QuestionQ43

Detecting Exploitation and Covert Communications Tools

You are worried that rootkits on your network are communicating with attackers outside the network. Without using an IDS, how can you detect this type of activity?

  • A By examining your domain controller server logs.
  • B You cannot, you need an IDS.
  • C By examining your firewall logs.
  • D By setting up a DMZ.
Explanation

Firewall logs record network connections crossing the network boundary. Reviewing them can expose unexpected outbound connections, suspicious destinations, or unusual inbound traffic associated with a compromised host communicating externally.

Community Discussion

No comments yet. Be the first to start the discussion!