Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which THREE of the following are commonly used network forensic data sources?

⚠ Common exam trap

The CHFI exam often tests the distinction between host-based forensic artifacts (like Prefetch files and registry hives) and network-based forensic sources, so candidates mistakenly include local system artifacts when the question explicitly asks for network forensic data sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetFlow logs

NetFlow logs (A) are a core network forensic source because routers and switches export flow records containing metadata such as source/destination IP, ports, protocol, byte/packet counts, and timestamps, enabling traffic pattern and anomaly analysis without full payload capture. IDS/IPS alerts (C) are network forensic data because they record detections of malicious or policy-violating traffic (e.g., Snort/Suricata signatures, anomaly events) with associated IPs, ports, and timestamps that support incident reconstruction. Packet captures (D) are the richest network forensic source, preserving full packet payloads at layers 2–7 (typically stored as PCAP/PCAPNG via tools like Wireshark or tcpdump) for protocol-level and content analysis. Prefetch files (B) and Windows registry hives (E) are host-based artifacts stored on the endpoint's filesystem, not network traffic data sources, so they do not belong in this list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NetFlow logs

    Why this is correct

    NetFlow logs are network-level metadata records generated by Cisco and other network devices that summarize traffic flows between hosts. Each flow record contains the source and destination IP addresses, ports, protocol, timestamps, total bytes and packets, and sometimes TCP flags — but critically no payload content. This makes NetFlow valuable for high-level pattern analysis such as detecting command-and-control beacons, anomalous data-transfer volumes, or internal lateral movement, while remaining relatively lightweight to store. As a core source of network telemetry, NetFlow is a mainstream network forensics artifact.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch files are Windows operating system artifacts stored in C:\Windows\Prefetch that are designed to accelerate application startup by caching information about executable's loaded files and libraries. Each .pf file records the executable's path, the file's last run time, and a run count, which means they are host-based evidence of program execution. They contain no IP addresses, port numbers, connection states, or any other network communication data, rendering them irrelevant to network forensics. Thus they are an incorrect option for a question about network-based evidence sources.

  • ✓

    IDS/IPS alerts

    Why this is correct

    IDS/IPS alerts are notifications generated by intrusion detection and prevention systems that inspect network traffic for malicious signatures, anomalies, or policy violations. These systems produce logs with timestamp, source/destination addresses, severity, attack type, and often a snapshot of the triggering packet or session metadata, giving investigators a starting point for suspicious activity. Since IDS/IPS appliances are placed on network segments or at network boundaries, their alert logs are direct network evidence of detected security events, even if they don't retain full traffic history. Therefore they are a valid network forensics data source.

  • ✓

    Packet captures (PCAP)

    Why this is correct

    Packet captures (PCAP) are raw recordings of entire network frames observed on an interface or wire, typically collected with tools like tcpdump, Wireshark, or Zeek. A PCAP file preserves complete packet headers and application payloads, letting investigators perform deep protocol decoding, session reassembly, and exact content recovery — for example, extracting a transferred file or decoding a cleartext HTTP request. This is the most comprehensive network forensics evidence, providing undeniable proof of communication, but it is also storage-intensive and consumes significant CPU during capture. As such, PCAP is unquestionably a commonly used network forensics source.

  • ✗

    Windows registry hives

    Why it's wrong here

    Windows registry hives (e.g., SYSTEM, SOFTWARE, NTUSER.DAT) are hierarchical host-based databases that store OS and application configuration, user preferences, autostart entries, and recent activity artifacts. While some registry keys can reflect network adapter settings, cached credentials, or shared-drive mappings, the registry does not systematically record live network connections or traffic flows. It is an endpoint artifact, not a network sensor log, and therefore it is not considered a network forensics data source. Investigators looking for network activity would instead consult firewall logs, DHCP logs, or EDR telemetry — not the registry.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.