← All CDFI Flashcard Decks

CDFI Network Forensics & Traffic Analysis Flashcards

6 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CDFI Network Forensics & Traffic Analysis flashcards as text
  1. Which log source is BEST for correlating multiple network events across an enterprise during a forensic investigation?

    Answer: SIEM (Security Information and Event Management) system

    A SIEM aggregates and correlates logs from multiple sources enterprise-wide, making it the best tool for building a timeline of network-based incidents.

  2. What is 'IP geolocation' used for in network forensics?

    Answer: Estimating the physical location of an IP address

    IP geolocation maps an IP address to an approximate geographic location, helping investigators identify the origin of malicious traffic.

  3. When investigating a potential data exfiltration event, which traffic characteristic is most suspicious?

    Answer: Large outbound transfers to unknown external IPs at night

    Large outbound data transfers to unknown IPs during off-hours is a classic indicator of data exfiltration that warrants deep forensic investigation.

  4. Which technique allows a forensic investigator to reassemble fragmented IP packets for analysis?

    Answer: Packet defragmentation

    Packet defragmentation reassembles split IP datagrams in the correct order so investigators can examine the complete payload of transmitted data.

  5. What does TLS/SSL decryption capability allow a forensic investigator to do during network analysis?

    Answer: Inspect the plaintext content of encrypted sessions

    With access to private keys or using a MITM proxy, TLS decryption lets investigators read the actual plaintext content of otherwise encrypted communications.

  6. In network forensics, what is the significance of a 'golden ticket' attack in Kerberos traffic logs?

    Answer: It means an attacker forged a Kerberos TGT for persistent unauthorized access

    A golden ticket attack involves forging a Kerberos Ticket Granting Ticket using a stolen KRBTGT hash, granting attackers long-term, stealthy domain access.