nerdexam
EC-Council

212-89 · Question #170

Which of the following is NOT a network forensic tool?

The correct answer is C. Advancec NTFS Journaling Parser. Network forensic tools are designed to capture, record, and analyze network traffic. Tools like Capsa Network Analyzer, Tcpdump, and Wireshark are specifically designed for this purpose, providing capabilities to capture live traffic, analyze packets, and understand network…

Computer Forensics in Incident Handling

Question

Which of the following is NOT a network forensic tool?

Options

  • ACapsa Network Analyzer
  • BTcpdurnp
  • CAdvancec NTFS Journaling Parser
  • DWireshark

How the community answered

(38 responses)
  • B
    3% (1)
  • C
    95% (36)
  • D
    3% (1)

Explanation

Network forensic tools are designed to capture, record, and analyze network traffic. Tools like Capsa Network Analyzer, Tcpdump, and Wireshark are specifically designed for this purpose, providing capabilities to capture live traffic, analyze packets, and understand network activities. Capsa Network Analyzer is a comprehensive network monitoring tool, Tcpdump is a powerful command-line packet analyzer, and Wireshark is a widely used network protocol analyzer that provides detailed information about network traffic. Advanced NTFS Journaling Parser, on the other hand, is not a network forensic tool but a tool used for forensic analysis of NTFS file systems. It parses the NTFS journal ($LogFile), which contains a log of changes made to files on an NTFS volume. This tool is valuable for forensic analysts who are investigating the file system activities on a Windows system, such as file creation, modification, and deletion times, rather than analyzing network traffic. Therefore, it does not fit the category of a network forensic tool.

Topics

#network forensics tools#packet capture#Wireshark#NTFS forensics

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice