โ† All CHFI Flashcard Decks

Network Forensics Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Forensics flashcards as text
  1. Which protocol is primarily analyzed when investigating DNS-based data exfiltration attacks?

    Answer: DNS

    DNS tunneling encodes data within DNS query/response payloads to exfiltrate data, making DNS traffic the primary focus of such investigations.

  2. A forensic investigator captures a packet with TTL value of 1. What does this most likely indicate?

    Answer: The packet was crafted to expire after one hop

    A TTL of 1 means the packet will be dropped after crossing one router, often seen in traceroute probes or deliberately crafted reconnaissance packets.

  3. Which Wireshark display filter would isolate only TCP SYN packets without ACK flags?

    Answer: tcp.flags.syn == 1 && tcp.flags.ack == 0

    The filter `tcp.flags.syn == 1 && tcp.flags.ack == 0` precisely isolates TCP SYN packets that initiate connections without an acknowledgment flag.

  4. During a network forensics investigation, an analyst notices many short-duration flows to a single external IP. This pattern is most consistent with:

    Answer: Beaconing malware behavior

    Regular short-duration connections to a single external IP at consistent intervals are a hallmark of malware beaconing for command-and-control communication.

  5. What is the primary purpose of NetFlow data in network forensics?

    Answer: Providing summarized metadata about network traffic flows

    NetFlow records summarize traffic flow metadata (source/destination IPs, ports, byte counts, timestamps) without capturing full payloads, enabling efficient large-scale traffic analysis.

  6. An investigator finds ARP replies with no preceding ARP request in a packet capture. This is a sign of:

    Answer: ARP cache poisoning

    Unsolicited ARP replies (gratuitous ARP) sent by an attacker are the primary mechanism of ARP cache poisoning, used to associate the attacker's MAC with a legitimate IP.

  7. Which tool is specifically designed for reconstructing TCP streams from packet captures to recover transferred files?

    Answer: NetworkMiner

    NetworkMiner passively captures packets and automatically reassembles TCP streams to extract transferred files, credentials, and messages from network traffic.