Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 3

Identifying IoCs from Network Logs DFE Practice Questions (Page 5)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
6concepts

Questions 21–25

  1. 21application · medium

    After identifying several IoCs from firewall logs, an analyst must document them for a forensic report. Which format best supports structured sharing with other analysts and automated tools?

    Select an answer first
  2. 22application · medium

    An analyst has identified several IPs and domains as IoCs. What is the most important information to include in the IoC report to ensure other analysts can verify the findings?

    Select an answer first
  3. 23application · medium

    An analyst has a threat intelligence feed that contains IP addresses and domains. The analyst wants to identify any internal hosts that have communicated with these indicators in the last 24 hours. Which combination of log sources would provide the most complete picture?

    Select an answer first
  4. 24application · medium

    An analyst is reviewing raw proxy logs that contain entries like '2024-05-01 10:23:45 192.168.1.50 http://evil.example.com/payload.exe'. The analyst needs to extract the destination domain and the client IP to compare against a threat intelligence feed. Which normalization step is most appropriate?

    Select an answer first
  5. 25foundation · easy

    What is the primary purpose of reporting IoCs in a structured format?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.