Quiz 2 Question 20 of 20

An IDS generates a signature alert for a known SMB exploit from an internal host to a file server. The alert includes timestamp and source/destination but no process or packet payload. What should the analyst do first to validate the alert?

Select an answer to reveal the explanation.

Motivation