Question 16

Refer to the exhibit. What should an engineer determine from this Wireshark capture of suspicious network traffic?
Question 17
Refer to the exhibit.

Which encoding technique is represented by this HEX string?

Which encoding technique is represented by this HEX string?
Question 18

Refer to the exhibit. An HR department submitted a ticket to the IT helpdesk indicating slow performance on an internal share server. The helpdesk engineer checked the server with a real-time monitoring tool and did not notice anything suspicious. After checking the event logs, the engineer noticed an event that occurred 48 hour prior. Which two indicators of compromise should be determined from this information?
(Choose two.)
Question 19
What is the transmogrify anti-forensics technique?
Question 20
A security team received an alert of suspicious activity on a user's Internet browser. The user's anti-virus software indicated that the file attempted to create a fake recycle bin folder and connect to an external IP address. Which two actions should be taken by the security analyst with the executable file for further analysis? (Choose two.)
