
EC-CouncilCertified Security Specialist
Domain 6Objective 3
Network Forensics ECSS Practice Questions (Page 8)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
50questions here
10free pages
11concepts
Questions 36–40
- 36
A network administrator notices that a single internal host has been communicating with a remote server on port 443 at a steady rate of 2 Mbps for the past 72 hours. The host is a standard user workstation. NetFlow records confirm the traffic is continuous and bidirectional. Which type of activity does this pattern most likely indicate?
Select an answer first - 37
A network forensic analyst is examining a PCAP file and notices a series of TCP SYN packets sent to a single host on consecutive ports (1, 2, 3, ...) with no corresponding SYN-ACK replies. Which attack pattern does this represent?
Select an answer first - 38
An investigator needs to analyze a large PCAP file to extract all HTTP requests that contain the string 'password' in the URI. Which tool is most appropriate for this task?
Select an answer first - 39
A security analyst is investigating a possible malware infection that communicates with a command-and-control (C2) server. The analyst has access to firewall logs, proxy logs, DNS logs, and NetFlow data. Which combination of evidence sources would provide the most complete picture of the C2 communication?
Select an answer first - 40
A forensic investigator is analyzing a packet capture from a compromised host. The capture shows a TCP connection to an external IP on port 4444. The payload appears to be encrypted, but the investigator notices that the connection was initiated shortly after the host received a phishing email. The investigator suspects a reverse shell. Which additional evidence in the packet capture would most strongly confirm the reverse shell hypothesis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.