Network Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Forensics flashcards as text
What does the 'conversation' view in Wireshark primarily help an investigator accomplish?
Answer: Identify all unique bidirectional communication pairs in a capture
Wireshark's Conversations window displays all unique endpoint pairs communicating in the capture, showing statistics like packet counts and bytes exchanged per conversation.
During investigation, an analyst finds that a system sent a DHCP request claiming to be a different device's MAC address. This attack is called:
Answer: MAC spoofing
MAC spoofing involves changing the source MAC address in frames to impersonate another device, which can be detected by comparing DHCP requests against switch MAC address tables.
Which RFC defines the syslog protocol commonly used to collect network device logs for forensic analysis?
Answer: RFC 5424
RFC 5424 defines the current syslog protocol standard, specifying the format for system log messages used by network devices, servers, and security appliances.
An investigator wants to determine all websites visited by a user using only proxy server logs. Which log field is most critical for this analysis?
Answer: Requested URL or CONNECT hostname
The requested URL or CONNECT hostname in proxy logs directly identifies which web resources the client accessed, making it the primary field for website visit reconstruction.
What network forensics technique involves correlating traffic across multiple capture points to trace the path of an attacker through the network?
Answer: Traffic path reconstruction
Traffic path reconstruction correlates timestamps and connection metadata from multiple network taps or logs to trace how an attacker moved laterally through network segments.
A sudden spike in outbound traffic on port 25 from a workstation not running a mail server most likely indicates:
Answer: The workstation is part of a spam botnet
Workstations unexpectedly generating SMTP traffic on port 25 are typically compromised and enrolled in a botnet being used to send spam email.
Which analysis technique examines the timing intervals between network packets to identify covert communication channels even when content is encrypted?
Answer: Traffic timing analysis / inter-arrival time analysis
Traffic timing analysis examines inter-packet arrival times to detect patterns that may indicate covert channels where timing itself encodes information, bypassing content-level inspection.