QuestionQ331

Logs and Network Forensics

After a suspected malware incident at a Los Angeles retail chain, forensic investigators note degraded performance on a compromised server and indicators of unauthorized external communications. To confirm malicious activity affecting the system, which evidence should investigators examine first to corroborate an active compromise?

  • A Unknown running processes
  • B System slowdown and longer reboot times
  • C Abnormal network traffic flows
  • D Changes in web browser configurations
Explanation

Abnormal network traffic flows can directly reveal unauthorized communications with external hosts, including command-and-control traffic or data exfiltration, which is strong evidence of an active compromise.

Community Discussion

No comments yet. Be the first to start the discussion!