200-201 · Question #228
Refer to the exhibit. During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events. Which technology provided these logs?
The correct answer is D. firewall. Logs detailing local TCP connection events, especially in the context of suspicious scanning activity, are typically generated by a firewall that monitors and controls network traffic.
Question
Refer to the exhibit. During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events. Which technology provided these logs?
Exhibit
Options
- Aantivirus
- Bproxy
- CIDS/IPS
- Dfirewall
How the community answered
(36 responses)- A6% (2)
- B3% (1)
- C3% (1)
- D89% (32)
Why each option
Logs detailing local TCP connection events, especially in the context of suspicious scanning activity, are typically generated by a firewall that monitors and controls network traffic.
Antivirus software focuses on detecting and mitigating malicious software on endpoints and does not primarily generate logs of general network connection events.
Proxy servers log web-related traffic that passes through them, not all local TCP connection events across various ports and protocols.
IDS/IPS systems primarily generate alerts and logs related to detected threats or anomalies, rather than comprehensive logs of all network connection events like a firewall.
Firewalls are designed to monitor, filter, and log network connection attempts, including local TCP connection events and suspicious scanning activities, making them the primary source for such logs.
Concept tested: Identifying firewall logs for connection events
Source: https://learn.microsoft.com/en-us/azure/firewall/firewall-logs-metrics
Topics
Community Discussion
No community discussion yet for this question.
