Question 101

Refer to the exhibit.

What information is depicted?
  • Question 102

    A malicious file has been identified in a sandbox analysis tool.

    Which piece of information is needed to search for additional downloads of this file by other hosts?
  • Question 103

    An organization's security team has detected network spikes coming from the internal network. An investigation has concluded that the spike in traffic was from intensive network scanning How should the analyst collect the traffic to isolate the suspicious host?
  • Question 104

    Refer to the exhibit.

    What is the expected result when the "Allow subdissector to reassemble TCP streams" feature is enabled?
  • Question 105

    What are indicators of attack?