QuestionQ41

Security Operations

A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbound traffic from any infected machines. Which of the following is the most appropriate action for the systems administrator to take?

Explanation

NetFlow logs capture detailed metadata about network traffic flows (source/destination IPs, ports, volume), enabling detection of anomalous egress traffic patterns typical of ransomware exfiltration or command-and-control communication. This network-level analysis approach directly identifies infected machines through unusual outbound traffic volumes without requiring signature-based IoC matching, which is a complementary SOC-level activity.

Community Discussion

No comments yet. Be the first to start the discussion!