SY0-501 · Question #62
While reviewing the monthly internet usage it is noted that there is a large spike in traffic classified as "unknown" and does not appear to be within the bounds of the organizations Acceptable Use…
The correct answer is B. IDS logs. To investigate a large spike in 'unknown' network traffic potentially violating an Acceptable Use Policy, an Intrusion Detection System (IDS) is the most effective tool.
Question
While reviewing the monthly internet usage it is noted that there is a large spike in traffic classified as "unknown" and does not appear to be within the bounds of the organizations Acceptable Use Policy. Which of the following tool or technology would work BEST for obtaining more information on this traffic?
Options
- AFirewall logs
- BIDS logs
- CIncreased spam filtering
- DProtocol analyzer
How the community answered
(51 responses)- A2% (1)
- B80% (41)
- C6% (3)
- D12% (6)
Why each option
To investigate a large spike in 'unknown' network traffic potentially violating an Acceptable Use Policy, an Intrusion Detection System (IDS) is the most effective tool.
Firewall logs primarily record basic connection details (allowed/denied ports, IPs, protocols) but generally lack the deep packet inspection and behavioral analysis capabilities needed to classify ambiguous 'unknown' traffic or identify specific AUP violations beyond simple rule matching.
An Intrusion Detection System (IDS) continuously monitors network traffic for suspicious activity, policy violations, and known attack patterns. Its logs can provide detailed insights and classifications for 'unknown' traffic, flagging it based on signatures or anomaly detection, which is crucial for investigating potential AUP breaches.
Increased spam filtering is designed to manage email-based threats and unwanted messages and is irrelevant for investigating a general spike in 'unknown' network traffic.
While a protocol analyzer provides extremely granular packet-level data, it is typically used for real-time capture and deep troubleshooting of specific network segments or issues, and it is not the best or most scalable tool for automatically monitoring, alerting on, and classifying a large, ongoing spike of 'unknown' traffic across an entire network for policy violations compared to an IDS.
Concept tested: Network monitoring and incident investigation tools
Source: https://www.cisco.com/c/en/us/products/security/intrusion-prevention-systems-ips/what-is-ips.html
Topics
Community Discussion
No community discussion yet for this question.