QuestionQ36

Network Intrusion Analysis

An organization’s security team has detected network spikes originating from its internal network. An investigation concluded that the traffic spike resulted from intensive network scanning. How should the analyst collect the traffic to isolate the suspicious host?

Explanation

Intensive network scanning produces a large amount of outbound traffic from the scanning host, often directed at numerous internal destinations and ports. Grouping the collection by the most active source IP reveals the host generating the abnormal volume and isolates the likely source of the scan.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!