InterviewStack.io LogoInterviewStack.io

Network, Mobile, and Cloud Forensics Questions

Forensics across specialized evidence sources. Covers network forensics and traffic-log analysis, mobile device forensics, cloud and virtual-environment investigation, cloud storage and synchronization forensics, and Internet-of-Things device forensics. The specialization layer for evidence that does not live on a single seized disk.

HardTechnical
38 practiced

An APT is suspected of maintaining persistence across hybrid (cloud + on-prem) infrastructure. Discuss the forensic challenges unique to hybrid environments (ephemeral instances, cloud metadata services, cross-account roles, distributed logging) and propose a methodology to identify persistence mechanisms (malicious IAM roles, instance user-data, cron jobs, service accounts) and remove them safely without causing data loss.

HardTechnical
39 practiced

You are provided with a PCAP containing network traffic around a suspected intrusion. Describe a step-by-step analysis plan to identify C2 channels, data staging and exfiltration, and potential pivoting activity. Include the tools, filters and heuristics you would apply (for example Zeek conn logs, HTTP host header anomalies, TLS SNI, frequency and sizes of flows, timing patterns).

HardTechnical
40 practiced

Discuss techniques to preserve forensic integrity of evidence located on ephemeral cloud instances and containers (Kubernetes pods, autoscaling groups). Cover immediate collection tactics (snapshots, container filesystem dumps), logging best practices (centralized, immutable logs), chain-of-custody for cloud artifacts, and how to handle legal admissibility when instances are short-lived by design.

HardTechnical
50 practiced

Given raw PCAPs that may show TLS downgrade and MITM activity, describe how you would reconstruct sessions to determine whether data exfiltration occurred. Include tools, filters to apply in Wireshark, artifacts that indicate TLS manipulation or forged certificates, and steps to preserve chain-of-custody for evidence.

That is every published Network, Mobile, and Cloud Forensics question for Information Security Analyst so far. Browse the other topics in this category, or practice this one interactively.