Network-Based Attack Source Identification | IPv4 Packet Data Viewing Techniques | Exam SY0-601

Viewing IPv4 Packet Data on Internal Network Segment

Prev Question Next Question

Question

A network technician is trying to determine the source of an ongoing network based attack.

Which of the following should the technician use to view IPv4 packet data on a particular internal network segment?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B.

The correct answer to this question is B. Protocol analyzer.

A protocol analyzer, also known as a packet sniffer or network analyzer, is a tool used to capture and analyze network traffic. It can be used to examine the contents of individual packets, including the source and destination IP addresses, protocols, and payloads.

When trying to determine the source of a network-based attack, a protocol analyzer can be used to capture traffic on a specific internal network segment. By examining the captured packets, the technician can identify the source of the attack and the type of traffic being generated.

Using a proxy, switch, or firewall would not be as effective in this situation. A proxy is used to route traffic between networks, and while it can log traffic, it may not provide the level of detail needed to identify the source of an attack. A switch is used to connect devices on a network, and while it can provide some information about network traffic, it may not capture the level of detail needed to analyze individual packets. A firewall is used to filter and block network traffic, but it may not provide the level of detail needed to analyze the contents of individual packets.

In summary, a protocol analyzer is the best tool to use when trying to determine the source of a network-based attack on a particular internal network segment.