A network administrator needs to monitor enterprise traffic volumes, protocol distributions, and IP communication pairs across internal routers without inspecting or storing packet payloads. Which of the following monitoring mechanisms should the administrator implement?
- NetFlow flow telemetry collectionCevap
- BInline honeypot deployment
- CWeb application firewall inspecting SQL payloads
- DHost-based antivirus signature scanner
Cevap
NetFlow flow telemetry collection is the correct mechanism because it captures network session metadata (source/destination IPs, ports, and transfer sizes) across network devices without storing full packet payloads.
NetFlow flow telemetry collection gathers lightweight session metadata—including source and destination IP addresses, ports, protocol types, and byte counts—from network devices. It allows security analysts to observe network traffic statistics across the enterprise without the overhead of full packet payload capture.
Adım Adım Çözüm
Anahtar Kavram
Network Flow Monitoring (NetFlow/IPFIX)
Tahmini Süre:45s