A network defender uses a threat intelligence platform to enrich ACL log data. Which enrichment action provides the most context for a suspicious source IP?
-
A
Reverse DNS lookup only
-
B
WHOIS, ASN, geolocation, and reputation scoring
-
C
Ping latency measurement
-
D
ARP table lookup on the local switch