Knowledge ID: K0301
Knowledge Description: Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).
Work Roles with this Knowledge:
- Work Role ID: IN-FOR-002Work Roles: Cyber Defense Forensics AnalystWork Role Description: Analyzes digital evidence and investigates computer security incidents to derive useful information in support of system/network vulnerability mitigation.Category: InvestigateSpecialty Area(s): Digital Forensics
- Work Role ID: PR-CDA-001Work Roles: Cyber Defense AnalystWork Role Description: Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats.Category: Protect and DefendSpecialty Area(s): Cyber Defense Analysis
- Work Role ID: PR-VAM-001Work Roles: Vulnerability Assessment AnalystWork Role Description: Performs assessments of systems and networks within the network environment or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Category: Protect and DefendSpecialty Area(s): Vulnerability Assessment and Management