🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)58 / 145
Question 58 of 145
A SOC analyst investigating a suspected endpoint compromise pulls the following data types from their monitoring platform: NetFlow records, firewall logs, and full packet capture from the network segment. The malware is confirmed to run entirely in memory on the host, injects into a legitimate signed process, and communicates only over TLS 1.3 to a domain that later resolves to a known-good CDN. Which additional data source would most directly reveal the malicious activity that the network-based sources are missing?
Reviewed for accuracy · Report an issueNext question