ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 355 - CS0-003 discussion

Report
Export

A network security analyst for a large company noticed unusual network activity on a critical system. Which of the following tools should the analyst use to analyze network traffic to search for malicious activity?

A.

WAF

Answers
A.

WAF

B.

Wireshark

Answers
B.

Wireshark

C.

EDR

Answers
C.

EDR

D.

Nmap

Answers
D.

Nmap

Suggested answer: B

Explanation:

Wireshark is a network protocol analyzer that allows analysts to capture and inspect data packets traveling through a network. This makes it ideal for investigating unusual network activity, as it provides detailed insights into the nature and content of network traffic. In this case, Wireshark can help identify potentially malicious packets and understand the nature of the observed traffic. Options A (WAF) and C (EDR) are primarily used for monitoring and protecting web applications and endpoints, respectively, and Nmap (D) is typically used for network discovery and mapping, not detailed traffic analysis. According to CompTIA CySA+, packet analysis tools like Wireshark are invaluable for deep-dive investigations into network anomalies.

asked 17/10/2024
Pieter Louw
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first