subject

Based on some old siem alerts, you have been asked to perform some forensic analysis on a particular host. you have noticed that some ssl network connections are occurring over ports other than port 443. additionally, the siem alerts state that copies of svchost. exe and cmd. exe have been found in the %temp% folder on the host, as well as showing that rdp connections have previously connected with an ip address that is external to the corporate intranet. what threat might you have uncovered during your analysis?

ansver
Answers: 2

Another question on Computers and Technology

question
Computers and Technology, 22.06.2019 07:00
Idon understand these and need some ! ?
Answers: 2
question
Computers and Technology, 22.06.2019 11:30
To hide gridline when you display or print a worksheet
Answers: 1
question
Computers and Technology, 23.06.2019 01:30
Negative methods of behavior correction include all but this: sarcasm verbal abuse setting an example for proper behavior humiliation
Answers: 1
question
Computers and Technology, 24.06.2019 01:00
How can the temperature of a room be raised by 5degreesf?
Answers: 1
You know the right answer?
Based on some old siem alerts, you have been asked to perform some forensic analysis on a particular...
Questions
question
Mathematics, 15.01.2021 01:00
question
Mathematics, 15.01.2021 01:00
question
Social Studies, 15.01.2021 01:00
question
Chemistry, 15.01.2021 01:00
question
English, 15.01.2021 01:00
question
Mathematics, 15.01.2021 01:00
question
Chemistry, 15.01.2021 01:00
question
Mathematics, 15.01.2021 01:00
Questions on the website: 13722367