Network Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Forensics flashcards as text
Which log source would provide the most reliable evidence of an internal host performing port scanning?
Answer: Firewall or IDS/IPS logs showing repeated connection attempts
Firewall and IDS/IPS logs capture connection attempts across multiple ports and IPs, making them the best source for identifying port scanning activity.
What does a high number of RST packets from a single source typically indicate during forensic analysis?
Answer: A port scan where the scanner receives RST responses from closed ports
TCP RST packets in response to connection attempts indicate closed ports; many RSTs from one target in response to one scanner suggest a port scanning probe.
In HTTPS traffic analysis, what information CAN be obtained without decrypting the traffic?
Answer: Server Name Indication (SNI) hostname
SNI is transmitted in plaintext during the TLS handshake, revealing the target hostname even when payload content remains encrypted.
A forensic analyst is examining Zeek (Bro) logs. Which log file contains records of all DNS queries and responses observed on the network?
Answer: dns.log
Zeek's dns.log records all DNS transaction details including query names, types, responses, and TTL values observed on the network.
What is the forensic significance of identifying a 'long tail' domain (very low query frequency) in DNS logs?
Answer: It may indicate a dynamically generated domain used by malware (DGA)
Domain Generation Algorithm (DGA) malware produces rarely-seen algorithmically generated domains; these appear as 'long tail' entries with very low query counts in DNS logs.
Which command-line tool is used to display active network connections and their associated process IDs on a Windows system?
Answer: netstat -ano
`netstat -ano` shows all active TCP/UDP connections, listening ports, and the PID of the owning process on Windows systems.
When analyzing a suspect's network traffic, an investigator observes large ICMP packets with payloads containing structured data. This suggests:
Answer: ICMP tunneling for covert data exfiltration
ICMP tunneling embeds data inside ICMP echo request/reply payloads, exploiting protocols often allowed through firewalls to create a covert communication channel.