Courseiva

CCNA Network and Cloud Forensics Questions

12 questions · Network and Cloud Forensics · All types, answers revealed

1
MCQmedium

During a cloud forensics investigation, the investigator discovers that the cloud provider uses shared storage for multiple tenants. Which challenge is MOST likely to arise when acquiring a forensic image?

A.Physical acquisition of the storage device is required
B.No API access to the storage system
C.Inability to decrypt data at rest
D.Data commingling with other tenants
AnswerD

Data commingling with other tenants is the core challenge, as shared storage causes multiple organizations' data to occupy the same physical media, including potentially unallocated or leftover blocks. A forensic acquisition from such media may inadvertently capture another tenant's data, creating privacy, legal, and chain-of-custody complications. Investigators must employ careful isolation techniques, such as acquiring only the specific virtual disk or object while documenting that surrounding media contains unrelated data. This makes tenant-to-tenant isolation the primary difficulty in multi-tenant cloud forensics.

Why this answer

In cloud environments with shared storage, data from multiple tenants resides on the same physical or logical volume. When acquiring a forensic image, the investigator cannot isolate a single tenant's data without also capturing other tenants' data, leading to data commingling. This violates chain-of-custody and privacy principles, making it the primary challenge.

Exam trap

EC-Council often tests the misconception that physical access or encryption are the main hurdles, but the real challenge in cloud forensics is data commingling due to shared tenancy, which complicates legal and technical acquisition.

How to eliminate wrong answers

Option A is wrong because cloud storage is abstracted from physical hardware; physical acquisition is rarely possible or necessary, as forensic acquisition is performed via APIs or snapshots. Option B is wrong because cloud providers typically offer APIs (e.g., AWS S3 API, Azure Blob Storage REST API) for accessing storage, though permissions may be restricted. Option C is wrong because while encryption at rest is common, it is not an inherent challenge of shared storage; decryption keys are usually managed by the provider or tenant and can be obtained through proper legal channels.

2
MCQhard

A forensic analyst is examining a network intrusion detection system (NIDS) alert that triggered on a packet with the FIN, PSH, and URG flags set. What type of scan does this indicate?

A.Xmas scan
B.NULL scan
C.SYN scan
D.ACK scan
AnswerA

A Christmas tree (Xmas) scan sends TCP packets with the FIN, PSH, and URG flags simultaneously enabled, creating a deliberate anomaly that evades stateless packet filters and forces RFC-compliant hosts to respond in distinct ways: closed ports return a RST, while open ports drop the packet silently. This flag combination is the key signature that IDS/IPS systems use to flag an Xmas scan, and it is fundamentally different from single-flag scans because the unusual number of set bits is itself a heuristic indicator.

Why this answer

A is correct because an Xmas scan sends packets with the FIN, PSH, and URG flags set (like a Christmas tree lit up). According to RFC 793, a closed port must respond with an RST packet, while an open port should drop the packet silently (no response). The NIDS alert triggered on these three flags together, which is the signature of an Xmas scan.

Exam trap

EC-Council often tests the distinction between Xmas, NULL, and SYN scans by focusing on the exact flag combinations; the trap here is that candidates confuse the FIN, PSH, URG combination with a NULL scan (no flags) or a SYN scan (single flag).

How to eliminate wrong answers

Option B is wrong because a NULL scan sends packets with no flags set (all flags off), not the FIN, PSH, and URG flags. Option C is wrong because a SYN scan sends packets with only the SYN flag set, used for half-open connections, not the combination of FIN, PSH, and URG. Option D is wrong because an ACK scan sends packets with only the ACK flag set, used to map firewall rules, not the FIN, PSH, and URG flags.

