QuestionQ4
Intrusion Detection and Packet AnalysisAn analyst will capture traffic from an air-gapped network that does not use DNS. The analyst needs to identify unencrypted Syslog data in transit. Which of the following is the most efficient for this purpose?
- A tcpdump –s0 –i eth0 port 514
- B tcpdump –nnvvX –i eth0 port 6514
- C tcpdump –nX –i eth0 port 514
- D tcpdump –vv –i eth0 port 6514
Community Discussion