ExamGecko
Question list
Search
Search

Related questions











Question 209 - 200-201 discussion

Report
Export

Refer to the exhibit.

During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events Which technology provided these logs?

A.

antivirus

Answers
A.

antivirus

B.

proxy

Answers
B.

proxy

C.

IDS/IPS

Answers
C.

IDS/IPS

D.

firewall

Answers
D.

firewall

Suggested answer: D

Explanation:

The logs indicating multiple local TCP connection events are typically provided by a firewall. Firewalls are responsible for monitoring and controlling incoming and outgoing network traffic based on predetermined security rules, and they generate logs that detail such events, which can be used for further analysis and incident response.Reference:= Cisco Cybersecurity Operations Fundamentals

asked 07/10/2024
Nogueira Elder
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first