SY0-501 · Question #434
A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?
The correct answer is B. Traffic and logs. For a network incident, a security analyst is most likely to obtain network traffic and system logs as primary evidence to determine the incident's scope and nature.
Question
A security analyst is acquiring data from a potential network incident. Which of the following evidence is the analyst MOST likely to obtain to determine the incident?
Options
- AVolatile memory capture
- BTraffic and logs
- CScreenshots
- DSystem image capture
How the community answered
(54 responses)- A7% (4)
- B80% (43)
- C11% (6)
- D2% (1)
Why each option
For a network incident, a security analyst is most likely to obtain network traffic and system logs as primary evidence to determine the incident's scope and nature.
Volatile memory capture is crucial for host-based forensic analysis to identify running processes, open network connections, and malware resident in RAM, but it does not directly capture the historical network traffic or logs needed to understand a network incident's broader scope.
Network traffic (e.g., packet captures, NetFlow) provides direct visibility into the communications occurring on the network, revealing malicious payloads, unauthorized connections, and data exfiltration attempts. Logs from network devices (firewalls, routers, IDS/IPS), servers, and applications offer chronological records of events, connections, and system activities, which are critical for reconstructing the incident timeline, identifying affected systems, and understanding the attacker's actions at the network level.
Concept tested: Network incident response evidence collection
Source: https://learn.microsoft.com/en-us/azure/architecture/guide/security/incident-response-handbook
Topics
Community Discussion
No community discussion yet for this question.