QuestionQ74

Defensive Technologies and Emerging Intelligence

You are concerned that rootkits on your network may be communicating with attackers outside the network. Without using an IDS, how can you detect this type of activity?

  • A By examining your firewall logs.
  • B By examining your domain controller server logs.
  • C By setting up a DMZ.
  • D You cannot, you need an IDS.
Explanation

Firewall logs can reveal suspicious outbound connections from internal hosts to external addresses, including the relevant source, destination, port, and time information. Reviewing those records can expose rootkit communications with outside attackers without an IDS.

Community Discussion

No comments yet. Be the first to start the discussion!