
EC-CouncilDigital Forensics Essentials
Domain 5Objective 3
Identifying IoCs from Network Logs DFE Practice Questions (Page 4)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
6concepts
Questions 16–20
- 16
Which of the following network traffic patterns would be considered an anomaly that may indicate protocol misuse?
Select an answer first - 17
In a network log, which of the following is an example of an indicator of compromise (IoC) that falls into the category of 'malicious IP addresses'?
Select an answer first - 18
An analyst has firewall logs showing connections to an IP address that appears in a threat intelligence feed. The analyst must document this finding for the incident response team. Which action best ensures the documentation is useful for further forensic analysis?
Select an answer first - 19
In network traffic logs, which pattern is most commonly associated with data exfiltration?
Select an answer first - 20
A security team has a threat feed that lists a malicious domain. The DNS logs show that several internal hosts queried this domain, but the proxy logs show no corresponding HTTP requests. Which conclusion is most defensible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.