Unit 2: Log and Network Traffic Analysis - Subjective Questions

INT244 — Securing Computing Systems • Practice Questions with Detailed Answers

20 questions

1

Explain the role and importance of log and event analysis in securing computing systems.

2

Describe four advanced log analysis techniques used to identify security threats.

3

How can anomalies be detected in system and security logs? Explain the process with suitable examples.

4

Explain how log analysis can be integrated across an enterprise environment. Include the major components of an effective integration architecture.

5

Discuss the methods used to enhance the security, integrity, and confidentiality of log data.

6

Describe how an analyst reconstructs an attack chain using logs and events from multiple sources.

7

Explain how APIs can be used to support advanced threat detection and automated log analysis.

8

What challenges arise in cross-platform log analysis, and how can they be addressed?

9

Explain how log analysis can be used to detect cloud cryptojacking.

10

How should an organization evaluate the effectiveness of its log analysis program?

11

Explain traffic segmentation and normalization in network traffic analysis. Why are both important?

12

Describe how threat intelligence can be integrated into network traffic analysis.

13

What is contextual protocol analysis? Explain how it differs from simple port-based traffic identification.

14

Compare Network Intrusion Detection Systems (NIDS) and Network Intrusion Prevention Systems (NIPS). Discuss their advantages and limitations.

15

Explain how network traffic analysis can be used for vulnerability validation.

16

What are jarring signals in network traffic, and how can analysts investigate them?

17

Describe protocol behavior modelling and explain how it helps detect abnormal network activity.

18

Design an integrated workflow that combines log analysis and network traffic analysis for detecting and responding to a multi-stage attack.

19

Distinguish between signature-based detection and anomaly-based detection in log and network analysis.

20

Explain the importance of time synchronization, event correlation, and data quality in security analysis.