A security analyst is performing a forensic analysis on a machine that was the subject of some historic SIEM alerts. The analyst noticed some network connections utilizing SSL on non-common ports, copies of svchost.exe and cmd.exe in %TEMP% folder, and RDP files that had connected to external IPs. Which of the following threats has the security analyst uncovered?
A. DDoS
B. APT
C. Ransomware
D. Software vulnerability
A security analyst is performing a forensic analysis on a machine that was the subject of some historic SIEM alerts. The
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
A security analyst is performing a forensic analysis on a machine that was the subject of some historic SIEM alerts. The
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!