subject

Based on some old siem alerts, you have been asked to perform some forensic analysis on a particular host. you have noticed that some ssl network connections are occurring over ports other than port 443. additionally, the siem alerts state that copies of svchost. exe and cmd. exe have been found in the %temp% folder on the host, as well as showing that rdp connections have previously connected with an ip address that is external to the corporate intranet. what threat might you have uncovered during your analysis?

ansver
Answers: 2

Other questions on the subject: Computers and Technology

image
Computers and Technology, 24.06.2019 11:20, isabelperez063
Every telecommunication setup uses two devices: one device to transmit data and one device to receive data. which device transmits frequencies to mobile phones? towers transmit frequencies to mobile phones.
Answers: 1
image
Computers and Technology, 24.06.2019 15:30, PresleyPie9452
George is working as a programming team lead. which statements correctly describe the skills that he requires?
Answers: 3
image
Computers and Technology, 24.06.2019 20:30, LaughingAlanna
Does the query hawaiian photographers fully meets results?
Answers: 1
image
Computers and Technology, 25.06.2019 01:00, lilybear1700
What phrase indicates someone has knowledge and understanding of computer, internet, mobile devices and related technologies?
Answers: 1
You know the right answer?
Based on some old siem alerts, you have been asked to perform some forensic analysis on a particular...

Questions in other subjects:

Konu
Mathematics, 11.01.2021 15:50