SY0-701 · Question #1084
A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports. Which of the following data sources should the analyst use…
The correct answer is D. Packet captures. Packet captures allow the analyst to examine traffic characteristics such as destination IPs, ports, protocols, timing, and traffic patterns, which helps determine whether encrypted traffic on non- standard ports is indicative of malicious activity.
Question
A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports. Which of the following data sources should the analyst use first to confirm whether this traffic is malicious?
Options
- AApplication logs
- BVulnerability scans
- CEndpoint logs
- DPacket captures
How the community answered
(43 responses)- A14% (6)
- B7% (3)
- C33% (14)
- D47% (20)
Explanation
Packet captures allow the analyst to examine traffic characteristics such as destination IPs, ports, protocols, timing, and traffic patterns, which helps determine whether encrypted traffic on non- standard ports is indicative of malicious activity.
Community Discussion
No community discussion yet for this question.