Q18Fundamentals
A security analyst is examining suspicious network-traffic patterns in a segmented environment. During a 2-hour period, the analyst identifies this event sequence: an external IP address scans multiple ports on a web server, followed by a surge of HTTP requests with unusually large payloads. Shortly afterward, the database server exhibits anomalous outbound traffic over an unencrypted channel to that same external IP. In addition, DNS queries resolving to previously unknown domains increase sharply. How should the analyst interpret this sequence of events?
← → navigate · a answer
Discussion · 0
No comments yet. Be the first.