CAS-003 · Question #972
A company wants to analyze internal network traffic for IOCs. The security solution consists of a network collector appliance and a separate server which security analysts access via a browser to…
The correct answer is C. install multiple network collector appliances closer to the access layer switches. In a collapsed core Layer 2 architecture, significant east-west traffic (host-to-host within the same VLAN or segment) never traverses the core switch and therefore would not be visible to a single collector placed at or near the core (A) or distribution layer (B). Deploying…
Question
A company wants to analyze internal network traffic for IOCs. The security solution consists of a network collector appliance and a separate server which security analysts access via a browser to visualize and review the alerts generated from the network traffic. The company uses a collapsed core operating at Layer 2 at 100Gbps. The server win be placed in the datacenter. Which of the following architectures should be used to ensure the solution can provide visibility into all the company's internal network traffic including DNS and URL requests without impacting network traffic flow?
Options
- AInstall the network collector appliance closer to the core switching infrastructure
- BInstall the network collector appliance closer to the distribution switches
- Cinstall multiple network collector appliances closer to the access layer switches
- DInstall the network collector appliance physically inline between the core switch and the firewall
How the community answered
(18 responses)- A22% (4)
- B11% (2)
- C61% (11)
- D6% (1)
Explanation
In a collapsed core Layer 2 architecture, significant east-west traffic (host-to-host within the same VLAN or segment) never traverses the core switch and therefore would not be visible to a single collector placed at or near the core (A) or distribution layer (B). Deploying multiple network collector appliances at the access layer - where endpoints connect - captures all traffic at its source before it aggregates, providing comprehensive visibility including DNS queries and HTTP/HTTPS URL requests. A single inline placement between the core switch and the firewall (D) is explicitly ruled out because it would create a bottleneck and a single point of failure, directly impacting network traffic flow at 100 Gbps.
Topics
Community Discussion
No community discussion yet for this question.