Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

In network forensics, which tool is specifically designed for packet capture and analysis, allowing examiners to inspect individual packets and reconstruct network conversations?

⚠ Common exam trap

The EC-CHFI exam often tests the distinction between packet capture tools (Tcpdump, Wireshark) and network diagnostic/scanning tools (Netstat, Nmap), leading candidates to confuse Tcpdump's capture capability with Wireshark's advanced analysis and reconstruction features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wireshark

Wireshark is the correct answer because it is a full-featured packet analyzer that captures live network traffic and provides deep inspection of hundreds of protocols. It allows examiners to filter packets, follow TCP streams, and reconstruct entire network conversations, making it the standard tool for network forensics analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tcpdump

    Why it's wrong here

    Tcpdump is a command-line packet capture tool that uses libpcap to capture raw packets and can save them to a pcap file for later review. However, it lacks an interactive GUI and does not provide the deep, multi-layer protocol dissection, stream reassembly, or color-coded traffic classification that Wireshark offers. While tcpdump is excellent for quick CLI captures or scripted acquisition, its static text output makes it far less suited for complex forensic examination and interactive browsing of captured traffic.

  • ✗

    Netstat

    Why it's wrong here

    Netstat is a network statistics and connection inspection utility, not a packet analyzer. It reports the current state of TCP/UDP sockets, local and remote addresses, routing tables, and interface counters, but it does not capture or decode the actual packet payloads. In network forensics, netstat is useful only for snapshotting active connections at a single moment on a live host, such as identifying a suspicious outbound link, not for reconstructing the content or timeline of network communications.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is an active network scanning and host discovery tool designed for port enumeration, service version detection, OS fingerprinting, and security auditing. It sends crafted probes to targets and analyzes their responses to map the attack surface, but it never passively intercepts or reassembles traffic between other hosts. Thus, while Nmap can reveal what endpoints and services exist on a network, it cannot capture the actual conversation contents, making it inappropriate as a dedicated network forensic analysis tool compared to Wireshark.

  • ✓

    Wireshark

    Why this is correct

    Wireshark is a full-featured network protocol analyzer that captures live traffic from network interfaces and also reads saved pcap/pcapng files. Its interactive GUI lets investigators drill down through every protocol layer, reassemble TCP streams, decode hundreds of application protocols, follow HTTP/email/file transfers, and apply display filters or statistical summaries to isolate evidence. Wireshark's deep packet inspection, packet-bytes view, and exportable payload capabilities make it the standard go-to tool for network forensics.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.