Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst needs to capture network traffic on a segment for forensic analysis without introducing any latency or becoming a single point of failure. The current network switch only supports port mirroring (SPAN). What is the most appropriate and robust hardware solution to achieve this goal?
- AEnable NetFlow on the switch
- BInstall a network tap
- CDeploy an inline Intrusion Prevention System (IPS)
- DConfigure a router's interface for promiscuous mode
Show answer & explanationAnswer & explanation
Correct answer: B. Install a network tap
A network tap is a passive device that splits network traffic, sending a copy to a monitoring port without altering the production traffic flow or introducing latency, making it ideal for forensic capture without disruption.
Why the other options are wrong
- A. NetFlow provides flow statistics (who, what, where, when, how much) but does not capture full packet contents for deep forensic analysis.
- C. An inline IPS introduces latency and is a single point of failure, contrary to the requirements.
- D. Configuring a router interface for promiscuous mode is not a standard or robust way to capture all traffic on a segment and may not be supported or efficient.
Network Tap
A network tap (Test Access Point) is a passive hardware device that creates a copy of network traffic for monitoring, analysis, or security purposes without affecting the live network's performance or introducing a single point of failure.
- Passive device, does not alter traffic
- Provides a full copy of traffic
- No latency introduced
- Not a single point of failure (fails open)
Memory trick: To 'Fish' for packets, you can either mirror (SPAN) or physically tap the stream.