Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertNexus Exam CFR-410 Topic 4 Question 37 Discussion

Actual exam question for CertNexus's CFR-410 exam
Question #: 37
Topic #: 4
[All CFR-410 Questions]

Tcpdump is a tool that can be used to detect which of the following indicators of compromise?

Show Suggested Answer Hide Answer
Suggested Answer: A, B

Contribute your Thoughts:

Leota
16 days ago
I'm just glad they didn't ask about using tcpdump to detect 'unusual duck-billed platypus activity' - that would have really thrown me for a loop!
upvoted 0 times
...
Broderick
17 days ago
Ah, the old tcpdump question. It's like asking a carpenter which tool is best for measuring wood - the answer is obvious! A) Unusual network traffic is the way to go.
upvoted 0 times
Jennifer
10 hours ago
I agree, unusual network traffic is a clear indicator of compromise.
upvoted 0 times
...
...
Janine
24 days ago
Hmm, I was considering C) Poor network performance, but that's more of a sympAilene than a direct indicator of compromise. A) Unusual network traffic makes the most sense.
upvoted 0 times
Raymon
13 hours ago
I agree, A) Unusual network traffic is a clear sign of compromise.
upvoted 0 times
...
...
Ailene
1 months ago
I was thinking B) Unknown open ports, but now that I think about it, tcpdump is more about capturing and inspecting the actual traffic, not necessarily open ports.
upvoted 0 times
Essie
15 days ago
D) Unknown use of protocols is also an indicator that can be detected using tcpdump.
upvoted 0 times
...
Sue
20 days ago
A) Unusual network traffic is the correct answer.
upvoted 0 times
...
...
Oretha
2 months ago
I believe Tcpdump can also help in identifying unknown open ports.
upvoted 0 times
...
Louisa
2 months ago
Tcpdump is great for analyzing network traffic, so I'd say A) Unusual network traffic is the correct answer here.
upvoted 0 times
Yuriko
21 days ago
Poor network performance could also be a red flag for a compromise.
upvoted 0 times
...
Lynsey
22 days ago
Yes, that's true. Unknown open ports could also indicate a compromise.
upvoted 0 times
...
Ona
27 days ago
I think it could also be unknown use of protocols, right?
upvoted 0 times
...
Ty
1 months ago
I agree, unusual network traffic can be a sign of compromise.
upvoted 0 times
...
...
Antonio
2 months ago
I agree with Wendell, it can also detect unknown use of protocols.
upvoted 0 times
...
Wendell
2 months ago
I think Tcpdump can detect unusual network traffic.
upvoted 0 times
...

Save Cancel