✅ Перевірена відповідь на це питання доступна нижче. Наші рішення, перевірені спільнотою, допомагають краще зрозуміти матеріал.
An analyst notices that a workstation is making regular outbound connections to an unfamiliar host at 03:00 every night, several days after a staff member opened an email attachment. No files have been encrypted and nothing has yet been stolen.
Which stage of the malware attack lifecycle does this behaviour represent, and what does blocking it achieve?