SY0-701 · Question #194
An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)
The correct answer is D. Network E. Firewall. Network logs (Option D): These logs can help identify network connections to the command-and- control server and provide information about source IP addresses (the impacted host) and destination IP addresses (the command-and-control server). Firewall logs (Option E): Firewall…
Question
An organization experiences a cybersecurity incident involving a command-and-control server. Which of the following logs should be analyzed to identify the impacted host? (Choose two.)
Options
- AApplication
- BAuthentication
- CDHCP
- DNetwork
- EFirewall
- FDatabase
How the community answered
(15 responses)- A27% (4)
- B7% (1)
- C7% (1)
- D47% (7)
- F13% (2)
Explanation
Network logs (Option D): These logs can help identify network connections to the command-and- control server and provide information about source IP addresses (the impacted host) and destination IP addresses (the command-and-control server). Firewall logs (Option E): Firewall logs also track network traffic and can provide valuable information about source and destination IP addresses, helping identify the impacted host and its communication with the command-and-control server.
Community Discussion
No community discussion yet for this question.