nerdexam
EC-Council

312-49 · Question #24

Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.

The correct answer is A. True. This is True. Network forensics is a sub-branch of digital forensics focused on monitoring and analysis of network traffic for information gathering, legal evidence, or intrusion detection. It involves capturing, recording, and analyzing network packets and event logs to…

Submitted by renata2k· Apr 18, 2026Network Forensics

Question

Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.

Options

  • ATrue
  • BFalse

How the community answered

(46 responses)
  • A
    89% (41)
  • B
    11% (5)

Explanation

This is True. Network forensics is a sub-branch of digital forensics focused on monitoring and analysis of network traffic for information gathering, legal evidence, or intrusion detection. It involves capturing, recording, and analyzing network packets and event logs to reconstruct what happened during a security incident, identify attackers, trace attack paths, and support legal proceedings. Tools like Wireshark and NetWitness are commonly used in network forensic investigations.

Topics

#Network Forensics Definition#Network Traffic Analysis#Log Analysis#Incident Investigation

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice