Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

Network security monitoring logs report repeated periodic UDP bursts originating from an internal application server to an unfamiliar external IP address over port 123. System configuration audits confirm that standard Network Time Protocol (NTP) services are disabled on this host. Which of the following initial actions should the security team take to analyze and contain this anomalous network activity? (Select TWO.)

  1. Capture and analyze raw network packet payloads at the gateway interface to evaluate the internal structure of the non-standard UDP traffic.Cevap
  2. B
    Reconfigure perimeter firewalls to automatically route all outbound port 123 traffic into a deception honeypot to actively filter malicious traffic.
  3. Implement network isolation controls on the affected internal application server to restrict external outbound communication.Cevap
  4. D
    Deploy a web application firewall inspection rule to analyze and drop incoming HTTP POST requests directed at port 123.

Cevap

The correct actions are capturing network packet payloads at the gateway interface for deep inspection and implementing network isolation controls on the affected internal application server.
Analyzing raw packet payloads helps security teams identify covert tunneling or unauthorized communications disguised as standard protocols, while host isolation prevents potential data exfiltration without destroying evidence.

Adım Adım Çözüm

1
Analyze network traffic contents
Identify whether the UDP port 123 traffic represents legitimate protocol behavior or covert data encapsulation.
Packet capture and payload inspection are necessary to detect protocol tunneling when network flow monitoring flags disabled services transmitting data.
2
Contain the suspicious endpoint
Block further outbound network communication from the affected host.
Isolation stops potential exfiltration channels and command-and-control connectivity while allowing security analysts to conduct host forensics.

Anahtar Kavram

Network Security Monitoring and Anomaly Response
Tahmini Süre:1m 30s
Bu soruyu puanla