
EC-CouncilDigital Forensics Essentials
Domain 5Objective 1
Network Forensics Fundamentals DFE Practice Questions (Page 5)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
6concepts
Questions 21–25
- 21
Which activity is an example of analyzing network traffic to detect malicious activity?
Select an answer first - 22
A security analyst needs to review historical network traffic to identify patterns of communication with a known malicious domain. The analyst has access to the organization's DNS logs and netflow data. Which tool would be most appropriate for correlating these logs to find the internal hosts that communicated with the domain?
Select an answer first - 23
Which of the following is a significant challenge in network forensics?
Select an answer first - 24
During an incident response, a network administrator discovers that an attacker has been using SSH to move laterally between Linux servers. The administrator wants to preserve evidence for a forensic investigation. Which action best aligns with the preservation step of the network forensic process?
Select an answer first - 25
A forensic analyst is investigating a distributed denial-of-service (DDoS) attack that occurred over a 48-hour period. The network team captured traffic at the perimeter, but the volume is enormous, and the analyst has limited time to identify the attack patterns. The analyst must also preserve evidence for potential legal action. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.