Q36Network Intrusion Analysis
An organization’s security team has detected network spikes originating from its internal network. An investigation concluded that the traffic spike resulted from intensive network scanning. How should the analyst collect the traffic to isolate the suspicious host?
← → navigate · a answer
Community votes
Discussion · 3
B 1
Selected Answer: B
By the most active source IP
1
My daughter got that right just by knowing what an IP address is
B 1
Selected Answer: B
From an admin perspective, you'll want to know the source of the detected anomaly.
Normally, you'll search for the IP address or host.