Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 3

Identifying IoCs from Network Logs DFE Practice Questions (Page 8)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
6concepts

Questions 36–40

  1. 36application · medium

    An analyst has a list of internal IPs that contacted an external IP flagged by a threat intelligence feed. The analyst wants to confirm the communication and identify the specific protocol and port used. Which log source would provide the most reliable confirmation?

    Select an answer first
  2. 37foundation · easy

    When documenting an IoC for a forensic report, which of the following is the most essential information to include?

    Select an answer first
  3. 38application · medium

    A security analyst notices a workstation sending HTTP requests with an unusual User-Agent string that matches a known malware signature. Which category of IoC does this represent?

    Select an answer first
  4. 39application · medium

    A security analyst notices a workstation repeatedly connecting to a known-bad IP address on TCP port 4444. Which network log source would provide the most direct evidence of these repeated outbound connections, including source and destination IPs and ports?

    Select an answer first
  5. 40application · medium

    An analyst has a list of internal IPs that communicated with a known malicious IP. The analyst wants to determine which internal hosts were affected and when. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.