3
MCQhard

You are a forensic investigator responding to a data breach at a mid-sized company. The company uses a hybrid cloud environment with AWS for production workloads and on-premises servers for legacy applications. The breach was detected when an internal monitoring system flagged unusual outbound traffic from an AWS EC2 instance (i-0a1b2c3d4e5f) to an external IP address (198.51.100.20) on TCP port 4444 during off-hours. The EC2 instance runs a Linux-based web server. The security team has already isolated the instance by removing its security group rules and stopping the instance. You have been provided with the following: (1) AWS CloudTrail logs for the past 72 hours, (2) VPC Flow Logs for the same period, (3) a snapshot of the instance’s root volume (EBS), and (4) the instance metadata log from the AWS console. The company’s incident response policy requires preservation of all volatile data before powering off the instance. Which of the following steps should you take FIRST to ensure a forensically sound investigation?

A.Acquire a memory dump from the stopped instance by re-attaching the root volume to a forensic workstation.
B.Review the instance metadata log to identify the user who launched the instance.
C.Create a forensic copy of the EBS snapshot and attach it to a separate analysis EC2 instance in a different AWS account to avoid altering evidence.
D.Analyze the VPC Flow Logs to determine if other instances communicated with the same external IP.
AnswerC

Creating a forensic copy of the EBS snapshot and attaching that copy to a separate EC2 instance in a different AWS account is the correct first preservation step because the snapshot is the only durable disk evidence of the compromised instance. Attaching the original snapshot to an analysis instance—even read-only—risks unwitting writes from filesystem journal replay, and operating in the same account risks accidental modification or deletion. A copied snapshot in an isolated account grants a clean, authority-controlled workspace where forensic tools cannot alter the original evidence.

Why this answer

The first step in a forensically sound investigation is to create a forensic copy (bit-for-bit) of the EBS snapshot before any analysis. This preserves the original evidence integrity, as required by the order of volatility and chain of custody. Attaching the copy to a separate analysis EC2 instance in a different AWS account prevents accidental modification of the original snapshot and isolates the forensic environment from the compromised production account.

Exam trap

The trap here is that candidates confuse volatile data preservation with the need to acquire memory from a stopped instance (Option A), not realizing that stopping the instance already destroys RAM, and the snapshot only captures disk data.

How to eliminate wrong answers

Option A is wrong because the instance is already stopped, so volatile data (memory) is lost; re-attaching the root volume to a forensic workstation would not recover memory, and the snapshot is of the root volume, not RAM. Option B is wrong because reviewing the instance metadata log to identify the user who launched the instance is a non-forensic administrative step that does not preserve or acquire evidence; it should be done after securing the evidence. Option D is wrong because analyzing VPC Flow Logs is a valid investigative step, but it is not the first priority; the immediate need is to preserve the EBS snapshot evidence before any analysis that might alter or overlook the original data.

4
MCQmedium

You are investigating a network breach at a financial institution. The organization uses a network-based intrusion detection system (NIDS) and maintains full packet capture (PCAP) for critical segments. The incident allegedly started with a spear-phishing email that delivered a remote access trojan (RAT). The security team has isolated the infected host and provided you with a disk image of the host and a PCAP file covering the network traffic from the host for the 24-hour period before isolation. In the PCAP, you see a series of TCP connections from the host to an external IP address on port 443 (HTTPS). The external IP is known to be associated with a command-and-control (C2) server. However, the disk image shows no evidence of the RAT binary or any malicious files. The host's antivirus logs are clean. Which of the following is the most likely explanation for the lack of evidence on the disk?

A.The antivirus software deleted the malicious files before the image was taken
B.The hard drive was reimaged before the forensic image was taken
C.The RAT uses a rootkit to hide its files
D.The malware was fileless and only resided in memory
AnswerD

Fileless malware executes in volatile memory only, using legitimate tools like PowerShell, WMI, or .NET code, and never writes a persistent payload to the hard drive. Therefore a standard disk image, even a forensically sound one, will not contain the malicious code, as it lives entirely in RAM. To identify it, the investigator must capture and analyze memory (RAM) before the system is powered off; the absence of on-disk artifacts is the hallmark of this approach.

Why this answer

The absence of the RAT binary and any malicious files on the disk, combined with clean antivirus logs and active C2 traffic over HTTPS, strongly indicates a fileless malware infection. Fileless malware operates entirely in memory (RAM), never writing its payload to disk, which explains why the disk image shows no artifacts and why traditional file-scanning antivirus did not detect it. The TCP connections to the C2 server on port 443 are consistent with a memory-resident RAT that loads directly into a legitimate process (e.g., PowerShell, WMI, or a script interpreter) and communicates over encrypted HTTPS to evade network inspection.

Exam trap

EC-Council often tests the distinction between file-based and fileless malware, and the trap here is assuming that a rootkit (Option C) is the only way to hide files, when in fact fileless malware never writes files to disk at all, making rootkits unnecessary for evasion.

How to eliminate wrong answers

Option A is wrong because antivirus software typically quarantines or logs deleted files, and the scenario states antivirus logs are clean — if deletion had occurred, the logs would show a detection event. Option B is wrong because the question explicitly states the security team isolated the infected host and provided a disk image; if the drive had been reimaged, there would be no disk image to analyze, and the scenario would mention a reimage event. Option C is wrong because while rootkits can hide files from the operating system, they still leave traces on disk (e.g., in the Master File Table or alternate data streams) that forensic tools can detect, and the question says there is no evidence of any malicious files — not just hidden files.

5
MCQmedium

An investigator is analyzing cloud storage logs and finds an entry showing that a file was accessed using the root credentials from an IP address in a different geographic region. The organization has strict policies against root usage. What should the investigator do FIRST?

A.Check if the activity correlates with a known vulnerability or authorized task
B.Contact law enforcement for cybercrime investigation
C.Change the password of the root account
D.Immediately revoke the root access keys
AnswerA

Correlating the observed access against logged change tickets, vulnerability scanners (e.g., CVE data), and scheduled maintenance windows is the correct initial triage step. It lets you determine whether the activity is a false positive or expected administrative behavior before taking any action that would be disruptive or destructive. Cross-referencing source IP, user agent, and API call pattern against known vulnerability signatures or authorized task records preserves evidential integrity while filtering out benign anomalies.

Why this answer

The first step in any forensic investigation is to correlate the suspicious activity with known events, such as authorized tasks or vulnerabilities, to avoid false positives. Root access from an unfamiliar IP could be legitimate if tied to a scheduled maintenance window or a known vulnerability exploitation attempt that requires verification. Prematurely changing credentials or contacting law enforcement could destroy evidence or alert an attacker before the scope is understood.

Exam trap

The trap here is that candidates panic and choose a reactive security action (like revoking keys or changing passwords) instead of following forensic best practice: preserve and validate before acting.

How to eliminate wrong answers

Option B is wrong because contacting law enforcement is a premature escalation step that should only occur after internal validation and evidence preservation, not as the first action. Option C is wrong because changing the root password could alert an active attacker and destroy volatile evidence such as active sessions or memory artifacts. Option D is wrong because immediately revoking root access keys could disrupt legitimate operations and also destroy evidence; the investigator must first verify the activity's legitimacy and preserve logs.

6
MCQeasy

Based on the log exhibit, what type of attack is occurring?

A.Man-in-the-middle attack
B.SQL injection attack
C.Denial of Service attack
D.Brute-force attack on SSH
AnswerD

This is a classic SSH brute-force attack: the log shows repeated "Failed password for root" messages from the same source IP, indicating automated guesses against a privileged account. Attackers run dictionary or credential-stuffing tools to try many passwords in rapid succession, and the steady stream of failures from a single origin is the definitive signature. The target is the SSH service, not the application layer, and the goal is unauthorized access, not interception or resource exhaustion.

Why this answer

The log shows multiple failed SSH login attempts from the same IP address with different usernames and passwords, which is characteristic of a brute-force attack targeting SSH. The repeated 'Failed password' entries for various user accounts (e.g., root, admin, user) indicate an automated attempt to guess credentials, not a single successful compromise or a different attack type.

Exam trap

EC-Council often tests the distinction between a brute-force attack and a DoS attack by including logs with repeated authentication failures, leading candidates to mistakenly choose DoS due to the high volume of events, but the key indicator is the specific 'Failed password' message targeting SSH, not a flood of traffic.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack would involve intercepting or modifying traffic between two parties, not repeated failed login attempts; there is no evidence of ARP spoofing, session hijacking, or traffic redirection in the log. Option B is wrong because SQL injection attacks target web application databases via malicious SQL queries in input fields, not SSH authentication logs; the log shows no SQL syntax or database error messages. Option C is wrong because a Denial of Service attack aims to overwhelm a service with traffic to cause disruption, not to repeatedly attempt authentication; the log shows sequential login failures without a flood of packets or resource exhaustion indicators.

7
MCQeasy

An investigator needs to capture network traffic from a live network segment without altering the traffic flow. Which technique should they use?

A.Enable NetFlow on the router and capture flows
B.Configure a SPAN port on the switch
C.Deploy an ARP spoofing tool to redirect traffic
D.Set the NIC to promiscuous mode on the forensic workstation
AnswerB

Configuring a SPAN (Switched Port Analyzer) port on the switch copies ingress and egress frames from specified source ports or VLANs to a designated monitor port, where a forensic workstation can record full packets without altering the original traffic path. This non-intrusive mirroring preserves switch performance and avoids introducing latency or dropping frames, making it the standard method for lawful network capture at Layer 2.

Why this answer

A SPAN (Switched Port Analyzer) port, also known as a mirror port, copies all traffic from a specified source port or VLAN to a destination port where the forensic workstation is connected. This allows the investigator to capture traffic without injecting any frames or altering the forwarding behavior of the switch, thus preserving the integrity of the live network segment.

Exam trap

EC-Council often tests the misconception that promiscuous mode alone is sufficient for capturing all traffic on a switched network, but candidates forget that switches isolate traffic per port unless a SPAN port is configured.

How to eliminate wrong answers

Option A is wrong because NetFlow is a flow-based accounting and monitoring technology that exports aggregated flow records (e.g., source/destination IP, ports, protocol) rather than capturing full packet payloads; it cannot provide the raw packet-level data needed for deep forensic analysis. Option C is wrong because ARP spoofing actively sends forged ARP replies to redirect traffic through the attacker's machine, which alters the traffic flow and can cause network disruptions or detection, violating the requirement to not alter the traffic flow. Option D is wrong because setting a NIC to promiscuous mode only allows the workstation to receive all frames on the collision domain of its connected switch port, but on a modern switched network, the switch will not forward traffic destined for other ports to the forensic workstation, so promiscuous mode alone cannot capture traffic from other hosts without additional techniques like ARP spoofing or a SPAN port.

8
MCQeasy

During a network forensic investigation, the analyst recovers a PCAP file. What type of information can be directly extracted from this file?

A.Files transferred via HTTP
B.Operating system version of the source host
C.Registry data of the destination host
D.Disk partition table of the sending computer
AnswerA

HTTP file transfers are visible in the packet payload because HTTP is an unencrypted application-layer protocol. During a network forensic investigation, an analyst can reconstruct the entire file by reassembling TCP segments and extracting the HTTP message body (e.g., using Wireshark's 'Follow TCP Stream' or NetworkMiner). As long as the capture contains complete traffic, the transferred file's content is directly recoverable from the PCAP data, making this the correct answer.

Why this answer

A PCAP file captures raw network packets. HTTP is an application-layer protocol that transmits data (e.g., files, web pages) in cleartext over TCP. By reassembling TCP streams from the captured packets, an analyst can directly extract files transferred via HTTP, as the payload contains the actual file content.

Exam trap

EC-Council often tests the distinction between what is directly extractable from packet payloads (e.g., HTTP files) versus what requires inference or additional forensic artifacts (e.g., OS fingerprinting or disk data), leading candidates to overestimate the information available in a PCAP.

How to eliminate wrong answers

Option B is wrong because the operating system version of the source host is not directly stored in packet headers; it can only be inferred through techniques like TCP/IP fingerprinting (e.g., analyzing TTL values, window sizes), not directly extracted. Option C is wrong because registry data resides on the local disk of the destination host and is never transmitted over the network in standard protocols; a PCAP contains only network traffic, not local filesystem artifacts. Option D is wrong because the disk partition table is a low-level disk structure that is not sent over the network during normal communication; it would require a full disk image, not a packet capture.

9
MCQmedium

Based on the ARP table exhibit, what is the most likely security issue?

A.The gateway is unreachable
B.Duplicate IP addresses on the network
C.ARP poisoning attack
D.MAC address filtering is enabled
AnswerC

ARP poisoning (ARP spoofing) is the only explanation that matches the exhibit: the attacker sends forged ARP replies claiming their MAC address is associated with the gateway and numerous other hosts, overwriting the victim's ARP cache. Once the victim's cache is poisoned, all outbound traffic destined for those IPs is sent to the attacker's MAC, enabling man-in-the-middle sniffing, session hijacking, or denial of service. The presence of one unique MAC address across many IP entries is a classic forensic indicator of an ongoing ARP spoofing attack, especially when the duplicate MAC belongs to the attacker's interface.

Why this answer

The ARP table exhibit shows a single IP address (192.168.1.1) mapped to two different MAC addresses (00:11:22:33:44:55 and AA:BB:CC:DD:EE:FF). This is a classic indicator of an ARP poisoning attack, where an attacker sends forged ARP replies to associate their MAC address with the gateway's IP, enabling man-in-the-middle interception of traffic.

Exam trap

The trap here is that candidates may confuse ARP poisoning with duplicate IP addresses, but duplicate IPs cause a 'conflict' message and only one MAC survives in the ARP table, whereas ARP poisoning shows two distinct MACs for the same IP simultaneously.

How to eliminate wrong answers

Option A is wrong because the gateway being unreachable would result in no ARP entry or an incomplete entry, not multiple MAC addresses for the same IP. Option B is wrong because duplicate IP addresses cause address conflicts and connectivity issues, but the ARP table would typically show only one MAC per IP (the last to respond), not two simultaneous entries. Option D is wrong because MAC address filtering restricts which devices can connect, but it does not cause multiple MAC addresses to appear for a single IP in the ARP table.

10
MCQmedium

During a forensic investigation, the analyst runs netstat -ano on a compromised workstation. Based on the exhibit, which connection is MOST suspicious and should be investigated further?

A.The established HTTPS connection to 203.0.113.5:443 (PID 5678).
B.The DNS query to 192.168.1.1:53 in TIME_WAIT state.
C.The UDP listener on port 5353 (mDNS) with PID 910.
D.The listening RDP service on port 3389 (PID 1234).
AnswerA

An established HTTPS connection to 203.0.113.5:443 is the clearest anomaly because 203.0.113.0/24 is TEST-NET-3, a documentation-only range that real internet services never legitimately use. An outbound connection to that test address over the standard TLS port strongly suggests C2 traffic, data exfiltration, or a covert tunnel masquerading as HTTPS. PID 5678 enables triage to the responsible process, but the destination alone warrants immediate isolation and memory capture.

Why this answer

The established HTTPS connection to 203.0.113.5:443 (PID 5678) is most suspicious because it is an external IP address (not in the private RFC 1918 range) with an established TCP connection, indicating active data transfer. In a forensic context, an outbound HTTPS connection to an unknown external IP is a common indicator of command-and-control (C2) communication or data exfiltration, especially when the PID can be traced to an unknown or malicious process.

Exam trap

EC-Council often tests the misconception that any listening service (like RDP or mDNS) is inherently suspicious, when in fact established external connections to unknown IPs are far more indicative of active compromise.

How to eliminate wrong answers

Option B is wrong because a DNS query to 192.168.1.1:53 in TIME_WAIT state is normal internal network traffic; DNS queries are expected to resolve names, and TIME_WAIT indicates the connection has ended, not active malicious activity. Option C is wrong because a UDP listener on port 5353 (mDNS) with PID 910 is a standard service for local network discovery (RFC 6762) and is not inherently suspicious unless the PID is known to be malicious. Option D is wrong because the listening RDP service on port 3389 (PID 1234) is a common administrative service; while RDP can be exploited, a listening state alone does not indicate compromise without evidence of unauthorized access or unusual source IPs.

11
MCQmedium

In a cloud forensic investigation, the analyst needs to obtain a memory dump of a virtual machine. Which method is considered forensically sound?

A.Log into the VM and use a tool to create a crash dump
B.Copy the virtual disk file (.vmdk) and extract memory from it
C.Use a live forensic tool inside the VM to capture memory
D.Take a snapshot of the VM via the hypervisor and export the .vmem file
AnswerD

Taking a snapshot of the VM at the hypervisor level and exporting the .vmem file is the proper cloud-forensic technique because the hypervisor, operating below the guest OS, accesses the VM's volatile memory directly without injecting any code into the guest. This point-in-time snapshot suspends or copies the RAM state transparently, preserving the exact contents of memory in a forensically sound format, and the .vmem file represents the guest's full physical address space — including kernel, processes, and any in-memory encryption keys or malware.

Why this answer

Forensically sound because taking a snapshot of the VM via the hypervisor and exporting the .vmem file captures the entire volatile memory state from outside the guest OS, without altering any data inside the VM. This method preserves the memory in its pristine state and avoids the contamination that occurs when executing tools inside the suspect VM.

Exam trap

The CHFI exam often tests the misconception that a virtual disk file (.vmdk) contains memory data, when in fact it only stores persistent storage, and that live tools inside the VM are acceptable despite violating forensic soundness by altering the evidence.

How to eliminate wrong answers

Option A is wrong because logging into the VM and creating a crash dump modifies the guest OS state (e.g., writing to disk, altering page tables) and may trigger anti-forensic mechanisms, violating the principle of minimal interaction. Option B is wrong because the virtual disk file (.vmdk) contains only persistent storage data, not volatile memory; memory contents are stored in a separate .vmem or .vmsn file, and extracting memory from a disk image is technically impossible. Option C is wrong because using a live forensic tool inside the VM requires executing code within the compromised environment, which alters memory contents (e.g., overwriting pages, changing process states) and risks triggering malware or tampering with evidence.

12
MCQeasy

A security team needs to preserve network evidence for a potential legal case. What is the BEST practice for capturing volatile network data?

A.Wait until normal business hours to capture traffic
B.Only record summary logs from the firewall
C.Perform packet capture using a portable tool and store the capture with a cryptographic hash
D.Use a dedicated forensic workstation with a write blocker
AnswerC

Performing packet capture with a portable tool such as tcpdump or dumpcap on a mirror port preserves the live, volatile network state while minimizing footprint, and a cryptographic hash (like SHA-256) computed at acquisition time provides integrity verification for later evidence examination. The captured PCAP stores both headers and payloads, allowing protocol analysis and stream reassembly. Store the capture on write-protected media and record the hash in the chain-of-custody documentation to prove tamper-resistance.

Why this answer

Capturing volatile network data requires immediate acquisition of live traffic before it is lost, and using a portable tool (e.g., tcpdump, Wireshark) allows rapid deployment. Storing the capture with a cryptographic hash (e.g., SHA-256) ensures data integrity and chain of custody, which is essential for admissibility in legal proceedings. This approach preserves the most volatile evidence (packet contents) while providing verifiable proof that the data has not been altered.

Exam trap

EC-Council often tests the distinction between volatile and non-volatile evidence; the trap here is that candidates confuse the write blocker (used for disk forensics) with network capture tools, incorrectly assuming that a write blocker can somehow preserve network traffic.

How to eliminate wrong answers

Option A is wrong because waiting until normal business hours introduces unacceptable delay; volatile network data (e.g., active sessions, real-time traffic) is lost the moment it passes, and delaying capture risks losing critical evidence. Option B is wrong because recording only summary logs from the firewall discards the full packet payload and metadata (e.g., TCP sequence numbers, application-layer data), which are often necessary for reconstructing incidents and proving intent. Option D is wrong because a dedicated forensic workstation with a write blocker is designed for acquiring non-volatile storage media (e.g., hard drives, SSDs) to prevent writes; network traffic is volatile and cannot be captured via a write blocker, which has no role in live network packet capture.

Ready to test yourself?

Try a timed practice session using only Network and Cloud Forensics questions.