A user receives the following threat alert from the firewall: domain: 1 serial:0
ID: 3741811 • Letter: A
Question
A user receives the following threat alert from the firewall: domain: 1 serial:0018002000 seqno: 20790819 actionflags: Ox80oo00ooooo type: THREAT subtype: analysis config ver: O src: 200.71.0.1 dst: 198.134.5.6 rule: EXT-To-EmailAppliance srcuser: dstuser: srcloc: IN dstloc: US app smtp from: External logset: Log forwarding to controller repeatent: 1 sport: 53010 dport: 25 action: alert threatd: 52033 category: malicious severity: medium direction: client-to-server filetype: document misc: ticket_771546 doc
Explanation / Answer
Answer: C
Explanation:
from "app: smtp" we can say that it is 'Simple Mail Transfer protocol'. and to: DMZ states that email destination is current users DMZ (demilitarized zone). and catefory: Malicious says that email is malicious. finally severity: medium says that email is not blocked and not highly sever, we need to remediate email ourselves.
Related Questions
Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.