QuestionQ43

Threat Hunting Techniques

Refer to the exhibit.

Question Image

A security team detects a traffic spike originating from the company web server. After further investigation, the team finds that the server has established multiple connections to different IP addresses, but the web server logs include both expected traffic and DDoS traffic.

Which attribute must the team use to further filter the logs?

Explanation

TCP connection state distinguishes the suspicious connection pattern from normal active traffic. States such as ESTABLISHED and TIME_WAIT identify the lifecycle status of each TCP connection, whereas the protocol and web-server IP are shared and destination addresses and ports vary across both traffic types.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!