Your threat hunting team detects outbound traffic to a Tor node from an employee's...
Nopal Securities technical mcq question, verified with a worked answer. Free to practise - no sign-up.
Your threat hunting team detects outbound traffic to a Tor node from an employee's workstation during non-business hours. No legitimate reason exists for this activity. What is the most appropriate response to this detection?
Show answer & explanation
Before taking disruptive remediation, security analysts perform live forensic triage to identify the exact executable/PID establishing covert Tor channels.
Step-by-step Derivation:
Step 1: Outbound Tor traffic indicates potential data exfiltration or malware command & control.
Step 2: Analysts inspect process trees, network sockets (netstat/ss), and memory artifacts to locate the malicious binary.
Step 3: Hence, investigating the processes generating traffic is the appropriate investigative step.