
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 1
Network Forensics CHFI Practice Questions (Page 2)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
57questions here
12free pages
11concepts
Questions 6–10
- 6
A company has suffered a data breach. The incident response team has collected firewall logs, IDS alerts, and NetFlow data. The team is now in the forensic analysis phase. Which activity is most aligned with the goals of network forensics?
Select an answer first - 7
An investigator is analyzing a pcap file and sees a series of ICMP Echo Request packets with payloads containing random data sent to multiple hosts. The investigator suspects covert communication. Which analysis technique would best confirm this?
Select an answer first - 8
After completing a network forensic investigation, an investigator must write a report for legal counsel. Which element is MOST important to include?
Select an answer first - 9
An organization has firewall logs, IDS alerts, and web server logs, but the timestamps are not synchronized. The investigator needs to build a legally defensible timeline. Which approach is the MOST reliable?
Select an answer first - 10
What is a key requirement for a forensic report to be legally defensible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.