QuestionQ428
Tools/Systems/ProgramsAt a regional bank in Charlotte, North Carolina, investigators are analyzing a complete packet capture collected from a firewall span port during a suspected intrusion incident. The capture includes mixed inbound and outbound connections, and the team must apply community-maintained detection rules to the traffic to flag packets matching known exploit signatures or anomalous protocols before manual analysis.
Which tool should be chosen for this processing step?
- A HttpLog Browser
- B Snort IDS
- C Sumo Logic IIS Log Analyzer
- D HTTPS Logs Viewer
Community Discussion