
EC-CouncilDigital Forensics Essentials
Domain 5Objective 3
Identifying IoCs from Network Logs DFE Practice Questions (Page 9)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
48questions here
10free pages
6concepts
Questions 41–45
- 41
Which of the following IoC categories is best represented by the string 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36' appearing in a web proxy log?
Select an answer first - 42
An analyst is normalizing logs from different sources into a common format. Which step is essential to ensure that timestamps from different time zones can be compared accurately?
Select an answer first - 43
An analyst has confirmed that a server communicated with a known malicious IP. The analyst must document this IoC for the incident response team, but the organization requires that all reports be concise and actionable. Which documentation approach best meets this requirement?
Select an answer first - 44
A network log shows a connection to the IP address 198.51.100.7. A threat intelligence feed lists this IP as a known command-and-control server. What does this correlation indicate?
Select an answer first - 45
During an investigation, an analyst needs to identify which internal host communicated with a known malicious external IP. Which network log source would most directly provide this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.