Q16Processes
A security analyst is investigating an attack against an organization's database server and must establish the event sequence by analyzing traffic patterns. The following observations were made: 1. Multiple rapid connections to the database server from an external IP address were detected. 2. The database server began communicating with a known command-and-control server. 3. Numerous database records were accessed and modified in a short time. 4. A sudden rise in inbound traffic to the database server from various IP addresses was observed. Based on this information, what is the correct sequence of events during the attack?
← → navigate · a answer
Discussion · 0
No comments yet. Be the first.