EC-Council · Free Practice Questions · Last reviewed May 2026
77real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
8% of exam · 5 sample questions below
During a forensic investigation, an analyst discovers that the suspect's hard drive was encrypted using BitLocker. The analyst has obtained the recovery key. Which of the following is the best next step to ensure data integrity?
Decrypt the drive using the recovery key and then create a forensic image.
Run a live analysis tool to extract encryption keys from memory.
Create a forensic image of the encrypted drive, then decrypt the image.
Creating a bit-for-bit forensic image of the encrypted drive before any decryption preserves the original evidence in its native state, capturing the full encrypted volume, partition table, free space, and deleted data remnants. The analyst can then decrypt that image on a write-protected or isolated forensic workstation using the known recovery key or extracted keys, leaving the original exhibit untouched and maintaining chain of custody. This workflow is the accepted standard for full-disk-encrypted evidence because it separates acquisition from decryption and permits multiple independent analyses.
Boot the suspect computer and copy files to an external drive.
A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?
Immediately power on the server to check for running processes.
Copy all files from the server to an external USB drive.
Run antivirus scan to ensure no malware is present before imaging.
Secure the scene, photograph the setup, document connections, remove hard drives, and create forensic images using a write-blocker.
This is the correct forensic process: first secure the scene to prevent interference, then photograph and document the physical setup and all connections to preserve the context. Identify and collect volatile data if applicable, then remove the hard drives using proper anti-static procedures. Using a write-blocker when creating a forensic image prevents any write operations to the original drive, and hashing the image ensures the preservation of a verifiable, bit-for-bit copy for analysis and chain-of-custody.
An analyst executed the commands shown in the exhibit on a Windows system to prepare a forensic image for analysis. What is the most likely reason for the error message from e2fsck?
The analyst failed to properly dismount the source volume before imaging, leading to filesystem inconsistencies.
The sequence shows `fsutil dismount` being run on C:, but a forensic image taken afterward—especially after Windows remounts the volume or during a live acquisition—will capture the volume in an inconsistent state. When Windows later performs recovery on the dirty volume, metadata updates begin immediately, so e2fsck in the analyst's analysis environment will legitimately report superblock, group descriptor, or inode inconsistencies that were never present in the source. This is the classic 'dirty volume' imaging error, not a problem with the image tool.
The forensic image was not acquired with a write-blocker, causing data corruption.
The image file contains an NTFS filesystem, but e2fsck is designed for ext filesystems.
The e2fsck command syntax is incorrect; it should be 'e2fsck -f -n' instead.
A CHFI analyst is preparing a forensic workstation to image a suspect's USB flash drive. The analyst needs to ensure that the write-blocker is functioning correctly before connecting the drive. Which of the following is the most appropriate method to verify that the write-blocker is preventing write operations?
Connect the suspect's USB drive directly to the forensic workstation and attempt to write a test file; if the write succeeds, the write-blocker is not needed.
Connect the write-blocker to the forensic workstation, then use a known clean USB drive and attempt to write a file to it; if the write fails, the write-blocker is working.
This method directly tests the write-blocker's function by attempting a write operation to a known clean drive. If the write is blocked, it confirms the write-blocker is operational. It is safe because the drive is not evidence, and the test does not alter the original evidence. This is a standard validation procedure recommended in forensics.
Use a software write-blocker on the forensic workstation instead of a hardware write-blocker, as software blockers are more reliable and do not require validation.
Check the write-blocker's LED indicators; if the power light is on and the read/write switch is set to read-only, the write-blocker is functioning correctly.
A CHFI analyst is called to investigate a suspected insider threat. The suspect's laptop is turned on and logged in. The analyst needs to capture volatile data before shutting it down. Which of the following should the analyst capture first?
The contents of the RAM
RAM contains volatile data such as running processes, network connections, and encryption keys, which are lost when the system is powered off. Capturing RAM first preserves this critical evidence. It is the most volatile and should be prioritized. Tools like FTK Imager or Volatility can be used for memory capture.
The contents of the hard drive
The web browser cache
The system event logs
Want more Computer Forensics Investigation Process practice?
Practice this domain8% of exam · 6 sample questions below
A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?
Photograph the scene and secure the area
Documenting the scene through photographs and establishing a secure perimeter is the mandatory first step in digital forensics, as it creates a verifiable record of the original state of the computer, cables, and peripherals before any interaction. Securing the area prevents unauthorized personnel from touching the machine, which could alter timestamps, memory contents, or other volatile evidence. This step also grounds the chain of custody by showing exactly what was present when first responders arrived, and it should precede any hardware or software actions on the system.
Connect a write blocker and create a forensic image immediately
Immediately shut down the computer to prevent data alteration
Pull the power cord to ensure the system does not shut down normally
During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. What is the primary purpose of using a hardware write blocker?
To prevent the operating system from writing to the source drive
A hardware write blocker is an inline forensic bridge that sits between the source drive and the host system, filtering every ATA/SCSI command. It permits read requests to reach the drive while silently discarding or blocking write commands, so the operating system cannot modify file metadata, timestamps, directory entries, or any other data. This read-only enforcement at the physical interface level is the fundamental legal and technical guarantee of evidence preservation during acquisition.
To speed up the data transfer rate during imaging
To compress the forensic image to save storage space
To automatically hash the drive contents for integrity verification
During a forensic investigation, an analyst creates a forensic image using `dcfldd` with the command: `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=10M`. What is the purpose of the `hashwindow` parameter?
It limits the total amount of data to hash to 10 MB
It creates a hash for every 10 MB block of data
With `hashwindow=10M`, dcfldd computes an independent hash value for every 10 MB block of input, allowing the analyst to verify each segment individually rather than relying solely on a single whole-file digest. This block-wise hashing is crucial for large forensic images because it pinpoints exactly which 10 MB region has changed or become corrupted, enabling targeted re-acquisition or analysis. It does not alter the total data processed, and the root hash over the entire stream may still be generated simultaneously if requested.
It sets the hash algorithm to SHA-256
It enables error correction for every 10 MB
What is the primary goal of the chain of custody in a digital forensic investigation?
To maintain the integrity and admissibility of evidence
Documenting every transfer, handler and access point creates an unbroken audit trail proving the evidence was not altered or contaminated. This preserved integrity is what allows the artefact to be admitted as reliable in court or disciplinary proceedings.
To encrypt the evidence during transport
To speed up the forensic analysis process
To ensure that the forensic tools used are properly licensed
A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?
The file system is intact and readable
The image is an exact bit-for-bit copy of the original drive
Forensic acquisition tools such as FTK Imager or dd compute a cryptographic hash (typically MD5, SHA-1, or SHA-256) of both the source drive and the resulting image file; when those values match, the image is an exact bit-for-bit replica of the original media. This hash match assures the examiner that no bytes were altered, dropped, or inserted during acquisition, making it admissible and reliable for analysis. It is precisely why hash verification is the cornerstone of forensic soundness.
The drive contains malware
The drive was not encrypted
During a forensic investigation, a first responder notices that a computer is running and suspects that volatile data may be present. According to best practices, what should the responder do to preserve the most volatile data first?
