Browse all practice questions for the Computer Hacking Forensic Investigator (CHFI) v11 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Decode the Digital Vault: CHFI v11 Mastery Test 2026 – Hack Your Way to Success! course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is a drawback of pulling the power plug to shut down a system abruptly?
  • In Linux, seeing Zer0.tar.gz and copy.tar.gz during an investigation suggests which of the following?
  • Which tool is used to scan for open ports on a target host?
  • From a honeypot log excerpt, which IP address is shown as performing a port scan?
  • On a Linux system, which device name identifies the slave disk on the secondary IDE controller?
  • In DriveSpy, which format correctly specifies a copy of 150 sectors starting at sector 1709 on the primary hard drive?
  • Which statement about copyright duration is correct?
  • Which encryption option would have best prevented theft of data from laptops?
  • Why is it important to consider health and safety factors in forensic work at all stages?
  • What is the primary advantage of sector-by-sector disk imaging in forensics?
  • Which OSI layer is primarily responsible for end-to-end communication and error recovery?
  • What type of steganography did the suspects use?
  • From the log excerpt, which line indicates a DNS version query?
  • Digital evidence is not fragile in nature.
  • Hard disk data addressing is a method of allotting addresses to each ____ of data on a hard disk.
  • Anomaly-based IDS tends to produce the most false alarms because it relies on what?
  • What type of attack sends SYN requests to a target system with spoofed IP addresses?
  • What should you do when approached by a reporter about a case you are investigating?
  • In an investigation of a potential email crime, what is often the first step?
  • After an external IT audit, to mitigate DDoS attacks, which countermeasure would you implement?
  • What is the essential tool to prevent alteration of evidence when imaging a drive?
  • Which of the following is an IT security focus within organizational security?
  • During first responder procedure you should follow all laws while collecting the evidence, and contact a computer forensic examiner as soon as possible.
  • For preliminary investigations in a sexual harassment case, how many investigators are recommended?
  • During the seizure of digital evidence, is the suspect allowed to touch the computer system?
  • Shortcuts with extension .Ink are created and accessed by users. They provide information about:
  • Which Outlook file type is typically used to store archived emails offline?
  • Which deposition practice is not standard?
  • Which statement best explains why Linux/Unix-based computers are preferred for idle scanning in the given scenario?
  • In routers, which memory area contains the startup configuration?
  • Which statement about a sheepdip computer is true?
  • If a network employs NAT and IPsec, which combination is likely to cause connectivity problems?
  • All Blackberry email is eventually sent and received through what proprietary mechanism operated by RIM?
  • Which wireless access control attack allows the attacker to set up a rogue access point outside the corporate perimeter and lure employees to connect to it?
  • Router log files provide detailed Information about the network traffic on the Internet. It gives information about the attacks to and from the networks. The router stores log files in the____________.
  • Where is the startup configuration located on a router?
  • Julia used which principle of social engineering when she posed as an IT technician and obtained credentials?
  • Which hashing method is used to password protect Blackberry devices?
  • In an email header, which field is typically used to trace the path a message has traversed across multiple mail servers?
  • In a TCP header, how many bits is the Source Port Number?
  • Which device interference could cause intermittent wireless dropouts in a home network with no encryption?
  • First sector of a hard disk is known as:
  • Which file system is typically used on floppy disks?
  • What is a chain of custody?
  • Hash injection attack allows attackers to inject a compromised hash into a local session and use the hash to validate network resources.
  • A method used to maintain state in HTTP communications across requests is the use of cookies.
  • Which command shows you the NetBIOS name table for the local machine?
  • Which option represents a recommended method for permanently erasing a hard drive so it can be reused?
  • In a scenario involving seizure of equipment, which US Amendment is implicated in protecting against unreasonable searches?
  • In digital security, what is a honeypot used for?
  • Which marker is placed in the first byte of a FAT directory entry to indicate that a file has been deleted?
  • In general, which field involves investigating data retrieved from hard disks by applying scientific methods?
  • Who is responsible for securing the scene and maintaining it in a secure state until the forensic team advises, and for making notes for the forensic team?
  • An investigator is searching through firewall logs and notices ICMP packets larger than 65,536 bytes. What type of activity is this?
  • What can an investigator examine to verify that a file has the correct extension?
  • Dumpster diving refers to:
  • Which binary coding is most often used for email?
  • Which registry key stores the values typed into the Run dialog box in the Start menu?
  • What is the minimum number of bit-stream copies recommended for a suspect drive?
  • What does the Windows SAM file store?
  • Which IDS approach typically yields the most false alarms due to unpredictable user and network behavior?
  • Which element should be recorded when documenting an electronic crime scene?
  • Which security control best prevents tailgating into a restricted area?
  • What is the role of metadata in a forensic investigation?
  • What element is unique to ISO 9660 images compared to typical hard drive file systems?
  • Which registry hive contains hardware and software configuration information?
  • What does ADS stand for in Windows forensic terminology?
  • In the web services stack, which layer is vulnerable to fault code leaks?
  • Which file in Novel GroupWise stores information about user accounts?
  • System software password cracking is defined as cracking the operating system and all other utilities that enable a computer to function.
  • If a suspect computer location may involve toxic chemicals, what is the proper response?
  • Under what circumstances would you conduct searches without a warrant?
  • A rogue/unauthorized access point is one that is not authorized for operation by a particular firm or network.
  • Firewalk aims to map which layer's firewall rules by sending packets with specific TTL values?
  • What is the primary function of a SIM card in mobile networks?
  • Email archiving: Local archives: Which statement is correct while dealing with local archives?
  • What is the first step taken in an investigation by laboratory forensic staff members?
  • The newer Macintosh Operating System (MacOS X) is based on which of the following?
  • Office documents include a code that tracks the MAC address of the machine that created the document. What is this code called?
  • ISO 9660 is primarily used with which type of physical media?
  • Interpreting the Nmap command 'nmap -sU -p445 192.168.0.0/24', which statement is correct?
  • What advantage does a forensic disk image have over a simple backup copy in investigations?
  • Which HTTP status code indicates the requested resource could not be located?
  • Which filesystem is used by Mac OS X?
  • Which technique hides data inside an image by manipulating the least significant bits?
  • If an attacker wants to perform a new line injection attack in a log file, what would they inject into the log?
  • Which of the following is not an example of a cyber-crime?
  • Which of the following commands shows all network services currently running on Windows-based servers?
  • The SIM file system resides in which type of memory?
  • Using Lophtcrack in sniffing mode, what information can be gathered about a target's account?
  • In forensic practice, what is the purpose of creating a forensic bit-stream image of a storage device?
  • In a court case, a lay witness is asked to testify. In terms of expertise, in what field would a lay witness be considered an expert?
  • Event correlation is the process of
  • Which constitutional protection prevents the police from breaking down a door and seizing equipment without a warrant?
  • Mobile phone forensics is the science of recovering digital evidence from a mobile phone under forensically sound conditions.
  • During a DoS testing engagement, what is a primary objective?
  • If you are concerned about a high level of compression but not concerned about any possible data loss, what type of compression would you use?
  • How many hexadecimal characters does an MD5 checksum have?
  • In digital forensics, what maintains hash signatures for known software to help identify components in a system?
