Questions
Answer the following questions to test your knowledge of this chapter:
- A filtered log review is one where the responder or analyst filters out specific logs based on a set parameter.
- True
- False
- What is not a component of the Elastic Stack?
- Elasticsearch
- Log forwarder
- Logstash
- Kibana
- Which packet analysis tool places the packet capture into sessions as the default view?
- Wireshark
- NetFlow
- Elastic Stack
- Arkime
- Wireshark does not allow for DNS name resolution.
- True
- False