Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCED Topic 3 Question 36 Discussion

Actual exam question for GIAC's GCED exam
Question #: 36
Topic #: 3
[All GCED Questions]

An analyst wants to see a grouping of images that may be contained in a pcap file. Which tool natively meets this need?

Show Suggested Answer Hide Answer
Suggested Answer: A

A company needs to classify its information as a key step in valuing it and knowing where to focus its protection.

Rotation of duties and separation of duties are both key elements in reducing the scope of information access and the ability to conceal malicious behavior.

Separation of duties helps minimize ''empire building'' within a company, keeping one individual from controlling a great deal of information, reducing the insider threat.

Security awareness programs can help other employees notice the signs of an insider attack and thus reduce the insider threat.

Detection is a reactive method and only occurs after an attack occurs. Only preventative methods can stop or limit an attack.


Contribute your Thoughts:

Ivette
13 hours ago
A) Scapy? What is this, a trick question? Scapy is for packet manipulation, not pcap analysis. D) Wireshark is the way to go, folks.
upvoted 0 times
...
Golda
4 days ago
C) TCPReplay? Really? I mean, it's a great tool for replaying captured traffic, but it's not gonna help me see any images. D) Wireshark all the way!
upvoted 0 times
...
Avery
15 days ago
I'm not sure, but I think Wireshark makes sense because it's a popular tool for analyzing network traffic.
upvoted 0 times
...
Brock
16 days ago
I'm gonna have to go with B) NetworkMiner. It's designed specifically for pcap analysis and can extract all kinds of juicy data, including images.
upvoted 0 times
...
Sharmaine
19 days ago
D) Wireshark seems like the obvious choice here. It's pretty much the go-to tool for analyzing network traffic and pcap files.
upvoted 0 times
...
Anglea
19 days ago
I agree with Wava, Wireshark is the tool for viewing images in a pcap file.
upvoted 0 times
...
Wava
23 days ago
I think the answer is D) Wireshark.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77