Question

A security analyst is interested in setting up an IDS to monitor the company network. The...

A security analyst is interested in setting up an IDS to monitor the company network. The analyst has been told there can be no network downtime to implement the solution, but the IDS must capture all of the network traffic. Which of the following should be used for the IDS implementation?

A. Network tap

B. Honeypot

C. Aggregation

D. Port mirror

0 0
Add a comment Improve this question Transcribed image text
✔ Recommended Answer
Answer #1

Add a comment
Answer #2

Solution: A. Network tap

Explanation: Once a network tap is in place, the network can be monitored without interfering with the network itself. Other network monitoring solutions require in-band changes to network devices, which means that monitoring can impact the devices being monitored.

Network Taps are analogous to phone taps. They are completely passive methods of getting network traffic to a central location. Port mirroring would get all the traffic to the IDS but is not completely passive. It requires the use of resources on switches to route a copy of the traffic. Incorrect switch configuration can cause looping. Configuring loop detection can prevent looped ports.

Add a comment
Know the answer?
Add Answer to:
A security analyst is interested in setting up an IDS to monitor the company network. The...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT