
EC-CouncilDigital Forensics Essentials
Domain 5Objective 3
Identifying IoCs from Network Logs DFE Practice Questions (Page 3)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
6concepts
Questions 11–15
- 11
A network analyst observes a workstation sending ICMP echo requests to multiple external IPs in rapid succession, each with a payload larger than the standard 32 bytes. Which anomaly does this most likely indicate?
Select an answer first - 12
An analyst is correlating proxy logs with a threat intelligence feed that uses UTC timestamps. The proxy logs are in local time (UTC+5). A suspicious entry appears at 14:30 local time. What normalized timestamp should the analyst use for correlation?
Select an answer first - 13
A network administrator observes that a server is sending a steady stream of small UDP packets to an external IP address on port 123 (NTP) every few seconds. The server is not configured as an NTP client. Which type of IoC does this behavior most likely represent?
Select an answer first - 14
A security team has a threat intelligence feed that updates hourly. An analyst is investigating a potential compromise and finds a connection to an IP that was flagged in the feed only 30 minutes ago. The analyst wants to determine if the connection occurred before or after the IP was flagged. Which approach is most appropriate?
Select an answer first - 15
A company suspects a malware infection that uses DNS tunneling to exfiltrate data. Which log source would provide the most direct evidence of the tunneling activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.