nerdexam
Cisco

200-201 · Question #504

A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was…

The correct answer is C. protocol. The 5-tuple approach in network traffic analysis consists of the following elements: 1. Source IP address 2. Destination IP address 4. Destination port This method helps network administrators track and identify suspicious traffic flows based on these parameters. Protocol…

Submitted by anna_se· Mar 6, 2026Network Intrusion Analysis

Question

A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was following 5-tuple to collect needed data. Which information was gathered based on this approach?

Options

  • Adirect path
  • Buser name
  • Cprotocol
  • DNAT

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    89% (42)
  • D
    6% (3)

Explanation

The 5-tuple approach in network traffic analysis consists of the following elements: 1. Source IP address 2. Destination IP address 4. Destination port This method helps network administrators track and identify suspicious traffic flows based on these parameters. Protocol (e.g., TCP, UDP, ICMP) is one of the key attributes in the 5-tuple

Topics

#5-tuple#network flow data#network monitoring#protocol analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice