nerdexam
Splunk

SPLK-5001 · Question #24

Which of the following data sources can be used to discover unusual communication within an organization's network?

The correct answer is B. Net Flow. Net Flow (B) captures metadata about IP traffic flows - source/destination IPs, ports, protocols, bytes, and duration - across the entire network, making it ideal for spotting anomalies like unexpected lateral movement, unusual port usage, or data exfiltration patterns without…

Security Data Onboarding and Normalization

Question

Which of the following data sources can be used to discover unusual communication within an organization's network?

Options

  • AEDS
  • BNet Flow
  • CEmail
  • DIAM

How the community answered

(17 responses)
  • B
    88% (15)
  • C
    6% (1)
  • D
    6% (1)

Explanation

Net Flow (B) captures metadata about IP traffic flows - source/destination IPs, ports, protocols, bytes, and duration - across the entire network, making it ideal for spotting anomalies like unexpected lateral movement, unusual port usage, or data exfiltration patterns without needing to inspect packet payloads.

  • EDS (A) is not a standard network monitoring tool; it doesn't provide the traffic flow visibility needed to detect unusual communication.
  • Email (C) is a communication channel itself, not a data source for analyzing broader network behavior patterns.
  • IAM (D) manages user identities and access rights - useful for access auditing, but it doesn't observe or record network traffic flows.

Memory tip: Think "Net Flow = Network Telescope" - just as a telescope shows you patterns of movement across a large space without touching anything directly, Net Flow watches traffic patterns across your network without capturing full packet content.

Topics

#NetFlow#network monitoring#data sources#network communication

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice