ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 9 - N10-009 discussion

Report
Export

A network engineer wants to implement a new IDS between the switch and a router connected to the LAN. The engineer does not want to introduce any latency by placing the IDS in line with the gateway. The engineer does want to ensure that the IDS sees all packets without any loss. Which of the following is the best way for the engineer to implement the IDS?

A.
Use a network tap.
Answers
A.
Use a network tap.
B.
Use Nmap software.
Answers
B.
Use Nmap software.
C.
Use a protocol analyzer.
Answers
C.
Use a protocol analyzer.
D.
Use a port mirror.
Answers
D.
Use a port mirror.
Suggested answer: D

Explanation:

To ensure that an IDS sees all packets without any loss and without introducing latency, the best approach is to use a port mirror, also known as a SPAN (Switched Port Analyzer) port. Port mirroring copies network packets seen on one switch port (or an entire VLAN) to another port where the IDS is connected. This method allows the IDS to monitor traffic passively without being in the direct path of network traffic, thus avoiding any additional latency.

Reference: CompTIA Network+ Certification Exam Objectives - Network Security section.

asked 02/10/2024
Muzammil Mirza
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first