Certified SOC Analyst (CSA) — Question 94

Which of the following data source will a SOC Analyst use to monitor connections to the insecure ports?

Answer options

Correct answer: A

Explanation

The correct answer is A, as Netstat Data provides information on active connections and listening ports, making it essential for monitoring insecure ports. The other options, such as DNS, IIS, and DHCP data, do not specifically focus on connection states or port activity, which are critical for identifying insecure port usage.