Questions

  1. What items are potential sources of network evidence?

A) Switches
B) Routers
C) Firewalls
D) All of the above

  1. Network diagrams are important in identifying potential areas where network evidence can be acquired.

A) True
B) False

  1. Which of the following is not a network forensic evidence capture tool?

A) RawCap
B) Wireshark
C) WinPcap
D) LogBeat

  1. When conducting evidence acquisition, it is not important to record the hash value of the file.

A) True
B) False