  • A law enforcement request to monitor all network traffic could potentially make you what if complied with?
  • In forensic reporting, which statement best describes an ISO image captured from optical media?
  • How many times can data be written to a DVD+R disk?
  • During a network investigation, DNS packets traveling across the network belonged to a non-company configured IP. Which attack can be inferred?
  • In a finance fraud investigation where files on a bitmap image appear not saved, what should you examine next?
  • In digital forensics, which artifact is used to verify a forensic image has not been altered?
  • For acquiring digital evidence from four 30 TB storage area networks, which method is most efficient?
  • When the operating system marks cluster as used, but does not allocate them to any file, these clusters are known as __________.
  • Which platform’s tooling is commonly used to mount an ISO image?
  • Which archive format commonly contains multiple files and directories and is used with compression to save space?
  • Which network protocol analyzer is commonly used for real-time packet capture in forensic investigations?
  • Where is the hidden swap file in Windows located?
  • What is cold boot (hard boot)?
  • To view who is connected remotely to a Windows machine, and from which client, you would use which command?
  • Digital evidence validation involves using a hashing algorithm utility to create a binary or hexadecimal number that represents the uniqueness of a data set. Which of the following hash algorithms produces a message digest that is 128 bits long?
  • Which standard uses publicly disclosed cybersecurity vulnerabilities with unique identifiers?
  • During the seizure process, which practice is incorrect?
  • Which protocol is used to describe the connection points of Web services?
  • Steven designing a computer forensics lab; how many exits should he include?
  • Which approach checks and compares all the fields systematically and intentionally for correlation with each other across one or multiple fields?
  • Which of the following is not a consideration in a forensic readiness planning checklist?
  • Which attack floods a network by sending ICMP echo requests to a broadcast address?
  • Why should you never power on a computer that you need to acquire digital evidence from?
  • Which steganography type is described as hiding the secret message in a pattern on the document that is unclear to the average reader?
  • Which technique involves impersonating another device by altering the MAC address to bypass access controls?
  • From the screenshot of the network device in a maintenance audit, which change should the client company make?
  • Which field in the log contains the date and time of the request?
  • In password cracking, what is the second step after creating a wordlist?
  • With regard to using an antivirus scanner during a computer forensics investigation, you should:
  • What is the size limit for the Recycle Bin in Vista and later versions of Windows?
  • If a web application responds with an error after entering a stray quotation mark in a user input field, what can you infer?
  • Which virus type mutates its decryption routine with every infection, altering its signature but not necessarily rewriting the entire code?
  • What type of equipment would a forensics investigator store in a StrongHold bag?
  • What type of analysis helps to identify the time and sequence of events in an investigation?
  • John should specify which type of shredder in guidelines to destroy outdated documents?
  • TCP/IP is a communication protocol used to connect different hosts in the Internet. It contains four layers, namely the network interface layer, Internet layer, transport layer, and application layer. Which of the following protocols works under the transport layer of TCP/IP?
  • What is the role of a Data Recovery Agent in Windows Encrypting File System (EFS)?
  • In digital forensics, what is the primary purpose of hashing the evidence container?
  • Which encryption algorithm does WPA2 use for enterprise and Wi-Fi security?
  • Why can files emptied from the Recycle Bin sometimes be recovered on Windows?
  • During a security assessment, why is it recommended to remove extraneous identifying information from service banners?
  • Which tool is used to perform an XMAS scan in the described scenario?
  • A buffer overflow attack can be used to modify the target process's address space to control the process execution.
  • Which Windows system file stores the contents of RAM when the system hibernates?
  • Which statement about a forensic tool's capability is true?
  • Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
  • What is the smallest physical storage unit on a hard drive?
  • In Windows, a Security Identifier (SID) uniquely identifies which of the following?
  • Graphics Interchange Format (GIF) is a ______ RGB bitmap Image format for images with up to 256 distinct colors per frame.
  • What is a primary reason for performing a penetration test from inside an organization?
  • Why is it important to set each wireless access point on a different channel when deploying multiple APs?
  • When a vulnerability scan is interrupted because the IDS cuts off your connection, what type of IDS is being used?
  • In social engineering training, which principle was demonstrated when an attacker leverages a superior's name to obtain credentials?
  • Which statement best describes CDFS in Windows?
  • Which Windows process is primarily responsible for starting the user session after credentials are validated during logon?
  • The role of the forensic investigator includes which of the following?
  • Which of the following is NOT a part of the environmental conditions of a forensics lab?
  • In the provided C code snippet, the vulnerability arises when copying argv[1] into a fixed-size buffer?
  • What type of flash memory card comes in Type I or Type II and consumes only five percent of the power required by small hard drives?
  • What feature of Decryption Collection allows an investigator to crack a password as quickly as possible?
  • In digital forensics, what is the primary purpose of a chain of custody form?
  • Identify the attack from the following sequence of actions? Step 1: A user logs in to a trusted site and creates a new session Step 2: The trusted site stores a session identifier for the session in a cookie in the web browser Step 3: The user is tricked to visit a malicious site Step 4: the malicious site sends a request from the user's browser using his session cookie
  • In a DHCP-enabled network, which log is most reliable for associating a specific IP with a MAC address at a moment in time?
  • Where is a honeypot best placed on a network according to recommended practice?
  • Which Google search string would locate the Microsoft Outlook Web Access Default Portal?
  • Which deposition scenario is considered a standard practice?
  • Kimberly wants to learn a networking protocol language that routers utilize; which is the appropriate choice?
  • If an attacker's IPID of 31400 to a zombie on an open port in IDLE scanning, what will be the response?
  • Which item is least likely to be stored in standard email server logs?
  • What is the maximum drive size supported by FAT32?
  • Which file structure database, commonly used on floppy disks, contains information about files stored on the drive?
  • What method of copying should always be performed first before carrying out an investigation?
  • Which organization provides tools and procedures for testing and validating computer forensics software?
  • In a TCP header, which field is 16 bits long and represents the source port?
  • While reviewing HTML code in a web page, you discover a tiny element that loads a resource from a remote server to report when the page is viewed. What is this element most commonly called?
  • Which term describes a vulnerability assessment result where the test reports no issues, but exploitable vulnerabilities exist?
  • Which attack uses a trusted site's cookie to forge a request from the victim's browser?
  • At a crime scene, if a computer is powered off, should you turn it on?
  • Which statute governs preservation of user emails by an ISP in response to a legal request, specifically the f subsection?
  • DNS poisoning primarily results in wrong responses from which component?
  • What port do you send an email to on the company SMTP server?
  • Daryl's data acquisition scenario asks how many data acquisition tools should be used when copying evidence. How many are recommended?
  • During the cataloging of digital evidence, what is the primary objective?
  • Which statement about a Fraggle attack is correct?
  • In the Davidson Trucking harassment case, whom should the prosecuting attorney call upon for not upholding company policy?
  • Which Operating System logs contain information about operational actions performed by OS components?
  • Which passwords are sent over the wire (and wireless) network, or stored on some media as it is typed without any alteration?
  • Which registry key stores the history of items entered in the Run dialog box?
  • Which site can be used to view archived web pages of defunct sites?
  • What is the primary purpose of an electronic crime scene checklist?
  • From the given sample log entries, which line is an Apache error log entry?
