Question 85:
When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?
Answer options:
A. firewall logs B. full packet capture C. session data D. NetFlow data
Answer correct:
C
Reference: https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/enterprise-network-security/white-paper-c11-736595.html