QuestionQ73

Threat Hunting and Detection

Bob, a network specialist in an organization, is trying to identify malicious activity on the network. During this process, Bob analyzed specific data that gave him a summary of a conversation between two network devices, including:

  • a source IP address and source port;
  • a destination IP address and destination port;
  • the conversation duration; and
  • the information exchanged during the conversation.

Which type of network-based evidence did Bob collect in this scenario?

  • A Statistical data
  • B Session data
  • C Full content data
  • D Alert data
Explanation

Session data records a network communication session at a summary level, including the source and destination IP addresses and ports, the duration of the connection, and details about the data exchanged. It does not require retaining the complete raw contents of every packet.

Community Discussion

No comments yet. Be the first to start the discussion!