Quiz 3 Question 3 of 20

An EDR alert flags a workstation sending short outbound HTTPS requests every 30 seconds to several IP addresses. You have full packet capture, but the sessions are TLS encrypted and you have no decryption keys. Which PCAP-derived metadata should you analyze first to characterize the suspicious encrypted sessions?

Select an answer to reveal the explanation.

Motivation