Network Monitor can inspect only traffic that reaches its capture interfaces and that its protocol and content-analysis components can meaningfully process. When the traffic volume exceeds the supported inspection rate, the first optimization is to eliminate unnecessary traffic before adding infrastructure. Filtering encrypted, unsupported, irrelevant, or otherwise unreadable traffic prevents Network Monitor from consuming capture and processing capacity on sessions that cannot produce useful DLP inspection results. Options A and B incorrectly refer to Network Prevent servers rather than the overloaded Network Monitor detector. Installing additional network taps changes how traffic is copied to Network Monitor but does not inherently reduce the excessive volume being processed. Therefore, filtering unreadable traffic is the appropriate first performance-remediation step, making option C correct.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit