| Exam 200-201 | Question id=6043 | Security policies and procedures |
When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
| A. |
firewall logs | |
| B. |
full packet capture | |
| C. |
session data | |
| D. |
NetFlow data |