Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 4Objective 1

Network Forensics CHFI Practice Questions (Page 6)

Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.

57questions here
12free pages
11concepts

Questions 26–30

  1. 26application · medium

    A network administrator needs to enable evidence collection on a network that currently has no monitoring. The administrator wants to capture full packet data for a critical server segment and also retain flow data for the entire network. Which combination of evidence sources should the administrator deploy?

    Select an answer first
  2. 27application · medium

    A network analyst notices a large volume of short-lived UDP flows from a single internal host to many different external IPs on port 53. The analyst suspects DNS amplification. Which flow data characteristic would BEST support this hypothesis?

    Select an answer first
  3. 28application · medium

    A company's legal team asks the forensic investigator to determine whether an employee exfiltrated sensitive data over the network. The investigator has access to firewall logs, NetFlow data, and a pcap of the employee's traffic. What is the PRIMARY goal of network forensics in this context?

    Select an answer first
  4. 29application · medium

    A forensic investigator needs to capture traffic on a 10 Gbps backbone link between two core switches to investigate a suspected data exfiltration. The capture must include full packet payloads and must not introduce noticeable latency. The investigator has a forensic workstation with a 10 Gbps NIC and a RAID array. Which approach should the investigator use?

    Select an answer first
  5. 30application · medium

    An investigator is analyzing firewall logs and sees a series of denied outbound connections from an internal host to a known command-and-control IP. The investigator wants to determine whether the host also communicated with other internal systems. Which additional log source would be MOST useful?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.