nerdexam
CompTIA

CAS-002 · Question #564

The security administrator has noticed a range of network problems affecting the proxy server. Based on reviewing the logs, the administrator notices that the firewall is being targeted with various…

The correct answer is C. 1. Deploy a protocol analyzer on the switch span port. Deploying a protocol analyzer on a switch SPAN port enables passive full-packet capture of all traffic for in-depth forensic analysis of web attacks and concurrent network problems.

Enterprise Security

Question

The security administrator has noticed a range of network problems affecting the proxy server. Based on reviewing the logs, the administrator notices that the firewall is being targeted with various web attacks at the same time that the network problems are occurring. Which of the following strategies would be MOST effective in conducting an in-depth assessment and remediation of the problems?

Options

  • A
    1. Deploy an HTTP interceptor on the switch span port;
  • B
    1. Deploy a protocol analyzer on the switch span port;
  • C
    1. Deploy a protocol analyzer on the switch span port;
  • D
    1. Deploy a network fuzzer on the switch span port;

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    9% (2)
  • C
    83% (19)
  • D
    4% (1)

Why each option

Deploying a protocol analyzer on a switch SPAN port enables passive full-packet capture of all traffic for in-depth forensic analysis of web attacks and concurrent network problems.

A1. Deploy an HTTP interceptor on the switch span port;

An HTTP interceptor captures only application-layer HTTP traffic, which is insufficient for diagnosing low-level network problems or non-HTTP attack vectors that may be occurring simultaneously.

B1. Deploy a protocol analyzer on the switch span port;

Although option B also begins with a protocol analyzer, its subsequent steps do not provide as complete or accurate an assessment and remediation path as those defined in option C.

C1. Deploy a protocol analyzer on the switch span port;Correct

A protocol analyzer (such as Wireshark) placed on a switch SPAN port passively captures a mirrored copy of all network traffic without disrupting live connections. This provides full packet-level visibility into both the web attacks targeting the firewall and the network problems affecting the proxy server simultaneously. The subsequent steps in option C follow up the capture phase with the appropriate analysis and remediation actions for this combined scenario.

D1. Deploy a network fuzzer on the switch span port;

A network fuzzer is an offensive tool that generates malformed inputs to discover vulnerabilities; it does not passively analyze existing attack traffic or help diagnose current network problems.

Concept tested: Protocol analyzer deployment for network traffic analysis

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/15-0SY/config_guide/sup2T/15_0_sy_swcg_2T/span.html

Topics

#web attacks#protocol analyzer#incident response#proxy security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice