QuestionQ73
Threat Hunting and DetectionBob, a network specialist in an organization, is trying to identify malicious activity on the network. During this process, Bob analyzed specific data that gave him a summary of a conversation between two network devices, including:
- a source IP address and source port;
- a destination IP address and destination port;
- the conversation duration; and
- the information exchanged during the conversation.
Which type of network-based evidence did Bob collect in this scenario?
- A Statistical data
- B Session data
- C Full content data
- D Alert data
Community Discussion