312-49V11 · Question #38
Arnold, a forensic investigator, was tasked with analyzing a corporate network that was suspected of having unauthorized access points. He was particularly concerned about the possibility of rogue…
The correct answer is D. Security Onion. According to the CHFI v11 Network Forensics, Incident Detection, and SIEM objectives, Security Onion is a widely used open-source platform designed specifically for network security monitoring, intrusion detection, and forensic analysis. It integrates multiple tools such as…
Question
Arnold, a forensic investigator, was tasked with analyzing a corporate network that was suspected of having unauthorized access points. He was particularly concerned about the possibility of rogue access points that might have been introduced by an attacker. To gain full visibility into the network and its components, Arnold employed a forensic tool that allowed him to analyze network traffic, monitor various access points for anomalies, and detect suspicious behaviors indicative of rogue devices. Arnold examined the log data provided by the tool, which gave him insights into the network's activities and helped him confirm whether any unauthorized devices were operating on the network. Which tool did Arnold employ in the above scenario?
Options
- ATime Machine
- BPromqry
- CFreta
- DSecurity Onion
How the community answered
(31 responses)- A16% (5)
- B3% (1)
- C6% (2)
- D74% (23)
Explanation
According to the CHFI v11 Network Forensics, Incident Detection, and SIEM objectives, Security Onion is a widely used open-source platform designed specifically for network security monitoring, intrusion detection, and forensic analysis. It integrates multiple tools such as Snort/Suricata (IDS/IPS), Zeek (Bro) for network traffic analysis, Elastic Stack, and SIEM capabilities, providing deep visibility into network activities. In the given scenario, Arnold required a solution capable of analyzing live and stored network traffic, monitoring access points, detecting anomalies, and identifying rogue or unauthorized devices. Security Onion fulfills all these requirements by collecting and correlating logs, monitoring network behavior, and generating alerts for suspicious patterns such as unknown MAC addresses, abnormal traffic flows, and unauthorized access point activity.
Topics
Community Discussion
No community discussion yet for this question.