
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 1
Network Forensics CHFI Practice Questions (Page 3)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
57questions here
12free pages
11concepts
Questions 11–15
- 11
What type of data does NetFlow provide that is useful for detecting data exfiltration?
Select an answer first - 12
What is the purpose of configuring port mirroring on a switch for network forensic capture?
Select an answer first - 13
Which network forensic tool provides a graphical interface for deep packet inspection and protocol analysis?
Select an answer first - 14
A forensic investigator has captured network traffic using tcpdump on a compromised server. The investigator needs to preserve the evidence for legal proceedings. Which action is most important to maintain the chain of custody and integrity of the captured data?
Select an answer first - 15
An investigator is correlating firewall logs, IDS alerts, and web server logs to reconstruct an attack timeline. The firewall logs show an allowed inbound connection from an external IP to the web server at 14:32:05, the IDS alert for a SQL injection attempt is timestamped 14:32:11, and the web server log shows a suspicious request at 14:32:09. The investigator notices that the firewall and IDS timestamps are in UTC, while the web server logs are in local time (UTC+2). What is the correct first step to ensure an accurate timeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.