
EC-CouncilDigital Forensics Essentials
Domain 5Objective 3
Identifying IoCs from Network Logs DFE Practice Questions (Page 2)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
6concepts
Questions 6–10
- 6
An analyst is correlating network logs with a threat intelligence feed. What is the primary purpose of this correlation?
Select an answer first - 7
An analyst has identified multiple IoCs from different log sources and needs to document them for a formal forensic report. The report will be reviewed by both technical and non-technical stakeholders. Which approach best balances clarity and technical detail?
Select an answer first - 8
A security analyst is reviewing firewall logs and notices a server making outbound connections to multiple external IPs on port 53 using TCP, with each connection transferring a small amount of data. The analyst suspects DNS tunneling. Which additional log source would provide the most direct confirmation?
Select an answer first - 9
An organization's firewall logs show a workstation making outbound connections to a known malicious IP on port 443. However, the organization's proxy logs show no corresponding HTTPS requests from that workstation. The analyst must determine whether the workstation is truly compromised. Which conclusion is most appropriate?
Select an answer first - 10
A network administrator notices that a database server, which normally communicates only with internal application servers, is sending large amounts of data to an external IP address on port 443 during business hours. Which indicator is most directly suggested by this observation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.