CompTIA Security+ SY0-601 – Question396

A host was infected with malware. During the incident response, Joe, a user, reported that he did not receive
any emails with links, but he had been browsing the internet all day. Which of the following would MOST likely
show where the malware originated?


A.
The DNS logs
B. The web server logs
C. The SIP traffic logs
D. The SNMP logs

Correct Answer: B

Explanation:

Reference: https://www.crowdstrike.com/cybersecurity-101/observability/web-ser…
20server%20log%20is,a%20defined%20period%20of%20time