Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A security analyst is investigating a phishing attack where an employee clicked a malicious link, potentially leading to malware infection. The analyst needs to determine if the link led to a download, what files were accessed, and if any data was exfiltrated. Which of the following incident response tools would provide the most relevant information for this initial investigation?
- ANetwork Packet Analyzer
- BVulnerability Scanner
- CFirewall
- DHardware Security Module (HSM)
Show answer & explanationAnswer & explanation
Correct answer: A. Network Packet Analyzer
A Network Packet Analyzer allows the analyst to capture and examine raw network traffic, which is crucial for determining if a malicious link led to a download, what network connections were made, and if any data was exfiltrated, providing direct insight into network-level activities.
Why the other options are wrong
- B. A vulnerability scanner finds weaknesses, not active attack details.
- C. A firewall controls traffic but doesn't provide detailed analysis of past communications.
- D. HSMs protect cryptographic keys but are not for network traffic analysis.
Network Packet Analyzer
A tool used to capture and inspect individual data packets traveling over a computer network, allowing for detailed analysis of network communication.
- Provides granular visibility into network traffic.
- Used for troubleshooting, security analysis, and protocol development.
- Can reveal malicious payloads, C2 communications, and data exfiltration.
Memory trick: Packet Analyzer: Peeking at Network's Invisible Conversations.