subject

Based on some old siem alerts, you have been asked to perform some forensic analysis on a particular host. you have noticed that some ssl network connections are occurring over ports other than port 443. additionally, the siem alerts state that copies of svchost. exe and cmd. exe have been found in the %temp% folder on the host, as well as showing that rdp connections have previously connected with an ip address that is external to the corporate intranet. what threat might you have uncovered during your analysis?

ansver
Answers: 2

Another question on Computers and Technology

question
Computers and Technology, 21.06.2019 18:00
Amara created a workbook to track the number of minutes she reads each week. each day, she entered the number of minutes into the workbook. identify the types of data in the workbook using the drop-down menus.
Answers: 3
question
Computers and Technology, 22.06.2019 23:30
Select all that apply. which of the following are proofreading options included in microsoft word? spell check find replace grammar check formatting check
Answers: 1
question
Computers and Technology, 23.06.2019 06:20
What is a point-in-time measurement of system performance?
Answers: 3
question
Computers and Technology, 24.06.2019 13:30
What process should be followed while giving a reference? sam has given a reference of his previous manager in his resume. sam should him in advance that the potential employers will him.
Answers: 1
You know the right answer?
Based on some old siem alerts, you have been asked to perform some forensic analysis on a particular...
Questions
question
Health, 18.10.2019 23:30