
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 1
Network Forensics CHFI Practice Questions (Page 11)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
57questions here
12free pages
11concepts
Questions 51–55
- 51
A security analyst suspects a compromised workstation is sending large amounts of data to an external IP on port 443. The analyst has access to NetFlow data but not full packet captures. Which NetFlow field would be MOST useful to confirm the volume of data transferred?
Select an answer first - 52
A forensic analyst has a pcap file containing a suspicious DNS tunnel. The analyst needs to extract the full DNS queries and responses to reconstruct the tunneled data. Which tool is BEST suited for this task?
Select an answer first - 53
A forensic investigator is correlating logs from a firewall, an IDS, and a web server to build an attack timeline. The investigator notices that timestamps differ by several seconds across devices. What should the investigator do FIRST to ensure accurate correlation?
Select an answer first - 54
What is the purpose of maintaining a chain of custody for network evidence?
Select an answer first - 55
An investigator is analyzing a pcap file and needs to extract the full contents of an HTTP session, including the request and response bodies, to document a web attack. Which Wireshark feature is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.