ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 14 - CWAP-404 discussion

Report
Export

When configuring a long-term, forensic packet capture and saving all packets to disk which of the following is not a consideration?

A.
Real-time packet decodes
Answers
A.
Real-time packet decodes
B.
Analyzer location
Answers
B.
Analyzer location
C.
Total capture storage space
Answers
C.
Total capture storage space
D.
Individual trace file size
Answers
D.
Individual trace file size
Suggested answer: A

Explanation:

Real-time packet decodes are not a consideration when configuring a long-term, forensic packet capture and saving all packets to disk. Real-time packet decodes are useful for live analysis and troubleshooting, but they consume CPU and memory resources that could affect the performance of the capture process. For a long-term, forensic packet capture, it is more important to consider the analyzer location, the total capture storage space, and the individual trace file size.These factors affect the quality and quantity of the captured packets and the ease of post-capture analysis34Reference:

CWAP-404 Study Guide, Chapter 2: Protocol Analysis, page 49

CWAP-404 Objectives, Section 2.1: Configure protocol analyzers

asked 16/09/2024
Bassem Louati
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first