200-201 Question 96
Single answerAn organization is deploying several cybersecurity tools to monitor and protect its network. Which of the following technologies is most likely to provide data such as IP addresses, port numbers, and protocol information for traffic entering and leaving the network?
- A
Firewall logs
- B
Endpoint Detection and Response (EDR)
- C
Vulnerability scanner
- D
SIEM (Security Information and Event Management)
Show answer and explanation
Correct answer: A
Explanation
Firewall logs are a primary source of network traffic data, including IP addresses, port numbers, and protocol information. This makes them a key tool for monitoring and analyzing traffic entering and leaving the network. Other technologies like EDR, vulnerability scanners, and SIEMs have different focuses and do not directly provide this type of data.
- A. Correct.
Firewall logs typically contain data such as IP addresses, port numbers, and protocol information for traffic entering and leaving the network. This information is crucial for identifying and analyzing network traffic patterns.
- B. Incorrect.
EDR focuses on endpoint activity and provides data on processes, file changes, and system behavior rather than network traffic details such as IP addresses or ports.
- C. Incorrect.
Vulnerability scanners identify and report on system vulnerabilities but do not provide detailed network traffic data such as IP addresses or protocol information.
- D. Incorrect.
SIEM aggregates and correlates data from multiple sources, including firewall logs, but it does not natively generate network traffic data such as IP addresses or protocol information.