  • Technical Steganography is defined as steganography that uses which method to hide the existence of a message?
  • What is the purpose of creating a forensic image?
  • In the context of mitigating DDoS, which option would help reduce broadcast-based amplification?
  • When a router receives a routing table update, how does the metric for that path typically change?
  • During a ping sweep to identify live hosts, you receive responses from only Unix-like systems. Which statement is most accurate?
  • Data Acquisition in digital forensics primarily involves imaging or obtaining information from a device and its peripherals.
  • In digital forensics, what is the primary advantage of using a disk imaging tool over a simple copy?
  • In a forensic investigative report, consistency of information is considered more important than adhering to a strict formatting style.
  • In the logon event ID table, which event ID represents a successful logging on to a computer?
  • When collecting electronic evidence at a crime scene, the data collection should proceed from most volatile to least volatile. Which statement best describes this principle?
  • What is the purpose of a DNS zone transfer?
  • During Windows forensics, which device helps prevent contamination to the evidence drive during acquisition?
  • In a case where encrypted NTFS EFS files on an employee's computer were copied to removable media, which option best describes how investigators can recover the encrypted data?
  • In Windows 7, where are Microsoft Security IDs (SIDs) located within the Registry?
  • Which statement reflects the policy on attempting to restore or recover information from a system containing electronic data during a forensic investigation?
  • What file is processed at the end of a Windows XP boot to initialize the logon dialog box?
  • When NTFS is formatted, the initial sectors are allocated to boot sectors and bootstrap code. How many of the first sectors are reserved?
  • Which table is used to convert huge word lists (i.e., dictionary files and brute-force lists) into password hashes?
  • In email logs, which item uniquely identifies a single message across systems?
  • Which tool is commonly used to perform man-in-the-middle attacks on a LAN to capture credentials?
  • Which category of forensic analysis involves examining data transmitted over networks to detect anomalies?
  • What advantage does the tool Evidor have over the built-in Windows search?
  • What is the goal of forensic science?
  • What term describes embedding information into something else for the sole purpose of hiding that information from the casual observer?
  • Which integrity check is used by EnCase to ensure forensic evidence remains unchanged?
  • What is the outcome of executing a vulnerable login query that ends with DROP TABLE members;--' in the same batch as a SELECT query?
  • To prevent an attacker from enumerating Cisco router model, OS version, and capabilities, which feature should be disabled?
  • What practice helps verify the integrity of a forensic image?
  • In a backbone router flood scenario, what will the other routers communicate to each other to maintain services?
  • You can interact with the Registry through intermediate programs. Graphical user interface (GUI) Registry editors such as Regedit.exe or Regedt32.exe are commonly used as intermediate programs in Windows 7. Which of the following is a root folder of the registry editor?
  • What happens when a file is deleted in Windows 7?
  • Centralized logging is defined as gathering logs in a central location for monitoring and detecting security incidents. Which statement is true?
  • In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?
  • The type of attack that floods a service to render it unavailable is called?
  • To prove that evidence has not been altered since it entered the lab, which action should you take?
  • On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?
  • In Windows IIS Web Server logs, how often is a new log file created?
  • Data files from original evidence should be used for forensics analysis.
  • TCP and UDP utilize which layer of the OSI model?
  • Which intrusion detection system audits events on a specific host?
  • In a forensics investigation, restoration of information should be attempted only by qualified computer forensics personnel.
  • Which statement correctly describes the duration of copyright protection for a published work?
  • Which log injection attack uses white space padding to create unusual log entries?
  • While looking through the IIS log file of a web server, you find the following entries: What is evident from this log file?
  • Microsoft Outlook stores email messages in what type of file?
  • Which statement best describes a legitimate use of the MD5 utility in digital forensics?
  • Which security control prevents unauthorized individuals from following an authorized person through a door?
  • In evidence collection, why should you note all cable connections for a seized computer?
  • In Windows 7 auditing, the event ID for changes to audit policy is:
  • Which protocol is primarily responsible for routing email messages between mail servers?
  • Identify the Apache error log from the Linux logs: which option represents an error log entry?
  • In echo data hiding, the secret message is embedded into which element as an echo?
  • Which serial communication standard is used in serial data acquisition systems when the data location is at a distance?
  • Which type of scan uses ICMP ECHO Requests to detect live hosts?
  • In a 20-digit ICCID, which digits denote the issuer identifier number?
  • Two common methods used by password cracking software?
  • Which statute authorizes an investigator to request preservation of all emails for a user account, compelling the ISP to preserve records?
  • At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.
  • Which statement reflects the guideline about attempting to restore or recover information from a system holding electronic information?
  • What determines the source, nature, and time of an attack on a compromised system?
  • Which statement about NTP Stratum Levels is true?
  • What is static executable file analysis?
  • Hard disk sectors typically contain how many bytes?
  • When a monitor is powered on but the display is blank at a crime scene, what is the recommended action?
  • To preserve digital evidence, an investigator should make two copies of each evidence item using different imaging tools.
  • To improve SNMP security without disabling remote monitoring, which action is recommended?
  • Which action best supports maintaining objectivity when evidence suggests innocence?
  • An image is an artifact that reproduces the likeness of some subject. These are produced by optical devices (i.e. cameras, mirrors, lenses, telescopes, and microscopes). Which property of the image shows you the number of colors available for each pixel in an image?
  • In Windows XP repair installation, which option could grant administrative rights during setup?
  • Which network attack refers to sending huge volumes of email to an address in an attempt to overflow the mailbox, or overwhelm the server where the email address is hosted, to cause a denial-of-service attack?
  • For log files to be admissible in court, how often must they be kept?
  • To prove that evidence has not been altered since entering the lab, which approach is correct?
  • A law enforcement officer may only search for and seize criminal evidence with ___________________, the standard that justifies a search.
  • In a forensic ISO image, which artifact is most likely to indicate the source medium type?
  • How should custody forms be stored for 15 hard drives to preserve chain of custody?
  • A honeypot is set up as a DMZ with no direct access to production networks. Why might pursuing legal action against the intruder be problematic?
  • On Linux/Unix based web servers, the daemon should run under which privilege level?
  • A vulnerability scan that identifies a vulnerability that is actually exploitable is called what?
  • During a security test, after an external DoS attack, an FTP session from an external IP to the internal network succeeds. What happened to the firewall?
  • Encrypting File System (EFS) is a feature of which Windows file system?
  • To avoid contaminating the suspect’s hard drive when starting up the computer, which hardware setting should be consulted?
  • LBA (Logical Block Address) addresses data by allotting a ___________to each sector of the hard disk.
  • During a DoS test, sending ICMP ECHO requests to the broadcast address corresponds to which type of attack?
  • Which TCP/UDP port is associated with the netstat toolkit as described in some practice materials?
  • In the given C program, which vulnerability arises when argv[1] is copied into a fixed-size buffer?
  • When investigating a computer, you find many files whose first letter has been replaced by the hex code 5h. What does this indicate?
  • What is the name of the service used to synchronize time among multiple computers?
  • Sniffers that place network interface cards in promiscuous mode operate at which layer of the OSI model?
  • Temporal Key Integrity Protocol (TKIP) enhances WEP by adding a rekeying mechanism to provide fresh encryption and integrity keys. Temporal keys are changed for every __________.
