N10-005 · Question #322
A security appliance is blocking a DDoS attack on the network. Which of the following logs would be used to troubleshoot the traffic patterns trying to go across the network?
The correct answer is A. IPS logs. An IPS (Intrusion Prevention System) is an active security device that both detects and blocks malicious traffic in real time. Because it is the device actively blocking the DDoS attack, its logs contain detailed records of the detected attack traffic patterns, source IPs, and…
Question
A security appliance is blocking a DDoS attack on the network. Which of the following logs would be used to troubleshoot the traffic patterns trying to go across the network?
Options
- AIPS logs
- BApplication logs
- CIDS logs
- DHistory logs
How the community answered
(41 responses)- A73% (30)
- B5% (2)
- C15% (6)
- D7% (3)
Explanation
An IPS (Intrusion Prevention System) is an active security device that both detects and blocks malicious traffic in real time. Because it is the device actively blocking the DDoS attack, its logs contain detailed records of the detected attack traffic patterns, source IPs, and blocked flows-making IPS logs the correct source for troubleshooting. An IDS (choice C) only detects and alerts but does not block, so its logs would be less relevant to an active blocking appliance. Application logs (choice B) track application-level events and would not capture network-layer flood traffic patterns. History logs (choice D) is a generic term that does not correspond to a specific network security log type.
Topics
Community Discussion
No community discussion yet for this question.