QuestionQ393

Technology and Security

Analyzing which of the following would BEST help validate whether suspicious network activity is malicious?

  • A Intrusion detection system (IDS) rules
  • B Penetration test reports
  • C Vulnerability assessment reports
  • D Logs and system events
Explanation

Logs and system events provide contemporaneous evidence of network connections, process activity, authentication attempts, configuration changes, and other indicators that can corroborate or refute malicious behavior.

Community Discussion

No comments yet. Be the first to start the discussion!