An analyst investigates an IDS alert and confirms suspicious traffic to a known malicious IP. What Enterprise Security data model would they use to investigate which process initiated the network connection?
Hey, I bet the answer is D) Web! You know, because the IDS alert was about 'suspicious traffic', and we all know the web is just one big suspicious place, am I right?
Aha, gotta be C) Network traffic! That's the obvious choice here. Maybe the exam writers are trying to trick us, but I'm sticking with my gut on this one.
Hmm, I think the answer here is C) Network traffic. That's where I'd expect to find information about the network connection that triggered the IDS alert.
Karina
15 days agoWayne
21 days agoCarry
1 months agoAn
1 days agoMillie
3 days agoHannah
20 days agoDelisa
1 months agoAbel
1 months agoAudria
7 days agoVivienne
8 days agoDyan
20 days agoMargurite
1 months agoJesus
2 months agoSena
2 months agoViola
2 months ago