In NSM data types, which two statements describe full packet capture and extracted content? (Choose two.)
- Extracted content records all the network traffic at some particular locations in the network.
- Full packet capture records all the network traffic at some particular locations in the network.
- A SOC analyst examining extracted content is analogous to a detective reviewing a wiretap.
- Most often, extracted content takes the form of files such as images retrieved by a web browser or attachments to email messages.
- Most often, full packet capture takes the form of files such as images retrieved by a web browser or attachments to email messages.
Explanation & Hint:
The two statements that correctly describe full packet capture and extracted content are:
The analogy of a SOC analyst examining extracted content to a detective reviewing a wiretap is somewhat fitting; however, a wiretap typically involves listening to and recording live voice communications, which is more akin to real-time packet capture or interception. Extracted content is more like evidence that has been collected and is being reviewed after the fact. |