Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A security analyst reviews firewall logs and sees repeated outbound connections from an internal server to an external IP on port 443. The server is not supposed to initiate outbound connections. Which action should the analyst take FIRST?

⚠ Common exam trap

Many exam-takers choose to block the IP immediately (Option A) or disable the server (Option C) without first investigating, failing to recognize that the CHFI methodology prioritizes evidence preservation and root cause analysis over immediate containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the server for signs of compromise

The server is exhibiting anomalous behavior by initiating outbound connections on port 443 (HTTPS) when it should not be doing so. This is a classic indicator of a potential compromise, such as a command-and-control (C2) callback or data exfiltration. The first priority is to investigate the server for signs of compromise to understand the scope and nature of the threat before taking any disruptive action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the external IP at the firewall

    Why it's wrong here

    Blocking the external IP at the firewall is a reactive containment step that may stop the immediate scanning, but it does not remediate any compromise that has already occurred. Evasion techniques such as IP spoofing, distributed source addresses, or anonymization proxies (e.g., Tor exit nodes) can bypass such a block, and the analyst loses visibility into follow-up activity. The correct first step is to determine whether the repeated connections indicate successful exploitation or merely reconnaissance.

  • ✗

    Ignore the traffic as it is encrypted

    Why it's wrong here

    Encrypted traffic cannot be treated as benign simply because its payload is opaque; modern malware and command-and-control (C2) channels routinely use TLS/HTTPS to conceal exfiltration and remote commands. Even without decryption, metadata such as connection frequency, payload size, destination reputation, and the server's internal logs can reveal malicious behavior. Ignoring the traffic would violate the fundamental security principle of verifying suspicious activity rather than dismissing it due to encryption.

  • ✗

    Disable the server's network connection

    Why it's wrong here

    Disconnecting the server from the network may be necessary in a confirmed active breach to prevent lateral movement, but doing so prematurely can destroy volatile evidence (e.g., memory contents, live processes, active network connections) and disrupt legitimate business services. It should be a deliberated decision made after preserving forensic data and after confirming that the server is indeed compromised. Without prior investigation, this action is both disruptive and potentially premature.

  • ✓

    Investigate the server for signs of compromise

    Why this is correct

    Investigating the server for signs of compromise is the appropriate first response to repeated connections, as it determines whether the external IP's activity has successfully exploited a vulnerability. This includes checking for unauthorized processes, anomalous registry entries, new user accounts, scheduled tasks, modified binaries, and indicators of compromise (IOCs) such as unusual outbound connections or file hashes. Establishing a baseline and correlating firewall logs with endpoint logs enables the analyst to identify the attack vector, scope, and appropriate remediation steps.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.