
EC-CouncilDigital Forensics Essentials
Domain 5Objective 1
Network Forensics Fundamentals DFE Practice Questions (Page 1)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
6concepts
Questions 1–5
- 1
Which network device configuration would be most useful as evidence in a network forensic investigation?
Select an answer first - 2
A security analyst is investigating a possible brute-force attack on the company's SSH server. The analyst has access to the server's authentication logs. Which tool would be most useful for analyzing the logs to identify the attacking IP addresses?
Select an answer first - 3
A forensic investigator is called to respond to a suspected network intrusion. The organization's network team has already captured several hours of traffic and saved it to a shared drive. The investigator needs to ensure the evidence is admissible in court. What should the investigator do first?
Select an answer first - 4
An analyst is examining a packet capture and sees a large number of DNS queries for random subdomains under a single domain. The analyst suspects DNS tunneling. Which analysis technique would best confirm this?
Select an answer first - 5
A security analyst is investigating a suspected data exfiltration from a corporate network. The analyst has access to the organization's NetFlow records, DNS query logs, and a packet capture taken from the network perimeter during the suspected timeframe. Which approach would most effectively identify the destination of the exfiltrated data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.