200-201 · Question #202
Refer to the exhibit. An engineer received an event log file to review. Which technology generated the log?
The correct answer is C. firewall. The exhibit, showing logs of allowed or denied connections with source/destination IPs and ports, is characteristic of a firewall's logging output.
Question
Refer to the exhibit. An engineer received an event log file to review. Which technology generated the log?
Exhibit
Options
- ANetFlow
- Bproxy
- Cfirewall
- DIDS/IPS
How the community answered
(54 responses)- A6% (3)
- B7% (4)
- C67% (36)
- D20% (11)
Why each option
The exhibit, showing logs of allowed or denied connections with source/destination IPs and ports, is characteristic of a firewall's logging output.
NetFlow logs focus on network flow statistics (e.g., volume, duration) rather than individual packet allow/deny decisions by security rules.
Proxy logs primarily detail web requests and responses handled by the proxy server, not general network connection activity across various protocols.
Firewall logs commonly record details about network connection attempts, including source and destination IP addresses, ports, protocols, and whether the traffic was permitted or blocked, aligning with the type of event log described.
IDS/IPS logs typically focus on security alerts, detected threats, and signatures, rather than comprehensive logging of all connection states (allowed/denied).
Concept tested: Identifying firewall log entries
Source: https://learn.microsoft.com/en-us/azure/firewall/firewall-logs-metrics
Topics
Community Discussion
No community discussion yet for this question.
