🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)105 / 147
Question 105 of 147
A SOC analyst reviews output from a predictive AI engine that models traffic patterns across the enterprise. The engine flags a sequence beginning with a single external host sending sequential TCP SYN packets to thousands of ports on multiple internal hosts, followed by targeted connection attempts to only the small subset of ports that responded. No authentication attempts or data transfers have occurred yet. Based on this sequence, what phase of the attack is the AI most likely indicating, and what should the analyst prioritize?
Reviewed for accuracy · Report an issueNext question