  • In the Nmap command shown, what does data_length 66000 test?
  • Which document must be obtained before an on-site digital investigation?
  • Warning banners are used to address employees' concerns about privacy when connecting to the company intranet, network, or VPN. They primarily address which right?
  • On Linux/Unix based web servers, under which privilege should the daemon service be run?
  • In CHS disk geometry, which term represents the factor multiplied by 512 bytes per sector to compute disk size?
  • Cyber-crime is defined as any Illegal act involving a gun, ammunition, or its applications.
  • How do the evidence handling procedures differ between criminal and civil cases?
  • Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.
  • Which protocol uses port 25 by default for email transfer?
  • What is a common method to bypass a BIOS password?
  • Why might Firewalk traffic not appear in a sniffer placed deeper in the network when testing a Cisco PIX firewall?
  • P0P3 (Post Office Protocol 3) is a standard protocol for receiving email. By default, to fetch emails, the client connects to the POP3 server on which port?
  • DBX files recovered during forensic investigation can be analyzed by which email client?
  • Which is a Linux journaling file system?
  • What must an investigator do before disconnecting an iPod from any type of computer?
  • What is the primary purpose of an Outlook PST file?
  • Which file system would you expect on very small removable media such as old floppy disks?
  • In wireless discovery, which action characterizes active scanning?
  • What is SCSI (Small Computer System Interface)?
  • You are testing a dynamic website for vulnerabilities and input a test string that triggers a pop-up saying 'This is a test.' What vulnerability does this indicate?
  • During a legal search with a valid warrant, officers observe an item of evidence in plain view that was not included in the warrant. What doctrine allows this evidence to be admissible?
  • The term Master Boot Record refers to the first sector of the disk that contains bootstrapping code. Which option reflects this?
  • Which NTFS component stores metadata about files?
  • What technique used by Encase makes it virtually impossible to tamper with evidence once acquired?
  • During evidence handling, which practice supports integrity and chain of custody?
  • In the example command 'firewalk -F 80 10.10.10.1', which IP is the target host used for the scan?
  • What RestrictAnonymous value is required for complete security against anonymous null sessions?
  • Which hash verification algorithm is explicitly supported by Decryption Collection?
  • What is the primary purpose of creating a forensic image using a write blocker?
  • In legacy Windows systems, which file is responsible for reading the boot configuration and loading the kernel components?
  • What is the primary purpose of a software dongle when distributing commercial software?
  • In chain of custody, what does a link refer to?
  • During the confession, which technique was used to hide pictures within other pictures?
  • In a forensic examination of hard drives, which type of user would have the most file slack to analyze?
  • Which operating system is associated with the Paraben Lockdown device for writing hard drive data?
  • When an iPod is connected to a Windows host, which file system is used?
  • In NTFS Master File Table, a data stream file corresponds to which descriptor?
  • What term describes the practice of locating wireless networks by moving around with a wireless device, often to map networks and collect data?
  • The efforts to obtain information before a trial by demanding documents, depositions, and examination of the scene is described as what legal term?
  • What is the primary purpose of centralized log management?
  • Which term describes evidence that supports guilt or involvement of a suspect?
  • To investigate threatening emails, which artifact should you examine to trace messages back to the sender?
  • Email spoofing refers to:
  • Which stage of incident handling would you perform immediately after containment to restore normal operations?
  • In vulnerability assessment, if a second utility verifies results by exploiting the system and finds exploitable weaknesses the initial analysis said were not exploitable, what type of result is this called?
  • Where is the default location for Apache access logs on a Linux computer?
  • When searching file headers for JPEG formats in hex, which sequence indicates a JPEG header?
  • Which property defines the number of colors available for each pixel?
  • Which registry hive stores system-wide configuration and hardware information?
  • An ISO image is best described as which type of forensic evidence?
  • Which wireless standard has bandwidth up to 54 Mbps and signals in a regulated frequency spectrum around 5 GHz?
  • In the sample honeypot log, which event indicates an FTP password retrieval attempt?
  • One way to identify the presence of hidden partitions on a suspect's hard drive is to...
  • Which disk area is most commonly examined to recover remnants of deleted data in forensic analysis?
  • When should an MD5 hash check be performed during evidence processing?
  • Which term describes the smallest addressable unit on a disk in common terminology?
  • Which principle states that every contact leaves a trace and transfer occurs between objects and people?
  • What does the superblock in Linux define?
  • When an operating system marks a cluster as used but not allocated, the cluster is considered as which of the following?
  • JPEG compression is commonly described as lossy. Which statement correctly reflects this property?
  • Is digital photography accepted as evidence in the court of law?
  • Which port is used to receive SNMP traps?
  • Windows identifies which application to open a file with by examining which of the following?
  • Data compression maintains data integrity?
  • An ISO image of optical media stored in a CDFS format is being analyzed. What type of evidence does this ISO image represent?
  • Which steganography technique is described as creating a cover for secret communication?
  • In intrusion detection systems, which approach uses statistical models to establish a baseline of normal activity?
  • In the IIS log sample, which value represents the service status code?
  • In an IIS log entry, which field identifies the target resource requested by the client?
  • Which document is typically used to formally document the chain of custody for digital evidence?
  • Which of the following attacks allows attacker to acquire access to the communication channels between the victim and server to extract the information?
  • What is the purpose of the Recycle Bin in Windows?
  • In the computer forensics investigation methodology, in which step would you run an MD5 checksum on the evidence?
  • Which command would you use to view active network connections on a Windows machine?
  • What Linux command is commonly used to create bit-stream images?
  • In a vulnerable login scenario, a query containing DROP TABLE demonstrates what kind of vulnerability?
  • In professional computer forensics, how many mismanaged cases are said to ruin a practitioner’s reputation?
  • Which Windows Registry hive contains the user's password file?
  • In a Windows system, which statement best explains why the swap file is examined during forensics?
  • Which factor is most important to a CHFI professional's reputation?
  • Why would a scanner like Nessus not be recommended for stealthy wireless network testing?
  • Which TCP/IP header field is involved in the Ping of Death exploit?
  • What is the ISP's ability to assist in computer abuse investigations?
  • The MD5 checksum on evidence is used to:
  • RAID 5 provides fault tolerance by distributing parity across disks.
  • What is the Best Evidence Rule?
  • In raw data acquisition, the initial data set is typically stored as what type of file?
  • What is the primary purpose of a software firewall?
  • From the log excerpt, which line indicates a port scan detected from 194.222.156.169?
  • What is the first step required when preparing a computer for forensics investigation?
  • Can an employer file a criminal complaint if investigating within the workplace?
  • Which organization coordinates computer crime investigations across the United States?
  • Which action best maintains evidence integrity when collecting data?
  • After a file is deleted on a FAT file system, what is the status of its data blocks?
  • In the Recycle Bin rename Dxy.ext, the segment 'ext' stands for which of the following?
  • The newer Macintosh Operating System (MacOS X) is based on which Unix lineage?
  • What is the best practice to ensure evidence integrity during collection?
  • What does the acronym POST mean as it relates to a PC?
  • Which law addresses fraud and related activity in connection with computers?
  • Which is a standard procedure to perform during all computer forensics investigations?
  • What information do you need to recover when searching a victim computer for a crime committed with a specific e-mail message?
