ACI Network Forensics & Incident Response Flashcards
6 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 ACI Network Forensics & Incident Response flashcards as text
Which FTK Imager option should be used to create a forensically sound image of a live system's network share without powering it down?
Answer: Add Evidence Item using a logical evidence file
Adding a logical evidence item allows FTK Imager to capture files from a live network share without requiring the host system to be shut down.
During a network intrusion investigation, what is the significance of identifying a 'beaconing' pattern in firewall logs?
Answer: It suggests malware is periodically checking in with a C2 server
Beaconing—regular, timed outbound connections—strongly indicates malware performing periodic check-ins with a command-and-control server.
An investigator finds encrypted ZIP files on a suspect's machine that were sent over a corporate email server. What should be the first forensic step?
Answer: Image the system and preserve the email server logs before attempting decryption
Imaging the system and preserving email server logs ensures evidence integrity before any decryption attempts that could alter the evidence state.
What is lateral movement in the context of incident response investigations?
Answer: An attacker expanding access from one compromised system to others on the same network
Lateral movement describes how attackers pivot from an initial foothold to additional systems on the internal network to expand their access.
Which Windows artifact is most useful for detecting remote desktop protocol (RDP) connections to or from a suspect machine?
Answer: Event logs (specifically Event ID 4624/4625 and TerminalServices-RemoteConnectionManager)
Windows Event IDs 4624/4625 record logon events, and the TerminalServices-RemoteConnectionManager log specifically records RDP session details.
In a corporate incident response scenario, what is the purpose of network segmentation as a containment strategy?
Answer: To isolate compromised systems and prevent lateral spread of an attack
Network segmentation during containment isolates compromised hosts, limiting the attacker's ability to move laterally to other systems.