Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

An analyst captures network traffic during an incident and wants to extract files transferred over HTTP. Which Wireshark feature is BEST suited for this task?

⚠ Common exam trap

Many exam-takers confuse 'Follow TCP Stream' (which shows raw data) with a file extraction tool, not realizing that 'Export Objects > HTTP' is the dedicated feature for extracting files from HTTP traffic in Wireshark.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Export Objects > HTTP

Wireshark's 'Export Objects > HTTP' feature is specifically designed to extract files (e.g., images, documents, executables) transferred over HTTP by reassembling the TCP streams and parsing the HTTP response bodies. This feature automates the extraction process, saving the analyst from manually reconstructing each file from raw packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Follow TCP Stream

    Why it's wrong here

    Following a TCP stream displays a continuous byte-by-byte view of the conversation, rendering the payload as raw text or hex. This is a manual inspection tool: it simply linearizes the captured segments and does not distinguish HTTP headers from file bodies, nor does it decode content or transfer encodings. Because it cannot isolate and export the original binary object, it is not the way to extract transferred files.

  • ✗

    Statistics > HTTP

    Why it's wrong here

    Statistics > HTTP opens a summary dashboard that categorizes HTTP traffic by host, server, URI, request method, and status code. It is designed for high-level traffic analysis, such as spotting unusual hosts or numerous 404 responses, not for carving payload bytes out of a capture. There is no export mechanism in this view, and double-clicking a row only jumps to the corresponding packet rather than saving the transferred file.

  • ✓

    Export Objects > HTTP

    Why this is correct

    Export Objects > HTTP is the correct method: Wireshark parses the HTTP conversations in the capture, reassembles the response bodies, handles chunked transfer-encoding and content-encoding, and then presents each recovered object as an individual file ready to be saved. This directly recovers binaries, documents, images, or any other file that was transferred over HTTP, providing the actual artifact for forensic analysis and hash comparison.

  • ✗

    Analyze > Expert Info

    Why it's wrong here

    Analyze > Expert Info scans the capture for protocol anomalies, malformed packets, retransmissions, or application-level warnings, then groups them by severity, such as chatty, note, warning, and error. It is a diagnostic summary meant to explain network behavior or highlight suspicious events, but it contains no packet data and offers no action to save or export file content. Thus it can indicate that an artifact exists, but it cannot extract the artifact itself.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.