CAS-003 · Question #191
A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of the following can…
The correct answer is D. HIDS F. Protocol analyzer. A protocol analyzer can be used to capture and analyze signals and data traffic over a communication channel which makes it ideal for use to assess a company's network from within under the circumstances. HIDS is used as an intrusion detection system that can monitor and…
Question
A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of the following can the network administrator use to detect the presence of a malicious actor physically accessing the company's network or information systems from within? (Select TWO).
Options
- ARAS
- BVulnerability scanner
- CHTTP intercept
- DHIDS
- EPort scanner
- FProtocol analyzer
How the community answered
(41 responses)- B2% (1)
- C5% (2)
- D83% (34)
- E10% (4)
Explanation
A protocol analyzer can be used to capture and analyze signals and data traffic over a communication channel which makes it ideal for use to assess a company's network from within under the circumstances. HIDS is used as an intrusion detection system that can monitor and analyze the internal company network especially the dynamic behavior and the state of the computer systems; behavior such as network packets targeted at that specific host, which programs accesses what resources etc.
Topics
Community Discussion
No community discussion yet for this question.