nerdexam
Cisco

350-201 · Question #48

What should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?

The correct answer is A. Tapping interrogation replicates signals to a separate port for analyzing traffic. Traffic tapping passively copies network signals to a separate out-of-band port for analysis, while inline interrogation places a device directly in the traffic path and can actively block threats.

Techniques

Question

What should a security analyst consider when comparing inline traffic interrogation with traffic tapping to determine which approach to use in the network?

Options

  • ATapping interrogation replicates signals to a separate port for analyzing traffic
  • BTapping interrogations detect and block malicious traffic
  • CInline interrogation enables viewing a copy of traffic to ensure traffic is in compliance with security
  • DInline interrogation detects malicious traffic but does not block the traffic

How the community answered

(24 responses)
  • A
    92% (22)
  • C
    4% (1)
  • D
    4% (1)

Why each option

Traffic tapping passively copies network signals to a separate out-of-band port for analysis, while inline interrogation places a device directly in the traffic path and can actively block threats.

ATapping interrogation replicates signals to a separate port for analyzing trafficCorrect

A network TAP or SPAN port replicates traffic signals to a dedicated monitoring port without interfering with the live traffic stream, which is the defining characteristic of passive tapping. This out-of-band approach means tapping introduces no latency and cannot drop or block packets, but it provides full traffic visibility for forensic or compliance analysis. This fundamental difference is the primary consideration when choosing between tapping and inline deployment.

BTapping interrogations detect and block malicious traffic

Tapping is an out-of-band passive technique and physically cannot block or drop malicious traffic because it only receives a copy of the data, not the live stream.

CInline interrogation enables viewing a copy of traffic to ensure traffic is in compliance with security

Viewing a copy of traffic describes tapping, not inline interrogation - inline devices sit directly in the live traffic path and process actual packets, not replicated copies.

DInline interrogation detects malicious traffic but does not block the traffic

Inline devices such as an IPS are capable of both detecting and actively blocking malicious traffic because all live packets pass through them before reaching the destination.

Concept tested: Inline vs passive tap traffic monitoring approaches

Source: https://www.cisco.com/c/en/us/products/security/intrusion-prevention-system/index.html

Topics

#traffic tapping#inline interrogation#network monitoring#traffic analysis

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice