nerdexam
CompTIA

N10-005 · Question #322

A security appliance is blocking a DDoS attack on the network. Which of the following logs would be used to troubleshoot the traffic patterns trying to go across the network?

The correct answer is A. IPS logs. An IPS (Intrusion Prevention System) is an active security device that both detects and blocks malicious traffic in real time. Because it is the device actively blocking the DDoS attack, its logs contain detailed records of the detected attack traffic patterns, source IPs, and…

Network operations

Question

A security appliance is blocking a DDoS attack on the network. Which of the following logs would be used to troubleshoot the traffic patterns trying to go across the network?

Options

  • AIPS logs
  • BApplication logs
  • CIDS logs
  • DHistory logs

How the community answered

(41 responses)
  • A
    73% (30)
  • B
    5% (2)
  • C
    15% (6)
  • D
    7% (3)

Explanation

An IPS (Intrusion Prevention System) is an active security device that both detects and blocks malicious traffic in real time. Because it is the device actively blocking the DDoS attack, its logs contain detailed records of the detected attack traffic patterns, source IPs, and blocked flows-making IPS logs the correct source for troubleshooting. An IDS (choice C) only detects and alerts but does not block, so its logs would be less relevant to an active blocking appliance. Application logs (choice B) track application-level events and would not capture network-layer flood traffic patterns. History logs (choice D) is a generic term that does not correspond to a specific network security log type.

Topics

#IPS logs#DDoS#network monitoring#security logs

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice