Valid 350-201 Dumps shared by ExamDiscuss.com for Helping Passing 350-201 Exam! ExamDiscuss.com now offer the newest 350-201 exam dumps, the ExamDiscuss.com 350-201 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com 350-201 dumps with Test Engine here:
An engineer notices that every Sunday night, there is a two-hour period with a large load of network activity. Upon further investigation, the engineer finds that the activity is from locations around the globe outside the organization's service area. What are the next steps the engineer must take?
Correct Answer: C
When there is a significant load of network activity from locations outside the organization's service area, especially at unusual times, it is important to investigate the nature of this traffic. The engineer should review the logs from network monitoring tools like StealthWatch or SIEM to identify the access points through which the traffic is coming. Understanding the services being accessed during these hours and cross-correlating with other source events can help in determining whether the activity is legitimate or if it indicates a potential security threat1