
EC-CouncilDigital Forensics Essentials
Domain 5Objective 1
Network Forensics Fundamentals DFE Practice Questions (Page 8)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
6concepts
Questions 36–40
- 36
A network administrator is investigating a security incident where an attacker used a compromised account to access a file server. The administrator wants to determine the source IP address of the attacker. Which evidence source would provide this information?
Select an answer first - 37
In which scenario would network forensics be most directly applied?
Select an answer first - 38
A company's legal team asks the IT department to provide evidence of a former employee's unauthorized access to the network after termination. The IT department has access to the VPN logs, firewall logs, and the employee's workstation logs. What is the best way to present this evidence?
Select an answer first - 39
A company suspects that an employee is using an unauthorized remote access tool to connect to the internal network from home. The security team wants to determine whether any such connections occurred and when. Which combination of evidence sources would provide the most reliable answer?
Select an answer first - 40
A forensic analyst is investigating a data breach that occurred over a period of several months. The organization's network traffic is encrypted, and the analyst only has access to netflow data and firewall logs, not full packet captures. The analyst needs to identify which internal hosts communicated with a known malicious IP. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.