Perform a graceful shutdown to avoid data corruption
Remove the hard drive immediately while the system is running
Capture the contents of RAM using a forensic tool, then shut down
This is the correct action because RAM is the most volatile data store and must be captured first per the forensics order of volatility (RFC 3227). A trusted memory acquisition tool — such as FTK Imager, WinPmem, or LiME — creates a bit-for-bit copy of physical memory, which is hashed (e.g., SHA-256) to preserve integrity. After the memory image is securely stored on external media, an administrator-issued shutdown writes only unavoidable OS logs and closes services in a controlled manner, preserving the disk while the critical volatile evidence is already secured.
Immediately unplug the power cord to freeze the system state
Want more Computer Forensics Fundamentals and Process practice?
Practice this domain8% of exam · 6 sample questions below
A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?
Cross-site scripting (XSS)
Path traversal
Remote file inclusion
SQL injection
The presence of UNION SELECT in the request parameter is a hallmark of in-band SQL injection. By injecting a quote to close the original SQL string and then using UNION, the attacker can append arbitrary columns to the result set and exfiltrate data from other tables. The server-side SQL query executes the combined statement, and the output is reflected in the HTTP response, allowing non-blind data extraction. This is why the log entry is correctly classified as SQL injection.
A cloud forensics investigator is analyzing an incident in AWS. The suspect is alleged to have deleted an S3 bucket. Which AWS service log would contain the DeleteBucket API call details, including the source IP and user identity?
AWS CloudTrail
AWS CloudTrail is the correct answer because it is the primary service for logging all API activity in AWS, including management events like DeleteBucket. It records the identity of the principal who made the call, the source IP, the timestamp, and the request parameters, providing a complete audit trail for investigating management-plane incidents. Without CloudTrail, you would lack the forensic evidence of who issued the destructive bucket deletion command.
VPC Flow Logs
Amazon S3 access logs
AWS Config
An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?
Server-side request forgery (SSRF)
SQL injection
Webshell
A webshell is a script uploaded to a web server that accepts commands over HTTP and executes them on the host, giving the attacker remote control. The .aspx extension and POST-based command execution match this pattern exactly.
Cross-site request forgery (CSRF)
An organization uses Azure. A security analyst needs to investigate a suspicious login event. Which Azure log contains details about user sign-ins, including IP address, timestamp, and success/failure status?
Azure Monitor Metrics
Microsoft Entra ID Sign-in logs
Microsoft Entra ID Sign-in logs are the canonical record of user authentication events in Microsoft Entra ID. Each entry contains the user principal name, IP address, client application, timestamp, location, conditional access policies applied, and the sign-in status (success, failure, or interrupted). These logs cover interactive and non-interactive sign-ins and are accessible via the Azure portal, Microsoft Graph API, or by streaming to a SIEM. They provide the granular evidence needed to trace exactly when, from where, and how an account was accessed.
Azure Activity Logs
Azure Security Center alerts
In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?
Audit log
Error log
Transaction log
The transaction log (also known as the redo log or write-ahead log) is the authoritative database component that sequentially records every data modification operation before it is committed to the main data files. In crash recovery, this log ensures ACID durability by enabling rollback of uncommitted transactions and replay of committed ones. Because it captures the before-and-after images (or logical changes) of all successful and incomplete transactions, it is the correct answer for a log that records every transaction.
Slow query log
An analyst finds the following in an IIS log: 10.0.0.5, -, 02/15/2024, 14:23:56, GET /../../windows/system32/cmd.exe, 404, 0, 0, 0, Mozilla/4.0. Which attack technique does this log entry represent?
Cross-site scripting
SQL injection
Path traversal
Correct because the raw HTTP request includes ../ in the URL path, which is the classic path traversal pattern that, when decoded or normalized by the server, tries to climb above the web root into restricted directories. In IIS, unencoded or URL-encoded traversal sequences such as %2e%2e%5c can expose system files, and even though the server returned 404, the request itself demonstrates a deliberate traversal attempt against the file-system namespace.
Remote code execution
Want more Application, Email and Cloud Forensics practice?
Practice this domain7% of exam · 6 sample questions below
A security analyst is reviewing output from a Cuckoo Sandbox analysis of a suspicious executable. The report shows that the process created a mutex named 'Global\GLOBAL_MUTEX_123' and modified the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\. Which behavioral indicator is MOST evident?
Command and control communication
Persistence mechanism
The Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a well-known autorun persistence location that executes a designated binary every time the targeted user logs on. By adding a value here, malware ensures it survives reboots and is relaunched automatically, a behavior that directly maps to the MITRE ATT&CK technique T1547.001 (Registry Run Keys / Startup Folder). In a sandbox report, seeing this registry modification is strong evidence the sample is establishing persistence, making this the correct classification.
Anti-debugging technique
Privilege escalation
A forensic analyst is examining a Windows malware sample using static analysis. Which tool is BEST suited for viewing the PE header structure, including sections, imports, and exports?
Strings
Ghidra
IDA Pro
PEiD
PEiD (Portable Executable Identifier) is a specialized forensic and reverse-engineering tool that statically parses PE files to identify the compiler, linker, and—most importantly—the packer or protector used. It extracts and displays PE header details such as the entry point, the section table with names and sizes, and optional header fields, then cross-references them against a signature database of known packers (e.g., UPX, ASPack, Themida) using byte patterns and section heuristics. For a malware analyst performing triage, PEiD instantly reveals whether a binary is packed and which tool packed it, making it the correct choice for PE header and packer analysis.
A forensic examiner is analyzing an Android device that has been factory reset. Which artefact is MOST likely to persist after a factory reset, providing potential evidence of prior usage?
Google account artefacts
On modern Android builds, factory reset intentionally preserves Factory Reset Protection (FRP) data—the last verified Google account identifier (and often an authentication token sealed with device-bound keys) is retained in dedicated persistent storage or in Google's cloud-side device registry. Even if the userdata partition is reformatted, a forensic examiner can extract the FRP Google account from a physical image of protected/persistent blocks or obtain it via Google Takeout/Google Dashboard log retrieval, making this the only listed item that survives by design.
App installation logs
Deleted SMS messages
Wi-Fi passwords
An analyst runs 'regshot' before and after executing a suspicious binary. The report shows that the binary added a value to HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to C:\Windows\system32\malware.exe and 'Start' set to 2. What is the MOST likely purpose?
Hiding network connections
Encrypting files
Disabling a legitimate service
Persistence as a service
The Start value of 2 (SERVICE_AUTO_START) in a newly created service registry key instructs the Service Control Manager to launch the service automatically during system startup, before a user logs on. This is a well-known persistence technique because the malicious binary is executed with SYSTEM privileges on every boot, surviving reboots. The presence of this service key, with its image path pointing to the suspect executable, is direct evidence that the malware has installed a persistent service. This matches the observed change exactly and explains why the analyst sees a new service entry rather than a modification to an existing one.
A malware analyst uses Cuckoo Sandbox to analyze a sample. The report shows that the sample sends HTTP POST requests to 'http://malicious.example.com/gate.php' with encrypted data. Which type of indicator of compromise (IoC) is this?
Host-based IoC
Memory-based IoC
Hash-based IoC
Network-based IoC
The URL and domain are classic network-based IoCs because they represent communication channels between the infected host and the attacker's command-and-control (C2) infrastructure. In Cuckoo's analysis, these are extracted from captured DNS queries, HTTP requests, or IRC/HTTPS sessions, making them directly associated with network traffic rather than host state or file content.
