPs, ports, protocols, timing, and traffic patterns, which helps determine whether encrypted traffic on non- standard ports is indicative of malicious activity.

Submitted by ngozi_ng· Mar 6, 2026Security Operations

Question

A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports. Which of the following data sources should the analyst use first to confirm whether this traffic is malicious?

Options

  • AApplication logs
  • BVulnerability scans
  • CEndpoint logs
  • DPacket captures

How the community answered

(43 responses)
  • A
    14% (6)
  • B
    7% (3)
  • C
    33% (14)
  • D
    47% (20)

Explanation

Packet captures allow the analyst to examine traffic characteristics such as destination IPs, ports, protocols, timing, and traffic patterns, which helps determine whether encrypted traffic on non- standard ports is indicative of malicious activity.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice