Question 16

Refer to the exhibit.

An engineer is analyzing a PCAP file after a recent breach An engineer identified that the attacker used an aggressive ARP scan to scan the hosts and found web and SSH servers. Further analysis showed several SSH Server Banner and Key Exchange Initiations. The engineer cannot see the exact data being transmitted over an encrypted channel and cannot identify how the attacker gained access How did the attacker gain access?
  • Question 17

    Which type of evidence supports a theory or an assumption that results from initial evidence?
  • Question 18

    What does cyber attribution identify in an investigation?
  • Question 19

    Which process is used when IPS events are removed to improve data integrity?
  • Question 20

    How does an attack surface differ from an attack vector?