CHFI OS and Network Forensics Practice Question
An analyst captures network traffic during an incident and wants to extract files transferred over HTTP. Which Wireshark feature is BEST suited for this task?
⚠ Common exam trap
Many exam-takers confuse 'Follow TCP Stream' (which shows raw data) with a file extraction tool, not realizing that 'Export Objects > HTTP' is the dedicated feature for extracting files from HTTP traffic in Wireshark.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Export Objects > HTTP
Wireshark's 'Export Objects > HTTP' feature is specifically designed to extract files (e.g., images, documents, executables) transferred over HTTP by reassembling the TCP streams and parsing the HTTP response bodies. This feature automates the extraction process, saving the analyst from manually reconstructing each file from raw packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Follow TCP Stream
Why it's wrong here
Following a TCP stream displays a continuous byte-by-byte view of the conversation, rendering the payload as raw text or hex. This is a manual inspection tool: it simply linearizes the captured segments and does not distinguish HTTP headers from file bodies, nor does it decode content or transfer encodings. Because it cannot isolate and export the original binary object, it is not the way to extract transferred files.
- ✗
Statistics > HTTP
Why it's wrong here
Statistics > HTTP opens a summary dashboard that categorizes HTTP traffic by host, server, URI, request method, and status code. It is designed for high-level traffic analysis, such as spotting unusual hosts or numerous 404 responses, not for carving payload bytes out of a capture. There is no export mechanism in this view, and double-clicking a row only jumps to the corresponding packet rather than saving the transferred file.
- ✓
Export Objects > HTTP
Why this is correct
Export Objects > HTTP is the correct method: Wireshark parses the HTTP conversations in the capture, reassembles the response bodies, handles chunked transfer-encoding and content-encoding, and then presents each recovered object as an individual file ready to be saved. This directly recovers binaries, documents, images, or any other file that was transferred over HTTP, providing the actual artifact for forensic analysis and hash comparison.
- ✗
Analyze > Expert Info
Why it's wrong here
Analyze > Expert Info scans the capture for protocol anomalies, malformed packets, retransmissions, or application-level warnings, then groups them by severity, such as chatty, note, warning, and error. It is a diagnostic summary meant to explain network behavior or highlight suspicious events, but it contains no packet data and offers no action to save or export file content. Thus it can indicate that an artifact exists, but it cannot extract the artifact itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.