CDFI Network Forensics & Traffic Analysis Flashcards
6 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CDFI Network Forensics & Traffic Analysis flashcards as text
Which protocol uses port 443 and is commonly scrutinized in network forensics for tunneling malicious traffic?
Answer: HTTPS/TLS
HTTPS on port 443 is commonly abused by attackers to tunnel C2 traffic because it blends with legitimate encrypted web traffic and is rarely blocked.
What is the purpose of examining 'beaconing' patterns in network traffic during a forensic investigation?
Answer: Identifying malware that regularly contacts a C2 server at fixed intervals
Beaconing—regular, periodic outbound connections at consistent time intervals—is a hallmark of malware checking in with a command-and-control server.
During network forensics, what does analyzing 'TTL (Time to Live)' values help investigators determine?
Answer: The approximate number of network hops a packet traversed
TTL decrements by one at each router hop; by examining the TTL in captured packets, investigators can estimate how many network hops the traffic traveled.
What is 'flow analysis' in the context of network forensics?
Answer: Reviewing summarized metadata about network conversations without full packet contents
Flow analysis examines NetFlow/IPFIX metadata (source, destination, ports, bytes, duration) to detect anomalies without needing full packet payloads.
Which forensic artifact from a firewall is most valuable for reconstructing an attacker's lateral movement through a network?
Answer: Firewall connection logs showing accepted/denied traffic between internal hosts
Firewall connection logs record accepted and denied traffic between hosts, allowing investigators to trace an attacker's path as they moved laterally across the network.
In a CDFI investigation, what is the primary concern when using a 'man-in-the-middle' proxy to decrypt TLS traffic for analysis?
Answer: Legal and privacy authorization to intercept encrypted communications
Decrypting encrypted communications without proper legal authorization may violate wiretapping laws, so investigators must have explicit legal authorization before deploying MitM decryption.