Which mobile forensics tool is specifically designed for physical extraction of iOS devices, including bypassing passcodes and extracting full file system images?
Oxygen Forensic Detective
Magnet AXIOM
Cellebrite UFED
GrayKey
GrayKey, developed by Grayshift, is a dedicated iOS forensic tool engineered specifically for physical extraction and passcode bypass. It exploits hardware and software vulnerabilities to gain full file-system access from locked iPhones/iPads, bypassing the Secure Enclave's retry limits. Law enforcement agencies use GrayKey for targeted deep extraction of iOS devices, making it the only option in this list uniquely designed for this purpose.
Want more Mobile and Malware Forensics practice?
Practice this domain7% of exam · 6 sample questions below
An investigator needs to capture network traffic from a live network segment without altering the traffic flow. Which technique should they use?
Enable NetFlow on the router and capture flows
Configure a SPAN port on the switch
Configuring a SPAN (Switched Port Analyzer) port on the switch copies ingress and egress frames from specified source ports or VLANs to a designated monitor port, where a forensic workstation can record full packets without altering the original traffic path. This non-intrusive mirroring preserves switch performance and avoids introducing latency or dropping frames, making it the standard method for lawful network capture at Layer 2.
Deploy an ARP spoofing tool to redirect traffic
Set the NIC to promiscuous mode on the forensic workstation
During a cloud forensics investigation, the investigator discovers that the cloud provider uses shared storage for multiple tenants. Which challenge is MOST likely to arise when acquiring a forensic image?
Physical acquisition of the storage device is required
No API access to the storage system
Inability to decrypt data at rest
Data commingling with other tenants
Data commingling with other tenants is the core challenge, as shared storage causes multiple organizations' data to occupy the same physical media, including potentially unallocated or leftover blocks. A forensic acquisition from such media may inadvertently capture another tenant's data, creating privacy, legal, and chain-of-custody complications. Investigators must employ careful isolation techniques, such as acquiring only the specific virtual disk or object while documenting that surrounding media contains unrelated data. This makes tenant-to-tenant isolation the primary difficulty in multi-tenant cloud forensics.
A security team needs to preserve network evidence for a potential legal case. What is the BEST practice for capturing volatile network data?
Wait until normal business hours to capture traffic
Only record summary logs from the firewall
Perform packet capture using a portable tool and store the capture with a cryptographic hash
Performing packet capture with a portable tool such as tcpdump or dumpcap on a mirror port preserves the live, volatile network state while minimizing footprint, and a cryptographic hash (like SHA-256) computed at acquisition time provides integrity verification for later evidence examination. The captured PCAP stores both headers and payloads, allowing protocol analysis and stream reassembly. Store the capture on write-protected media and record the hash in the chain-of-custody documentation to prove tamper-resistance.
Use a dedicated forensic workstation with a write blocker
In a cloud forensic investigation, the analyst needs to obtain a memory dump of a virtual machine. Which method is considered forensically sound?
Log into the VM and use a tool to create a crash dump
Copy the virtual disk file (.vmdk) and extract memory from it
Use a live forensic tool inside the VM to capture memory
Take a snapshot of the VM via the hypervisor and export the .vmem file
Taking a snapshot of the VM at the hypervisor level and exporting the .vmem file is the proper cloud-forensic technique because the hypervisor, operating below the guest OS, accesses the VM's volatile memory directly without injecting any code into the guest. This point-in-time snapshot suspends or copies the RAM state transparently, preserving the exact contents of memory in a forensically sound format, and the .vmem file represents the guest's full physical address space — including kernel, processes, and any in-memory encryption keys or malware.
During a network forensic investigation, the analyst recovers a PCAP file. What type of information can be directly extracted from this file?
Files transferred via HTTP
HTTP file transfers are visible in the packet payload because HTTP is an unencrypted application-layer protocol. During a network forensic investigation, an analyst can reconstruct the entire file by reassembling TCP segments and extracting the HTTP message body (e.g., using Wireshark's 'Follow TCP Stream' or NetworkMiner). As long as the capture contains complete traffic, the transferred file's content is directly recoverable from the PCAP data, making this the correct answer.
Operating system version of the source host
Registry data of the destination host
Disk partition table of the sending computer
An investigator is analyzing cloud storage logs and finds an entry showing that a file was accessed using the root credentials from an IP address in a different geographic region. The organization has strict policies against root usage. What should the investigator do FIRST?
Check if the activity correlates with a known vulnerability or authorized task
Correlating the observed access against logged change tickets, vulnerability scanners (e.g., CVE data), and scheduled maintenance windows is the correct initial triage step. It lets you determine whether the activity is a false positive or expected administrative behavior before taking any action that would be disruptive or destructive. Cross-referencing source IP, user agent, and API call pattern against known vulnerability signatures or authorized task records preserves evidential integrity while filtering out benign anomalies.
Contact law enforcement for cybercrime investigation
Change the password of the root account
Immediately revoke the root access keys
Want more Network and Cloud Forensics practice?
Practice this domain8% of exam · 6 sample questions below
An analyst recovers a hard drive from a suspect's computer. The drive has a partition table that uses a 32-bit identifier and a maximum partition size of 2 TB. Which partition table type is present?
HFS+
GPT
APFS
MBR
MBR (Master Boot Record) is a legacy partition table that uses 32-bit entries in its partition table, limiting the maximum addressable partition size to 2 TB (or 2.2 TB with 512-byte sectors). It resides in the first 512 bytes of the disk and contains boot code plus four primary partition entries. This 2 TB ceiling is the exact characteristic indicated in the question, making MBR the correct answer.
During a forensic investigation, an examiner wants to recover deleted files from a FAT32 file system. Which structure is most critical for file recovery?
File Allocation Table (FAT)
The File Allocation Table is the core metadata structure of FAT32, storing a linked list of cluster numbers (cluster chains) for every file. When a file is deleted, its directory entry is marked with byte 0xE5 but the associated FAT cluster chain is often left intact until those clusters are reused, and the directory entry still contains the starting cluster and file size. By reading the starting cluster and following the FAT chain to the end-of-chain marker, forensic tools can reassemble the deleted file's data clusters back into a contiguous stream for recovery.
Master File Table (MFT)
Journal
Inode table
Which tool is specifically designed for file carving and can recover files based on headers and footers without relying on file system metadata?
FTK Imager
Foremost
Foremost is a dedicated command-line file carver that recovers files by scanning raw disk images and matching known binary signatures for file headers, footers, and internal data structures. It was originally developed from the Air Force Office of Special Investigations' carving tool and is configured via a customizable configuration file (foremost.conf), allowing investigators to add custom signatures. Its sole purpose is to extract data based on file structure, making it the classic, focused file-carving utility rather than a general forensic suite.
Autopsy
Volatility
An analyst notices that a file on an NTFS volume occupies 4096 bytes on disk but its actual data is only 100 bytes. The extra space contains remnants of a previously deleted file. What is this extra space called?
