
EC-CouncilDigital Forensics Essentials
Domain 5Objective 2
Event Correlation Concepts and Techniques DFE Practice Questions (Page 8)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
41questions here
9free pages
5concepts
Questions 36–40
- 36
Which correlation technique relies on predefined patterns or signatures to identify known attack sequences?
Select an answer first - 37
A forensic analyst is investigating a web server breach. The server logs show a single failed login attempt from an internal IP at 02:14:03, and the firewall logs show an outbound connection from that same IP to a known command-and-control domain at 02:14:05. The analyst wants to establish a causal link between these two events. Which action best applies event correlation to support the investigation?
Select an answer first - 38
Which sequence correctly represents the typical steps in the event correlation process?
Select an answer first - 39
An incident responder is correlating events from multiple servers to investigate a suspected web attack. The responder notices that the timestamps in the web server logs are 30 minutes ahead of the firewall logs, even though both are supposed to be in UTC. What is the most likely cause of this discrepancy, and what should the responder do to ensure accurate correlation?
Select an answer first - 40
During an investigation, an analyst collects logs from a web server, a database server, and a firewall. The logs use different formats: some are in JSON, some in CSV, and some in syslog. Before correlating the events, what is the most important step the analyst should perform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.