QuestionQ428

Tools/Systems/Programs

At a regional bank in Charlotte, North Carolina, investigators are analyzing a complete packet capture collected from a firewall span port during a suspected intrusion incident. The capture includes mixed inbound and outbound connections, and the team must apply community-maintained detection rules to the traffic to flag packets matching known exploit signatures or anomalous protocols before manual analysis.

Which tool should be chosen for this processing step?

  • A HttpLog Browser
  • B Snort IDS
  • C Sumo Logic IIS Log Analyzer
  • D HTTPS Logs Viewer
Explanation

Snort IDS performs packet-level network inspection using rules that define malicious or suspicious traffic patterns. It can process a packet-capture file and apply community rule sets to alert on packets that match exploit signatures or protocol-related detection criteria.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!