
EC-CouncilDigital Forensics Essentials
Domain 5Objective 3
Identifying IoCs from Network Logs DFE Practice Questions (Page 6)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
6concepts
Questions 26–30
- 26
An analyst has a raw firewall log line: 'src=192.168.1.10 dst=203.0.113.5 sport=49152 dport=443 proto=tcp action=allow'. The analyst needs to compare this with a threat feed that lists IP addresses. Which extracted field is the direct match for the feed?
Select an answer first - 27
An organization suspects that an internal user is visiting phishing websites. Which combination of log sources would provide the most complete evidence of the user's browsing activity and the associated network connections?
Select an answer first - 28
A raw network log entry contains the string 'src=192.168.1.10 dst=10.0.0.5 sport=12345 dport=80 proto=tcp'. After normalizing this log, which field would be extracted as the destination port?
Select an answer first - 29
A security analyst is correlating proxy logs with a threat intelligence feed. The feed contains both IP addresses and domains, but the proxy logs only contain the requested URL and the client IP. The analyst must identify internal hosts that accessed known malicious content. Which approach is most effective?
Select an answer first - 30
An analyst is correlating firewall logs with a threat intelligence feed that lists IP addresses. The firewall logs show a connection to an IP that is one octet different from an IP in the feed (e.g., 203.0.113.5 vs 203.0.113.6). The analyst must decide whether to flag this as a match. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.