GCFA · Question #269
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate the DoS attack on a computer network of SecureEnet Inc. Which of the following meth
The correct answer is A. Look for unusual traffic on Internet connections and network segments. C. Look for core files or crash dumps on the affected systems. D. Sniff network traffic to the failing machine.. DoS forensic investigation relies on traffic analysis, system artifact review, and packet capture - physical seizure of all equipment is unnecessary and disruptive.
Question
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate the DoS attack on a computer network of SecureEnet Inc. Which of the following methods will you perform to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
Options
- ALook for unusual traffic on Internet connections and network segments.
- BSeize all computers and transfer them to the Forensic lab.
- CLook for core files or crash dumps on the affected systems.
- DSniff network traffic to the failing machine.
How the community answered
(42 responses)- A81% (34)
- B19% (8)
Why each option
DoS forensic investigation relies on traffic analysis, system artifact review, and packet capture - physical seizure of all equipment is unnecessary and disruptive.
Unusual traffic patterns on network segments and Internet connections are primary indicators of a DoS attack, providing evidence of flood vectors and source addresses.
Seizing all computers is disproportionate and operationally destructive for a DoS investigation, which centers on network behavior and system logs rather than physical hardware forensics.
Core files and crash dumps are system-level artifacts generated when processes or the OS fail under attack load, preserving evidence of the attack impact.
Sniffing network traffic to the failing machine captures live or recorded attack packets, revealing the attack type, source, and volume in real time.
Concept tested: DoS forensic investigation methods and evidence collection
Source: https://www.eccouncil.org/train-certify/computer-hacking-forensic-investigator-chfi/
Topics
Community Discussion
No community discussion yet for this question.