CHFI Module 7 Network Forensics Questions and Answers Graded A+
CHFI Module 7 Network Forensics Questions and Answers Graded A+ Network Forensics The process of collecting and analyzing raw network data and systematically tracking network traffic to determine how security incidents occur. Network Forensics is considered what kind of data Volatile - Real-Time for best results - Postmortem - after event FRE 803 Hearsay Rule Logs as evidence if... - Regular business activity records - Trustworthiness (chain of custody) - Before, during, after Event correlation Recognizing two or more security events as being related and leveraging that relationship for further process of analysis. Event correlation Codebook Base Stores sets of events in codes Event correlation Rule Based Rules are used to correlate events Event correlation Automated Field Correlation Compare some or all of the fields in the data and determines any correlation across fields Event correlation Bayesian Uses statistics and probability to predict next steps Event correlation Time/Role Based Monitors the user and computer behavior for abnormal activity UTC Coordinated Universal Time Log management Challenges Variety of logs Sources of data are distributed Data sources change constantly Sensitivity of data Format of log data Log Fatigue Retention Centralized Logging Syslog Separation of log generation, log storage, and log analysis Central repository (printers, routers, etc...) Event correlation types Same-Platform; same OS Cross-Platform; different OS's Transmission of Data (authentication and encryption) Normalization; after data is transmitted, return to a common format for use Data Reduction; reducing or Event correlation
Written for
- Institution
- CHFI Module 7
- Course
- CHFI Module 7
Document information
- Uploaded on
- March 9, 2024
- Number of pages
- 4
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
-
chfi module 7 network forensics questions and answ
Also available in package deal