Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 3

Identifying IoCs from Network Logs DFE Practice Questions (Page 10)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
6concepts

Questions 46–48

  1. 46application · medium

    A security team uses a threat intelligence feed that lists malicious domains. An analyst wants to identify any internal hosts that have resolved these domains. Which log source would be most effective for this correlation?

    Select an answer first
  2. 47expert · hard

    An analyst is correlating logs from multiple sources (firewall, proxy, DNS) with a threat intelligence feed. The firewall logs use epoch time, the proxy logs use local time, and the DNS logs use UTC. The analyst must produce a unified timeline of events. Which normalization step is most critical to perform first?

    Select an answer first
  3. 48expert · hard

    An organization has both an IDS and a firewall. The IDS logs show a suspicious outbound connection from an internal host to a known malicious IP, but the firewall logs show the connection was blocked. The analyst must determine whether the host was actually compromised. Which conclusion is most appropriate?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to DFE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.