CDFI Network Forensics & Traffic Analysis Flashcards
6 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CDFI Network Forensics & Traffic Analysis flashcards as text
Which protocol is most commonly analyzed in network forensics to reconstruct TCP session data?
Answer: TCP
TCP is the primary protocol analyzed in network forensics because its three-way handshake and sequencing allow investigators to reconstruct complete sessions.
What tool is widely used by CDFI investigators to capture and analyze live network traffic packets?
Answer: Wireshark
Wireshark is the industry-standard open-source packet analyzer used to capture and inspect live and recorded network traffic during forensic investigations.
In network forensics, what does a 'pcap' file contain?
Answer: Raw captured network packets
A pcap (packet capture) file stores raw network packet data recorded from an interface, allowing forensic replay and analysis of network activity.
Which NetFlow data element is most useful for identifying the volume of data transferred between two hosts?
Answer: Byte count
The byte count field in NetFlow records indicates the total bytes transferred in a flow, which is key to detecting data exfiltration.
What is the primary purpose of analyzing DNS logs during a digital forensic investigation?
Answer: Identifying C2 communication and domain lookups
DNS logs reveal which domains hosts queried, helping investigators identify command-and-control servers, phishing domains, and data exfiltration channels.
During a network forensic investigation, a 'SYN flood' pattern in captured traffic most likely indicates which type of activity?
Answer: A denial-of-service attack
A SYN flood—many TCP SYN packets without corresponding ACKs—is a classic signature of a denial-of-service attack designed to exhaust server resources.