Question 156

What is the difference between the ACK flag and the RST flag in the NetFlow log session?
  • Question 157

    Which event artifact is used to identity HTTP GET requests for a specific file?
  • Question 158

    An analyst is investigating an incident in a SOC environment.
    Which method is used to identify a session from a group of logs?
  • Question 159


    An analyst is investigating a host in the network that appears to be communicating to a command and control server on the Internet. After collecting this packet capture the analyst cannot determine the technique and payload used for the communication.
    Which obfuscation technique is the attacker using?
  • Question 160

    Which type of evidence supports a theory or an assumption that results from initial evidence?