exam questions

Exam CS0-001 All Questions

View all questions & answers for the CS0-001 exam

Exam CS0-001 topic 1 question 163 discussion

Actual exam question from CompTIA's CS0-001
Question #: 163
Topic #: 1
[All CS0-001 Questions]

An analyst has noticed unusual activities in the SIEM to a .cn domain name. Which of the following should the analyst use to identify the content of the traffic?

  • A. Log review
  • B. Service discovery
  • C. Packet capture
  • D. DNS harvesting
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jeend
2 years, 3 months ago
use to identify the content of the traffic Packet capture
upvoted 1 times
...
playerX
3 years, 3 months ago
C Packet capture would be the only choice that could identify the CONTENT of the traffic, if it were plaintext, A,B,and D would not be able to capture the content.
upvoted 1 times
...
Kuku55
4 years, 3 months ago
Its packet capture, keyword is content. Can you get the actual content using log? No, pcap can do that.
upvoted 1 times
...
xose
4 years, 8 months ago
I think this is a packet capture, currently, this is the real practice in our organization. If there is suspicious traffic we capture it and analyze. It might be a legal issue if you are getting 3rd party services
upvoted 3 times
...
Blind_Hatred
4 years, 10 months ago
Actually this should be A. You can't just go ahead and run packet captures on your network as there might me legal issues with that. This is just "unusual" network activity, so the first thing one would do is go through the logs.
upvoted 1 times
MagicianRecon
4 years, 9 months ago
Where does the question even remotely mention that you need to take into consideration legal issues?
upvoted 3 times
...
...
Blind_Hatred
4 years, 10 months ago
I mean, if the payload in the logs is not sufficient, I guess a Packet Capture can help identify the CONTENTS of the traffic. I guess.
upvoted 1 times
Blind_Hatred
4 years, 9 months ago
NIST 800-61 does state that it's best to run a packet capture as soon as an incident is suspected: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf#page=39.
upvoted 1 times
...
...
TheThreatGuy
4 years, 10 months ago
Unless you have tools in place to run a packet capture when unusual activity is detected, then A is the correct choice.
upvoted 1 times
...
s3curity1
4 years, 11 months ago
If the unusual activity is already detected by the SIEM, then the logs should contain the payload which can identify/give details regarding the content of the traffic. Otherwise, the answer is C.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago