Sample questions
Computer Hacking Forensic Investigator CHFI practice questions
An investigator acquires an SSD from a laptop that has been turned off for 24 hours. The suspect recently deleted several incriminating files. Using a forensic imager, the investig…
Storage Forensics and File System AnalysishardSee the answer and why each option is right or wrong →An investigator needs to testify in court as an expert witness. Which of the following qualifications is MOST important for the court to accept their testimony?
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →A forensic analyst is examining a RAID 5 array consisting of three disks. One disk has failed and has been replaced. The array is rebuilt automatically. However, the analyst needs…
Storage Forensics and File System AnalysishardSee the answer and why each option is right or wrong →A forensic investigator examines a hard drive and needs to recover deleted files. Which tool is specifically designed for file carving by scanning raw data for file headers and foo…
Storage Forensics and File System AnalysiseasySee the answer and why each option is right or wrong →A forensic analyst is examining an Android device that has been factory reset. Which type of data is LEAST likely to be recoverable using forensic tools?
Which type of evidence is a witness's statement that they saw someone log into a computer?
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →Which TWO of the following are tools that can be used for timeline analysis in digital forensics?
What is the primary goal of the chain of custody in a digital forensic investigation?
Computer Forensics Fundamentals and ProcesseasySee the answer and why each option is right or wrong →A forensic analyst is preparing to testify as an expert witness in court. Which of the following characteristics is MOST essential for the court to accept the analyst's testimony?
Computer Forensics Fundamentals and ProcesshardSee the answer and why each option is right or wrong →You are investigating a Windows 10 workstation that exhibits slow performance and frequent pop-ups. The user reports that the system started acting strangely after installing a 'PD…
An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "…
A forensic analyst reviews a Windows system for signs of malware persistence. Which TWO registry locations are commonly used to achieve persistence via auto-start programs?
During dynamic analysis of a suspicious executable in Cuckoo Sandbox, the report shows that the process created a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\…
A forensic analyst is preparing to acquire an image from a suspect's hard drive. The analyst connects the drive to a write blocker, then uses FTK Imager to create a forensic image.…
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →During a mobile forensic investigation, an examiner wants to recover deleted WhatsApp messages from an Android device. Which of the following artefacts should the examiner examine?…
An investigator needs to recover deleted files from a USB drive formatted with FAT32. Which of the following techniques would be most effective, assuming the files have not been ov…
Storage Forensics and File System AnalysiseasySee the answer and why each option is right or wrong →You are a forensic investigator responding to a security incident at a medium-sized company. The incident involved an attacker gaining unauthorized access to a Windows Server 2019…
A security analyst arrives at a suspected computer crime scene. The computer is on and a user is logged in. The analyst needs to preserve volatile data. According to first responde…
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →An incident responder receives an alert that a workstation is beaconing to a known malicious IP address. The responder captures network traffic and analyzes it with Wireshark. Whic…
During an iOS forensic examination, an analyst extracts an iTunes backup and finds the file '3d0d7e5fb2ce288813306e4d4636395e047a3d28'. Which type of data does this file typically…
An expert witness is preparing to testify in a computer forensics case. Which of the following is a key requirement for the expert's testimony to be admissible under the Daubert st…
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →During a forensic investigation, you need to acquire the RAM of a running Linux system. Which tool is specifically designed for memory acquisition on Linux?
Storage Forensics and File System AnalysismediumSee the answer and why each option is right or wrong →A security analyst reviewing Windows Security Event Logs sees multiple Event ID 4625 entries for a single user account, followed by a successful Event ID 4624. The account is a dom…
During a Windows forensic investigation, an analyst finds prefetch files with the .pf extension. Which TWO pieces of information can the analyst obtain from analyzing prefetch file…