200-201 · Question #504
A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was…
The correct answer is C. protocol. The 5-tuple approach in network traffic analysis consists of the following elements: 1. Source IP address 2. Destination IP address 4. Destination port This method helps network administrators track and identify suspicious traffic flows based on these parameters. Protocol…
Question
A suspicious user opened a connection from a compromised host inside an organization. Traffic was going through a router and the network administrator was able to identify this flow. The admin was following 5-tuple to collect needed data. Which information was gathered based on this approach?
Options
- Adirect path
- Buser name
- Cprotocol
- DNAT
How the community answered
(47 responses)- A2% (1)
- B2% (1)
- C89% (42)
- D6% (3)
Explanation
The 5-tuple approach in network traffic analysis consists of the following elements: 1. Source IP address 2. Destination IP address 4. Destination port This method helps network administrators track and identify suspicious traffic flows based on these parameters. Protocol (e.g., TCP, UDP, ICMP) is one of the key attributes in the 5-tuple
Topics
Community Discussion
No community discussion yet for this question.