Eccouncil 312-39 Exam - Topic 7 Question 4 Discussion
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.Which of the following data source will he use to prepare the dashboard?
D) Apache/ Web Server logs with IP addresses and Host Name.
A) DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
B) IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
C) DNS/ Web Server logs with IP addresses.
Josephine
10 months agoEdwin
10 months agoGlenn
10 months agoOliva
11 months agoMicaela
11 months agoLinn
11 months agoJenise
11 months agoElinore
11 months agoCordelia
11 months agoAriel
11 months agoSheron
11 months agoNoel
11 months agoSabrina
11 months agoFletcher
11 months ago