Quiz 1 Question 11 of 20

A firewall log shows suspicious outbound traffic from a single public IP, but the SOC knows many internal hosts use NAT. What should the analyst do first to identify the true endpoint?

Select an answer to reveal the explanation.

Motivation