• Post author:
  • Post category:Blog
  • Reading time:1 mins read
  • Post last modified:June 12, 2024

You work as a SOC analyst. Which option is an element of the security architecture that might report on beaconing activity between an infected host and a botnet command-and-control server?

  • sandbox
  • vulnerability scan
  • IPS
  • external router with firewall configured
Explanation & Hint:

The element of the security architecture that might report on beaconing activity between an infected host and a botnet command-and-control server is an Intrusion Prevention System (IPS).

IPS is designed to monitor network traffic for malicious activity, including communication patterns between infected hosts and known command-and-control servers. When it detects beaconing or suspicious traffic, it can generate alerts or block the communication, thus providing a layer of defense against botnet activity and other network-based threats.

For more Questions and Answers:

Security Operations Center Post-Assessment | CBROPS

Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments