nerdexam
EC-Council

312-49V11 · Question #95

A company's network experiences a sudden slowdown, prompting suspicion of a cyberattack. Network administrators utilize log analysis tools to scrutinize traffic patterns and pinpoint anomalies…

The correct answer is B. Identifying the source of the cyberattack. According to the CHFI v11 curriculum under Network Forensics and Analyzing Network Attacks, the primary purpose of using network log analysis tools during a suspected Distributed Denial-of- Service (DDoS) attack is to identify the source and nature of the attack traffic. DDoS…

Network Forensics

Question

A company's network experiences a sudden slowdown, prompting suspicion of a cyberattack. Network administrators utilize log analysis tools to scrutinize traffic patterns and pinpoint anomalies, aiding in the detection of a distributed denial-of-service (DDoS) attack. In the described scenario, what is the primary purpose of using network log analysis tools?

Options

  • AEnhancing network security protocols
  • BIdentifying the source of the cyberattack
  • COptimizing network performance
  • DMonitoring employee internet usage

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    74% (31)
  • C
    14% (6)
  • D
    5% (2)

Explanation

According to the CHFI v11 curriculum under Network Forensics and Analyzing Network Attacks, the primary purpose of using network log analysis tools during a suspected Distributed Denial-of- Service (DDoS) attack is to identify the source and nature of the attack traffic. DDoS attacks overwhelm network resources by flooding them with a massive volume of malicious traffic originating from multiple compromised systems. By analyzing firewall logs, IDS/IPS logs, router logs, and server access logs, investigators can detect abnormal traffic patterns such as unusually high connection rates, repeated requests from multiple IP addresses, malformed packets, or protocol misuse. These indicators help forensic investigators trace the origin of attack traffic, identify botnet behavior, determine attack vectors (e.g., SYN flood, UDP flood, HTTP flood), and assess the scope and impact of the attack.

Topics

#network log analysis#DDoS detection#traffic pattern analysis#anomaly detection

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice