300-215 Question 5
Single answerA cybersecurity analyst is tasked with investigating suspicious activity on a company's network. During the investigation, the analyst uses Cisco Secure Network Analytics (formerly Stealthwatch) to identify unusual traffic patterns. Which fundamental concept of forensic analysis does this scenario primarily involve?
- A
Baseline analysis
- B
Chain of custody
- C
Memory forensics
- D
File integrity monitoring
Show answer and explanation
Correct answer: A
Explanation
Baseline analysis is a fundamental principle in cybersecurity forensic analysis. By leveraging Cisco Secure Network Analytics, the analyst is comparing current traffic behavior to a known baseline to detect deviations, such as unusual traffic patterns. This method helps in identifying potentially malicious activities on the network.
- A. Correct.
Baseline analysis involves comparing current network behavior against established normal patterns to identify anomalies, which is the primary concept being used in this scenario.
- B. Incorrect.
Chain of custody refers to the proper handling and documentation of evidence, which is unrelated to the activity described here.
- C. Incorrect.
Memory forensics involves analyzing volatile data from a system's memory, which is not applicable to the network traffic analysis described in this scenario.
- D. Incorrect.
File integrity monitoring focuses on detecting unauthorized changes to files and is unrelated to analyzing network traffic patterns.