โ† All CHFI Flashcard Decks

Network Forensics Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Forensics flashcards as text
  1. In the context of wireless network forensics, what does a 'deauthentication flood' attack leave as evidence in wireless packet captures?

    Answer: High volume of deauthentication frames from a spoofed BSSID

    A deauthentication flood generates massive quantities of 802.11 deauth management frames with a spoofed source BSSID, forcing clients offline; these frames are clearly visible in wireless captures.

  2. Which network forensics artifact would best help an investigator determine the exact time a specific external IP address first communicated with an internal host?

    Answer: Firewall log timestamps for the first allowed session

    Firewall logs record timestamped allow/deny decisions for every connection attempt, providing the most reliable record of when external communication with an internal host first occurred.

  3. What is 'passive OS fingerprinting' in network forensics?

    Answer: Identifying operating systems by analyzing characteristics of traffic they generate without sending probes

    Passive OS fingerprinting identifies remote operating systems by analyzing observable TCP/IP stack characteristics (TTL values, TCP window sizes, flag combinations) in captured traffic without generating any probe traffic.

  4. An analyst captures traffic and notices that HTTP responses contain an unusually large number of Set-Cookie headers with random-looking values. This may indicate:

    Answer: Cookie-based data exfiltration or C2 channel using HTTP

    Malware can use HTTP cookies to smuggle data and commands between compromised hosts and C2 servers, with encoded payloads embedded in seemingly legitimate cookie values.

  5. Which forensic evidence would confirm that a VPN tunnel was established between two hosts, even if the tunneled content is encrypted?

    Answer: Presence of encapsulating protocols such as GRE, ESP, or OpenVPN's UDP traffic on known VPN ports

    VPN protocols leave identifiable traces such as ESP (IPsec), GRE encapsulation headers, or UDP traffic on well-known VPN ports (e.g., 1194 for OpenVPN, 500/4500 for IKE) even when payload is encrypted.

  6. During investigation of a data breach, an analyst finds large volumes of traffic to a cloud storage IP during off-hours. What forensic step should be taken next?

    Answer: Correlate the traffic with user authentication logs to identify which account or process initiated the transfers

    Correlating suspicious network traffic with authentication and process logs identifies the specific user account or process responsible for the transfers, establishing attribution before taking remediation steps.

  7. What is the purpose of analyzing 'flow records' with a tool like nfdump in a network forensics investigation?

    Answer: Querying and filtering large volumes of NetFlow data to identify anomalous traffic patterns

    nfdump is a command-line tool for reading, filtering, and aggregating NetFlow records stored by nfcapd, enabling investigators to query large traffic datasets for anomalous flows without processing full packet captures.