Volume slack
Free space
RAM slack
File slack
File slack is the unused area within the last allocated cluster of a file, spanning from the bytes beyond the logical end of the file to the physical end of that cluster, and it is composed of both RAM slack and the remaining sector space. On NTFS, these bytes are not zeroed when a file is written, so they may contain residual data from previously deleted files or older versions of the current file, making them a valuable forensic source. This exactly matches the analyst's observation of a file occupying 40 clusters where some space is unused, because that space remains attributed to the file's allocated cluster rather than to free or volume slack.
A forensic investigator is analyzing a Linux ext4 file system. They suspect a file was deleted but its inode may still be intact. Which tool can be used to recover the file by referencing the inode?
dd
scalpel
foremost
debugfs
debugfs is a filesystem debugger built specifically for ext2/ext3/ext4 that provides direct access to the on-disk inode structures. Commands such as `lsdel` list unlinked inodes and `cat <inode>` display file content by inode number, allowing targeted recovery of deleted files when the inode is still valid. Unlike carving tools, debugfs leverages the filesystem metadata itself, making it the correct choice for inode-based recovery.
During a forensic examination of an NTFS drive, an investigator finds that a file 'notes.txt' has an additional data stream named 'hidden.txt' attached. Which feature of NTFS allows this?
USN Journal
MFT
Alternate Data Streams (ADS)
Alternate Data Streams (ADS) is a native NTFS capability that allows multiple data streams to be associated with a single file or directory, each identified by a name after a colon (e.g., file.txt:hidden.txt). Data written to an ADS is not shown by typical file size listings or directory views, yet it consumes logical disk space and can contain executables or other arbitrary content. Forensic tools such as `streams` or PowerShell's `Get-Item -Stream *` are required to enumerate and recover ADS, and the Zone.Identifier stream is a legitimate example, while attackers exploit this feature for stealth.
Slack space
Want more Storage Forensics and File System Analysis practice?
Practice this domain7% of exam · 6 sample questions below
An organization uses Microsoft SQL Server 2019 with full recovery model. A database administrator accidentally executed a DROP TABLE statement. The transaction log was backed up immediately after the incident. Which forensic technique would allow the analyst to restore the dropped table?
Restore the transaction log backup taken after the DROP TABLE and apply it to the database.
Use the RESTORE LOG statement with the NO_TRUNCATE option to recover the table.
Perform a tail-log backup, then restore the full backup and all subsequent transaction log backups, stopping before the DROP TABLE.
The correct procedure is to first back up the tail of the transaction log to capture all log records generated since the last backup, including the DROP TABLE transaction. Then restore the most recent full backup in NORECOVERY mode, followed by every subsequent transaction log backup using STOPAT (or STOPBEFOREMARK) set to a time just before the drop. This rolls the database forward to the pre-drop state while preserving all earlier committed changes.
Restore the most recent full backup and ignore subsequent transaction log backups.
During a forensic investigation of a MongoDB database, the analyst needs to identify which user executed a particular write operation. Which MongoDB log or feature should the analyst examine?
Journal (journal directory)
System log (mongod.log)
Audit log (auditLog)
The audit log (auditLog) is the authoritative forensic source because MongoDB Enterprise's auditing feature, when enabled, emits structured events for user actions including authentication, schema changes, and select CRUD operations. Each audit record contains critical metadata such as the authenticated user (authUser), the exact timestamp, the operation type, and the source IP, enabling precise attribution. Its behavior can be tuned with auditFilter and operationTypes to capture the full scope of actions, making it indispensable for identifying what a user did within the database.
Oplog (local.oplog.rs)
Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?
The time the DELETE statement was executed on the MySQL server
The timestamp in the binary log entry records when the MySQL server executed the DELETE statement, as part of its statement-based or row-based logging. This is the server's authoritative clock at the moment the statement was processed, not when the client sent it or when the file was flushed. MySQL writes this event timestamp into the binary log header for replication and point-in-time recovery, reflecting execution time.
The time the client sent the query to the server
The time the binary log file was written to disk
The time the transaction was committed
You are a forensic investigator responding to an incident at a financial institution. The organization uses Microsoft SQL Server 2016 for its transaction processing system. The database is configured with full recovery model and transaction log backups are taken every 15 minutes. The incident response team has identified that an attacker gained access to the database server via compromised credentials and executed a series of malicious SQL statements, including data exfiltration and deletion of critical records. The time of the attack is estimated to be between 2:00 PM and 2:05 PM. The last full backup was taken at 12:00 AM (midnight) the same day. Transaction log backups are available for the entire day. The last transaction log backup before the attack was taken at 1:45 PM. The next transaction log backup after the attack was taken at 2:15 PM. The database is still online and being used by the business. Management wants to recover the database to a point just before the attack (2:00 PM) to minimize data loss, while preserving evidence for investigation. Which of the following actions should you take FIRST?
Perform a tail-log backup of the database using the NORECOVERY option to capture all transactions since the last log backup.
Performing a tail-log backup with NORECOVERY captures every transaction that was recorded in the active portion of the transaction log after the last full transaction log backup, including transactions in flight or not yet backed up. The NORECOVERY option transitions the database into the Restoring state, preserving the current transaction log as a backup file that can be used for point-in-time recovery. This is the only way to preserve the complete post-backup forensic evidence, and it must be done before any restore operation is attempted.
Immediately restore the full backup from midnight and all transaction log backups up to 1:45 PM to a separate server for forensic analysis.
Shut down the SQL Server service to prevent further changes and then restore the database from backup.
Restore the database to a point in time using the full backup and all transaction log backups up to 1:45 PM, then apply the 2:15 PM backup to recover lost data.
During a database forensic investigation, an analyst recovers a MySQL binary log file (binlog.000012) from a compromised server. Which command should the analyst use to extract the actual SQL statements from this binary log in a human-readable format?
mysqldump --binlog binlog.000012
mysqlimport --binlog binlog.000012
mysqlcheck --binlog binlog.000012
mysqlbinlog binlog.000012
mysqlbinlog is the official MySQL utility for reading binary log files and converting their events into human-readable SQL statements or, with appropriate options, into replayable SQL for database restoration. It supports statement-based, row-based, and mixed binlog formats, and it allows selective forensic analysis using time ranges, position ranges, and offset filters. In a database forensic investigation, running mysqlbinlog binlog.000012 reveals the exact transactional operations, timestamps, server IDs, and event sequence recorded in that log, enabling reconstruction of unauthorized changes or data exfiltration attempts.
Refer to the exhibit. A database administrator finds the above error log entries when attempting to start the MySQL service. The server was working fine yesterday. What is the most likely cause of this issue?
The MySQL user does not have write permissions to the data directory.
The binary log is full and cannot be rotated.
The server ran out of memory due to high innodb_buffer_pool_size.
The InnoDB system tablespace file (ibdata1) is corrupted.
The InnoDB system tablespace file (ibdata1) holds the data dictionary, rollback segments, and undo tablespaces; its first page contains a header that InnoDB validates at startup. If that header or any critical internal page is corrupted, InnoDB cannot initialize its storage engine and aborts with errors such as 'Database page corruption' or 'Cannot open datafile'. This matches the administrator's exhibit, making corruption of ibdata1 the correct explanation; recovery requires restoring the tablespace from backup or rebuilding it with new setup.
