Courseiva
OS and Network Forensics →hardMultiple Select

CHFI OS and Network Forensics Practice Question

A network forensic analyst is investigating a suspected data exfiltration incident. The analyst captures live traffic and wants to identify covert channels that might be used to transfer data out of the network. Which two of the following techniques are MOST likely to indicate a covert channel? (Choose two.)

⚠ Common exam trap

The trap here is focusing on common malicious activities like port scanning or suspicious HTTP traffic, while overlooking that covert channels specifically involve hiding data within allowed protocols such as DNS or ICMP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ICMP echo request packets with large payloads that contain non-standard data.

Covert channels often exploit protocols that are commonly allowed through firewalls, such as DNS and ICMP. Long, encoded DNS subdomains suggest DNS tunneling, while ICMP packets with large, non-standard payloads indicate ICMP tunneling. Both techniques can transfer data stealthily. The other options describe normal traffic or reconnaissance activities that do not involve hiding data within protocol fields.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ARP requests broadcast to the local subnet to resolve IP addresses to MAC addresses.

    Why it's wrong here

    ARP requests are normal network traffic used to resolve IP addresses to MAC addresses within a local subnet. They do not carry external data and are not used for exfiltration. While ARP spoofing can be malicious, the scenario describes standard ARP requests, which are benign. Covert channels typically exploit protocols that can carry payloads outside the local network, such as DNS or ICMP.

  • ✗

    TCP SYN packets sent to multiple ports on a single host during a port scan.

    Why it's wrong here

    TCP SYN packets to multiple ports indicate a port scan, which is a reconnaissance activity, not a covert channel for data exfiltration. While port scans are suspicious, they do not transfer data out of the network. The scenario focuses on data exfiltration, so port scanning is not the best indicator. Covert channels involve hiding data within allowed protocols, not probing for open ports.

  • ✓

    ICMP echo request packets with large payloads that contain non-standard data.

    Why this is correct

    ICMP tunneling can be used to exfiltrate data by embedding it in the payload of ICMP echo requests or replies. Legitimate ICMP packets typically have small, predictable payloads (e.g., 32 bytes of data). Large or non-standard payloads containing encoded data are a hallmark of ICMP covert channels. This allows attackers to bypass firewalls that permit ICMP but do not inspect payloads deeply.

  • ✓

    DNS queries with unusually long subdomains containing encoded data.

    Why this is correct

    DNS tunneling often uses long, random-looking subdomains to encode data in queries and responses. Attackers may exfiltrate data by encoding it in subdomain labels, which are then sent to an attacker-controlled authoritative DNS server. This technique bypasses many firewalls because DNS is often allowed. Unusually long subdomains with high entropy are a strong indicator of covert data transfer over DNS.

  • ✗

    HTTP POST requests to a known legitimate website with normal-sized payloads.

    Why it's wrong here

    Normal-sized HTTP POST requests to legitimate websites are common and typically benign. While data could be exfiltrated via HTTP POST, the scenario specifies normal-sized payloads, which do not suggest a covert channel. Covert channels often involve unusual patterns, such as large or encoded payloads. Without additional indicators like anomalous timing or encoding, this is not a likely covert channel.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.