nerdexam
GAQM

CPEH-001 · Question #790

An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet traffic was…

The correct answer is A. Protocol analyzer. See the full explanation below for the reasoning.

Question

An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet traffic was captured by the IDS and saved to a PCAP file. What type of network tool can be used to determine if these packets are genuinely malicious or simply a false positive?

Options

  • AProtocol analyzer
  • BNetwork sniffer
  • CIntrusion Prevention System (IPS)
  • DVulnerability scanner

How the community answered

(22 responses)
  • A
    86% (19)
  • B
    5% (1)
  • D
    9% (2)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice