
EC-CouncilDigital Forensics Essentials
Domain 5Objective 1
Network Forensics Fundamentals DFE Practice Questions (Page 3)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
6concepts
Questions 11–15
- 11
A small business has been the victim of a ransomware attack. The IT administrator wants to understand how the ransomware entered the network. The administrator has access to the firewall logs, email gateway logs, and a packet capture from the time of the attack. What is the best way to determine the entry vector?
Select an answer first - 12
Which tool is commonly used for packet capture in network forensics?
Select an answer first - 13
A forensic investigator is analyzing a network capture from a compromised server that communicated with a command-and-control (C2) server over HTTPS. The investigator has the server's private key. Which approach would allow the investigator to decrypt and analyze the C2 traffic?
Select an answer first - 14
During an investigation of a network breach, the forensic team discovers that the attacker used TLS-encrypted communications to an internal server. The team has full packet captures from the perimeter, but the sessions are encrypted. The organization uses a proxy that can decrypt TLS traffic, but the proxy logs were not retained for the incident period. What is the most practical next step to obtain the plaintext of the encrypted sessions?
Select an answer first - 15
Why is the high volume of network data a challenge in network forensics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.