โ† All CHFI Flashcard Decks

Network Forensics Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Forensics flashcards as text
  1. Which log source would provide the most reliable evidence of an internal host performing port scanning?

    Answer: Firewall or IDS/IPS logs showing repeated connection attempts

    Firewall and IDS/IPS logs capture connection attempts across multiple ports and IPs, making them the best source for identifying port scanning activity.

  2. What does a high number of RST packets from a single source typically indicate during forensic analysis?

    Answer: A port scan where the scanner receives RST responses from closed ports

    TCP RST packets in response to connection attempts indicate closed ports; many RSTs from one target in response to one scanner suggest a port scanning probe.

  3. In HTTPS traffic analysis, what information CAN be obtained without decrypting the traffic?

    Answer: Server Name Indication (SNI) hostname

    SNI is transmitted in plaintext during the TLS handshake, revealing the target hostname even when payload content remains encrypted.

  4. A forensic analyst is examining Zeek (Bro) logs. Which log file contains records of all DNS queries and responses observed on the network?

    Answer: dns.log

    Zeek's dns.log records all DNS transaction details including query names, types, responses, and TTL values observed on the network.

  5. What is the forensic significance of identifying a 'long tail' domain (very low query frequency) in DNS logs?

    Answer: It may indicate a dynamically generated domain used by malware (DGA)

    Domain Generation Algorithm (DGA) malware produces rarely-seen algorithmically generated domains; these appear as 'long tail' entries with very low query counts in DNS logs.

  6. Which command-line tool is used to display active network connections and their associated process IDs on a Windows system?

    Answer: netstat -ano

    `netstat -ano` shows all active TCP/UDP connections, listening ports, and the PID of the owning process on Windows systems.

  7. When analyzing a suspect's network traffic, an investigator observes large ICMP packets with payloads containing structured data. This suggests:

    Answer: ICMP tunneling for covert data exfiltration

    ICMP tunneling embeds data inside ICMP echo request/reply payloads, exploiting protocols often allowed through firewalls to create a covert communication channel.