CHFI OS and Network Forensics Practice Question
Which TWO of the following are typical sources of evidence for network forensics? (Select TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse host-based artifacts (registry, bash_history, Prefetch) with network-based evidence, failing to distinguish between evidence collected from a single endpoint versus evidence collected from network infrastructure or traffic captures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firewall logs
Firewall logs (C) are a canonical network-forensics source because they record connection metadata such as source/destination IP addresses, ports, protocol, timestamps, and allow/deny actions, which lets an investigator reconstruct traffic flows and identify blocked or permitted communications. Packet capture (pcap) files (E) are also a core network-forensics source because they contain the actual captured frames/packets (e.g., from tcpdump/Wireshark), enabling deep protocol-level analysis of payloads, sessions, and anomalies. The other options are host-based artifacts rather than network evidence: Windows registry hives (A) store OS and application configuration, bash_history (B) records shell commands executed by a user, and Prefetch files (D) are Windows execution artifacts showing program run times and loaded modules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows registry hives
Why it's wrong here
Windows registry hives (e.g., SYSTEM, SOFTWARE, NTUSER.DAT) store host-centric configuration data, user activities, installed applications, and device history. Although some network parameters like TCP/IP settings or firewall rules can be present, the registry does not log actual connections, traffic, or network sessions. Therefore, registry hives are not typical sources of network forensic evidence; they are local system artifacts.
- ✗
bash_history
Why it's wrong here
The bash_history file is a Linux user-level artifact that records commands typed into an interactive shell, such as ls, cd, or vim. Even when a command like ssh or curl appears, it only shows that the command was invoked, not the network packets or session contents. It reflects a specific user's local activity, making it unsuitable as a primary network evidence source.
- ✓
Firewall logs
Why this is correct
Firewall logs are a cornerstone of network forensics because they contain timestamped records of each connection attempt, including source and destination IP addresses, ports, protocol, and the action taken (allow, deny, or drop). These logs enable investigators to reconstruct attack paths, spot port scans, and identify successful or blocked outbound communications. They provide metadata about network transactions, even though they do not capture payloads.
- ✗
Prefetch files
Why it's wrong here
Prefetch files (.pf) are created by the Windows operating system to optimize application launch times, recording executable names, run counts, and loaded modules. They are strictly host-based execution artifacts that show when and how often a program ran on a local machine. Prefetch data does not contain network connections or packet-level details, so it is not a typical network forensic source.
- ✓
Packet capture (pcap) files
Why this is correct
Packet capture (PCAP) files store raw network traffic at the data-link or network layer, preserving packet headers and, depending on settings, full payloads. Investigators can reassemble TCP streams, extract transferred files, decode application protocols, and hunt for malware command-and-control activity. PCAPs provide the most granular network evidence, but their availability depends on pre-deployed sensors or timely collection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.