Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A security team detects exfiltration via HTTP POST requests to a suspicious domain. Which network forensic technique would BEST identify the data being sent in these requests?

⚠ Common exam trap

It's easy for candidates to choose NetFlow analysis (Option D) because they confuse flow-level metadata with full packet capture, not realizing that NetFlow cannot reconstruct payload content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wireshark packet capture with HTTP follow stream

Wireshark packet capture with HTTP follow stream allows the investigator to reassemble the full HTTP conversation, including the body of POST requests. By following the TCP stream, the exact payload (e.g., exfiltrated data) is reconstructed in plain text, making it the best technique to identify the data being sent. This method directly captures and decodes the application-layer content, unlike log-based or flow-based analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall log review

    Why it's wrong here

    Firewall logs are connection-level records that capture the five-tuple (source/destination IP and port, protocol), timestamp, and action, but not the application-layer HTTP POST body. They can show that a host communicated with an external IP over TCP/80, but cannot reveal the data being exfiltrated in the request. This makes them useful for situational awareness, not for proving what data left the network.

  • ✗

    IDS alert correlation

    Why it's wrong here

    An IDS can perform deep packet inspection and generate an alert when it sees a suspicious HTTP POST, but it stores only the alert metadata and at most a few captured bytes from the triggering packet, not the full reassembled session. Even with alert correlation across sensors, you get a picture of 'potential exfiltration' rather than the actual POST payload. Full stream extraction requires a separate capture or a full-content log with proper TCP reassembly.

  • ✓

    Wireshark packet capture with HTTP follow stream

    Why this is correct

    Wireshark performs full packet capture at the NIC and saves complete frames, including TCP payloads. Its 'Follow HTTP Stream' feature reassembles individual TCP segments in sequence order and applies HTTP decoding, presenting the entire POST body — e.g., a form field, file content, or encrypted data — in plaintext or raw hex. This is the only option listed that provides direct, forensic-grade evidence of what was transmitted in the exfiltration POST. (Note that capturing must occur on the affected segment; if HTTPS, TLS decryption requires keys.)

  • ✗

    NetFlow analysis

    Why it's wrong here

    NetFlow (or IPFIX) exports aggregated flow records that contain only metadata — source/dest IP, ports, protocol, packets, bytes, and timestamps — never the HTTP request content. It might flag an unusually large or long-lived POST to a suspicious destination, but cannot confirm that data was harvested. This is flow-level visibility, not content-level evidence.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.