Question 16


Refer to the exhibit. What should an engineer determine from this Wireshark capture of suspicious network traffic?
  • Question 17

    Refer to the exhibit.

    Which encoding technique is represented by this HEX string?
  • Question 18


    Refer to the exhibit. An HR department submitted a ticket to the IT helpdesk indicating slow performance on an internal share server. The helpdesk engineer checked the server with a real-time monitoring tool and did not notice anything suspicious. After checking the event logs, the engineer noticed an event that occurred 48 hour prior. Which two indicators of compromise should be determined from this information?
    (Choose two.)
  • Question 19

    What is the transmogrify anti-forensics technique?
  • Question 20

    A security team received an alert of suspicious activity on a user's Internet browser. The user's anti-virus software indicated that the file attempted to create a fake recycle bin folder and connect to an external IP address. Which two actions should be taken by the security analyst with the executable file for further analysis? (Choose two.)