CyberSecurity Lab v1.0

Module: Firewall Traffic Analysis & Incident Response

Lab Task

You are acting as a Security Analyst. Review the live firewall logs on the right. A specific internal host has been flagged for violating egress policies.

Objective: Identify the source IP address that triggered a "DENY" action from the firewall ruleset.

fw-core-primary: /var/log/syslog
Timestamp Source IP Destination Port Action