Quiz 1 Question 12 of 20

A SOC analyst investigates a series of SQL injection attempts targeting a public-facing web application. The WAF logs show the attacks originated from a single external IP and were successfully blocked. However, when the analyst queries the SIEM for the specific internal host that received the blocked payload, the logs only show traffic hitting the load balancer's VIP. No individual backend server logs contain the attack string. What architectural characteristic most likely explains this lack of host-level attribution?

Select an answer to reveal the explanation.

Motivation