Want more Database and Application Forensics practice?
Practice this domain8% of exam · 6 sample questions below
An analyst receives an alert indicating a suspicious process (PID 3342) is making outbound connections on port 443 to an unknown IP. The system is a Windows 10 workstation. Which first responder action is MOST appropriate?
Capture a full memory dump using a tool like FTK Imager (Memory Capture) or DumpIt.
Capturing a full memory dump with FTK Imager (Memory Capture) or DumpIt preserves the entire contents of RAM, including running processes, loaded drivers, active network sockets, decrypted data, and injected code that exist only in volatile memory at that instant. This adheres to the order of volatility and allows analysis of the live system state without altering or destroying it. Memory imaging is the highest-priority step because many advanced threats operate solely in memory and leave minimal traces on disk.
Immediately disconnect the system from the network to contain the threat.
Check the Windows Event Logs for related entries.
Reboot the system to clear any malicious processes from memory.
A security team suspects a data breach via an external attacker. The incident response plan requires preservation of evidence for legal proceedings. Which order of volatility should the first responder follow?
Capture disk image, then memory, then network connections.
Record network connections, capture disk image, then memory.
Capture memory, record network connections, acquire disk image, then collect backups.
This is the correct order of volatility: memory first because RAM contains live evidence like decryption keys, running processes, and transient malware that disappears on shutdown; network connections second because they show active command-and-control sessions and can vanish with session teardown; disk image third because persistence preserves it for later analysis; and backups last because they are the least volatile and can be obtained at any time. This sequence maximizes evidence preservation and aligns with RFC 3227 and NIST forensic guidelines, while also supporting a defensible chain of custody.
Collect backups first, then disk image, then memory.
During an incident response, a first responder needs to collect evidence from a Linux server that is still running. The server has sensitive data and cannot be shut down. Which technique is BEST for acquiring a forensic image of the hard disk?
Use dd if=/dev/sda of=/mnt/evidence/image.dd conv=noerror,sync
Use dd if=/dev/sda of=/mnt/evidence/image.dd bs=4M
Imaging the entire block device /dev/sda with bs=4M captures the complete physical disk, including the master boot record, partition tables, each partition, and unallocated space. The bs=4M argument is only a performance optimization that increases the read/write buffer size; it does not change the output data, so the result is still a bit-for-bit forensically sound copy. This is the correct first-responder action because it preserves all potential evidence on the drive.
Use dd if=/dev/mapper/root of=/mnt/evidence/image.dd
Use dd if=/dev/sda1 of=/mnt/evidence/image.dd
You are responding to a suspected malware infection on a Windows 10 system. The system is still running. Which of the following should you collect FIRST?
Acquire a memory dump using a tool like WinPmem.
RAM is the most volatile component in a Windows system and must be captured before any other action, because it holds currently running processes, active network sockets, loaded kernel modules, injected code, and plaintext encryption keys. Using WinPmem (or similar tools) creates a raw memory image that can be analyzed for malware artifacts that exist only in volatile memory, such as reflective DLLs or rootkits. Any subsequent step in the incident response workflow will alter memory contents, so the order of volatility dictates that memory acquisition comes first.
Collect the Windows Event Logs.
Export the contents of the Windows Registry.
Create a forensic image of the hard drive.
A first responder is called to investigate a potential insider threat. The suspect's computer is turned off. What is the BEST procedure?
Compute a hash of the hard drive using a live CD.
Check the power cord and peripherals for tampering.
Seize the computer and transport it to a forensic lab for imaging.
Seizing the computer and transporting it to a forensic lab preserves the original evidence for a proper bit-for-bit image using a write-blocker, ensuring data integrity and admissibility. A controlled lab environment allows for secure storage and careful analysis before any acquisition, maintaining a documented chain of custody from the scene onward. This is the recognized best practice for first responders.
Turn on the computer to see if it boots normally.
During the initial response to a suspected data exfiltration, which THREE pieces of volatile data should be collected first? (Choose three.)
Current network connections.
Network connections are transient and may disappear.
List of running processes.
Processes can start/stop quickly; must be captured early.
Contents of system memory (RAM).
Memory contains the most volatile data including encryption keys and active malware.
Windows registry hives.
Forensic image of the hard drive.
Want more Incident Response and First Responder Skills practice?
Practice this domain8% of exam · 6 sample questions below
A forensic lab is designing a network architecture to ensure the integrity of evidence during acquisition. What is the most critical design consideration?
Deploy multiple forensic workstations to parallelize tasks
Use a segmented network to isolate forensic tools
Encrypt all data in transit over the network
Implement hardware write-blockers on all acquisition stations
A hardware write-blocker is inserted between the source drive and the forensic workstation, electrically or logically blocking write commands at the SATA/USB/IDE interface, so the operating system and forensic software cannot modify the original media under any circumstances. This is the direct technical control that preserves bit-for-bit integrity and enables valid cryptographic hash matching before and after acquisition. Using a write-blocker on every acquisition station is considered best practice in digital forensics and is required for standardized forensic imaging workflows.
A forensic lab is establishing a chain of custody procedure. Which practice is considered best according to CHFI guidelines?
Require biometric authentication for all lab personnel
Store evidence in a secure room with limited access
Use encryption to protect evidence files
Document every transfer of evidence with signatures and timestamps
Proper chain-of-custody documentation requires an unbroken chronological record that identifies every individual who had control of the evidence, the exact date and time of each transfer, and the reason for the transfer. Each exchange must be signed by both the releasing and receiving custodians to verify that the evidence was in their possession and was not unaccounted for. This documentation is pivotal in court to demonstrate that the evidence is authentic and has not been substituted, altered, or tampered with. Without signatures and timestamps, a court may deem the evidence inadmissible on the grounds of a broken custody chain.
Which TWO of the following are essential components of a computer forensics lab according to CHFI best practices?
Server farm for data processing
Evidence storage area with controlled access
Evidence storage area with controlled access is essential to a forensic lab because it establishes a physically secure, restricted environment where seized media can be preserved, inventoried, and protected from tampering, environmental damage, or unauthorized access. This directly supports the chain of custody and evidentiary integrity that courts require for admissibility, and is a core component per forensic laboratory best-practice standards. Without such an area, the entire examination process loses its evidentiary foundation.
Public-facing website for case management
Coffee machine for staff convenience
Forensic workstation with specialized software
A forensic workstation with specialized software is required for the actual examination and analysis of digital evidence, providing the necessary platform for disk imaging, carving, keyword searches, and artifact extraction using validated tools. In addition to software, the workstation must incorporate write-blockers and follow procedures to ensure data is not altered, making it a core functional element whose capabilities directly determine what evidence can be recovered. This is why it is considered an essential component of a computer forensics lab.
A forensic lab manager is setting up a new lab and must decide on the physical security measures. Which of the following is the MOST important to implement first?
Construct Faraday cages around the evidence storage area
Deploy CCTV cameras covering all entry points
Install a gas-based fire suppression system
Implement a biometric access control system
Biometric access control authenticates individuals using unique physiological characteristics—such as fingerprints, iris patterns, or facial geometry—making it nearly impossible to lend, steal, or duplicate credentials. This enforces physical access as a preventive control, ensuring only pre-authorized personnel enter evidence storage areas, thereby maintaining chain of custody and legal defensibility. Unlike keys or cards, biometrics provide non-repudiation because each entry attempt is tied to a specific person and can be logged for audit. It directly addresses the foundational risk of unauthorized access, which is the first and most critical security requirement for a forensic lab.
