200-201 · Question #18
Drag and Drop Question Drag and drop the technology on the left onto the data type the technology provides on the right. Answer:
The correct mappings are: tcpdump → full packet capture (tcpdump captures entire packets at the wire level, providing complete payload data); NetFlow → session data (NetFlow records metadata about network flows/sessions such as IP addresses, ports, byte counts, and duration…
Question
Drag and Drop Question Drag and drop the technology on the left onto the data type the technology provides on the right. Answer:
Exhibit
Options
- Atcpdump
- Bweb content filtering
- Ctraditional stateful firewall
- DNetFlow
- Esession data
- Ffull packet capture
- Gtransaction data
- Hconnection event
Explanation
The correct mappings are: tcpdump → full packet capture (tcpdump captures entire packets at the wire level, providing complete payload data); NetFlow → session data (NetFlow records metadata about network flows/sessions such as IP addresses, ports, byte counts, and duration without capturing payload content); web content filtering → transaction data (web content filtering logs URLs, domains, and HTTP transaction details representing application-layer transactions); traditional stateful firewall → connection event (stateful firewalls track the state of TCP/UDP connections and generate logs when connections are allowed or denied, producing connection events). These pairings reflect each technology's primary data output type in network security monitoring.
Topics
Community Discussion
No community discussion yet for this question.
