ExamGecko
Question list
Search
Search

Related questions











Question 780 - 350-401 discussion

Report
Export

A network administrator for a small office is adding a passive IDS to its network switch for the purpose of inspecting network traffic. Which of the following should the administrator use?

A.

SNMPtrap

Answers
A.

SNMPtrap

B.

Port mirroring

Answers
B.

Port mirroring

C.

Syslog collection

Answers
C.

Syslog collection

D.

API integration

Answers
D.

API integration

Suggested answer: B

Explanation:

This is because port mirroring is a feature that allows a switch to copy the traffic from one or more ports to another port, where a passive IDS can be connected. A passive IDS is a device that monitors the network traffic and detects any malicious or suspicious activity, but does not take any action to block or prevent it. Port mirroring can enable a passive IDS to inspect the network traffic without affecting the performance or availability of the network. The source of this answer is the Cisco ENCOR v1.1 course, module 6, lesson 6.2: Implementing SPAN, RSPAN, and ERSPAN.

asked 10/10/2024
Jose Osnayo
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first