nerdexam
CompTIA

SY0-501 · Question #62

While reviewing the monthly internet usage it is noted that there is a large spike in traffic classified as "unknown" and does not appear to be within the bounds of the organizations Acceptable Use…

The correct answer is B. IDS logs. To investigate a large spike in 'unknown' network traffic potentially violating an Acceptable Use Policy, an Intrusion Detection System (IDS) is the most effective tool.

Submitted by mike_84· Mar 4, 2026Security operations

Question

While reviewing the monthly internet usage it is noted that there is a large spike in traffic classified as "unknown" and does not appear to be within the bounds of the organizations Acceptable Use Policy. Which of the following tool or technology would work BEST for obtaining more information on this traffic?

Options

  • AFirewall logs
  • BIDS logs
  • CIncreased spam filtering
  • DProtocol analyzer

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    80% (41)
  • C
    6% (3)
  • D
    12% (6)

Why each option

To investigate a large spike in 'unknown' network traffic potentially violating an Acceptable Use Policy, an Intrusion Detection System (IDS) is the most effective tool.

AFirewall logs

Firewall logs primarily record basic connection details (allowed/denied ports, IPs, protocols) but generally lack the deep packet inspection and behavioral analysis capabilities needed to classify ambiguous 'unknown' traffic or identify specific AUP violations beyond simple rule matching.

BIDS logsCorrect

An Intrusion Detection System (IDS) continuously monitors network traffic for suspicious activity, policy violations, and known attack patterns. Its logs can provide detailed insights and classifications for 'unknown' traffic, flagging it based on signatures or anomaly detection, which is crucial for investigating potential AUP breaches.

CIncreased spam filtering

Increased spam filtering is designed to manage email-based threats and unwanted messages and is irrelevant for investigating a general spike in 'unknown' network traffic.

DProtocol analyzer

While a protocol analyzer provides extremely granular packet-level data, it is typically used for real-time capture and deep troubleshooting of specific network segments or issues, and it is not the best or most scalable tool for automatically monitoring, alerting on, and classifying a large, ongoing spike of 'unknown' traffic across an entire network for policy violations compared to an IDS.

Concept tested: Network monitoring and incident investigation tools

Source: https://www.cisco.com/c/en/us/products/security/intrusion-prevention-systems-ips/what-is-ips.html

Topics

#protocol analyzer#traffic analysis#network monitoring#deep packet inspection

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice