CHFI OS and Network Forensics Practice Question
Which TWO of the following are tools commonly used for network forensics analysis? (Select two.)
⚠ Common exam trap
The CHFI exam often tests the distinction between network forensics tools (which capture/analyze packets) and host-based forensics tools (which analyze disks, memory, or files), leading candidates to mistakenly select Autopsy or Volatility as network tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
tcpdump
tcpdump (A) is a command-line packet capture and analysis tool that uses libpcap to intercept and decode live network traffic, making it a staple for network forensics. Wireshark (E) is the de facto GUI protocol analyzer that captures packets and provides deep dissection of hundreds of protocols, so it is also a core network forensics tool. By contrast, Autopsy (B) is a disk/image forensics platform for file system and artifact analysis, Volatility (C) is a memory forensics framework for RAM dumps, and dd (D) is a low-level imaging/duplication utility — none of these are primarily used to capture or analyze network traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
tcpdump
Why this is correct
tcpdump is a command-line packet capture tool that uses the libpcap library to intercept and display network packets transiting a specific interface. It supports powerful Berkeley Packet Filter (BPF) syntax for targeted capture and can write raw packets to a pcap file, preserving the exact frame traversal timing and payloads crucial for reconstructing network events. Its headless, scriptable nature makes it the de facto standard for remote or unattended network forensics collection.
- ✗
Autopsy
Why it's wrong here
Autopsy is a graphical digital forensics platform built on The Sleuth Kit, primarily designed for disk and file system analysis. It recovers deleted files, parses artifacts like browser history and registry hives, and examines partition layouts, but it does not directly interact with network interfaces or capture live traffic. Therefore, it is unsuitable for network forensics, which requires packet-level evidence.
- ✗
Volatility
Why it's wrong here
Volatility is an open-source memory forensics framework used to analyze volatile RAM captures, extracting running processes, open network connections, kernel objects, and injected code from a memory dump. While it can reveal active sockets or network artifacts at a given instant, its evidentiary source is memory, not the wire itself. It cannot capture or replay network packets, so it is not a network forensic tool.
- ✗
dd
Why it's wrong here
dd is a low-level utility for reading from and writing to block devices or files, commonly used to create bit-for-bit disk images for forensic preservation. It operates at the storage layer, duplicating filesystems, partitions, or raw drives, but has no capability to collect, parse, or analyze live network traffic. Thus it is a storage forensics tool, not a network forensics tool.
- ✓
Wireshark
Why this is correct
Wireshark is a full-featured packet analyzer that provides a graphical user interface for live packet capture and offline inspection of pcap files captured by tools like tcpdump. It offers deep protocol dissection, reassembly of TCP streams, and rich filtering and statistical analysis, making it the primary interactive tool for examining network forensic evidence. Unlike tcpdump, its strength lies in visualization and protocol-level decoding rather than headless capture.
Go deeper
Related to this question
Learn chapter
Windows Forensics: File Systems and Artifacts
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
Volatility Framework
An open-source memory forensics tool used to extract digital evidence from a computer's RAM (random access memory).
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.