An analyst investigates an IDS alert and confirms suspicious traffic to a known malicious IP. What Enterprise Security data model would they use to investigate which process initiated the network connection?
Hey, I bet the answer is D) Web! You know, because the IDS alert was about 'suspicious traffic', and we all know the web is just one big suspicious place, am I right?
Aha, gotta be C) Network traffic! That's the obvious choice here. Maybe the exam writers are trying to trick us, but I'm sticking with my gut on this one.
Hmm, I think the answer here is C) Network traffic. That's where I'd expect to find information about the network connection that triggered the IDS alert.
Karina
1 months agoWayne
1 months agoArthur
2 days agoLashon
7 days agoCarry
2 months agoEmiko
Wilda
1 days agoShala
8 days agoAn
16 days agoMillie
18 days agoHannah
1 months agoDelisa
2 months agoAbel
2 months agoAudria
22 days agoVivienne
23 days agoDyan
1 months agoMargurite
2 months agoJesus
2 months agoSena
2 months agoViola
2 months ago