A security analyst is establishing passive network security monitoring across a corporate local area network to monitor traffic without interrupting active host operations or injecting network probes. Which TWO of the following techniques represent passive network monitoring methods?
- Capturing and analyzing frame traffic replicated from a network switch SPAN portCevap
- Collecting NetFlow and IPFIX telemetry records exported by network routersCevap
- CExecuting scheduled synthetic Nmap port sweeps to query active host responses across all internal subnets
- DDeploying a interactive network honeypot to dynamically intercept and block unauthorized inbound packet flows
Cevap
Capturing frame traffic via a switch SPAN port and collecting NetFlow telemetry from routers are passive monitoring methods.
Passive network monitoring relies on reading existing network traffic without generating additional packets or modifying traffic flows. Replicating switch traffic using a SPAN port and aggregating NetFlow telemetry exported by network routers both inspect network activity passively.
Adım Adım Çözüm
Anahtar Kavram
Passive vs. Active Network Security Monitoring