QuestionQ53

Network operations, monitoring, and performance

An organization wants to assess network behavior using a network-monitoring tool that is not inline. The organization will use the logs for additional correlation and analysis of potential threats. Which of the following is the best solution?

Explanation

NetFlow provides non-inline network flow telemetry that can be exported to a SIEM, where it can be correlated with other logs and security events to investigate potential threats.

Community Discussion

No comments yet. Be the first to start the discussion!