Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CompTIA Security+ Exam 2026 SY0-701 Question # 193 Topic 20 Discussion

CompTIA Security+ Exam 2026 SY0-701 Question # 193 Topic 20 Discussion

SY0-701 Exam Topic 20 Question 193 Discussion:
Question #: 193
Topic #: 20

A company suffered a critical incident where 30GB of data was exfiltrated from the corporate network. Which of the following actions is the most efficient way to identify where the system data was exfiltrated from and where it was sent?


A.

Analyze firewall and network logs for large amounts of outbound traffic to external IP addresses or domains.


B.

Analyze IPS and IDS logs to find the IP addresses used by the attacker for reconnaissance scans.


C.

Analyze endpoint and application logs to see whether file-sharing programs were running.


D.

Analyze external vulnerability scans to identify exploitable systems.


Get Premium SY0-701 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.