  • A picture file recovered from a computer is enlarged 500% without degradation. What kind of image is this?
  • If you come across a sheepdip computer at a client site, what would you infer?
  • What does LBA stand for in disk addressing?
  • Which term refers to data that may remain in a cluster after the original file has been overwritten by another file?
  • In a 1,000,000-population city, how many law enforcement computer investigators should staff the forensics lab?
  • In the Master File Table of an NTFS disk, what type of file is represented by a colon followed by a name?
  • Which HTTP request method is shown in the sample log line?
  • Which method will allow you to trace all ever-established user accounts on a Windows 2000 server over its lifetime?
  • What is the purpose of a hardware write-blocking device in digital evidence acquisition?
  • In incident response, who is responsible for collecting, preserving, and packaging electronic evidence?
  • Which security log contains logs of network and host-based security software?
  • Which artifact did Heather find that suggested covert communication among the suspects?
  • Which element is most useful for tracing the source of a threatening email?
  • After running rdisk /s to grab the backup SAM file, where should you navigate on the system to find the file?
  • What type of attack occurs when a router is flooded with many open connections so that all hosts behind it are effectively disabled?
  • Routers operate at which layer of the OSI model?
  • Which federal statute is associated with Fraud and related activity in connection with computers?
  • If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system during an investigation, what can you conclude?
  • Which DNS operation transfers a complete zone data from master to slave?
  • Which term describes luring a suspect to commit a crime by presenting a fake vulnerability in a controlled environment?
  • Which command shows you the names of all open shared files on a server and the number of file locks on each file?
  • Which artifact is most likely to retain remnants of deleted data on a bitmap image?
  • In the physical storage format used by the Recycle Bin, files are renamed as Dxy.ext. What does the placeholder X represent?
  • Which statement is NOT correct while preparing for testimony?
  • Which action is performed by the fdisk utility on a Linux system?
  • Which type of memory is volatile and loses its contents when power is lost?
  • Syslog is a client/server protocol standard for forwarding log messages across an IP network. Which transport protocol does Syslog use to transfer log messages in a clear text format?
  • A forensics investigator needs to copy data around 42 GB to removable media for analysis at another location. Which type of media would be suitable?
  • Which statement is not part of securing and evaluating electronic crime scene checklist?
  • Which type of credential content is identified in HKLM\SECURITY\Policy\Secrets as being stored in plain text?
  • During evidence collection, what action represented evidence tampering?
  • Which protocol operates in the transport layer of TCP/IP and provides connectionless communication?
  • In an XMAS scan where most ports do not respond, in what state are these ports?
  • Which of the following is not a part of the technical specification of the laboratory-based imaging system?
  • Which statement best defines forensic computing?
  • A computer forensics investigator analyzing firewall logs observes unusual traffic patterns. What can be inferred?
  • Larry plans on shutting down the city’s network using BGP devices and zombies. What type of Penetration Testing is this?',
  • In computer forensic analysis, which practice helps prevent the work from expanding beyond the original scope?
  • In the aa/ddmmyy/nnnn/zz format of evidence labeling, what does the nnn denote?
  • In web server logs, timestamps are typically recorded using which standard to ensure consistent correlation across servers?
  • George, recently fired as an IT analyst, wants to break into the company network by cracking service accounts. Which password cracking technique should he use in this situation?
  • If a company has not published a policy on inspecting computing assets, what privacy risk does this create for employees?
  • What is the first step that needs to be carried out to investigate wireless attacks?
  • The main role of computer forensics is to:
  • Which stage of incident handling involves reporting events?
  • Which statement is not correct when dealing with a powered-on computer at a crime scene?
  • Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
  • What is kept in the registry key HKLM\SECURITY\Policy\Secrets?
  • Which folder name is associated with the Recycle Bin on Windows file systems as used in the example?
  • Which extension is commonly associated with Photoshop documents?
  • In a compromised Active Directory environment, which port and tool combination is typically used to interrogate LDAP on a Domain Controller?
  • A packet is sent to a router that does not have the destination address in its route table. What mechanism allows it to be forwarded toward the proper destination?
  • Under US federal rules, what is the most appropriate reason for denying the eligibility of a computer forensic expert as an expert witness?
  • Which Task List command provides information about listed processes, including the image name, PID, name, and the session number?
  • Which statement best describes the action of a Network Intrusion Prevention System (NIPS)?
  • What operating system would respond to the command 'C:\> nmap -sW 10.10.145.65'?
  • If a user closes a browser on a public computer without logging out, and an attacker later reuses the same browser session to impersonate the user, which vulnerability type best describes this exploitation?
  • JPEG compression uses a lossy algorithm that divides the image into blocks of pixels. These blocks are of what size?
  • What type of testimony is presented by someone who performed the actual fieldwork and does not offer a view in court?
  • In a FAT32 system using 512-byte sectors, a 123 KB file occupies how many sectors?
  • During a forensic examination, which procedure is performed with the hard drive removed?
  • Log management includes all processes and techniques used to collect, aggregate, and analyze computer-generated log messages. True or False?
  • In a Linux forensic write operation, using /dev/zero as the input device to /dev/hda results in what?
  • In the Ping of Death exploit, which header field is manipulated?
  • Steganography is a technique of hiding a secret message within an ordinary message and extracting it at the destination to maintain the confidentiality of data.
  • Which type of report is delivered under oath to a board of directors/managers/panel of jury?
  • During evidence transport, which practice helps preserve integrity?
  • Which password cracking technique works like a dictionary attack but adds some numbers and symbols to words from the dictionary?
  • The ARP table maps IP addresses to MAC addresses on a local network. Which statement correctly describes this mapping?
  • You have compromised a lower-level administrator account on an Active Directory network of a small company. While enumerating, you connect to a Domain Controller on port 389 using ldp.exe. What are you trying to accomplish here?
  • In Linux forensic imaging, what would the command dcfldd if=/dev/zero of=/dev/hda bs=4096 conv=noerror, sync accomplishes?
  • Which statement is NOT part of disk imaging tool requirements?
  • Using DNS DIG with AXFR/IXFR, what is the attacker attempting to do?
  • Which tool is commonly used to generate a hash for verifying data integrity?
  • Injection flaws are web application vulnerabilities that allow untrusted data to be interpreted and executed as part of a command or query. Which injection flaw involves injecting malicious code through a web application?
  • Which practice is most consistent with a stealthy security assessment in wireless networks?
  • In mobile device forensics, if the display is on and you want to preserve evidence, you should:
  • Information posted in a job listing that reveals internal technology details is considered what?
  • Which mobile operating system architecture corresponds to a system that manages communication between a mobile device and other devices such as computers, televisions, or printers?
  • Which statement is true about the physical security of a forensics lab?
  • Which practice ensures data integrity of digital evidence during transfer?
  • In the CIDR example shown, which prefix length is indicated?
  • Before starting a search in EnCase, which item should be prepared to guide the search?
  • Which file extension is used by Microsoft Outlook to store its data?
  • In Windows security, a SID is best described as what?
  • What does IDS stand for in security?
  • Which hashing method is used to password protect Blackberry devices?
  • If you discover a criminal act while investigating a corporate policy abuse, it becomes a public-sector investigation and should be referred to law enforcement?
  • Which file system metadata marks a deleted file in Windows 7?
  • Diskcopy is which of the following?
  • You have been given the task to investigate web attacks on a Windows-based server. Which of the following commands will you use to look at which sessions the machine has opened with other systems?
  • What is the primary purpose of email archiving?
  • What is the purpose of the Exchange message tracking log?
  • Which tool is recommended for passive footprinting of a target web presence?
  • Where is the Windows Security Accounts Manager (SAM) file typically located?
  • What will this search produce?
  • After three failed PIN attempts, which option allows access to SIM data?
  • In handling computer-related incidents, which IT role is typically responsible for recovery, containment, and prevention to constituents?
  • Which step is essential before presenting evidence in court?
  • A data acquisition system is described as a combination of tools or processes used to gather, analyze and record information about a phenomenon. Which option best represents this definition?
  • What information will the virtual memory scan reveal when inspecting a system potentially used as a botnet server?
  • Where does Encase search to recover NTFS files and folders?
  • Which statement best describes a bit-for-bit copy?
  • Harold wants to allow FTP-PUT; which firewall would be most appropriate?
  • During a test, when an external firewall unexpectedly allows an internal connection after a DoS event, what is the most likely explanation?
  • Which file should be used to restore archived email messages for someone using Microsoft Outlook?
  • In a breach scenario, which term describes the attack on a PBX system used to store music files?
  • Which IDS capability analyzes events in real time to detect anomalies as they occur?
  • An attack vector is a path or means by which an attacker can gain access to computer or network resources in order to deliver an attack payload or cause a malicious outcome.
  • Given the drive dimensions 22,164 cylinders per disk, 80 heads per cylinder, and 63 sectors per track, what is the approximate capacity?
  • Which standard emphasizes testing, peer review, error rates, and general acceptance in admissibility of scientific evidence?
  • Which forensic investigation concept traces the entire sequence of an incident from its initiation to the impact on the victim?
  • Which action is NOT recommended when preserving evidence?
  • In Windows NTLM authentication, the passwords stored on domain controllers are in which database?
  • Why should you not delete a partition on a dynamic disk during a forensic investigation?
  • Determine the message length from the following hex viewer record:
  • Buffer Overflow occurs when an application writes more data to a block of memory, or buffer, than the buffer is allocated to hold. Buffer overflow attacks allow an attacker to modify the __________ in order to control the process execution, crash the process and modify internal variables.
  • At what layer does a cross site scripting attack occur on?
  • Quality of a raster image is determined by the __________ and the amount of information in each pixel.
  • In forensic reporting, what type of evidence supports a suspect's guilt?
  • In an email header, which entity represents the email's first origin?
  • Which encryption algorithm is used by Blackberry devices for Password Keeper?
  • Why were passwords set to 14 characters cracked quickly in the password audit?
  • In Microsoft file structures, sectors are grouped together to form which of the following?
  • In a FAT32 file system with 512-byte sectors, how many sectors are needed to store a 125 KB file?
  • In the Nmap command shown, which flag increases the verbosity of the output?
  • Which tool is commonly used to burn ISO images to optical media?
  • File signature analysis involves collecting information from the __________ of a file to determine the type and function of the file
  • Which statement does not support the case assessment?
  • Digital evidence validation uses a hashing algorithm to create a fingerprint of the data. Which of the following best describes this purpose?
  • The ARP table of a router is used to map IP addresses to MAC addresses. Which command in Windows 7 displays this mapping?
  • A steganographic file system is a method to store the files in a way that encrypts and hides the data without the knowledge of others.
  • Which steganography type hides the secret message in a pattern on the document that is unclear to the average reader?
  • Which protocol is commonly used to synchronize time between machines?
  • What is the first step to crack the password?
  • From the following spam mail header excerpt, which host IP is the one that sent the spam?
  • To verify the integrity of evidence during processing, which practice is recommended?
  • MAC filtering uses a network card's address of which bit length?
  • In the standard Linux Ext2 file system, a file is deleted when the inode internal link count reaches what value?
  • Which is a valid property of disk imaging when capturing evidence?
  • Data Acquisition is the process of imaging or otherwise obtaining information from a digital device and its peripheral equipment and media. Which statement is true?
  • Which tool is commonly used to obtain password hashes when sniffing mode is used by an attacker?
  • Abrupt power loss results in loss of which type of memory most directly?
  • Which file system is not designed for removable media and is typically associated with larger, non-removable volumes?
  • When examining a file with a hex editor, which part of the file contains the header?
  • In an unpatched IIS web server, a path traversal exploit to cmd.exe could result in which outcome?
  • In an investigation of corporate policy abuse, discovering an act that constitutes a crime should be referred to law enforcement authorities?
  • What is the smallest allocation unit of a hard disk?
  • Profiling is a forensic technique for analyzing evidence. After a system is compromised, which factor would be most important in forming a profile of the incident?
  • Which practice is recommended regarding antivirus scanning on a forensic workstation?
  • In a honeypot log, which event line indicates a port scan from an external IP?
  • Which of the following is not a role of the first responder at a computer crime scene?
  • Which file contains records that correspond to each deleted file in the Recycle Bin?
  • Which component of WPA uses a rekeying mechanism to provide fresh encryption and integrity keys?
  • Which encryption type would have prevented stolen corporate information from laptops if properly applied?
  • Which term describes the unauthorized change of the apparent source of an email message?
  • What does ICMP Type 3 Code 13 indicate?
  • In legacy Windows boot processes, which file is responsible for reading the boot configuration and loading the kernel components?
  • A computer forensic report describes the complete investigation process.
  • _______________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
  • Forensic computing: Which description best captures the goal?
  • A suspect is accused of viewing adult websites. The search history and downloaded files have been cleared. What is the most feasible way for the investigator to prove the violation?
  • SMTP (Simple Mail Transfer protocol) receives outgoing mail from clients and validates source and destination addresses, and also sends and receives emails to and from other SMTP servers.
  • Which component is NOT part of ISO 9660 and is used to extend compatibility, including longer file names in images?
  • Which statement about a steganographic file system is accurate?
  • Application and Web server logs are most useful in detecting which of the following?
  • What will the following Linux command accomplish? dd if=/dev/mem of=/home/sam/mem.bin bs=1024
  • True or False: Volatile information can be easily modified or lost when the system is shut down or rebooted.
  • What is a primary objective when securing relevant media at a crime scene?
  • A forensics investigator searches C:\RECYCLED but finds nothing. Why might nothing be found?
  • Which artifact typically reveals the route an email took from sender to recipient, including servers it passed through?
  • Which of the following statements is incorrect when preserving digital evidence?
  • From a 20-digit ICCID, identify the issuer identifier number.
  • The disk in the disk drive rotates at high speed, and heads in the disk drive are used only to read data.
  • Which steganography technique uses transform domain methods?
  • At which OSI layer are you primarily observing when monitoring traffic on a router for investigative purposes?
  • What step verifies that digital evidence has not been altered since collection?
  • Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server's root directory?
  • Netstat: Which netstat option lists all active TCP and UDP connections along with their process IDs and listening ports?
  • In Windows XP, what is a security risk associated with the repair installation?
  • Which risk is associated with performing evidence collection without proper safeguards?
  • Under the Daubert standard, which factor is commonly considered to validate forensic tools?
  • The attack that corrupts DNS cache causing users to be directed to the wrong site is called what?
  • Which command displays the network configuration of the NICs on the system?
  • What would be the next sequence of events after securing the incident scene and labeling cables?
  • Which file type is typically created for Windows printer spool processing?
  • To determine source, nature, and time of an attack from Application and Web server logs, you should:
  • In preparing an investigative report, which electronic format should be used for the primary electronic copy?
  • Which two methods are commonly used by password cracking tools?
  • Which statement is true about the combination of EFS, HFS+, EXT2, and NFS?
  • When examining a hard disk without a write-blocker, you should not start Windows because Windows will write data to the:
  • Which methodology is associated with ECSA-style security testing?
  • Using Linux to carry out a forensics investigation, what would the following command accomplish? dd if=/usr/home/partition.image of=/dev/sdb2 bs=4096 conv=notrunc,noerror
  • Which term describes an attack that exhausts network bandwidth by flooding traffic?
  • An 'idle' system is also referred to as what?
  • Which of the following is NOT a graphics file?
  • Which memory card type comes in Type I or II and consumes only five percent of the power?
  • In expert witness criteria, which option expresses the requirement that opinions rely on specialized knowledge?
  • Promiscuous mode on a NIC allows the device to capture what?
  • In a wireless security investigation, determining the gateway IP helps identify which device?
  • A grant of a property right for a new machine, process, utile composition of matter or manufacture is called what?
  • During security testing, you use virus code that rewrites itself entirely and changes the signatures with each infection but preserves functionality. What type of virus is this?
  • What is the primary purpose of an intrusion detection system?
  • Web applications provide an Interface between end users and web servers through a set of web pages that are generated at the server-end or contain script code to be executed dynamically within the client Web browser.
  • When should an MD5 hash check be performed during processing of evidence?
  • In a false survey website designed to harvest credentials, what information will you be able to gather?
  • When is computer forensics appropriate?
  • In a partition with an 8 GB size and a 4 KB cluster size, a 1 KB file is stored. How much slack space is wasted?
  • An on-site incident response team is called to investigate an alleged case of computer tampering within their company. The CEO classifies the incident as low level. How long will the team have to respond?
  • Which statement about logon warning banners is correct?
  • What is the maximum number of computers over which Decryption Collection can distribute processing?
  • Which action could compromise forensic integrity if not prevented during ISO imaging?
  • Which memory type loses its contents when power is removed?
  • Which document is typically used to establish legal control over evidence and its admissibility in court?
  • Why do PDF passwords not provide maximum protection when sending PDFs via email?
  • Damaged portions of a disk on which no read/Write operation can be performed is known as __________.
  • Where are files temporarily written in Unix when printing?
  • In a BGP test scenario, when a router fails, what do the remaining routers communicate to maintain routing?
  • In web server logs, the resource not found message corresponds to which HTTP status code?
  • Which of the following network attacks refers to a process in which an attacker changes his or her IP address so that he or she appears to be someone else?
  • An employee attempts to wipe data from CDs and DVDs with a magnet. CDs and DVDs are ________ media and are not affected by the magnet.
  • A rogue access point is defined as one that is not authorized for operation.
  • MD5 checksums serve what purpose in digital forensics?
  • During a hacking ring investigation, you recover a PDA attached to several peripherals. What is the first step to preserve the integrity of the evidence?
  • In NTP terminology, a Stratum-1 time server is linked to UTC sources such as GPS via what medium?
  • Raw data acquisition format creates ____________ of a data set or suspect drive.
  • What technique is used by JPEGs for compression?
  • Volatile Memory capture: which is most appropriate to overcome capturing volatile memory?
  • In incident response, which log would contain entries about security software alerts and policy violations on endpoints?
  • On a FAT-based file system, what happens when a file is deleted?
  • To check for POP3 traffic using Ethereal, which port should you filter by?
  • Which log-file naming format is used by IIS for daily rotation, as described in the source?
  • Which term best describes network-enabled corporate spying?
  • An expert witness is someone whose education, profession, or experience gives them specialized knowledge beyond the average person.
  • Which action is least appropriate during documentation of chain of custody?
  • Which mobile operating system is free and open source?
  • To recover the IMEI number from a Nokia device, which key combination should you use?
  • In NTFS, which structure contains detailed metadata for files and directories used by forensic tools to locate and recover data?
  • An ISO image of a CD contains which of the following as part of its structure?
  • What is the term used for Jacob's testimony regarding the accuracy and integrity of technical log files gathered in an investigation?
  • Which protocol commonly uses port 445 for Windows file sharing?
  • What information can be obtained from DHCP logs?
  • Which CIDR prefix length corresponds to a subnet mask of 255.255.255.0?
  • Attack using dot-dot-slash sequences is known as what?
  • Where could the investigator search to find the message tracking log file on the Exchange server?
  • Which command shows the username and IP address used to access the system via a remote login session and the Type of client from which they are accessing the system?
  • Which term describes an attack performed by a computer program rather than manual steps?
  • In a setup with Microsoft Exchange and Blackberry Enterprise Server, where would you search to find emails sent from a Blackberry device?
  • In the context of file deletion process, which statement holds true?
  • Web applications provide an interface between end users and web servers through pages generated on the server or via client-side scripts.
  • When collecting evidence from the RAM, where do you look for data?
  • Accessing a router's configuration via an HTTP URL demonstrates which vulnerability?
  • If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?
  • Which response organization tracks hoaxes as well as viruses?
  • Network forensics allows investigators to inspect network traffic and logs to identify and locate the attack system. Which statement best describes a typical outcome?
  • To sniff FTP credentials between the Swiss bank and its London subsidiary, which tool would you use?
  • In Linux, what is the smallest possible shellcode?
  • Which term describes the unwanted or uncontrolled growth of a project’s scope?
  • Which organization serves as the certifying body for forensic laboratories?
  • A web bug is commonly used to track a user's activity on a website. Which option best describes this?
  • Setting APs on different channels primarily reduces which type of interference?
  • In a DHCP-enabled network, which logs should you examine to determine which system (MAC address) held a specific IP address at a given time?
  • Which steganography technique is used to create cover for secret communication?
  • Which federal statute addresses Fraud by wire, radio, or television?
  • Which statute protects critical infrastructure by prohibiting willful damage to power or communications lines?
  • During data acquisition, you should typically work on a duplicated copy rather than the original to preserve evidence.
  • If exculpatory evidence is found and is not released to the defense, what should you do?
  • Which data source is most reliable for reconstructing the creation events of user accounts on a Windows server?
  • In a wireless local area network (WLAN), which device determines the next network point to which a packet should be forwarded toward its destination?
  • Which vulnerability allows an attacker to execute shell commands on an IIS server by constructing SQL statements?
  • When carving a disk image, recovering the original image primarily depends on which factor?
  • Which of the following is not a part of data acquisition forensics Investigation?
  • Which Wi-Fi chalking method refers to drawing symbols in public places to advertise open Wi-Fi networks?
  • Which of the following is not correct when documenting an electronic crime scene?
  • What does CDFS stand for in the context of optical media and ISO images?
  • Which standard is based on a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?
  • Which statement best describes an expert witness?
