Q32Network Intrusion Analysis
While reviewing packet-capture data, an analyst observes that a single IP address sends and receives traffic for multiple devices by altering the IP header. Which technology enables this behavior?
← → navigate · a answer
Community votes
Discussion · 6
7
the answer is right, Network address translation (NAT) is a method of mapping an IP address space into another by changing network address information in the IP header of packets while they are in transit across a traffic routing device.
D 3
Selected Answer: D
D. is the correct answer
NAT (Network Address Translation ) ==> is a method of mapping an IP address space into another by changing network address information in the IP header of packets while they are in transit across a traffic routing device.
2
Sorry, after re-reading the question more carefully, I agree that the correct answer is D
2
Changing IP headers is exactly what NAT does... How else are you meant to route the data? NAT replaces the RFC1989 addresses with the public IP then adds it to a state table, allowing a return translation.
Tunneling encapsulates IP headers by adding a new outer IP header for public routing. It's not the same at all.
C 1
Selected Answer: C
The correct answer is C. tunneling.
The behavior described, where one IP is sending and receiving traffic for multiple devices by modifying the IP header, is made possible by tunneling technology.
Tunneling means encapsulating one network protocol within another, which allows the encapsulated protocol to pass over a network that would not natively support it. In the context of the given scenario, tunneling is used to encapsulate traffic from multiple devices within the IP header of a single IP address.
Option D, "NAT" (Network Address Translation), means translating IP addresses between different networks. While NAT can be used to let multiple devices share a single public IP address, it does not usually involve modifying IP headers to route traffic for multiple devices through a single IP address.
1
The answer is C. tunneling.
Tunneling is a technology that lets one network be encapsulated within another network. That means all of the traffic from the first network is sent over the second network, as though it were part of the second network.
In this question, the analyst is seeing one IP address sending and receiving traffic for multiple devices. This can happen because the traffic is being tunneled through the one IP address.