Obviously is "C"
"EX" = exfiltration
And there are three.
Also the "suspect long flow" and "suspect data heading" suggest, for example, DNS exfiltration
The question requires a single answer, and clearly there are three active exfiltration alerts. So a second choice cannot be made, and as mentioned by s1m0n below, a single host by definition would not be the sole machine in a DDoS attack. Answer choice C is best.
DDOS attacker should have DS attibute, and it is not there
DDoS Source
Alarm Category Index: DS
Indicates that a host has been identified as the source of a DDoS attack.
The following security events are associated with the DDoS Source alarm.
https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/management_console/smc_users_guide/SW_6_9_0_SMC_Users_Guide_DV_1_2.pdf page 177.
I vote for C.
There is one with DT flagged, indicated as a target.
Alarm Category Index: DT
Indicates that a host has been identified as the target of a DDoS attack
upvoted 1 times
...
...
This section is not available anymore. Please use the main Exam Page.200-201 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
s1m0n
Highly Voted 2 years, 2 months agobeowolf
2 years, 2 months agofejec
1 year, 9 months agoanonymous1966
Highly Voted 1 year, 9 months agoEng_ahmedyoussef
Most Recent 8 months agoweganos
9 months agoadodoccletus
11 months, 2 weeks agotor_bap
1 year, 5 months agoqz999
1 year, 9 months agosnahta
1 year, 10 months agognuga
1 year, 10 months agognuga
1 year, 10 months ago