ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 552 - SY0-601 discussion

Report
Export

A host was infected with malware. During the incident response. Joe, a user, reported that he did not receive any emails with links, but he had been browsing the internet all day. Which of the following would most likely show where the malware originated?

A.
The DNS logs
Answers
A.
The DNS logs
B.
The web server logs
Answers
B.
The web server logs
C.
The SIP traffic logs
Answers
C.
The SIP traffic logs
D.
The SNMP logs
Answers
D.
The SNMP logs
Suggested answer: A

Explanation:

The web server logs are records of the requests and responses that occur between a web server and a web client, such as a browser. The web server logs can show where the malware originated by indicating the source IP address, the destination URL, the date and time, the HTTP status code, the user agent, etc., of each request and response. The web server logs can help the incident response team to trace back the malicious website that infected the host with malware.

asked 02/10/2024
Marco Di Munno
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first