QuestionQ450

Logs and Network Forensics

During a wireless-network forensics operation at a technology company in Austin, Texas, investigators use standard capture tools to collect live traffic from a suspected internal intrusion. Although they remain close to the affected area, they obtain only partial packet captures, and the extracted logs contain substantial gaps that prevent correlating device identifiers with timestamps. Which condition most directly explains this limitation?

  • A Inability to collect traffic from multiple access points
  • B Interoperability with other wireless networks
  • C Inaccuracy of results
  • D Difficulty in gathering solid evidence in case of impersonation attacks
Explanation

Wireless forensic captures taken from a fixed vantage point can typically monitor only one access point or channel at a time, so when investigated devices roam or communicate across multiple access points, the capture inevitably misses frames exchanged with the access points outside the monitored range; this produces partial packet captures with gaps that break the correlation between a device's identifier and the timestamps of its full communication session, which is the direct consequence of being unable to simultaneously collect traffic from multiple access points.

Community Discussion

No comments yet. Be the first to start the discussion!