Questions
Here are a few questions to test your understanding of the chapter:
- NetFlow/IPFIX are protocols that are used for:
- Continuous monitoring of packets/bytes/gits per second
- Packet analysis and deep packet inspection (DPI)
- IP (Layer 3) and TCP/UDP (Layer 4) statistics
- All of the above
- In the
Example 1.pcap
capture file, you will see STUN packets. What are they used for in this example?- Malware discovered in the end device (user laptop)
- A connection to Cisco Webex servers
- A connection to a streaming server that is used for video transmission
- A video conference application
- A network traffic baseline includes:
- Any information on users and what they send to or receive from networks
- IP addresses and TCP/UDP port numbers
- IP addresses and TCP/UDP port numbers and conversations
- Application types and TCP/IP information
- A scanning pattern will have the following identifiers (IDs):
- A single station that sends packets to the entire network
- Many stations that send packets to a single...