
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 1
Network Forensics CHFI Practice Questions (Page 12)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
57questions here
12free pages
11concepts
Questions 56–57
- 56
An investigator needs to analyze a pcap file that contains both HTTP and HTTPS traffic. The investigator has the server's private key. Which tool feature would allow decryption of the HTTPS traffic for analysis?
Select an answer first - 57
During analysis of a pcap file, an investigator sees a TCP stream with a three-way handshake, a burst of HTTP GET requests, and a FIN-ACK exchange. The investigator needs to prove the session was a single logical conversation. Which Wireshark feature should be used?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CHFI
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.