Quiz 13 Question 6 of 20

An EDR alert shows a workstation making a single 30-second beacon to an unfamiliar external IP. NetFlow confirms the connection, but the payload is not available. You query a threat-intel platform for the IP's reputation, ASN, and recent malware associations. What is the best use of that enrichment when deciding containment?

Select an answer to reveal the explanation.

Motivation