Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Other organizations similar to your own have been reporting an increase in advanced persistent threat ( APT ) attacks. In the reported cases, initial compromise
Other organizations similar to your own have been reporting an increase in advanced persistent threat APT attacks. In the reported cases, initial compromise has been through email attachment malware infections exploiting zeroday vulnerabilities, which download and install RATs from C&C servers at various locations scattered around the Internet. This is followed by lateral movement of the attackers throughout the organizations network. The attackers are using passthehash techniques to gain administrative credentials; with those, they easily spread from host to host. The director of IT has asked you to prepare recommendations on how best to prepare for such an attack on your own organizations network.
Which of the following is LEAST likely to help you detect attempted or successful compromise of your organizations network?
Scanning computers for indicators of compromise IOC such as file hashes and registry entries, shared by partner organizations that have already suffered attacks.
Reviewing DMZ web server logs for HTTP requests with unusual or unexpected useragent strings.
Reviewing Windows domain controller security logs for anomalous user logon events.
Reviewing perimeter firewall logs for anomalous outbound Internet traffic.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started