
EC-CouncilCertified Security Specialist
Domain 6Objective 3
Network Forensics ECSS Practice Questions (Page 7)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
50questions here
10free pages
11concepts
Questions 31–35
- 31
A security analyst is reviewing NetFlow records to identify a possible distributed denial-of-service (DDoS) attack. The analyst notices a large number of flows from many different source IPs to a single destination IP on port 80. Each flow has a low packet count and short duration. Which pattern in the flow data best supports the DDoS hypothesis?
Select an answer first - 32
What is the primary function of an Intrusion Detection System (IDS)?
Select an answer first - 33
During an incident response, a forensic investigator is correlating events from a firewall, a proxy server, and an IDS. The firewall logs show outbound connections to a suspicious IP, the proxy logs show HTTP requests to a malicious domain, and the IDS alerts show a signature match for a known exploit. The timestamps on the three devices differ by up to 30 seconds. What is the most important first step to ensure accurate correlation?
Select an answer first - 34
A forensic investigator has collected packet captures, firewall logs, and NetFlow records as evidence in a network intrusion case. The investigator must ensure the evidence is admissible in court. Which action is most critical to maintain the chain of custody?
Select an answer first - 35
A forensic investigator has collected network evidence from multiple sources, including packet captures, firewall logs, and IDS alerts. The investigator needs to present the evidence in court. The defense attorney challenges the authenticity of the evidence, claiming it could have been altered. Which practice would best support the authenticity of the evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.