nerdexam
GIAC

GCFA · Question #269

You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate the DoS attack on a computer network of SecureEnet Inc. Which of the following meth

The correct answer is A. Look for unusual traffic on Internet connections and network segments. C. Look for core files or crash dumps on the affected systems. D. Sniff network traffic to the failing machine.. DoS forensic investigation relies on traffic analysis, system artifact review, and packet capture - physical seizure of all equipment is unnecessary and disruptive.

Advanced Incident Response & Digital Forensics Fundamentals

Question

You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate the DoS attack on a computer network of SecureEnet Inc. Which of the following methods will you perform to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ALook for unusual traffic on Internet connections and network segments.
  • BSeize all computers and transfer them to the Forensic lab.
  • CLook for core files or crash dumps on the affected systems.
  • DSniff network traffic to the failing machine.

How the community answered

(42 responses)
  • A
    81% (34)
  • B
    19% (8)

Why each option

DoS forensic investigation relies on traffic analysis, system artifact review, and packet capture - physical seizure of all equipment is unnecessary and disruptive.

ALook for unusual traffic on Internet connections and network segments.Correct

Unusual traffic patterns on network segments and Internet connections are primary indicators of a DoS attack, providing evidence of flood vectors and source addresses.

BSeize all computers and transfer them to the Forensic lab.

Seizing all computers is disproportionate and operationally destructive for a DoS investigation, which centers on network behavior and system logs rather than physical hardware forensics.

CLook for core files or crash dumps on the affected systems.Correct

Core files and crash dumps are system-level artifacts generated when processes or the OS fail under attack load, preserving evidence of the attack impact.

DSniff network traffic to the failing machine.Correct

Sniffing network traffic to the failing machine captures live or recorded attack packets, revealing the attack type, source, and volume in real time.

Concept tested: DoS forensic investigation methods and evidence collection

Source: https://www.eccouncil.org/train-certify/computer-hacking-forensic-investigator-chfi/

Topics

#DoS investigation#network traffic analysis#crash dumps#network forensics

Community Discussion

No community discussion yet for this question.

Full GCFA Practice