QuestionQ5

Threat Hunting Techniques

Refer to the exhibit.

Question Image

A company was recently breached and decided to strengthen its security posture going forward. A security assessment was commissioned specifically to test the weaknesses exploited during the breach. A security analyst reviews server logs to identify activity related to that security assessment.

Which entry indicates a delivery method associated with an authorized assessment?

Explanation

A web crawler requesting a public-facing page is consistent with authorized reconnaissance to gather publicly available information. This activity is nonintrusive compared with executing a shutdown command or attempting unauthorized administrative access.

Community Discussion

No comments yet. Be the first to start the discussion!