セキュリティ アナリストは、組織の環境外の IP アドレスから大量のスキャン アクティビティが発生していることを観察しています。このアクティビティをブロックするためにアナリストが行うべきことは次のうちどれですか?
正解:C
A firewall is a device or software that controls the incoming and outgoing network traffic based on predefined rules. Creating a firewall rule to block the IP address that is scanning the organization's environment is an effective way to stop this activity and prevent potential attacks. Creating an IPS rule to block the subnet, sinkholing the IP address, or closing all unnecessary open ports are other possible actions, but they are not as specific or efficient as creating a firewall rule to block the IP address. Reference: https://www.cisco.com/c/en/us/solutions/small-business/resource-center/security/firewall.html