QuestionQ54

Threat Hunting Techniques

A security team is alerted to unusual, blocked web traffic. While investigating proxy logs, the team finds traffic from rarely used user agents to domains classified as malware.

Which two additional proxy-log threat indicators should the team identify?

Choose two
Explanation

URLs that substitute a direct IP address for a domain can indicate suspicious or evasive web activity. HTTP POST and PUT requests that transfer data to external cloud-storage services can indicate data exfiltration; both are observable in proxy logs.

Community Discussion

No comments yet. Be the first to start the discussion!