312-49 · Question #547
Which of the following tool can the investigator use to analyze the network to detect Trojan activities?
The correct answer is D. Capsa. Capsa (by Colasoft) is a real-time network analyzer and packet sniffer that can monitor network traffic, identify suspicious connections, detect unusual port usage, and flag unauthorized data exfiltration - all common indicators of Trojan activity. Regshot is a registry…
Question
Which of the following tool can the investigator use to analyze the network to detect Trojan activities?
Options
- ARegshot
- BTRIPWIRE
- CRAM Computer
- DCapsa
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- D94% (33)
Explanation
Capsa (by Colasoft) is a real-time network analyzer and packet sniffer that can monitor network traffic, identify suspicious connections, detect unusual port usage, and flag unauthorized data exfiltration - all common indicators of Trojan activity. Regshot is a registry monitoring tool, TRIPWIRE is a file integrity monitoring tool, and 'RAM Computer' is not a recognized forensic tool for network analysis.
Topics
Community Discussion
No community discussion yet for this question.