CHFI OS and Network Forensics Practice Question
Which THREE of the following are commonly used network forensic data sources?
⚠ Common exam trap
The CHFI exam often tests the distinction between host-based forensic artifacts (like Prefetch files and registry hives) and network-based forensic sources, so candidates mistakenly include local system artifacts when the question explicitly asks for network forensic data sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow logs
NetFlow logs (A) are a core network forensic source because routers and switches export flow records containing metadata such as source/destination IP, ports, protocol, byte/packet counts, and timestamps, enabling traffic pattern and anomaly analysis without full payload capture. IDS/IPS alerts (C) are network forensic data because they record detections of malicious or policy-violating traffic (e.g., Snort/Suricata signatures, anomaly events) with associated IPs, ports, and timestamps that support incident reconstruction. Packet captures (D) are the richest network forensic source, preserving full packet payloads at layers 2–7 (typically stored as PCAP/PCAPNG via tools like Wireshark or tcpdump) for protocol-level and content analysis. Prefetch files (B) and Windows registry hives (E) are host-based artifacts stored on the endpoint's filesystem, not network traffic data sources, so they do not belong in this list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NetFlow logs
Why this is correct
NetFlow logs are network-level metadata records generated by Cisco and other network devices that summarize traffic flows between hosts. Each flow record contains the source and destination IP addresses, ports, protocol, timestamps, total bytes and packets, and sometimes TCP flags — but critically no payload content. This makes NetFlow valuable for high-level pattern analysis such as detecting command-and-control beacons, anomalous data-transfer volumes, or internal lateral movement, while remaining relatively lightweight to store. As a core source of network telemetry, NetFlow is a mainstream network forensics artifact.
- ✗
Prefetch files
Why it's wrong here
Prefetch files are Windows operating system artifacts stored in C:\Windows\Prefetch that are designed to accelerate application startup by caching information about executable's loaded files and libraries. Each .pf file records the executable's path, the file's last run time, and a run count, which means they are host-based evidence of program execution. They contain no IP addresses, port numbers, connection states, or any other network communication data, rendering them irrelevant to network forensics. Thus they are an incorrect option for a question about network-based evidence sources.
- ✓
IDS/IPS alerts
Why this is correct
IDS/IPS alerts are notifications generated by intrusion detection and prevention systems that inspect network traffic for malicious signatures, anomalies, or policy violations. These systems produce logs with timestamp, source/destination addresses, severity, attack type, and often a snapshot of the triggering packet or session metadata, giving investigators a starting point for suspicious activity. Since IDS/IPS appliances are placed on network segments or at network boundaries, their alert logs are direct network evidence of detected security events, even if they don't retain full traffic history. Therefore they are a valid network forensics data source.
- ✓
Packet captures (PCAP)
Why this is correct
Packet captures (PCAP) are raw recordings of entire network frames observed on an interface or wire, typically collected with tools like tcpdump, Wireshark, or Zeek. A PCAP file preserves complete packet headers and application payloads, letting investigators perform deep protocol decoding, session reassembly, and exact content recovery — for example, extracting a transferred file or decoding a cleartext HTTP request. This is the most comprehensive network forensics evidence, providing undeniable proof of communication, but it is also storage-intensive and consumes significant CPU during capture. As such, PCAP is unquestionably a commonly used network forensics source.
- ✗
Windows registry hives
Why it's wrong here
Windows registry hives (e.g., SYSTEM, SOFTWARE, NTUSER.DAT) are hierarchical host-based databases that store OS and application configuration, user preferences, autostart entries, and recent activity artifacts. While some registry keys can reflect network adapter settings, cached credentials, or shared-drive mappings, the registry does not systematically record live network connections or traffic flows. It is an endpoint artifact, not a network sensor log, and therefore it is not considered a network forensics data source. Investigators looking for network activity would instead consult firewall logs, DHCP logs, or EDR telemetry — not the registry.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.