Quiz 3 Question 8 of 20

A SOC analyst reviews firewall logs after an EDR alert. The logs show repeated TCP SYN packets from 203.0.113.10 to internal hosts on port 3389, each with action 'deny'. Which log element most directly confirms attempted malicious network activity?

Select an answer to reveal the explanation.

Motivation