QuestionQ245

Tools/Systems/Programs

An investigator is assigned to analyze extensive network logs after a suspected data breach in a large enterprise. The work requires a tool that not only gathers and manages logs from multiple network devices, but also supports real-time alert management, metadata analysis, and a clear view of anomalous traffic patterns. The investigator must identify the most effective solution for organizing logs and correlating network events to understand the full scope of the attack. Which of the following tools is most appropriate for this task?

  • A OSFClone
  • B Tableau
  • C Security Onion
  • D Intella Pro
Explanation

Security Onion integrates log management, intrusion-detection alerts, network metadata, packet capture, dashboards, and threat-hunting capabilities. Its Security Onion Console supports alert investigation and drilldowns, while Zeek and Suricata supply protocol metadata and network-security events for correlation across the environment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!