Study. uk . com
  1. Home
  2. All questions
  3. Question 510

CompTIA Security+ study material · question 510 of 611

An attacker wiped the endpoint's logs before leaving. Which evidence source may still show what was taken?

  1. Captured network traffic and flow records
  2. The endpoint's registry hives
  3. The user's browser cache
  4. The application's configuration files
Show the answer

Answer: A. Captured network traffic and flow records

Network evidence is collected off the host, so wiping the endpoint does not reach it.

Source: NIST SP 800-86 (NIST) — SP 800-86 § 6.2.6 Network Forensic Analysis Tools

Challenge yourself on this topic → Study as cards