nerdexam
EC-Council

312-49V11 · Question #38

Arnold, a forensic investigator, was tasked with analyzing a corporate network that was suspected of having unauthorized access points. He was particularly concerned about the possibility of rogue…

The correct answer is D. Security Onion. According to the CHFI v11 Network Forensics, Incident Detection, and SIEM objectives, Security Onion is a widely used open-source platform designed specifically for network security monitoring, intrusion detection, and forensic analysis. It integrates multiple tools such as…

Network Forensics

Question

Arnold, a forensic investigator, was tasked with analyzing a corporate network that was suspected of having unauthorized access points. He was particularly concerned about the possibility of rogue access points that might have been introduced by an attacker. To gain full visibility into the network and its components, Arnold employed a forensic tool that allowed him to analyze network traffic, monitor various access points for anomalies, and detect suspicious behaviors indicative of rogue devices. Arnold examined the log data provided by the tool, which gave him insights into the network's activities and helped him confirm whether any unauthorized devices were operating on the network. Which tool did Arnold employ in the above scenario?

Options

  • ATime Machine
  • BPromqry
  • CFreta
  • DSecurity Onion

How the community answered

(31 responses)
  • A
    16% (5)
  • B
    3% (1)
  • C
    6% (2)
  • D
    74% (23)

Explanation

According to the CHFI v11 Network Forensics, Incident Detection, and SIEM objectives, Security Onion is a widely used open-source platform designed specifically for network security monitoring, intrusion detection, and forensic analysis. It integrates multiple tools such as Snort/Suricata (IDS/IPS), Zeek (Bro) for network traffic analysis, Elastic Stack, and SIEM capabilities, providing deep visibility into network activities. In the given scenario, Arnold required a solution capable of analyzing live and stored network traffic, monitoring access points, detecting anomalies, and identifying rogue or unauthorized devices. Security Onion fulfills all these requirements by collecting and correlating logs, monitoring network behavior, and generating alerts for suspicious patterns such as unknown MAC addresses, abnormal traffic flows, and unauthorized access point activity.

Topics

#Security Onion#rogue access points#wireless network forensics#network traffic analysis

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice