nerdexam
EC-Council

312-49V11 · Question #13

During a forensic investigation into a suspected cyberattack, the investigator checks network logs that were collected during the period of the incident. The investigator's objective is to examine…

The correct answer is B. The investigator performs a postmortem analysis of system records to evaluate previous security. This scenario aligns closely with CHFI v11 objectives under Procedures and Methodology, specifically postmortem analysis and log-based forensic investigation. Postmortem analysis refers to the examination of collected system, application, and network logs after an incident has…

Troubleshooting and Maintenance

Question

During a forensic investigation into a suspected cyberattack, the investigator checks network logs that were collected during the period of the incident. The investigator's objective is to examine these logs to determine the exact sequence of events that took place, identify the source of the attack, and understand the nature of the incident. This analysis helps in uncovering what occurred, how it happened, and who was responsible for it. Which of the following techniques is the investigator using in this case?

Options

  • AThe investigator performs eavesdropping on communications to intercept sensitive information.
  • BThe investigator performs a postmortem analysis of system records to evaluate previous security
  • CThe investigator conducts a real-time analysis of network traffic logs to detect the nature of the
  • DThe investigator carries out IP address spoofing to identify the source of the attack.

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    74% (26)
  • C
    14% (5)
  • D
    3% (1)

Explanation

This scenario aligns closely with CHFI v11 objectives under Procedures and Methodology, specifically postmortem analysis and log-based forensic investigation. Postmortem analysis refers to the examination of collected system, application, and network logs after an incident has occurred, with the goal of reconstructing events and determining the root cause of a security In this case, the investigator is reviewing historical network logs collected during the incident window, not monitoring live traffic. CHFI v11 emphasizes that postmortem analysis is essential for answering the core forensic questions: what happened, how it happened, when it happened, and who was responsible. By correlating timestamps, IP addresses, protocols, and event sequences across logs, investigators can identify attack vectors, trace the origin of the attack, and understand attacker behavior.

Topics

#postmortem analysis#network logs#incident investigation#log analysis

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice