CHFI OS and Network Forensics • Set 9
CHFI OS and Network Forensics Practice Test 9 — 15 questions with explanations. Free, no signup.
During a network forensic investigation, the analyst examines firewall logs and notices a large number of outbound connections from an internal server to various IP addresses on port 443 at regular intervals. The connections are all initiated by a process called 'svchost.exe' running from a non-standard location (C:\Windows\Temp). What is the MOST likely explanation?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.