nerdexam
Huawei

H12-821_V1.0 · Question #897

After the tracking can find the attack source user or attack source interface based on the information in the attack packet, so that the administrator can be alerted through alarms and logs, or the…

The correct answer is A. TRUE. A (TRUE) is correct because network attack tracking systems are specifically designed to analyze packet headers and metadata to trace attacks back to their origin - identifying either the source user (via credentials, session data) or the source interface (via IP address, MAC…

Network Security

Question

After the tracking can find the attack source user or attack source interface based on the information in the attack packet, so that the administrator can be alerted through alarms and logs, or the packet can be discarded directly.

Options

  • ATRUE
  • BFALSE
  • C
  • D

How the community answered

(26 responses)
  • A
    85% (22)
  • B
    8% (2)
  • C
    4% (1)
  • D
    4% (1)

Explanation

A (TRUE) is correct because network attack tracking systems are specifically designed to analyze packet headers and metadata to trace attacks back to their origin - identifying either the source user (via credentials, session data) or the source interface (via IP address, MAC address, port). Once the source is identified, security systems can trigger automated responses: sending alerts/logs to administrators or dropping malicious packets at the network level.

B (FALSE) is incorrect because this capability is a core function of modern Intrusion Detection/Prevention Systems (IDS/IPS) and network monitoring tools - it is not beyond their capability.

Memory tip: Think of tracking like a "return address" on a malicious envelope - the system reads the packet's metadata to find where it came from, then either flags the mailman (alert) or refuses delivery (discard). If tracking couldn't find the source, there would be no point in having it.

Topics

#Intrusion Detection#Attack Source Tracking#Security Alerting#Packet Filtering

Community Discussion

No community discussion yet for this question.

Full H12-821_V1.0 Practice