ECCouncil Certified SOC Analyst (CSA) 312-39 Question # 25 Topic 3 Discussion

ECCouncil Certified SOC Analyst (CSA) 312-39 Question # 25 Topic 3 Discussion

312-39 Exam Topic 3 Question 25 Discussion:
Question #: 25
Topic #: 3

John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.

Which of the following data source will he use to prepare the dashboard?


A.

DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.


B.

IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.


C.

DNS/ Web Server logs with IP addresses.


D.

Apache/ Web Server logs with IP addresses and Host Name.


Get Premium 312-39 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.