Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 43 Topic 5 Discussion

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 43 Topic 5 Discussion

312-39 Exam Topic 5 Question 43 Discussion:
Question #: 43
Topic #: 5

A government agency needs to monitor its network for unusual data exfiltration attempts. Traditional log data is insufficient to identify traffic anomalies, so the SIEM team integrates traffic flow data to detect large transfers and unexpected spikes. The team must choose the appropriate protocol to collect IP traffic information from routers and switches. Which protocol should be used?


A.

SNMP (Simple Network Management Protocol)


B.

NetFlow (RFC 3954)


C.

Syslog


D.

IPFIX (IP Flow Information Export)


Get Premium 312-39 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.