GAQM
CPEH-001 · Question #790
An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet traffic was…
The correct answer is A. Protocol analyzer. See the full explanation below for the reasoning.
Question
An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet traffic was captured by the IDS and saved to a PCAP file. What type of network tool can be used to determine if these packets are genuinely malicious or simply a false positive?
Options
- AProtocol analyzer
- BNetwork sniffer
- CIntrusion Prevention System (IPS)
- DVulnerability scanner
How the community answered
(22 responses)- A86% (19)
- B5% (1)
- D9% (2)
Community Discussion
No community discussion yet for this question.