QuestionQ411

Logs and Network Forensics

After a post-breach investigation at a manufacturing company in Denver, Colorado, forensic analysts start capturing and analyzing live network traffic between internal and external hosts. Their goal is to reveal communication patterns, identify unauthorized access, and establish the attacker’s methods. Which activity is not among the primary objectives of network traffic investigation?

  • A To detect and examine an ongoing attack by monitoring network traffic communication patterns
  • B To identify hosts or networks involved in a network security incident
  • C To trace information or packets related to a security intrusion and collect them as evidence
  • D To erase the traces of intrusion by clearing captured packets from network devices
Explanation

Network traffic investigation preserves and analyzes communications evidence to detect attacks, identify involved systems, and reconstruct intrusion activity. Deleting captured packets or otherwise erasing traces destroys potential evidence rather than supporting the investigation.

Community Discussion

No comments yet. Be the first to start the discussion!