Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

An analyst reviews proxy logs and sees repeated requests to a known malicious domain from multiple internal hosts, each using a different User-Agent string. The requests are all GET requests for /images/icon.png. What technique is most likely being used to evade detection?

⚠ Common exam trap

EC-Council often tests the distinction between techniques that modify request headers (User-Agent randomization) versus those that change the destination (DGA) or transport (HTTPS tunneling), so candidates may confuse User-Agent randomization with DGA because both are used for evasion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User-Agent randomization

The repeated GET requests for the same resource (/images/icon.png) from multiple internal hosts, each with a different User-Agent string, is a classic indicator of User-Agent randomization. This technique is used by malware to evade signature-based detection that relies on static User-Agent values, making the traffic appear to originate from diverse browsers or devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    User-Agent randomization

    Why this is correct

    Repeated requests containing randomized User-Agent strings strongly indicate the client is deliberately changing that header on every request. User-Agent randomization is a standard anti-detection technique because unmodified command-line tools with absent or malformed User-Agents are easily filtered by security appliances, while frequent switching between browser-like values makes traffic appear to come from diverse legitimate clients. In proxy logs, varied User-Agents from the same source IP defeat naive signature matching, but the high rotation rate itself remains a suspicious behavioral pattern.

  • ✗

    HTTPS tunneling

    Why it's wrong here

    HTTPS tunneling, while encrypting the HTTP payload, does not randomize the User-Agent header—it merely hides it from a passive packet capture. A proxy log will typically record the TLS Server Name Indication (SNI) and the source/destination IPs, but the User-Agent sits inside the encrypted application data and is not part of the TLS handshake. Thus, even if the analyst is seeing decrypted/reassembled traffic, HTTPS only affects observability; it cannot explain why the client is sending different User-Agent values.

  • ✗

    IP spoofing

    Why it's wrong here

    IP spoofing is a Layer 3 technique that forges the source address in the IP header and would therefore change the apparent source IP, not the User-Agent. Moreover, an attacker carrying out a full TCP request/response session cannot reliably spoof the source IP because the three-way handshake would fail when SYN-ACK packets are sent to the nonexistent host. Proxy logs capture the actual socket-level client address from the established TCP connection, so the differing values the analyst observes are application-layer User-Agent headers, not altered network addressing.

  • ✗

    Domain generation algorithm (DGA)

    Why it's wrong here

    A Domain Generation Algorithm (DGA) creates numerous pseudorandom domain names to rotate command-and-control destinations and evade domain reputation lists, but it has no effect on HTTP header fields such as User-Agent. DGA activity appears in proxy logs as a high diversity of hostnames or FQDNs, whereas the repeated requests in this scenario show diverse User-Agent strings against the same destination. Therefore, DGA is the wrong answer because it explains domain flux, not HTTP-level header mutation.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.