
EC-CouncilDigital Forensics Essentials
Domain 5Objective 1
Network Forensics Fundamentals DFE Practice Questions (Page 4)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
6concepts
Questions 16–20
- 16
A network administrator is investigating a possible malware infection that is using DNS tunneling to exfiltrate data. Which evidence source would be most useful in detecting this activity?
Select an answer first - 17
An organization uses a network intrusion detection system (IDS) that generates alerts based on signature matching. The IDS has been missing some attacks because the attackers are using encryption and fragmentation. Which additional technique would most improve the detection of these evasive attacks?
Select an answer first - 18
Which step in the network forensic process involves ensuring that captured evidence is protected from alteration or destruction?
Select an answer first - 19
A network administrator is responding to a suspected malware infection that is beaconing to an external IP. The administrator wants to collect evidence that will help identify the malware's command-and-control (C2) traffic. Which evidence source would be most useful for this purpose?
Select an answer first - 20
A small company suspects that an employee is using the corporate network to upload proprietary source code to a personal cloud storage service. The IT manager wants to determine whether the upload actually occurred and, if so, what data was sent. Which combination of network forensic activities would best achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.