
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 1
Network Forensics CHFI Practice Questions (Page 5)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
57questions here
12free pages
11concepts
Questions 21–25
- 21
Which combination of evidence sources is most effective for reconstructing a network-based attack?
Select an answer first - 22
A forensic team must capture traffic on a 10 Gbps backbone link during a critical incident. The team has a forensic server with a 1 Gbps NIC and a switch that supports SPAN. The capture must not drop packets. Which approach is the BEST?
Select an answer first - 23
Which statement best describes the role of network forensics in a legal investigation?
Select an answer first - 24
A forensic investigator has captured network traffic using a laptop connected to a SPAN port. The investigator needs to ensure the evidence is admissible in court. Which action is MOST critical?
Select an answer first - 25
During packet analysis, an investigator sees a series of TCP packets with the PSH and ACK flags set, carrying small payloads to a single external IP at regular intervals. The investigator suspects a covert channel. Which analysis step would BEST confirm this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.