header bg

Scan QR code or get instant email to install app

Question:

Charlie intends to obtain network forensic data. Which tool should he utilize to collect this information?

A Wireshark.
explanation

Wireshark is a packet analyzer that can be used for forensic analysis by capturing and examining network traffic. Unlike disk forensics, network forensics necessitates pre-planning and deliberate data capture prior to its requirement since traffic is transitory. Firms that wish to obtain a view of network traffic without capturing all traffic may use NetFlow or sFlow to obtain some information on network traffic usage and patterns. Nessus is a vulnerability scanner, nmap is a port scanner, and Simple Network Management Protocol (SNMP) is a protocol utilized for transferring and gathering information on network devices and status.

Related Information

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

*