CHFI OS and Network Forensics Practice Question
An analyst is reviewing firewall logs and sees repeated outbound connections from an internal host to a known malicious IP on port 443. Which TWO network forensic data sources would BEST help determine if data exfiltration occurred?
⚠ Common exam trap
It's easy for candidates to choose NetFlow records (A) thinking they can detect exfiltration by abnormal traffic patterns, but they overlook that without payload inspection, you cannot confirm data was actually stolen; only PCAP and decrypted proxy logs provide the necessary content-level evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full packet capture (PCAP) of the sessions
Option B (Full packet capture (PCAP) of the sessions) is correct because PCAP records the actual bytes of each TCP session on port 443, allowing an analyst to inspect payloads, TLS handshake metadata, certificate details, and transferred content to confirm whether sensitive data left the host. Option E (Proxy logs with TLS interception and decrypted content) is correct because a TLS-intercepting proxy terminates the outbound TLS connection, decrypts the HTTP/HTTPS traffic, and logs URLs, methods, request/response bodies, and uploaded data, which directly reveals exfiltration over 443. Option A is not among the marked correct answers: flow records only show metadata such as byte/packet counts and timing, which can suggest large transfers but cannot confirm exfiltration content. Option C is not marked correct because IDS signature alerts indicate suspicious activity but do not by themselves prove that data was exfiltrated. Option D is not marked correct because Windows security event logs focus on host authentication, account, and policy events rather than the contents or destinations of outbound TLS sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network flow records showing packet sizes and counts
Why it's wrong here
NetFlow, sFlow, or IPFIX records summarize conversations as metadata: source and destination IPs, ports, protocol, timestamps, and cumulative packet/byte counts. This is fine for volumetric analysis or identifying a long-lived beaconing session, but it contains zero application payload. Consequently, flow records cannot prove what data was exfiltrated, only that traffic occurred with particular characteristics.
- ✓
Full packet capture (PCAP) of the sessions
Why this is correct
A full packet capture preserves the raw network frames, including the application-layer payload of every session. By reassembling the TCP streams, the analyst can reconstruct the exact data segments transmitted, such as uploaded files, commands, or stolen records. This makes PCAP the only log source that gives complete, packet-level proof of outbound data content, subject to encryption.
- ✗
IDS alerts for signatures
Why it's wrong here
Signature-based IDS alerts trigger on pattern matches within observed traffic, often using normalized streams or packet headers. While they can flag suspicious behavior like a known C2 beacon or exploit signature, they do not retain the full session payload, and a triggered alert is not evidence of the actual data exfiltrated. In complete packet capture, you can retrieve the original data; in alerts, you only get a summary or extracted rule match.
- ✗
Windows security event logs
Why it's wrong here
Windows security event logs record local system activity, including logon attempts, process creation, and object access, not the contents of network sessions. Even Event ID 5156 or 5157 for Windows Filtering Platform only lists destination addresses, ports, and application PID, not the payload bytes transferred. They might show which process initiated an outbound connection, but they cannot disclose the actual data sent.
- ✓
Proxy logs with TLS interception and decrypted content
Why this is correct
If the organization uses a forward proxy that performs SSL/TLS inspection, the proxy can decrypt inbound and outbound HTTPS sessions by presenting a trusted certificate and logging the decrypted HTTP requests, headers, and body content. This is a powerful source because it reveals actual data inside encrypted sessions that PCAP alone cannot decipher unless the analyst also captures the decryption keys. However, it only sees sessions routed through the proxy and assumes the client trusts the proxy's root CA.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.