You are a forensic examiner at a corporate security firm. You receive a laptop from the HR department that belonged to a terminated employee. The laptop was used for company business and is suspected of containing unauthorized file-sharing software. The laptop is running Windows 10 with BitLocker drive encryption enabled. Before shutdown, the employee was logged into the system. HR claims the laptop was shut down properly and then handed over within an hour. You are asked to acquire a forensic image of the hard drive for analysis. However, when you boot the laptop, you are prompted for the BitLocker recovery key. HR does not have the key, and the employee refuses to cooperate. The laptop also has a TPM chip. Which of the following is the most appropriate course of action to acquire the data?
Contact IT to obtain the BitLocker recovery key from Active Directory.
This is the correct first step because corporate BitLocker recovery keys are often backed up to Active Directory. Retrieving it is the most straightforward method to access the drive.
Perform a cold boot attack to extract the BitLocker key from memory.
Boot from a Linux live USB and use tools to bypass BitLocker.
Boot the laptop normally and let BitLocker unlock the drive using the TPM.
A forensic lab in a shared office building must protect evidence against unauthorized physical access, environmental damage, and electromagnetic interference. The lab manager is documenting the physical controls for an accreditation audit. Which control best addresses the risk of an intruder removing a seized hard drive from the evidence room?
A locked evidence locker with a keypad entry log and tamper-evident seals on each evidence bag
A locked evidence locker with logged keypad entry and tamper-evident seals directly prevents and detects unauthorized removal of a seized drive. The entry log creates an auditable record of who accessed the evidence room, while the seals reveal any attempt to open an evidence bag after seizure. Together they satisfy the physical security and chain-of-custody expectations for a forensics lab.
A UPS connected to the forensic workstation to prevent power loss during imaging
An antistatic wrist strap worn by the examiner while handling the drive
A Faraday bag used to store mobile phones during transport
Want more Computer Forensics Lab practice?
Practice this domain8% of exam · 6 sample questions below
A security analyst investigates a Windows system and finds an event with ID 4625 in the Security log. What does this event indicate?
A failed logon attempt
Event ID 4625 is the Windows Security log event that specifically records a failed logon attempt. It is generated whenever an authentication fails, carrying details such as the target account name, source IP address, logon type, and a status/error code like 0xC000006A (bad password). Since the question centers on this exact event identifier, the security analyst correctly identifies the event as a failed logon.
A successful user logon
A service was installed
A new user account was created
During a forensic analysis of a compromised Linux server, you notice that the file /var/log/auth.log has been cleared. However, you find that the attacker's commands are still partially recoverable. Which artifact most likely contains the attacker's command history?
/var/log/syslog
~/.bash_history
~/.bash_history is the correct artifact because it is the per-user history file that bash appends with every command entered interactively. When a shell exits cleanly, the session's commands are written here, making it a direct record of user activity. Investigators commonly use it to reconstruct an attacker's command sequence, though it can be disabled or truncated.
/proc/1/cmdline
/etc/shadow
An analyst suspects that an attacker used a web shell to execute commands on a Windows web server. Which Windows event ID should the analyst look for to detect service installation that may have been used for persistence?
7045
Event ID 7045 indicates that a new service was installed on the Windows system. When an attacker exploits a web shell, they often escalate privileges or establish persistence by installing a malicious service that executes a payload at system startup. Therefore, a 7045 event appearing alongside web shell traffic is a strong indicator of post-exploitation activity, making it the most relevant option.
4624
4648
4720
A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?
.plist files
FSEvents
Unified logging (log command)
Unified logging is the correct source because macOS's centralized logging system, introduced in macOS 10.12, captures all system, process, kernel, and user-level log messages through the os_log API. The `log` command (e.g., `log show`, `log collect`, `log stream`) provides forensic access to these persisted logs, including the compressed .tracev3 files in `/var/db/diagnostics`. This data, complete with precise timestamps and metadata, is exactly what an examiner needs for analyzing system events on a modern Mac.
Console.app logs
A network analyst is reviewing a packet capture and sees a large number of TCP SYN packets sent to various ports on a single host from multiple source IPs. This pattern is most indicative of which type of attack?
ARP spoofing
SYN flood
A SYN flood is a transport-layer denial-of-service attack that exploits the TCP three-way handshake by sending a massive number of SYN packets with spoofed or non-responsive source IP addresses. The server allocates a transmission control block (TCB) and memory for each half-open connection, then replies with SYN-ACK packets that are never answered, causing the listen backlog to fill and preventing legitimate clients from completing handshakes. This matches the capture of many SYN packets and represents a direct, stateful DoS mechanism.
DNS amplification
Ping of death
During a Linux forensic investigation, you find that the file /etc/cron.d/evil contains the entry: '* * * * * root /bin/bash /root/backdoor.sh'. What persistence mechanism is being used?
Systemd service
Init script
Cron job
Cron jobs are defined in /etc/cron.d, /etc/crontab, or a user's crontab and are executed by the cron daemon according to a schedule specified with time fields (minute, hour, day of month, month, day of week). A file in /etc/cron.d is a standard location for system cron jobs, and the syntax often includes the user account to run the job as well as the command. This matches the scenario where a file found during a Linux forensic investigation is executed on a schedule, making cron the correct classification. The five-field time specification is a unique characteristic that distinguishes cron from systemd services or init scripts.
At job
Want more OS and Network Forensics practice?
Practice this domainAn organization suspects a stealthy malware infection on a critical server. Traditional antivirus and EDR solutions have not detected anything. Which forensic approach would be most effective in identifying the malware, given that it likely resides only in memory?
Perform a full disk scan with updated antivirus signatures
Acquire a memory dump and perform memory forensics with tools like Volatility
Acquiring a memory dump and analyzing it with Volatility is the correct approach because it preserves the volatile state where fileless malware resides, capturing the actual code, injected processes, and hooked kernel structures. Memory forensics allows investigators to enumerate running processes, inspect process memory and VAD trees, and extract indicators that would be lost on reboot, providing the most direct evidence of the infection.
Conduct a live analysis using built-in Windows tools like Task Manager
Analyze network traffic for anomalies using a NetFlow analyzer
During malware analysis, an investigator finds that a suspicious process is injecting code into a legitimate system process (e.g., explorer.exe). Which technique is being used?
API hooking
Process hollowing
Code injection
Code injection is the correct classification because the finding that code was inserted into a running process directly matches this term. It encompasses any technique that places executable code into the virtual address space of another process and then causes it to run, often by creating a remote thread or using an asynchronous procedure call. The stem's description is a general definition of code injection, not limited to a specific delivery vector.
DLL injection
Refer to the exhibit. An investigator is examining a disk image using TSK. The output from 'fls' shows the directory structure. What is the significance of the entry 'V/V 113-128-1: $OrphanFiles'?
