Eccouncil 312-39 Exam - Topic 7 Question 4 Discussion
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.Which of the following data source will he use to prepare the dashboard?
D) Apache/ Web Server logs with IP addresses and Host Name.
A) DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
B) IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
C) DNS/ Web Server logs with IP addresses.
Josephine
8 months agoEdwin
9 months agoGlenn
9 months agoOliva
9 months agoMicaela
9 months agoLinn
9 months agoJenise
9 months agoElinore
9 months agoCordelia
9 months agoAriel
9 months agoSheron
10 months agoNoel
10 months agoSabrina
10 months agoFletcher
10 months ago