nerdexam
EC-Council

312-49 · Question #547

Which of the following tool can the investigator use to analyze the network to detect Trojan activities?

The correct answer is D. Capsa. Capsa (by Colasoft) is a real-time network analyzer and packet sniffer that can monitor network traffic, identify suspicious connections, detect unusual port usage, and flag unauthorized data exfiltration - all common indicators of Trojan activity. Regshot is a registry…

Submitted by khalil_dz· Apr 18, 2026Network Forensics

Question

Which of the following tool can the investigator use to analyze the network to detect Trojan activities?

Options

  • ARegshot
  • BTRIPWIRE
  • CRAM Computer
  • DCapsa

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • D
    94% (33)

Explanation

Capsa (by Colasoft) is a real-time network analyzer and packet sniffer that can monitor network traffic, identify suspicious connections, detect unusual port usage, and flag unauthorized data exfiltration - all common indicators of Trojan activity. Regshot is a registry monitoring tool, TRIPWIRE is a file integrity monitoring tool, and 'RAM Computer' is not a recognized forensic tool for network analysis.

Topics

#Network Analysis Tools#Trojan Detection#Packet Sniffing#Network Monitoring

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice