CHFI Network and Cloud Forensics • Set 2
CHFI Network and Cloud Forensics Practice Test 2 — 15 questions with explanations. Free, no signup.
A forensic investigator is analyzing a compromised Linux web server. The server's network interface was in promiscuous mode, and a full packet capture was running via tcpdump when the attacker exfiltrated data over HTTPS. The investigator needs to determine the exact bytes transferred during the exfiltration session. Which artifact from the packet capture will BEST provide this information?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.