  • A clothing designer uses the same graphic symbol as their employer with different wording; which area of law is implicated?
  • Which Windows feature is associated with alternate data streams?
  • Netstat is a tool for collecting Information regarding network connections. It provides a simple view of TCP and UDP connections, and their state and network traffic statistics. Which of the following commands shows you the TCP and UDP network connections, listening ports, and the identifiers?
  • NFS is designed to provide access to a network file system over which protocol?
  • In Windows Security Event Log, event ID 531 indicates what?
  • What is the primary purpose of warning banners in corporate networks?
  • Which of the following should a computer forensics lab used for investigations have?
  • Which option describes formatting the drive with a low-level disk utility to wipe data?
  • George wants to monitor only SFTP traffic in Ethereal. Which filter should he apply?
  • Area density on storage media refers to the amount of data per which metric?
  • Paraben Lockdown device uses which operating system to write hard drive data?
  • If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system during an investigation, what can you conclude?
  • What does the Linux command 'fdisk /dev/hda' do?
  • In hexadecimal notation, what does the prefix 0x indicate?
  • Which practice best helps ensure ISO image integrity during forensic acquisition?
  • Refusing a law enforcement request to place a network sniffer on your network is appropriate because doing so would:
  • Which technique involves manually typing different user IDs into logging tools, suggesting tampering?
  • During ISO image creation, which aspect is most likely preserved to maintain evidence integrity?
  • The Electronic Serial Number (ESN) is a unique 32-bit identifier recorded on a secure chip in a mobile device by the manufacturer.
  • Which of the following would indicate an external network scanning activity in firewall logs?
  • Which tool is commonly used to search for a string within a file on a disk image during a forensic investigation?
  • The doctrine of handing over the results of private investigations to authorities due to indications of criminal activity is known as which doctrine?
  • What is the formal term for the custody of evidence from collection to court?
  • Data is striped at a byte level across multiple drives and parity information is distributed among all member drives. Which RAID level is represented here?
  • In a network packet capture, what do the Sequence (Seq) and Acknowledgment (Ack) fields primarily indicate?
  • Which method would be most efficient for acquiring evidence from large storage arrays in a network, minimizing time and space?
  • Before testifying as an expert witness, what must an attorney do first?
  • Which security objective is most directly concerned with protecting data confidentiality?
  • The data acquisition process should include preserving evidence by protecting it from temperature extremes and by using controlled handling.
  • Technical Steganography is defined as steganography that uses which method to hide a message?
  • What does CHS stand for in disk geometry?
  • In a storage partition, if the cluster size is 32 KB and the file size is 10 KB, the entire 32 KB cluster is allocated. How much slack space remains in that cluster?
  • In netstat output, what do 0.0.0.0 IP addresses indicate about the connections?
  • Which step should you take first when handling a PDA found during a hacking ring investigation?
  • During a Daubert challenge in court, which argument could weaken the case for a forensic tool that hasn't been peer-reviewed?
  • What time standard is used by IIS 6.0 in its logs?
  • Event correlation type used when an organization operates across different operating systems and hardware platforms.
  • When the INF02 entry is deleted, it is recreated after which action?
  • What is the purpose of a write-blocker?
  • Which IDS capability is required to satisfy a time-based induction machine mandate and supports detecting anomalies in real time?
  • What type of copy is needed to obtain deleted files or fragments from a suspect's hard drive?
  • Wireless discovery tools use two scanning methods: active and passive. Active scanning works by sending a specific frame and waiting for responses. Which frame is used in active scanning?
  • Which program is the boot loader when Windows XP starts up?
  • In GSM devices, the first eight digits of an IMEI identify the model and country of origin. What does TAC stand for?
  • During evidence collection, which device is used to prevent the system from writing data to the evidence disk?
  • Corporate investigations are typically easier than public investigations because:
  • Which organization maintains a database of hash signatures for known software used in digital forensics?
  • Which type of device most commonly responds to ICMP ping requests in a typical network?
  • Which nbtstat switch lists NetBIOS sessions?
  • What rule prevents sharing the status of an investigation with the CEO in a law-firm setting?
  • What security measure is essential in a computer forensics lab to protect evidence and limit access?
  • Which statement best describes local archives in email forensics?
  • To determine whether an observed vulnerability is new, which database or organization should you submit the information to?
  • Recovery of the deleted partition is the process by which the investigator evaluates and extracts the deleted partitions.
  • In a credential harvesting exercise, which scenario would most clearly indicate an attacker collecting credentials through a fake login page?
  • What is the primary purpose of a write-blocker in digital forensics?
  • Which federal statute specifically addresses fraud and related activity involving access devices like routers?
  • What step could help secure SNMP on a network after a SAS 70 audit?
  • In a session hijacking test using Ettercap, which protocol is not inherently session-based, allowing hijacking?
  • Which command shows the currently running processes on a Windows system?
  • When obtaining a warrant, what is important to include?
  • Network forensics data collection typically includes which components?
  • Which memory artifact is most likely to indicate covert processes running in the system when investigating potential botnet activity?
  • What will the following command accomplish? dd if=/dev/xxx of=mbr.backup bs=512 count=1
  • Which measure confirms the integrity of forensic copies?
  • During a security audit, a tester disguised as a technician follows employees into restricted areas, enabling access to the server room. What attack type is this?
  • What does GLBA stand for?
  • Which organization is the certifying body of forensics labs?
  • Software firewalls operate at which layer of the OSI model?
  • Which disk structure is typically found on fixed disks and contains boot information?
  • Which statement best describes Slack space in a file system?
  • What best defines a bit-for-bit copy?
  • Regarding handling evidence, you should always work with original evidence.
  • Which Windows artifact is best for reconstructing user logon sequences on a host?
  • How many possible sequence number combinations are there in TCP/IP protocol?
  • When bypassing a switch by sending an IP packet with the ACK bit and spoofed source address, what is the attacker attempting?
  • In the dd command shown, which parameter specifies the input device or file?
  • Why is it not recommended for a small firm to conduct its own breach investigation instead of hiring professionals?
  • Which attribute of a forensics report can render it inadmissible in a court of law?
  • What is considered the most common type of white-collar crime in corporate America forensics investigators focus on?
  • If a file of 2600 bytes on a hard disk uses 512-byte sectors, how many sectors are normally allocated to the file?
  • Which action is not a responsibility of the first responder at a computer crime scene?
  • If DNS queries in captured traffic point to non-company IPs, which attack is most likely?
  • Which act aimed to protect consumers' personal financial information held by financial institutions and their service providers?
  • Which type of firewall must you implement to ensure that incoming connections are initiated by internal computers?
  • Which statement is incorrect related to acquiring electronic evidence at a crime scene?
  • Which site provides archived web pages and is commonly used to view past versions of websites?
  • Which of the following is a common source within a system that can retain data before it is swapped in memory?
  • As a CHFI professional, which of the following is the most important to your professional reputation?
  • In incident response, what is the primary purpose of synchronizing time across multiple hosts?
  • BMP (Bitmap) is a standard file format for Windows. Which element specifies the dimensions, compression type, and color format for the bitmap?
  • Tracks numbering ends at which value on a typical hard disk?
  • Which type of attack sends spoofed UDP packets to the IP broadcast address of a large network?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy