โ† All CCE Flashcard Decks

CCE Network Forensics & Investigations Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCE Network Forensics & Investigations flashcards as text
  1. During a network investigation, an examiner finds traffic on port 4444. This is commonly associated with which tool?

    Answer: Metasploit Meterpreter default listener

    Port 4444 is the default listening port for Metasploit's Meterpreter payload and is a common indicator of compromise in forensic investigations.

  2. What does TTL (Time to Live) manipulation in network packets potentially indicate to a forensic examiner?

    Answer: Possible OS fingerprinting evasion or firewall bypass attempts

    Abnormal TTL values can indicate OS fingerprinting evasion, firewall bypass techniques, or packet crafting by an attacker.

  3. In network forensics, what is a 'pivot' host?

    Answer: A compromised system used as a relay to attack internal network resources

    A pivot host is a compromised system that attackers use as a launching point to reach other network segments or systems that are not directly accessible.

  4. Which type of log would a CCE examiner most likely review to determine whether an attacker exfiltrated data via HTTP?

    Answer: Web proxy or web server access logs

    Web proxy and server access logs record HTTP/HTTPS requests, URLs, user agents, response codes, and transferred bytes useful for detecting data exfiltration.

  5. What is DNS tunneling, and why is it significant in CCE investigations?

    Answer: Encoding data within DNS queries/responses to covertly exfiltrate data or establish C2 channels

    DNS tunneling encodes arbitrary data within DNS traffic to bypass firewalls and exfiltrate data or communicate with command-and-control servers covertly.

  6. An examiner captures HTTPS traffic in a corporate environment and cannot read the payload. What is the most forensically sound approach to decrypt this traffic?

    Answer: Obtain the server's private key or pre-master secret log from the server's TLS configuration

    With access to the server's private key or the pre-master secret log (e.g., from a corporate SSL inspection proxy), investigators can decrypt TLS traffic in tools like Wireshark.