Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO of the following are tools commonly used for network forensics analysis? (Select two.)

⚠ Common exam trap

The CHFI exam often tests the distinction between network forensics tools (which capture/analyze packets) and host-based forensics tools (which analyze disks, memory, or files), leading candidates to mistakenly select Autopsy or Volatility as network tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

tcpdump

tcpdump (A) is a command-line packet capture and analysis tool that uses libpcap to intercept and decode live network traffic, making it a staple for network forensics. Wireshark (E) is the de facto GUI protocol analyzer that captures packets and provides deep dissection of hundreds of protocols, so it is also a core network forensics tool. By contrast, Autopsy (B) is a disk/image forensics platform for file system and artifact analysis, Volatility (C) is a memory forensics framework for RAM dumps, and dd (D) is a low-level imaging/duplication utility — none of these are primarily used to capture or analyze network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    tcpdump

    Why this is correct

    tcpdump is a command-line packet capture tool that uses the libpcap library to intercept and display network packets transiting a specific interface. It supports powerful Berkeley Packet Filter (BPF) syntax for targeted capture and can write raw packets to a pcap file, preserving the exact frame traversal timing and payloads crucial for reconstructing network events. Its headless, scriptable nature makes it the de facto standard for remote or unattended network forensics collection.

  • ✗

    Autopsy

    Why it's wrong here

    Autopsy is a graphical digital forensics platform built on The Sleuth Kit, primarily designed for disk and file system analysis. It recovers deleted files, parses artifacts like browser history and registry hives, and examines partition layouts, but it does not directly interact with network interfaces or capture live traffic. Therefore, it is unsuitable for network forensics, which requires packet-level evidence.

  • ✗

    Volatility

    Why it's wrong here

    Volatility is an open-source memory forensics framework used to analyze volatile RAM captures, extracting running processes, open network connections, kernel objects, and injected code from a memory dump. While it can reveal active sockets or network artifacts at a given instant, its evidentiary source is memory, not the wire itself. It cannot capture or replay network packets, so it is not a network forensic tool.

  • ✗

    dd

    Why it's wrong here

    dd is a low-level utility for reading from and writing to block devices or files, commonly used to create bit-for-bit disk images for forensic preservation. It operates at the storage layer, duplicating filesystems, partitions, or raw drives, but has no capability to collect, parse, or analyze live network traffic. Thus it is a storage forensics tool, not a network forensics tool.

  • ✓

    Wireshark

    Why this is correct

    Wireshark is a full-featured packet analyzer that provides a graphical user interface for live packet capture and offline inspection of pcap files captured by tools like tcpdump. It offers deep protocol dissection, reassembly of TCP streams, and rich filtering and statistical analysis, making it the primary interactive tool for examining network forensic evidence. Unlike tcpdump, its strength lies in visualization and protocol-level decoding rather than headless capture.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.