
EC-CouncilCertified Security Specialist
Domain 6Objective 3
Network Forensics ECSS Practice Questions (Page 5)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
50questions here
10free pages
11concepts
Questions 21–25
- 21
A security analyst is investigating a suspected data exfiltration from a corporate web server. The analyst has access to the server's access logs and a packet capture taken from the server's network interface during the incident window. The analyst wants to determine whether the exfiltration used HTTPS or a covert tunnel over DNS. Which approach would most directly answer this question?
Select an answer first - 22
What is the primary purpose of maintaining a chain of custody for network evidence?
Select an answer first - 23
A small company has experienced a security breach. The only network evidence available is the firewall logs and a partial packet capture from a single switch. The company does not have a SIEM or centralized logging. The investigator needs to reconstruct the attack path. What is the most significant limitation of this evidence?
Select an answer first - 24
An investigator has captured a PCAP file that is 50 GB in size. The investigator needs to preserve the evidence for a court case that may take months to resolve. The storage budget is limited. Which approach best balances the need for integrity and cost?
Select an answer first - 25
Which of the following is a forensically sound practice when preserving network evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.