Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 4Objective 1

Network Forensics CHFI Practice Questions (Page 7)

Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.

57questions here
12free pages
11concepts

Questions 31–35

  1. 31foundation · easy

    What is the primary purpose of reconstructing a network attack timeline?

    Select an answer first
  2. 32foundation · easy

    Which network evidence source provides the most detailed information about the actual content of a communication?

    Select an answer first
  3. 33application · medium

    During incident response, a forensic investigator is asked to determine the scope of a network breach. The investigator has access to firewall logs, IDS alerts, and NetFlow data. What is the primary goal of network forensics in this context?

    Select an answer first
  4. 34expert · medium

    A forensic investigator is writing a report for a case involving network evidence. The investigator used Wireshark to analyze a pcap file and tcpdump to capture the traffic. The report must be clear and legally defensible. Which practice is most important to include in the report?

    Select an answer first
  5. 35foundation · easy

    When analyzing a packet capture, what does the 'Follow TCP Stream' feature in Wireshark allow an investigator to do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.