List of questions
Related questions
Question 309 - CAS-004 discussion
A security engineer has been informed by the firewall team that a specific Windows workstation is part of a command-and-control network. The only information the security engineer is receiving is that the traffic is occurring on a non-standard port (TCP 40322). Which of the following commands should the security engineer use FIRST to find the malicious process?
A.
tcpdump
B.
netstar
C.
tasklist
D.
traceroute
E.
ipconfig
Your answer:
0 comments
Sorted by
Leave a comment first