Comparing inline traffic interrogation techniques
As you will have realized, the Cisco Certified CyberOps Associate (200-201) certification is entirely based on detecting, analyzing, and preventing threats within an enterprise network. Additionally, throughout the course of this book, you have gained knowledge and skills on various types of security solutions and how to perform various tasks as a cybersecurity professional. However, regardless of whether you are working in a SOC or are part of the Information Technology (IT) team within an organization, you definitely need to monitor network traffic in real time to detect any potential threats that may be moving across the network.
While there are security appliances such as an NGFW and next-generation IPS on your network, sometimes these devices may miss a new emerging threat that hasn't been seen before in the wild (the internet). Implementing inline traffic interrogation techniques will allow you, as a cybersecurity professional...