ExamGecko
Question list
Search
Search

Related questions











Question 231 - 200-201 discussion

Report
Export

When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?

A.

full packet capture

Answers
A.

full packet capture

B.

NetFlow data

Answers
B.

NetFlow data

C.

session data

Answers
C.

session data

D.

firewall logs

Answers
D.

firewall logs

Suggested answer: A

Explanation:

Full packet capture provides the complete recording of all the packets that are transmitted over the network. This data is essential for in-depth analysis during an investigation, as it allows investigators to reconstruct the session, observe the content of the traffic, and determine if data exfiltration has occurred.

asked 07/10/2024
Sumit Dhar
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first