โ† All CCE Flashcard Decks

CCE Network Forensics & Investigations Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCE Network Forensics & Investigations flashcards as text
  1. Which RFC defines the Syslog protocol commonly used for collecting log data from network devices during an investigation?

    Answer: RFC 5424

    RFC 5424 defines the Syslog protocol used by network devices to forward log messages to a centralized log server for analysis.

  2. Why is time synchronization (NTP) critical when performing network forensics across multiple devices?

    Answer: It ensures log timestamps are consistent, allowing accurate event correlation

    Consistent timestamps across devices are essential for building an accurate timeline; without NTP synchronization, logs from different systems cannot be reliably correlated.

  3. What is an ARP poisoning attack, and what evidence would indicate it in network forensic analysis?

    Answer: An attack mapping a fake MAC to a legitimate IP; evidenced by duplicate ARP replies in packet captures

    ARP poisoning maps an attacker's MAC address to a victim's IP, enabling MITM attacks; this appears as duplicate/conflicting ARP replies in packet captures.

  4. In the context of CCE network investigations, what is the significance of analyzing firewall 'DENY' logs?

    Answer: They can reveal reconnaissance activity, blocked exfiltration attempts, or lateral movement

    Firewall DENY logs record blocked connection attempts, which can reveal port scans, blocked data exfiltration, or attacker attempts to reach restricted network segments.

  5. A CCE examiner finds a large number of ICMP echo requests from one internal host to many IP addresses in rapid succession. This most likely indicates:

    Answer: Network reconnaissance or ping sweep activity

    A ping sweep involves sending ICMP echo requests to many IPs to discover live hosts, which is a common first step in network reconnaissance by attackers.

  6. Which network forensic artifact would best help determine if a user connected to an unauthorized external VPN service?

    Answer: Firewall logs showing outbound connections on VPN ports (e.g., UDP 1194 for OpenVPN)

    Firewall logs showing outbound UDP 1194 (OpenVPN), TCP 1723 (PPTP), or other VPN protocol ports to external IPs indicate unauthorized VPN usage.