Conducting Forensic Analysis and Incident Response Using Cisco Technologies (CBRFIR) — Question 25

An engineer received a call to assist with an ongoing DDoS attack. The Apache server is being targeted, and availability is compromised. Which step should be taken to identify the origin of the threat?

Answer options

Correct answer: D

Explanation

The correct answer is D because checking the access log will provide information about recent requests to the server, which can help identify the source of the DDoS attack. The other options focus on user sessions, processes, and services, which do not directly reveal the origin of incoming traffic affecting the server's availability.