Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 1

Network Forensics Fundamentals DFE Practice Questions (Page 6)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

51questions here
11free pages
6concepts

Questions 26–30

  1. 26expert · hard

    A forensic team is investigating a breach that occurred over a weekend. The organization's network uses dynamic IP assignment for internal hosts, and the DHCP logs were not retained. The team has packet captures from the core switch, but the captures only show IP addresses, not hostnames. What is the most significant challenge this presents, and what is the best way to address it?

    Select an answer first
  2. 27application · medium

    An analyst is investigating a possible command-and-control (C2) communication. The analyst notices regular, periodic connections to an external IP address on a non-standard port. The connections are short and use a small amount of data. Which analysis technique would best help confirm this is C2 traffic?

    Select an answer first
  3. 28application · medium

    A network forensic analyst needs to capture traffic on a high-speed link without dropping packets. The analyst also needs to save the captures for later analysis. Which tool or approach is best suited for this task?

    Select an answer first
  4. 29expert · hard

    A forensic investigator is analyzing network traffic from a compromised host that used a VPN to communicate with a C2 server. The VPN traffic is encrypted, and the investigator does not have the VPN keys. Which approach would be most effective in identifying the C2 server's IP address?

    Select an answer first
  5. 30expert · hard

    A forensic analyst is investigating a data breach that involved a web application. The analyst has access to the web server logs, the application logs, and a packet capture of the attack traffic. Which approach would best reconstruct the attack timeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.