QuestionQ331
Logs and Network ForensicsAfter a suspected malware incident at a Los Angeles retail chain, forensic investigators note degraded performance on a compromised server and indicators of unauthorized external communications. To confirm malicious activity affecting the system, which evidence should investigators examine first to corroborate an active compromise?
- A Unknown running processes
- B System slowdown and longer reboot times
- C Abnormal network traffic flows
- D Changes in web browser configurations
Community Discussion