GIAC Certified Enterprise Defender GCED Question # 19 Topic 2 Discussion

GIAC Certified Enterprise Defender GCED Question # 19 Topic 2 Discussion

GCED Exam Topic 2 Question 19 Discussion:
Question #: 19
Topic #: 2

An analyst will capture traffic from an air-gapped network that does not use DNS. The analyst is looking for unencrypted Syslog data being transmitted. Which of the following is most efficient for this purpose?


A.

tcpdump –s0 –i eth0 port 514


B.

tcpdump –nnvvX –i eth0 port 6514


C.

tcpdump –nX –i eth0 port 514


D.

tcpdump –vv –i eth0 port 6514


Get Premium GCED Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.