CCE Network Forensics & Investigations Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCE Network Forensics & Investigations flashcards as text
Which protocol captures full packet data at the network level and is commonly analyzed in network forensics investigations?
Answer: PCAP (Packet Capture)
PCAP files store full packet data captured from network interfaces and are the standard format analyzed by tools like Wireshark in network forensics.
In network forensics, what does a NetFlow record primarily capture?
Answer: Metadata about traffic flows between endpoints
NetFlow records capture metadata such as source/destination IPs, ports, protocol, and byte counts without storing full packet contents.
Which layer of the OSI model do MAC addresses belong to, and why is this relevant to network forensics?
Answer: Layer 2 – Data Link
MAC addresses operate at Layer 2 (Data Link) and can help investigators identify specific network interface cards involved in an incident.
An investigator observes a large volume of outbound DNS queries to randomly generated domain names. This pattern most likely indicates:
Answer: Domain Generation Algorithm (DGA) malware activity
Domain Generation Algorithms (DGAs) are used by malware to generate pseudo-random domain names to contact command-and-control servers while evading blacklists.
Which tool is most appropriate for reconstructing TCP sessions from a PCAP file during a network forensics investigation?
Answer: Wireshark (Follow TCP Stream)
Wireshark's 'Follow TCP Stream' feature reassembles the full conversation from individual TCP packets for analysis.
What is the primary purpose of analyzing DHCP logs in a network forensics investigation?
Answer: To correlate IP addresses with MAC addresses at specific times
DHCP logs record which MAC address was assigned which IP address and when, enabling investigators to link network activity to a physical device.