Q47
Single choice
A security analyst investigates abnormal outbound traffic from a corporate endpoint. The traffic is encrypted and uses non-standard ports.
Which of the following data sources should the analyst use first to confirm whether this traffic is malicious?