Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium

A security analyst is investigating a phishing attack where an employee clicked a malicious link, potentially leading to malware infection. The analyst needs to determine if the link led to a download, what files were accessed, and if any data was exfiltrated. Which of the following incident response tools would provide the most relevant information for this initial investigation?

  1. ANetwork Packet Analyzer
  2. BVulnerability Scanner
  3. CFirewall
  4. DHardware Security Module (HSM)
Show answer & explanation

Correct answer: A. Network Packet Analyzer

A Network Packet Analyzer allows the analyst to capture and examine raw network traffic, which is crucial for determining if a malicious link led to a download, what network connections were made, and if any data was exfiltrated, providing direct insight into network-level activities.

Why the other options are wrong

  • B. A vulnerability scanner finds weaknesses, not active attack details.
  • C. A firewall controls traffic but doesn't provide detailed analysis of past communications.
  • D. HSMs protect cryptographic keys but are not for network traffic analysis.

Network Packet Analyzer

A tool used to capture and inspect individual data packets traveling over a computer network, allowing for detailed analysis of network communication.

  • Provides granular visibility into network traffic.
  • Used for troubleshooting, security analysis, and protocol development.
  • Can reveal malicious payloads, C2 communications, and data exfiltration.

Memory trick: Packet Analyzer: Peeking at Network's Invisible Conversations.

More Incident Handling questions