โ† All CHFI Flashcard Decks

Network Forensics Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Forensics flashcards as text
  1. What does the 'conversation' view in Wireshark primarily help an investigator accomplish?

    Answer: Identify all unique bidirectional communication pairs in a capture

    Wireshark's Conversations window displays all unique endpoint pairs communicating in the capture, showing statistics like packet counts and bytes exchanged per conversation.

  2. During investigation, an analyst finds that a system sent a DHCP request claiming to be a different device's MAC address. This attack is called:

    Answer: MAC spoofing

    MAC spoofing involves changing the source MAC address in frames to impersonate another device, which can be detected by comparing DHCP requests against switch MAC address tables.

  3. Which RFC defines the syslog protocol commonly used to collect network device logs for forensic analysis?

    Answer: RFC 5424

    RFC 5424 defines the current syslog protocol standard, specifying the format for system log messages used by network devices, servers, and security appliances.

  4. An investigator wants to determine all websites visited by a user using only proxy server logs. Which log field is most critical for this analysis?

    Answer: Requested URL or CONNECT hostname

    The requested URL or CONNECT hostname in proxy logs directly identifies which web resources the client accessed, making it the primary field for website visit reconstruction.

  5. What network forensics technique involves correlating traffic across multiple capture points to trace the path of an attacker through the network?

    Answer: Traffic path reconstruction

    Traffic path reconstruction correlates timestamps and connection metadata from multiple network taps or logs to trace how an attacker moved laterally through network segments.

  6. A sudden spike in outbound traffic on port 25 from a workstation not running a mail server most likely indicates:

    Answer: The workstation is part of a spam botnet

    Workstations unexpectedly generating SMTP traffic on port 25 are typically compromised and enrolled in a botnet being used to send spam email.

  7. Which analysis technique examines the timing intervals between network packets to identify covert communication channels even when content is encrypted?

    Answer: Traffic timing analysis / inter-arrival time analysis

    Traffic timing analysis examines inter-packet arrival times to detect patterns that may indicate covert channels where timing itself encodes information, bypassing content-level inspection.

Network Forensics Flashcards โ€” CHFI Study Cards with Answers