CHFI OS and Network Forensics Practice Question
An analyst detects a large amount of data being exfiltrated from a network over DNS queries. Which type of network analysis would BEST detect this activity?
⚠ Common exam trap
EC-Council often tests the misconception that IDS/IPS logs (D) are sufficient for detecting all types of network attacks, but in the case of DNS tunneling, the logs only show alerts for known signatures, not the raw payload data required to confirm exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Packet capture analysis
Packet capture analysis (C) is the best method because DNS exfiltration involves encoding stolen data into DNS query or response fields (e.g., subdomains, TXT records). Only full packet capture allows inspection of the raw DNS payloads, including the actual query names and response data, which is necessary to detect the anomalous patterns of data being tunneled over DNS. Proxy, firewall, and IDS/IPS logs typically only record metadata (source/destination, timestamps, allowed/denied actions) and do not provide the granularity to see the encoded data within DNS packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proxy log analysis
Why it's wrong here
Proxy logs only record HTTP/HTTPS requests made through an explicit or transparent web proxy, and DNS exfiltration rides on UDP/TCP port 53 packets that normally bypass the proxy stack entirely. They also omit full DNS query names and payloads, so the encoded labels or TXT records used by tunneling tools like dnscat2 would be invisible. At best, proxy logs could expose a separate covert HTTPS channel, not the DNS channel that is causing the bulk data loss.
- ✗
Firewall log analysis
Why it's wrong here
Firewall logs typically contain session metadata—source/destination IPs, ports, timestamps, and allow/deny actions—but not the reconstructed application payload. An outbound firewall permitting DNS will log many DNS flows, yet it cannot reveal Base64-encoded subdomains or data embedded in DNS resource records because the packet content is not retained. While a surge in DNS traffic might be noticeable, firewall logging lacks the depth needed to confirm, quantify, or decode the exfiltration.
- ✓
Packet capture analysis
Why this is correct
Packet capture analysis is the definitive method because it records the raw DNS datagrams, preserving every byte of the query name and answer section. An analyst using Wireshark, tcpdump, or NetworkMiner can inspect individual DNS QNAME labels for high entropy, long subdomains, or unusual RR types, then decode the embedded data. This also provides the original evidence needed for forensic reconstruction rather than relying on summary logs.
- ✗
IDS/IPS log analysis
Why it's wrong here
IDS/IPS logs may contain signature matches for known DNS tunneling frameworks, but they depend on detection rules and can miss custom or obfuscated tunnels. Even when an alert fires, the log usually includes only the trigger signature and a metadata summary, not the full DNS query payload required to quantify or decode the stolen data. Packet capture offers direct visibility and complete evidentiary value, making IDS logs merely a supporting indicator.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.