Soru

Zorluk: KolayNetwork Security Monitoring and Alerting

A security analyst is establishing passive network security monitoring across a corporate local area network to monitor traffic without interrupting active host operations or injecting network probes. Which TWO of the following techniques represent passive network monitoring methods?

  1. Capturing and analyzing frame traffic replicated from a network switch SPAN portCevap
  2. Collecting NetFlow and IPFIX telemetry records exported by network routersCevap
  3. C
    Executing scheduled synthetic Nmap port sweeps to query active host responses across all internal subnets
  4. D
    Deploying a interactive network honeypot to dynamically intercept and block unauthorized inbound packet flows

Cevap

Capturing frame traffic via a switch SPAN port and collecting NetFlow telemetry from routers are passive monitoring methods.
Passive network monitoring relies on reading existing network traffic without generating additional packets or modifying traffic flows. Replicating switch traffic using a SPAN port and aggregating NetFlow telemetry exported by network routers both inspect network activity passively.

Adım Adım Çözüm

1
Identify the operational requirement for passive network security monitoring.
Passive monitoring mechanisms observe existing traffic streams without generating synthetic traffic probes or inline network latency.
Ensures monitoring tools collect network telemetry without risk of disrupting host services.
2
Evaluate candidate monitoring methods for passive operation.
SPAN port mirroring duplicates layer 2/3 traffic to a sensor silently, while NetFlow exports flow statistics compiled natively by routers.
Both methods operate in read-only telemetry modes.

Anahtar Kavram

Passive vs. Active Network Security Monitoring
Bu soruyu puanla