SY0-701 · Question #563
A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the…
The correct answer is C. Firewall. Firewall logs are the best source because they record all inbound and outbound network connections, including source/destination IPs, ports, and protocols - giving a direct view of where C2 traffic is going as it leaves the network perimeter. IDS logs (A) detect and alert on…
Question
A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?
Options
- AIDS
- BAntivirus
- CFirewall
- DApplication
How the community answered
(30 responses)- A3% (1)
- B7% (2)
- C77% (23)
- D13% (4)
Explanation
Firewall logs are the best source because they record all inbound and outbound network connections, including source/destination IPs, ports, and protocols - giving a direct view of where C2 traffic is going as it leaves the network perimeter. IDS logs (A) detect and alert on suspicious patterns but are focused on signatures and anomalies, not providing a clean record of connection destinations. Antivirus logs (B) track malware detections on endpoints, not network traffic flows. Application logs (D) are scoped to specific software behavior and won't capture arbitrary outbound C2 connections. Memory tip: Think of the firewall as the "border checkpoint" - everything leaving the network must pass through it, so it's always your go-to for tracking traffic destinations.
Topics
Community Discussion
No community discussion yet for this question.