What are security event logs commonly based on when sourced by traditional firewalls?

IT Exam Items RepositoryCategory: CCNA CyberOpsWhat are security event logs commonly based on when sourced by traditional firewalls?

What are security event logs commonly based on when sourced by traditional firewalls?

  • static filtering
  • application analysis
  • signatures
  • 5-tuples

Explanation: Traditional firewalls commonly provide security event logs based on the 5-tuples of source IP address and port number, destination IP address and port number, and the protocol in use.

Related exam: CCNA SECOPS 210-255 Dumps – Certification Practice Exam Answers
Related exam: Checkpoint Exam: Analyzing Security Data Group Exam