CAS-001 · Question #243
The security administrator has noticed a range of network problems affecting the proxy server. Based on reviewing the logs, the administrator notices that the firewall is being targeted with various…
The correct answer is C. 1. Deploy a protocol analyzer on the switch span port. The correct answer is C. When a firewall is under active web-based attack and causing proxy/network issues, the most effective approach begins with deploying a protocol analyzer (e.g., Wireshark) on a switch SPAN (mirror) port to passively capture and inspect all traffic in…
Question
The security administrator has noticed a range of network problems affecting the proxy server. Based on reviewing the logs, the administrator notices that the firewall is being targeted with various web attacks at the same time that the network problems are occurring. Which of the following strategies would be MOST effective in conducting an in-depth assessment and remediation of the problems?
Options
- A
- Deploy an HTTP interceptor on the switch span port;
- B
- Deploy a protocol analyzer on the switch span port;
- C
- Deploy a protocol analyzer on the switch span port;
- D
- Deploy a network fuzzer on the switch span port;
How the community answered
(39 responses)- A18% (7)
- B10% (4)
- C69% (27)
- D3% (1)
Explanation
The correct answer is C. When a firewall is under active web-based attack and causing proxy/network issues, the most effective approach begins with deploying a protocol analyzer (e.g., Wireshark) on a switch SPAN (mirror) port to passively capture and inspect all traffic in detail. This provides deep visibility into attack patterns, payloads, and affected hosts without disrupting traffic. The subsequent steps in option C - which differ from B in the remediation phase - correctly follow up captured analysis with targeted rule tuning and patching. Option A (HTTP interceptor) only handles Layer 7 HTTP traffic and misses other attack vectors. Option D (network fuzzer) is an offensive/testing tool inappropriate for live incident response.
Topics
Community Discussion
No community discussion yet for this question.