Question 176

An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?
  • Question 177

    Refer to the exhibit.

    Which alert is identified from this packet capture?
  • Question 178

    Which metric should be used when evaluating the effectiveness and scope of a Security Operations Center?
  • Question 179

    An engineer received an alert affecting the degraded performance of a critical server. Analysis showed a heavy CPU and memory load. What is the next step the engineer should take to investigate this resource usage?
  • Question 180

    Refer to the exhibit.

    What is shown in this PCAP file?