Exam 200-201 | Question id=6043 | Security policies and procedures |
When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
A. |
firewall logs | |
B. |
full packet capture | |
C. |
session data | |
D. |
NetFlow data |