CDFI Network Forensics & Traffic Analysis Flashcards
6 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CDFI Network Forensics & Traffic Analysis flashcards as text
Which log source is BEST for correlating multiple network events across an enterprise during a forensic investigation?
Answer: SIEM (Security Information and Event Management) system
A SIEM aggregates and correlates logs from multiple sources enterprise-wide, making it the best tool for building a timeline of network-based incidents.
What is 'IP geolocation' used for in network forensics?
Answer: Estimating the physical location of an IP address
IP geolocation maps an IP address to an approximate geographic location, helping investigators identify the origin of malicious traffic.
When investigating a potential data exfiltration event, which traffic characteristic is most suspicious?
Answer: Large outbound transfers to unknown external IPs at night
Large outbound data transfers to unknown IPs during off-hours is a classic indicator of data exfiltration that warrants deep forensic investigation.
Which technique allows a forensic investigator to reassemble fragmented IP packets for analysis?
Answer: Packet defragmentation
Packet defragmentation reassembles split IP datagrams in the correct order so investigators can examine the complete payload of transmitted data.
What does TLS/SSL decryption capability allow a forensic investigator to do during network analysis?
Answer: Inspect the plaintext content of encrypted sessions
With access to private keys or using a MITM proxy, TLS decryption lets investigators read the actual plaintext content of otherwise encrypted communications.
In network forensics, what is the significance of a 'golden ticket' attack in Kerberos traffic logs?
Answer: It means an attacker forged a Kerberos TGT for persistent unauthorized access
A golden ticket attack involves forging a Kerberos Ticket Granting Ticket using a stolen KRBTGT hash, granting attackers long-term, stealthy domain access.