Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 3

Network Forensics ECSS Practice Questions (Page 4)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

50questions here
10free pages
11concepts

Questions 16–20

  1. 16foundation · easy

    Which tool is commonly used to capture network packets for forensic analysis?

    Select an answer first
  2. 17foundation · easy

    When investigating an intrusion, what is the primary value of IDS/IPS alerts?

    Select an answer first
  3. 18foundation · easy

    In a digital investigation, network forensics is most often used to:

    Select an answer first
  4. 19application · medium

    A forensic investigator needs to capture live network traffic from a critical server without disrupting operations. The server has multiple network interfaces, and the investigator wants to ensure that the capture includes all traffic to and from the server, including traffic that may be encrypted. Which tool and configuration would best meet this requirement?

    Select an answer first
  5. 20expert · hard

    A forensic investigator needs to capture network traffic on a high-throughput link (10 Gbps) during a suspected breach. The investigator has a laptop with a 1 Gbps network interface and limited storage. The goal is to preserve as much evidence as possible without dropping packets. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.