🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)41 / 145
Question 41 of 145

A SOC analyst is investigating a suspected data exfiltration event. Session data and NetFlow records confirm a large transfer occurred between an internal host and an external IP over TCP port 443, but the analyst needs to examine the exact bytes sent, reconstruct the application-layer payload, and extract any transferred files to confirm what data left the network. Which data type should the analyst rely on to accomplish this?

Reviewed for accuracy · Report an issueNext question