Question 4 of 76 from exam 350-201-CBRCOR: Performing CyberOps Using Cisco Security Technologies

Question 4 of 76 from exam 350-201-CBRCOR: Performing CyberOps Using Cisco Security Technologies

Question

Refer to the exhibit.

A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker.

Which tool should the analyst use to identify the source IP of the offender?

Top
TCP
TCP
Top
Top
TOP
TCP

TOP
TCP
TCP
Top
Top
TCP
TCP
Top
Top
TCP
TCP
TOP
Top
TCP
TCP
Top

192.168.1.8:54580
192.168.1.8:54583
192.168.1.8:54916
192.168.1.8:54978
192.168.1.8:55094
192.168.1.8:55401
192.168.1.8:55730

192.168.1.8:55824
192.168.1.8:55825
192.168.1.8:55846
192.168.1.8:55847
192.168.1.8:55853
192.168.1.8:55879
192.168.1.8:55884
192.168.1.8:55893
192.168.1.8:55947
192.168.1.8:55966
192.168.1.8:55970
192.168.1.8:55972
192.168.1.8:55976
192.168.1.8:55979
192.168.1.8:55986
192.168.1.8:55988

vk-in-f108:imaps
132,245.61 50:https

72.21.194.109:https
wonderhowto:http
mia07s34-in-f78:https

a23-40-191-15:https
a23-40-191-15:https
mia07s25-in-f14:https
a184-51-150-89:http
187.55.56.154:40028
atl4s38-in-f4:https
208-46-117-174:https
vx-in-f95:https
stackoverflow:https
stackoverflow:https
mia07s34-in-f78:https
191.238.241.80:https
54,239.26.242:https
mia07s36-in-f14:https
server t:https
104.16.118.182:http

ESTABLISHED
ESTABLISHED
ESTABLISHED
ESTABLISHED
ESTABLISHED
ESTABLISHED
TIME WAIT

CLOSE_WAIT
CLOSE_WAIT
TIME_WAIT
CLOSE_WAIT
ESTABLISHED
ESTABLISHED
ESTABLISHED
TIME_WAIT
ESTABLISHED
ESTABLISHED
TIME_WAIT
TIME_WAIT
ESTABLISHED
ESTABLISHED
TIME_WAIT
ESTABLISHED

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.