A court IT team suspects large data exfiltration, but application logs do not show transfer volume. Which sources are most appropriate to estimate egress?
Select an answer to reveal the explanation.
Short Explanation
When app logs shrug about how much left the building, NetFlow and packet captures are the highway traffic counters. They show volume and where the bits drove off to. Badge printers and whiteboard photos will not measure exfil.
Full Explanation
Network data sources such as packet captures and flow records (NetFlow/IPFIX) provide visibility into volume, endpoints, and protocols when host or application logs lack transfer metrics. They help investigators confirm or refute exfiltration hypotheses. Non-network administrative artifacts do not quantify egress and are poor substitutes for network telemetry in this scenario.