312-49 · Question #156
Network forensics allows Investigators to inspect network traffic and logs to identify and locate the attack system. Network forensics can reveal: (Select three answers)
The correct answer is A. Source of security incidents' and network attacks B. Path of the attack C. Intrusion techniques used by attackers. Network forensics involves capturing and analyzing network traffic, packet logs, firewall logs, and IDS/IPS alerts. From this data, investigators can determine: (A) the source IP/system responsible for an attack, (B) the route or path the attack took through the network, and (C)
Question
Network forensics allows Investigators to inspect network traffic and logs to identify and locate the attack system. Network forensics can reveal: (Select three answers)
Options
- ASource of security incidents' and network attacks
- BPath of the attack
- CIntrusion techniques used by attackers
- DHardware configuration of the attacker's system
How the community answered
(48 responses)- A94% (45)
- D6% (3)
Explanation
Network forensics involves capturing and analyzing network traffic, packet logs, firewall logs, and IDS/IPS alerts. From this data, investigators can determine: (A) the source IP/system responsible for an attack, (B) the route or path the attack took through the network, and (C) the specific techniques used (e.g., port scans, exploit payloads, protocol abuse). Option D - hardware configuration of the attacker's system - cannot be reliably determined from network traffic alone, as network packets do not directly expose physical hardware details of the originating machine.
Topics
Community Discussion
No community discussion yet for this question.