Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is investigating a suspected insider threat. They need to capture all network traffic from a specific workstation to an external cloud storage service, but the workstation is connected to a Gigabit Ethernet switch that does not support port mirroring. Which network device would be most effective for passively capturing this traffic without disrupting the workstation's network connectivity?

  1. AA network tap
  2. BA firewall in transparent mode
  3. CA hub
  4. DA Layer 3 switch with routing capabilities
Show answer & explanation

Correct answer: A. A network tap

A network tap is a hardware device that allows passive, non-intrusive monitoring of network traffic by creating a copy of the data flow without affecting the original traffic. It is ideal when port mirroring is unavailable or undesirable.

Why the other options are wrong

  • B. A firewall in transparent mode would be in-line, actively filtering traffic, not passively capturing it without disruption.
  • C. A hub would indeed show all traffic, but they are obsolete in modern Gigabit Ethernet networks and would significantly degrade performance by creating a single collision domain.
  • D. A Layer 3 switch with routing would forward traffic but not necessarily copy it passively for monitoring without specific configuration (like mirroring, which is unavailable).

Network Tap

A hardware device that intercepts and copies network traffic passing between two points, providing a duplicate stream for monitoring and analysis without introducing delay or affecting the original traffic flow.

  • Passive monitoring device
  • No impact on network performance
  • Essential for full-duplex traffic capture

Memory trick: Passive Monitoring: Tap for Hardware, SPAN for Software.

More Network Intrusion Analysis questions