A city’s SOC cannot tell whether large outbound transfers from a records office are backups or exfiltration because no flow telemetry is collected on core egress. Which design addition best improves detection and fault awareness?
Select an answer to reveal the explanation.
Short Explanation
Without flow logs, the SOC is flying with a covered windshield. You don’t need every packet forever—just enough metadata to spot 'why is records office shipping terabytes to a strange place at 2 a.m.?'
Full Explanation
Network observability through flow telemetry supports both capacity planning and security anomaly detection such as data exfiltration. Capturing and analyzing egress and chokepoint flows provides destination, volume, and timing context that packet-blind operations lack. Capacity upgrades alone do not create detection capability, and discarding egress visibility removes a primary signal for abuse and faults.