nerdexam
CompTIA

SY0-501 · Question #434

A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?

The correct answer is B. Traffic and logs. For a network incident, a security analyst is most likely to obtain network traffic and system logs as primary evidence to determine the incident's scope and nature.

Submitted by daniela_cl· Mar 4, 2026Security operations

Question

A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?

Options

  • AVolatile memory capture
  • BTraffic and logs
  • CScreenshots
  • DSystem image capture

How the community answered

(54 responses)
  • A
    7% (4)
  • B
    80% (43)
  • C
    11% (6)
  • D
    2% (1)

Why each option

For a network incident, a security analyst is most likely to obtain network traffic and system logs as primary evidence to determine the incident's scope and nature.

AVolatile memory capture

Volatile memory capture is crucial for host-based forensic analysis to identify running processes, open network connections, and malware resident in RAM, but it does not directly capture the historical network traffic or logs needed to understand a network incident's broader scope.

BTraffic and logsCorrect

Network traffic (e.g., packet captures, NetFlow) provides direct visibility into the communications occurring on the network, revealing malicious payloads, unauthorized connections, and data exfiltration attempts. Logs from network devices (firewalls, routers, IDS/IPS), servers, and applications offer chronological records of events, connections, and system activities, which are critical for reconstructing the incident timeline, identifying affected systems, and understanding the attacker's actions at the network level.

CScreenshots
DSystem image capture

Concept tested: Network incident response evidence collection

Source: https://learn.microsoft.com/en-us/azure/architecture/guide/security/incident-response-handbook

Topics

#network forensics#incident response#packet capture#log analysis

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice