Question 156
What is the difference between the ACK flag and the RST flag in the NetFlow log session?
Question 157
Which event artifact is used to identity HTTP GET requests for a specific file?
Question 158
An analyst is investigating an incident in a SOC environment.
Which method is used to identify a session from a group of logs?
Which method is used to identify a session from a group of logs?
Question 159

An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture the analyst cannot determine the technique and payload used for the communication.
Which obfuscation technique is the attacker using?
Question 160
Which type of evidence supports a theory or an assumption that results from initial evidence?
