Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst needs to capture network traffic on a segment for forensic analysis without introducing any latency or becoming a single point of failure. The current network switch only supports port mirroring (SPAN). What is the most appropriate and robust hardware solution to achieve this goal?

  1. AEnable NetFlow on the switch
  2. BInstall a network tap
  3. CDeploy an inline Intrusion Prevention System (IPS)
  4. DConfigure a router's interface for promiscuous mode
Show answer & explanation

Correct answer: B. Install a network tap

A network tap is a passive device that splits network traffic, sending a copy to a monitoring port without altering the production traffic flow or introducing latency, making it ideal for forensic capture without disruption.

Why the other options are wrong

  • A. NetFlow provides flow statistics (who, what, where, when, how much) but does not capture full packet contents for deep forensic analysis.
  • C. An inline IPS introduces latency and is a single point of failure, contrary to the requirements.
  • D. Configuring a router interface for promiscuous mode is not a standard or robust way to capture all traffic on a segment and may not be supported or efficient.

Network Tap

A network tap (Test Access Point) is a passive hardware device that creates a copy of network traffic for monitoring, analysis, or security purposes without affecting the live network's performance or introducing a single point of failure.

  • Passive device, does not alter traffic
  • Provides a full copy of traffic
  • No latency introduced
  • Not a single point of failure (fails open)

Memory trick: To 'Fish' for packets, you can either mirror (SPAN) or physically tap the stream.

More Network Intrusion Analysis questions