ACI Network Forensics & Incident Response Flashcards
6 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 ACI Network Forensics & Incident Response flashcards as text
During a network forensics investigation, which type of log is most useful for reconstructing the timeline of a security breach?
Answer: Firewall and IDS/IPS logs
Firewall and IDS/IPS logs capture network traffic events with timestamps, making them essential for timeline reconstruction during a breach investigation.
What is the primary purpose of capturing a memory dump at the start of an incident response investigation?
Answer: To preserve volatile data such as running processes and network connections
Memory dumps preserve volatile artifacts like active processes, open network sockets, and decrypted data that are lost when a system is powered off.
In FTK, which feature allows an investigator to examine network packet captures alongside file system evidence?
Answer: Evidence Tree integration with PCAP parsing
FTK's evidence integration allows PCAP files to be parsed and examined alongside file system artifacts within the same case.
Which protocol is most commonly analyzed to identify data exfiltration over encrypted channels during a network forensics review?
Answer: HTTPS/TLS
Attackers frequently use HTTPS/TLS to blend exfiltration traffic with legitimate encrypted web traffic, making TLS metadata analysis critical.
During incident response, what is the correct order of evidence collection per the order of volatility?
Answer: CPU registers, memory, network state, hard drive
The order of volatility dictates collecting the most transient data first: CPU registers and cache → memory → network state → disk.
What does an abnormally high volume of DNS queries to a single external domain indicate during a network investigation?
Answer: Possible DNS tunneling or command-and-control communication
Excessive DNS queries to one domain are a hallmark of DNS tunneling, where attackers encode C2 communications or exfiltrated data in DNS requests.