CV0-002 · Question #411
Users at a university are experiencing slow response and performance issues with private cloud services. The university was compromised, and a loss of bandwidth utilization was reported. Without deplo
The correct answer is C. Install sniffing tools, catalog the type of traffic, and capture all traffic to and from the target systems.. Given slow performance, bandwidth loss, and a reported compromise without deploying new software, the best approach is to install sniffing tools to capture and analyze network traffic.
Question
Users at a university are experiencing slow response and performance issues with private cloud services. The university was compromised, and a loss of bandwidth utilization was reported. Without deploying new software, which of the following should be performed to determine the cause of the issues?
Options
- ASend all logs for all cloud components to an event and incident management system for correlation and
- BLocate all load balancers in the cloud and replace them with the latest version of content delivery
- CInstall sniffing tools, catalog the type of traffic, and capture all traffic to and from the target systems.
- DImplement and update an antivirus solution to the cloud infrastructure to detect potential threats.
How the community answered
(30 responses)- A17% (5)
- B7% (2)
- C67% (20)
- D10% (3)
Why each option
Given slow performance, bandwidth loss, and a reported compromise without deploying new software, the best approach is to install sniffing tools to capture and analyze network traffic.
Sending logs to a SIEM provides historical and aggregated data but might not offer the real-time, granular network traffic visibility needed to diagnose 'loss of bandwidth utilization' effectively without specific network flow logs or deep packet inspection.
Replacing load balancers with content delivery networks (CDNs) is a solution for content delivery optimization, not a diagnostic step for slow response, bandwidth loss, or compromise, and involves deploying new infrastructure/software.
Installing sniffing tools, cataloging traffic, and capturing all traffic to and from target systems allows for deep packet inspection and analysis of network activity. This directly addresses the reported loss of bandwidth utilization and potential compromise by identifying unusual traffic patterns, malicious activity, or misconfigurations that consume bandwidth and cause performance issues, all without deploying new software.
Implementing and updating an antivirus solution typically involves deploying new software, and while it's a security measure, it's focused on detecting known threats, not necessarily diagnosing unknown bandwidth loss or performance issues from a compromised system's network activity.
Concept tested: Network traffic analysis for performance and security diagnostics
Topics
Community Discussion
No community discussion yet for this question.