Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 3

Identifying IoCs from Network Logs DFE Practice Questions (Page 1)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
6concepts

Questions 1–5

  1. 1application · medium

    A company suspects that an internal host is communicating with a command-and-control server using HTTPS. Which log source would provide the most useful evidence of the communication, given that the traffic is encrypted?

    Select an answer first
  2. 2application · medium

    A web server log contains many requests from a single IP address, each with a different User-Agent string and each requesting a unique URL path that does not exist on the server. Which category of IoC does this pattern best represent?

    Select an answer first
  3. 3application · medium

    A proxy log entry shows: '2024-03-15 14:22:31 10.0.0.5 GET http://malicious.example.com/update.php HTTP/1.1 200 Mozilla/5.0'. An analyst wants to correlate this entry with a threat intelligence feed that lists malicious domains. Which field must be extracted and normalized to perform the correlation?

    Select an answer first
  4. 4expert · hard

    An analyst is correlating proxy logs with a threat intelligence feed. The proxy logs contain URLs, but the feed contains domains and IPs. The analyst notices that some URLs use IP addresses instead of domain names. What is the most effective way to ensure all indicators are matched?

    Select an answer first
  5. 5application · medium

    An IDS log shows a series of outbound connections from an internal host to a remote server on port 53, but the payloads are large and contain binary data rather than typical DNS queries. Which type of IoC does this represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.