A SOC analyst reviews firewall logs after an EDR alert. The logs show repeated TCP SYN packets from 203.0.113.10 to internal hosts on port 3389, each with action 'deny'. Which log element most directly confirms attempted malicious network activity?
Select an answer to reveal the explanation.
Short Explanation
Think of firewall logs as a bouncer's guest list: the action tells you what happened, not just what the traffic looked like. If you see repeated denies hitting remote administration, you've got attempted malicious activity, not just a weird port number. Don't get distracted by random source ports or half-open packets.
Full Explanation
Firewall logs are most useful when they combine the policy decision with the service being contacted. The action field tells you whether the connection was permitted, blocked, or dropped, while the destination port tells you what service the source was trying to reach. Repeated denied attempts aimed at a remote administration port show an external source trying to establish unauthorized access, even if the firewall stopped it. A random high source port is expected because clients usually use ephemeral ports, so it does not indicate malicious intent. A TCP SYN packet without completion is simply the normal beginning of a three-way handshake and can be seen in ordinary browsing, application startup, or scanning. A destination port such as TCP 3389 identifies a service, but the port number alone does not prove hostility because legitimate administrators may also use it when permitted. The malicious conclusion comes from the denied action against a sensitive administrative service, not from transport details alone. Exam caveat: CS0-004 telemetry questions often separate what the traffic is from what the traffic did, so prioritize the logged enforcement outcome. Operational check: pivot from the denied destination port to asset inventory, source reputation, and EDR events to determine whether any attempt reached an allowed path.