フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 4 / 20 問目

問題文

A university SOC sees that a workstation in the registrar's office made outbound connections to the same external address every 300 seconds for nine hours, each carrying about 800 bytes out and 200 bytes in. No large transfer occurred. Which attack behavior does this pattern most directly indicate, and which CIM data model holds the events that reveal it?

選択肢

  1. A denial of service attempt, visible in the Web data model since the repeated connections consume server capacity and outbound sessions from a workstation are normalized there.
  2. Data exfiltration, visible in the Network Traffic data model since a workstation in an administrative office has no legitimate reason to hold a connection open to an external address for nine hours in a row during the working day.
  3. A supply chain attack, visible in the Change data model.
  4. Command and control beaconing, visible in the Network Traffic data model through the regular interval and the small, consistent byte counts in each direction.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。