Which of the following describes what has occurred?
A security analyst discovers suspicious host activity while performing monitoring activities.
The analyst pulls a packet capture for the activity and sees the following:
Which of the following describes what has occurred?
A . The host attempted to download an application from utoftor.com.
B . The host downloaded an application from utoftor.com.
C . The host attempted to make a secure connection to utoftor.com.
D . The host rejected the connection from utoftor.com.
Answer: C
Explanation:
The packet capture shows that the host sent a Client Hello message to utoftor.com on port 443. This message is part of the TLS (Transport Layer Security) handshake protocol, which is used to establish a secure connection between a client and a server1. The Client Hello message contains information such as the supported TLS version, cipher suites, and extensions that the client can use for the secure connection. The server is expected to respond with a Server Hello message that selects the parameters for the secure connection. However, the packet capture does not show any response from the server, which means that the host only attempted to make a secure connection to utoftor.com, but did not succeed. The host did not download (B) or reject (D) any application from utoftor.com.
Reference: 1: https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/
Latest CS0-002 Dumps Valid Version with 220 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund