During a routine review of firewall logs, an analyst identified that an IP address from the organization's server subnet had been connecting during nighttime hours to a foreign IP address, and had been sending between 150 and 500 megabytes of data each time. This had been going on for approximately one week, and the affected server was taken offline for forensic review. Which of the following is MOST likely to drive up the incident's impact assessment?
slcc99
Highly Voted 5 years, 1 month agoJeend
Most Recent 2 years, 4 months agoJeend
2 years, 4 months agoAcrisius
4 years, 5 months agoshakevia463
3 years, 5 months ago