A security analyst is reviewing logs to identify the destination of command-and-control traffic originating from a compromised device within the on-premises network. Which of the following is the best log to review?
Choose an answer
Tap an option to check your answer.
Correct answer: Firewall.
Why this is the answer
The firewall log is the best choice because firewalls control network traffic flow and record connection attempts, including source and destination IP addresses, ports, and protocols. This information is crucial for identifying external command-and-control (C2) servers communicating with an internal compromised device. IDS logs primarily focus on detecting known attack signatures and anomalies, which might indicate C2 activity but won't definitively show the destination IP. Antivirus logs track malware detection and removal on endpoints, not network traffic destinations. Application logs detail application-specific events and errors, which are generally not relevant for identifying external C2 destinations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed