CHFI Network and Cloud Forensics Practice Question
During a network forensic investigation, the analyst recovers a PCAP file. What type of information can be directly extracted from this file?
⚠ Common exam trap
EC-Council often tests the distinction between what is directly extractable from packet payloads (e.g., HTTP files) versus what requires inference or additional forensic artifacts (e.g., OS fingerprinting or disk data), leading candidates to overestimate the information available in a PCAP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Files transferred via HTTP
A PCAP file captures raw network packets. HTTP is an application-layer protocol that transmits data (e.g., files, web pages) in cleartext over TCP. By reassembling TCP streams from the captured packets, an analyst can directly extract files transferred via HTTP, as the payload contains the actual file content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Files transferred via HTTP
Why this is correct
HTTP file transfers are visible in the packet payload because HTTP is an unencrypted application-layer protocol. During a network forensic investigation, an analyst can reconstruct the entire file by reassembling TCP segments and extracting the HTTP message body (e.g., using Wireshark's 'Follow TCP Stream' or NetworkMiner). As long as the capture contains complete traffic, the transferred file's content is directly recoverable from the PCAP data, making this the correct answer.
- ✗
Operating system version of the source host
Why it's wrong here
The operating system version of the source host is not stored in any network packet header or standard payload; it is a property of the host's local environment. Although an analyst might infer the OS family/version through TCP TTL values, window size, or HTTP User-Agent headers, this is heuristic fingerprinting, not a direct recovery of data from the capture. Unless the source intentionally transmits this information (e.g., an application querying OS info), the precise OS version cannot be extracted from PCAP traffic alone.
- ✗
Registry data of the destination host
Why it's wrong here
Registry data is a Windows-specific local database that stores hardware and software configuration for the destination host; it exists only on the host's disk and is not part of normal network communication. Network packets carry application-layer messages (e.g., HTTP, DNS), not the internal system state of the receiving machine. Even if a remote registry access protocol like WinRM/RPC is in use, the PCAP would only contain the transmitted registry values, not the full registry hive, making it an unreliable artifact for this scenario.
- ✗
Disk partition table of the sending computer
Why it's wrong here
The disk partition table is a low-level data structure written to the master boot record or GPT area of the physical disk, and it is never sent across the network during ordinary operations. In contrast to network traffic, partition metadata is accessed by the OS through block I/O and only leaves the host if an entire disk image is deliberately shared (e.g., for forensic duplication). Therefore, a PCAP capture of a network conversation will not contain any partition table information, as it is not part of the transmitted packet payload.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.