It is a sign that a rootkit has hidden files in the image
It indicates the location of the Master File Table (MFT) mirror
It is a virtual directory that contains files with no parent directory, often from deleted files
In tools like The Sleuth Kit (tsk) and Autopsy, the virtual directory named $OrphanFiles (or displayed as 'V/V') is not a literal directory stored on the disk. It is dynamically generated to represent files whose MFT entries exist but whose parent directory references were lost, typically because the directory entry was deleted, overwritten, or corrupted while the file record itself remains in the MFT. This commonly occurs after a file is deleted, when the directory index entry is removed but the file's MFT record is not yet reused, or after a malformed directory entry prevents normal linkage in the tree.
It is a standard NTFS metadata file that stores file permissions
You are a forensic analyst investigating a suspected malware infection on a Windows 10 workstation. The user reports that the system has been slow and that unexpected pop-ups appear. You have acquired a memory dump and a disk image. During analysis, you find a suspicious process named 'svch0st.exe' running with PID 4567. The process has loaded several DLLs, including 'wininet.dll' and 'ws2_32.dll'. You also find that the process has an active TCP connection to an external IP address 203.0.113.5 on port 4444. In the disk image, you find an executable file at C:\Users\Public\svch0st.exe with a creation date that matches the start of symptoms. The file's hash is not in any known malware database. You decide to perform dynamic analysis by running the file in a sandbox. However, the sandbox environment has no network connectivity. The executable runs but does not exhibit any malicious behavior. What should you do next to determine if the file is malicious?
Conduct a thorough static analysis using a disassembler and debugger to understand the code
Delete the suspicious file and run a full antivirus scan on the system
Re-run the sample in a sandbox with simulated network connectivity or a controlled network to observe C2 communication
Re-running the sample in a sandbox with simulated network connectivity or a controlled network is the correct approach because many malware families remain dormant until they establish C2 communication, at which point they download additional payloads, exfiltrate data, or execute commands. A network-enabled sandbox provides a safe, but realistic environment where the analyst can observe DNS queries, HTTP/S connections, beaconing intervals, and the exact data exchanged with the C2 server. This dynamic analysis yields actionable indicators of compromise (IoCs) and reveals the malware's full functionality without risking real network infection.
Perform a forensic imaging of the system again and compare with the original image
Based on the exhibit, what is the most likely indication of malware persistence?
services.exe PID 4321 is a known malware process
Windows Defender service is stopped, allowing malware to run
services.exe is listening on TCP port 4444, indicating possible code injection
services.exe is the Windows Service Control Manager and should never expose listening TCP endpoints on its own; its normal IPC is via a named pipe used by subprocesses, not a network socket. Port 4444 is a well-known default payload port for Metasploit's meterpreter and is frequently used by backdoors, so an established listening socket on services.exe is a classic sign of injected shellcode. Because services.exe runs as SYSTEM, attackers often inject code into it to steal its high privileges and evade detection.
svchost.exe hosting BFE and MpsSvc indicates a firewall bypass
You are investigating a Windows 10 workstation that exhibits slow performance and frequent pop-ups. The user reports that the system started acting strangely after installing a 'PDF Converter' from an email attachment. You suspect malware. You have captured a memory dump using FTK Imager and a network capture during the infection. In the memory dump, you find a suspicious process 'conhost.exe' running from a non-standard location (C:\Users\Public\Temp). The process has an open handle to a file named 'config.ini' in the same directory. The network capture shows periodic HTTPS connections to 'malicious.com' on port 443 from the workstation's IP. Using Volatility, you extract the process's command line: 'conhost.exe -hidden -log C:\Users\Public\Temp\output.log'. Which of the following is the BEST immediate course of action to contain the threat and preserve evidence?
Delete the config.ini file and the conhost.exe executable immediately.
Restore the system to a previous restore point.
Terminate the suspicious conhost.exe process and run a full antivirus scan.
Isolate the workstation from the network, then create a forensic image of the hard disk for analysis.
Isolating the workstation from the network by disconnecting the cable or disabling the NIC immediately severs Command & Control (C2) channels and halts any lateral movement to other hosts, preserving the network flow data and the current state of live connections. Creating a forensic image of the hard disk using a write-blocker and bit-for-bit imaging tools maintains the integrity of evidence, allowing recovery of deleted files, unallocated space, and file system slack that may contain residual malware or attacker artifacts. This evidence-preserving approach aligns with forensic best practices, keeps proper chain of custody, and enables thorough static and dynamic analysis in a controlled lab environment—unlike the destructive or ineffective alternatives.
Want more Malware Forensics practice?
Practice this domain8% of exam · 6 sample questions below
You are imaging a suspect's hard drive using a write blocker and dd command. After imaging, you verify the hash of the original drive and the image file. The original drive hash is SHA1: A1B2C3D4E5..., and the image hash is SHA1: F6G7H8I9J0... What is the most likely cause of the mismatch?
The dd command used a different block size
The write blocker malfunctioned and allowed writes to the original drive
A write blocker is a dedicated hardware or software mechanism that intercepts and blocks all write commands from the host system to the suspect drive during acquisition. If it malfunctions, the operating system or the acquisition tool may write temporary files, filesystem metadata, or other data onto the original evidence drive. Any such unintended write changes the drive's contents, so when the examiner later computes a hash of the original drive, it will no longer match the hash of the forensic image taken earlier. This is the only option that directly explains how the source itself could be altered, making it the correct cause of the hash discrepancy.
The dd command compressed the output
The image file was corrupted during transfer
A forensic examiner needs to acquire a hard drive that is part of a RAID 5 array. The RAID controller is unavailable. What is the best approach to acquire the data?
Acquire each disk individually, then reconstruct the array using software
Each physical disk must be imaged independently using a proper write blocker to preserve the raw device contents, including RAID metadata, superblocks, and any data sitting outside the array's logical volume. After all disks are imaged, a forensic RAID reconstruction tool (or mdadm with the correct parameters) can reassemble the logical volume by using the known stripe size, parity rotation, and disk order without needing the original controller. This preserves the exact state of the array and avoids the risk of the controller writing configuration changes during acquisition.
Acquire only one disk because RAID 5 can be reconstructed from a single disk
Use a hardware write blocker that supports RAID
Connect the RAID array to a similar controller and acquire as a single drive
Which of the following is the primary purpose of using a hardware write blocker during disk acquisition?
To decrypt the drive during acquisition
To prevent any writes to the original evidence drive
The primary purpose of a write blocker is to guarantee the integrity of the original evidence by creating a read-only interface between the drive and the forensic workstation. It intercepts and blocks all write commands issued by the operating system, including those that might occur from normal mounting, file system metadata updates, or malware, ensuring the source drive remains bit-for-bit unchanged. This preservation is essential for maintaining a legally defensible chain of custody and allowing a subsequent hash verification to prove evidence authenticity.
To compress the acquired image
To increase the speed of the acquisition
During a forensic acquisition, you notice that the target drive has bad sectors. What is the best approach to acquire the drive?
Use dd with a higher block size to skip bad sectors
Use ddrescue to recover as much data as possible
ddrescue is purpose-built for imaging failing or damaged storage devices. It reads the drive in a single pass, records errors in a logfile, and then retries difficult sectors with increasingly fine-grained reads, recovering the maximum amount of data while preserving a documented map of the damage. Because it can be re-run and continues from the logfile, it is the forensically sound choice when the target drive exhibits read errors.
