
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 1
Network Forensics CHFI Practice Questions (Page 6)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
57questions here
12free pages
11concepts
Questions 26–30
- 26
A network administrator needs to enable evidence collection on a network that currently has no monitoring. The administrator wants to capture full packet data for a critical server segment and also retain flow data for the entire network. Which combination of evidence sources should the administrator deploy?
Select an answer first - 27
A network analyst notices a large volume of short-lived UDP flows from a single internal host to many different external IPs on port 53. The analyst suspects DNS amplification. Which flow data characteristic would BEST support this hypothesis?
Select an answer first - 28
A company's legal team asks the forensic investigator to determine whether an employee exfiltrated sensitive data over the network. The investigator has access to firewall logs, NetFlow data, and a pcap of the employee's traffic. What is the PRIMARY goal of network forensics in this context?
Select an answer first - 29
A forensic investigator needs to capture traffic on a 10 Gbps backbone link between two core switches to investigate a suspected data exfiltration. The capture must include full packet payloads and must not introduce noticeable latency. The investigator has a forensic workstation with a 10 Gbps NIC and a RAID array. Which approach should the investigator use?
Select an answer first - 30
An investigator is analyzing firewall logs and sees a series of denied outbound connections from an internal host to a known command-and-control IP. The investigator wants to determine whether the host also communicated with other internal systems. Which additional log source would be MOST useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.