Courseiva

CHFI · topic practice

Network and Cloud Forensics practice questions

This domain covers collecting and analyzing evidence from networks and cloud environments: packet capture, volatile data, virtual machine memory acquisition, and cloud audit logs. Questions test forensically sound procedures, what artifacts each source yields, and how to preserve evidence so it stays admissible. Expect scenario items on PCAP analysis, cloud log anomalies, and proper order of volatility.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Network and Cloud Forensics

What the exam tests

What to know about Network and Cloud Forensics

Be able to select the right tool and method for capturing network or cloud evidence while preserving integrity. The single most important thing: follow the order of volatility and document chain of custody, because improperly captured or unhashed evidence is easily challenged and excluded.

Extracting IPs, ports, protocols, and payloads from PCAP files using Wireshark or tcpdump filters

Capturing volatile network data with tools like tcpdump, Wireshark, and NetFlow before it is lost

Acquiring virtual machine memory in cloud environments using hypervisor snapshots or memory capture tools

Reviewing cloud provider audit logs such as AWS CloudTrail for unauthorized access and credential misuse

Watch out for

Common Network and Cloud Forensics exam traps

  • ▸Assuming a PCAP contains full application content when traffic was encrypted, so only metadata like IPs and ports is recoverable
  • ▸Treating a live VM snapshot as a memory dump; snapshots capture disk state, not necessarily volatile RAM contents
  • ▸Pulling cloud logs without preserving chain of custody or hashing, weakening admissibility of the evidence later

Practice set

Network and Cloud Forensics questions

20 questions · select your answer, then reveal the explanation

A forensic analyst is investigating a network breach and finds that the attacker used a technique that bypasses Network Access Control (NAC). Which of the following methods is commonly used to evade 802.1X authentication?

An organization uses a cloud-based SIEM to collect logs from multiple sources. The investigator notices gaps in the log data for a critical system during the incident timeframe. What is the MOST likely cause?

Which TWO of the following are common challenges in cloud forensics?

Which THREE of the following are essential steps in network forensic investigation?

Which TWO of the following are effective methods for detecting a man-in-the-middle attack on a network?

An investigator finds the above IAM policy attached to an S3 bucket. What is the security concern?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}

You are a forensic investigator for a healthcare organization that uses a hybrid cloud model. Your team receives an alert that a large amount of protected health information (PHI) was exfiltrated from an AWS S3 bucket to an external IP address. The organization uses AWS CloudTrail for API logging and VPC Flow Logs for network traffic. The incident occurred between 02:00 and 03:00 UTC. Upon reviewing CloudTrail logs, you see that the bucket policy was modified at 01:55 UTC to allow public read access, and then a series of GetObject requests from an IP address in a foreign country occurred. The VPC Flow Logs show outbound traffic from the bucket's VPC to that IP. The bucket policy change was made using the root user credentials of the AWS account. The organization has multi-factor authentication (MFA) enabled for all users, including root. However, the CloudTrail log for the policy change does not indicate MFA usage. You need to determine the most likely root cause of the breach. Which of the following is the most plausible explanation?

During a forensic investigation of a cloud environment, a forensic analyst discovers that the virtual machine (VM) used by a suspect was terminated three days prior. The cloud provider offers snapshots, backups, and instance metadata. Which of the following is the BEST course of action to recover forensic evidence?

A forensic investigator needs to capture network traffic from a SPAN port on a switch to analyze an ongoing compromise. Which tool should the investigator use to collect the full packet capture (pcap) for later analysis?

A cloud forensic analyst is tasked with preserving evidence from an AWS S3 bucket that may contain malicious files. The bucket is publicly accessible, and the analyst wants to create a forensically sound copy. Which method BEST ensures integrity and chain of custody?

Which TWO of the following are valid techniques for collecting volatile network evidence from a live system during incident response?

During a cloud forensic investigation of an AWS EC2 instance, which TWO sources should be preserved to capture volatile data before instance termination?

You are investigating a network breach at a financial institution. The perimeter firewall logs show an inbound connection from IP 203.0.113.5 to the internal web server (192.168.1.10) on TCP port 443 at 02:34:12 UTC. At 02:34:15, an outbound connection from the web server to an external IP 198.51.100.20 on TCP port 80 is logged. Simultaneously, a network intrusion detection system (NIDS) detected a SQL injection payload in the inbound HTTP request. The web server's access logs show a successful login to the admin panel at 02:34:18 from the same external IP 203.0.113.5. The database server (192.168.1.20) logs show a query execution at 02:34:20 that exported customer records. The company uses a jump box for administrative access, and all admin sessions are logged. The jump box logs show no activity during the incident. The web server hosts a public-facing application and is in a DMZ. The database server is in the internal network, with a firewall rule allowing only the web server to connect to it on TCP port 3306. Which course of action is MOST appropriate to determine the root cause and scope?

Drag and drop the steps to create a forensic timeline using the Sleuth Kit (TSK) and log2timeline into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each forensic artifact to its location in Windows (typical).

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

C:\Windows\Prefetch

C:\Windows\System32\winevt\Logs

C:\$Recycle.Bin

C:\Windows\System32\config

C:\Users\[user]\AppData\Local\Microsoft\Windows\Explorer

A forensic investigator is analyzing a compromised Linux web server. The server's network interface was in promiscuous mode, and a full packet capture was running via tcpdump when the attacker exfiltrated data over HTTPS. The investigator needs to determine the exact bytes transferred during the exfiltration session. Which artifact from the packet capture will BEST provide this information?

A forensic analyst is investigating a security incident in a Microsoft Azure environment. The organization suspects that an attacker used compromised credentials to access an Azure virtual machine and exfiltrate data. The analyst needs to collect evidence from Azure that can show authentication events and network traffic related to the VM. Which TWO Azure sources should the analyst prioritize for this investigation? (Choose two.)

A forensic investigator is examining a PCAP file collected from a network tap. The investigator notices a large number of TCP SYN packets sent to various ports on a single target IP address, with no corresponding SYN-ACK responses. Which type of activity does this pattern MOST likely indicate?

An investigator needs to capture network traffic from a live network segment without altering the traffic flow. Which technique should they use?

During a cloud forensics investigation, the investigator discovers that the cloud provider uses shared storage for multiple tenants. Which challenge is MOST likely to arise when acquiring a forensic image?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network and Cloud Forensics sessions

Start a Network and Cloud Forensics only practice session

Every question in these sessions is drawn from the Network and Cloud Forensics domain — nothing else.

Related practice questions

Related CHFI topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CHFI exam test about Network and Cloud Forensics?
Be able to select the right tool and method for capturing network or cloud evidence while preserving integrity. The single most important thing: follow the order of volatility and document chain of custody, because improperly captured or unhashed evidence is easily challenged and excluded.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network and Cloud Forensics questions in a focused session?
Yes — the session launcher on this page draws every question from the Network and Cloud Forensics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CHFI topics?
Use the topic links above to move to related areas, or go back to the CHFI question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CHFI exam covers. They are not copied from any real exam or dump site.