CAS-005 · Question #98
A security review revealed that not all of the client proxy traffic is being captured. Which of the following architectural changes best enables the capture of traffic for analysis?
The correct answer is C. Configuring a span port on the perimeter firewall to ingest logs. The problem is that not all client proxy traffic is being captured, so you need an architectural change that lets a monitoring or analysis system see all the traffic that traverses the device, regardless of which proxy or VLAN it came from. A SPAN (mirror) port on the firewall…
Question
A security review revealed that not all of the client proxy traffic is being captured. Which of the following architectural changes best enables the capture of traffic for analysis?
Options
- AAdding an additional proxy server to each segmented VLAN
- BSetting up a reverse proxy for client logging at the gateway
- CConfiguring a span port on the perimeter firewall to ingest logs
- DEnabling client device logging and system event auditing
How the community answered
(45 responses)- A13% (6)
- B7% (3)
- C78% (35)
- D2% (1)
Explanation
The problem is that not all client proxy traffic is being captured, so you need an architectural change that lets a monitoring or analysis system see all the traffic that traverses the device, regardless of which proxy or VLAN it came from. A SPAN (mirror) port on the firewall or switch copies all relevant traffic to a monitoring/packet- capture/logging system, which directly addresses the visibility gap.
Community Discussion
No community discussion yet for this question.