A security analyst is reviewing packet captures from a system that was compromised. The system was already isolated from the network, but it did have network access for a few hours after being compromised. When viewing the capture in a packet analyzer, the analyst sees the following: Which of the following can the analyst conclude?
A) Malware is attempting to beacon to 128.50.100.3.
B) The system is running a DoS attack against ajgidwle.com.
C) The system is scanning ajgidwle.com for PII.
D) Data is being exfiltrated over DNS.
Correct Answer:
Verified
Q76: As part of an organization's information security
Q77: A security analyst is reviewing the following
Q78: Clients are unable to access a company's
Q79: A company wants to establish a threat-hunting
Q80: A security analyst discovers accounts in sensitive
Q82: A user's computer has been running slowly
Q83: An analyst is working with a network
Q84: An analyst is performing penetration testing and
Q85: A security analyst has received reports of
Q86: A cybersecurity analyst is contributing to a
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents