• Post author:
  • Post category:Blog
  • Reading time:2 mins read
  • Post last modified:June 12, 2024

Which of the following is a concern regarding full packet capture data?

  • NIC performance features such as TCP segmentation offload can distort the collected full packet capture.
  • Storage resources may limit the duration of full packet capture retention.
  • The location of sensing interfaces affects the visibility that the data provides.
  • The three options above are all concerns.
  • Only the second and third options above are concerns.
Explanation & Hint:

The correct answer is:

  • The three options above are all concerns.

Each of the mentioned points is a valid concern regarding full packet capture data:

  1. NIC performance features such as TCP segmentation offload can distort the collected full packet capture. Network Interface Card (NIC) performance features like TCP segmentation offload (TSO) and Generic Receive Offload (GRO) can indeed affect the accuracy of packet captures, as these features change how packets are processed and transmitted, potentially leading to discrepancies in the capture versus what is actually on the wire.
  2. Storage resources may limit the duration of full packet capture retention. Full packet captures can consume a significant amount of storage because they record all the packet data passing through the network. Therefore, storage capacity is a limiting factor in how long data can be retained.
  3. The location of sensing interfaces affects the visibility that the data provides. The placement of sensors (or the points where data is captured) in the network can greatly influence the scope and context of the visibility into network traffic. If sensors are not placed at strategic points, certain traffic may not be captured, leading to gaps in monitoring and data collection.

For more Questions and Answers:

Data Security Post-Assessment | CBROPS

Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments