312-39 Exam Question 56
Peter, a SOC analyst with Spade Systems, is monitoring and analyzing the router logs of the company and wanted to check the logs that are generated by access control list numbered 210.
What filter should Peter add to the 'show logging' command to get the required output?
What filter should Peter add to the 'show logging' command to get the required output?
312-39 Exam Question 57
Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?
312-39 Exam Question 58
Which of the following command is used to enable logging in iptables?
312-39 Exam Question 59
Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads.
What does this indicate?
What does this indicate?
312-39 Exam Question 60
According to the forensics investigation process, what is the next step carried out right after collecting the evidence?

