CCE Network Forensics & Investigations Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCE Network Forensics & Investigations flashcards as text
During a network investigation, an examiner finds traffic on port 4444. This is commonly associated with which tool?
Answer: Metasploit Meterpreter default listener
Port 4444 is the default listening port for Metasploit's Meterpreter payload and is a common indicator of compromise in forensic investigations.
What does TTL (Time to Live) manipulation in network packets potentially indicate to a forensic examiner?
Answer: Possible OS fingerprinting evasion or firewall bypass attempts
Abnormal TTL values can indicate OS fingerprinting evasion, firewall bypass techniques, or packet crafting by an attacker.
In network forensics, what is a 'pivot' host?
Answer: A compromised system used as a relay to attack internal network resources
A pivot host is a compromised system that attackers use as a launching point to reach other network segments or systems that are not directly accessible.
Which type of log would a CCE examiner most likely review to determine whether an attacker exfiltrated data via HTTP?
Answer: Web proxy or web server access logs
Web proxy and server access logs record HTTP/HTTPS requests, URLs, user agents, response codes, and transferred bytes useful for detecting data exfiltration.
What is DNS tunneling, and why is it significant in CCE investigations?
Answer: Encoding data within DNS queries/responses to covertly exfiltrate data or establish C2 channels
DNS tunneling encodes arbitrary data within DNS traffic to bypass firewalls and exfiltrate data or communicate with command-and-control servers covertly.
An examiner captures HTTPS traffic in a corporate environment and cannot read the payload. What is the most forensically sound approach to decrypt this traffic?
Answer: Obtain the server's private key or pre-master secret log from the server's TLS configuration
With access to the server's private key or the pre-master secret log (e.g., from a corporate SSL inspection proxy), investigators can decrypt TLS traffic in tools like Wireshark.