Question 8
When configuring a long-term, forensic packet capture and saving all packets to disk which of the following is not a consideration?
Total capture storage space
Individual trace file size
Correct answer: A
Explanation:
Real-time packet decodes are not a consideration when configuring a long-term, forensic packet capture and saving all packets to disk. Real-time packet decodes are useful for live analysis and troubleshooting, but they consume CPU and memory resources that could affect the performance of the capture process. For a long-term, forensic packet capture, it is more important to consider the analyzer location, the total capture storage space, and the individual trace file size.These factors affect the quality and quantity of the captured packets and the ease of post-capture analysis34Reference:CWAP-404 Study Guide, Chapter 2: Protocol Analysis, page 49CWAP-404 Objectives, Section 2.1: Configure protocol analyzers
Real-time packet decodes are not a consideration when configuring a long-term, forensic packet capture and saving all packets to disk. Real-time packet decodes are useful for live analysis and troubleshooting, but they consume CPU and memory resources that could affect the performance of the capture process. For a long-term, forensic packet capture, it is more important to consider the analyzer location, the total capture storage space, and the individual trace file size.These factors affect the quality and quantity of the captured packets and the ease of post-capture analysis34
Reference:
CWAP-404 Study Guide, Chapter 2: Protocol Analysis, page 49
CWAP-404 Objectives, Section 2.1: Configure protocol analyzers