List of questions
Related questions
Question 516 - SY0-601 discussion
During an incident, an EDR system detects an increase in the number of encrypted outbound connections from multiple hosts. A firewall is also reporting an increase in outbound connections that use random high ports. An analyst plans to review the correlated logs to find the source of the incident. Which of the following tools will best assist the analyst?
A.
A vulnerability scanner
B.
A NGFW
C.
The Windows Event Viewer
D.
A SIEM
Your answer:
0 comments
Sorted by
Leave a comment first