Use FTK Imager and ignore the errors
Perform a physical acquisition by removing platters
The command used to acquire a disk image resulted in an I/O error. What is the most likely cause?
The source disk has bad sectors
The source disk has bad sectors. When the imaging tool issues a raw read to a region containing a physically damaged or unreliable sector, the disk controller cannot return valid data and raises a hardware-level error. The operating system exposes this as an I/O error (EIO) on the read operation, causing the acquisition command to terminate or skip the sector. This is the classic cause of I/O errors during forensic imaging and requires error-handling flags such as 'conv=noerror,sync' in dd to continue.
The output file already exists and is being overwritten
The target directory does not have write permissions
The target drive is full
Based on the acquisition log, what can be concluded about the integrity of the acquired image?
The image is not forensically sound because the verification passed
The source and image have different data
The image is corrupted because only one hash algorithm was used
The image is an exact copy of the source
The acquisition log documents that the hash of the source and the hash of the acquired image are identical, and the subsequent verification step confirms these values still match. Identical hash digests plus a verified match provide strong cryptographic proof that the image is a precise, bit-for-bit duplicate of the source, which is the definition of a forensically sound copy.
Want more Evidence Acquisition and Duplication practice?
Practice this domain8% of exam · 6 sample questions below
During a forensic investigation, an analyst needs to preserve the integrity of evidence on a hard drive. Which of the following is the best practice for acquiring an image of the drive?
Use the 'dd' command to create a raw image without a write blocker.
Connect the drive to a forensic workstation and use the operating system's copy command.
Use a hardware write blocker and create a bit-stream image.
A hardware write blocker is the definitive forensic safeguard: it sits between the drive and the workstation and physically intercepts any write command at the ATA/SATA/USB interface, allowing only read operations. Creating a bit-stream image (e.g., using 'dd' or FTK Imager) then captures a sector-by-sector, bit-identical copy of the entire drive, including partition tables, unused sectors, slack space, and deleted files, ensuring the original evidence remains pristine and admissible in court.
Format the drive before imaging to ensure no hidden data is missed.
You are a forensic investigator responding to a security incident at a medium-sized company. The incident involved an attacker gaining unauthorized access to a Windows Server 2019 system. The server was taken offline by the IT team immediately after detection. Your task is to acquire forensic evidence from the server's hard drive. The server has a single 500 GB NTFS partition. You have a forensic workstation with a write blocker, a SATA-to-USB adapter, and a forensic imaging tool that supports both dd and EWF (E01) formats. The server is still physically in the server room, and the IT team has powered it off. You need to create a forensic image that preserves the integrity of the evidence and allows for efficient analysis. Which of the following is the most appropriate course of action?
Boot the server using a forensic live CD, connect an external USB drive to the server, and use 'dd' to create a raw image on the external drive.
Use the server's built-in backup utility to create a system state backup and copy it to a network share.
Remove the hard drive, connect it via a write blocker to the forensic workstation, and then use 'dd' over a network connection to send the image to a remote server.
Remove the hard drive, connect it via a write blocker to the forensic workstation, and create an EWF (E01) image stored locally on the forensic workstation's internal drive.
A write blocker prevents any modification to the 500 GB NTFS drive during acquisition, preserving evidential integrity. EWF (E01) stores metadata, compression and hashes, supporting efficient analysis and verification, satisfying the requirement to image the powered-off server while maintaining admissibility.
During a forensic investigation of a Windows 10 system, you need to analyze the file system to recover deleted files. Which TWO file system artifacts would be most useful for this purpose?
$LogFile
The $LogFile records transactional metadata changes, letting you reconstruct directory entries and cluster allocations before deletion, which supports recovering deleted files on NTFS. It satisfies the Windows 10 NTFS constraint directly, unlike FAT-based artifacts. Paired with $MFT, it exposes the pre-deletion state needed for forensic reconstruction.
$Boot file
$MFT (Master File Table)
$MFT holds one record per file, including name, timestamps, size and data runs. When a file is deleted, its record is marked unallocated but often retains this metadata, letting examiners recover the file or its fragments.
$Volume
$Bitmap
A forensic analyst is reviewing the syslog from a compromised Linux server. Based on the exhibit, what does the 'orphan inode deleted' message indicate?
A hidden file was permanently removed from the filesystem.
A file was deleted while still open, and the filesystem has cleaned up the orphan inode.
When a file is unlinked but a process still holds its file descriptor, the inode remains allocated until the descriptor closes, resulting in an orphan inode. On a journaling filesystem such as ext4, that inode is recorded in the orphan list during the transaction, and after an unclean shutdown or during mount, the filesystem deletes it to reclaim space and logs 'orphan inode' messages. This is expected lifecycle behavior, not a sign of an attack or corruption.
A rootkit has attempted to hide files by marking them as orphan inodes.
A critical system file has been deleted, and the filesystem is warning the administrator.
You are a forensic investigator responding to an incident on a Windows 10 workstation used by a finance manager. The user reports that a critical spreadsheet containing quarterly budget data was accidentally deleted from the Desktop yesterday at approximately 3:00 PM. The system has been used normally since then, and the user has not emptied the Recycle Bin. You have created a forensic image of the drive using FTK Imager. The Recycle Bin contains a file named 'Quarterly_Budget.xlsx', but it appears to be a shortcut (size 1 KB). The user insists the original file was several megabytes. You need to recover the original file. Which action should you take next?
Search the $Recycle.Bin folder on the forensic image to locate the original file data, which may be stored under a different name.
On the forensic image, the $Recycle.Bin folder contains the original file data in a renamed storage file (typically $R...) while a companion $I... file preserves the original name and metadata; relying on the live Recycle Bin UI is insufficient because it only exposes a virtual view of these entries. Searching this hidden system folder directly is the correct first step because the file is still fully allocated and recoverable without carving or relying on volume snapshots.
Restore a previous version of the Desktop folder from Volume Shadow Copy.
Use file carving techniques to recover the file from unallocated space on the Desktop.
Check the Recycle Bin on the live system; the file should be there and can be restored.
A forensic investigator is examining a Windows 10 workstation that was seized after a suspected data exfiltration. The user claims they only used legitimate cloud storage. The investigator wants to determine which USB mass storage devices were previously connected to the system by examining the Windows registry. Which registry location should the investigator examine to find the device instance IDs and associated volume serial numbers of previously connected USB storage devices?
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR key under the SYSTEM hive stores information about USB mass storage devices that have been connected. Each subkey represents a device instance and contains details such as the device serial number, friendly name, and sometimes the volume serial number. This is the primary location for tracing USB storage device history on Windows systems.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBHUB\Enum
Want more OS and File System Forensics practice?
Practice this domainThe CHFI exam has 125 questions and must be completed in 240 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 13 domains: Computer Forensics Investigation Process, Computer Forensics Fundamentals and Process, Application, Email and Cloud Forensics, Mobile and Malware Forensics, Network and Cloud Forensics, Storage Forensics and File System Analysis, Database and Application Forensics, Incident Response and First Responder Skills, Computer Forensics Lab, OS and Network Forensics, Malware Forensics, Evidence Acquisition and Duplication, OS and File System Forensics. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official EC-Council CHFI exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.