An analyst is trying to capture anomalous traffic from a compromised host. Which of the following are the best tools for achieving this objective? (Select two).
Tocapture and analyze network traffic, the two best tools are:
tcpdump (Option A)– A command-line packet capture tool used for network traffic analysis.
Wireshark (Option D)– A GUI-based network packet analysis tool that provides deep inspection capabilities.
Option B (SIEM)is forlog aggregationand does notcapturetraffic.
Option C (Vulnerability scanner)identifies weaknesses but does notcapturenetwork traffic.
Option E (Nmap)is used for network discovery and port scanning, not capturing traffic.
Option F (SOAR)automates security processes but does not capture traffic.
Thus,A (tcpdump) and D (Wireshark) are correct, asthey are the best tools for capturing and analyzing anomalous network traffic.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit