🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)50 / 145
Question 50 of 145
A SOC analyst is investigating a potential data exfiltration event. She has a large set of firewall connection logs and knows only that a malicious external server has the IP address 203.0.113.45 and receives data over TCP port 443. To isolate exactly which internal host is communicating with that server using the 5-tuple approach, which additional pieces of information must she still identify from the logs?
Reviewed for accuracy · Report an issueNext question