What is the purpose of detecting a high number of outbound DNS requests from the same host?
It's an indicator of ransomware
It is a port scan behavior
It's an indicator of a C&C connection
It's a normal behavior
What does IOC stand for?
Indicator of Compromise
Information of Compromise
Inspection of Computer
Injection of Computer
Which of the following can be an indicator of potential attacks in event logs?
BSOD
An event log was cleared
A failed user account login
All of the above
For the purpose of web log analysis, why do we analyze the external source client IP?
To identify whether it's a known bad IP or TOR exit node
To identify whether there are any abnormal geolocation changes within a short space of time
To identify ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month, and much more.