Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmasmnth

A security analyst uses a full pcap solution to extract all traffic from the last...

A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the 10.213.4.27 file server.

This file server is under investigation due to concerns about potential data exfiltration using Domain Name System (DNS) traffic.

Which of the following commands should the analyst use to extract any potentially leaked data from the suspicious.pcap file?

A.

strings suspicious.pcap | grep 10.213.4.27

B.

zeek -r suspicious.pcap; grep 10.213.4.27 file.log

C.

snort -r suspicious.pcap; grep eve.log 10.213.4.27

D.

tcpdump -r suspicious.pcap port 53 and host 10.213.4.27

CompTIA CS0-004 Summary

  • Vendor: CompTIA
  • Product: CS0-004
  • Update on: Sep 21, 2026
  • Questions: 82
Price: $52.5  $149.99
Buy Now CS0-004 PDF + Testing Engine Pack

Payments We Accept

Your purchase with ExamsVCE is safe and fast. Your products will be available for immediate download after your payment has been received.
The ExamsVCE website is protected by 256-bit SSL from McAfee, the leader in online security.

examsvce payment method