Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 4Objective 1

Network Forensics CHFI Practice Questions (Page 5)

Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.

57questions here
12free pages
11concepts

Questions 21–25

  1. 21foundation · easy

    Which combination of evidence sources is most effective for reconstructing a network-based attack?

    Select an answer first
  2. 22expert · hard

    A forensic team must capture traffic on a 10 Gbps backbone link during a critical incident. The team has a forensic server with a 1 Gbps NIC and a switch that supports SPAN. The capture must not drop packets. Which approach is the BEST?

    Select an answer first
  3. 23foundation · easy

    Which statement best describes the role of network forensics in a legal investigation?

    Select an answer first
  4. 24expert · hard

    A forensic investigator has captured network traffic using a laptop connected to a SPAN port. The investigator needs to ensure the evidence is admissible in court. Which action is MOST critical?

    Select an answer first
  5. 25expert · hard

    During packet analysis, an investigator sees a series of TCP packets with the PSH and ACK flags set, carrying small payloads to a single external IP at regular intervals. The investigator suspects a covert channel. Which analysis step would BEST confirm this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.