SPLK-5001 · Question #24
Which of the following data sources can be used to discover unusual communication within an organization's network?
The correct answer is B. Net Flow. Net Flow (B) captures metadata about IP traffic flows - source/destination IPs, ports, protocols, bytes, and duration - across the entire network, making it ideal for spotting anomalies like unexpected lateral movement, unusual port usage, or data exfiltration patterns without…
Question
Which of the following data sources can be used to discover unusual communication within an organization's network?
Options
- AEDS
- BNet Flow
- CEmail
- DIAM
How the community answered
(17 responses)- B88% (15)
- C6% (1)
- D6% (1)
Explanation
Net Flow (B) captures metadata about IP traffic flows - source/destination IPs, ports, protocols, bytes, and duration - across the entire network, making it ideal for spotting anomalies like unexpected lateral movement, unusual port usage, or data exfiltration patterns without needing to inspect packet payloads.
- EDS (A) is not a standard network monitoring tool; it doesn't provide the traffic flow visibility needed to detect unusual communication.
- Email (C) is a communication channel itself, not a data source for analyzing broader network behavior patterns.
- IAM (D) manages user identities and access rights - useful for access auditing, but it doesn't observe or record network traffic flows.
Memory tip: Think "Net Flow = Network Telescope" - just as a telescope shows you patterns of movement across a large space without touching anything directly, Net Flow watches traffic patterns across your network without capturing full packet content.
Topics
Community Discussion
No community discussion yet for this question.