Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 676–745

745 questions total · 10pages · All types, answers revealed

Page 9

Page 10 of 10

676
MCQhard

A forensic analyst is preparing to testify as an expert witness in court. Which of the following characteristics is MOST essential for the court to accept the analyst's testimony?

A.The analyst's methods are generally accepted in the forensic community
B.The analyst has direct knowledge of the case
C.The analyst has a certification in computer forensics
D.The analyst is employed by the prosecution
AnswerA

Expert testimony is admissible when the methodology is generally accepted within the relevant forensic community, satisfying the Daubert reliability criterion. This general-acceptance characteristic is what the court weighs most heavily when deciding whether to admit the analyst's findings as expert evidence.

Why this answer

The court's acceptance of expert testimony hinges on the reliability and validity of the methods used, not the analyst's personal involvement or credentials. Under the Daubert standard (or Frye standard in some jurisdictions), the key factor is whether the forensic methods have been subjected to peer review, are generally accepted within the relevant scientific community, and have a known error rate. This ensures the testimony is based on sound scientific principles, not just the analyst's qualifications or role in the case.

Exam trap

EC-Council often tests the distinction between an expert witness and a fact witness, trapping candidates who think direct knowledge or employment status is the primary criterion for expert testimony admissibility.

How to eliminate wrong answers

Option B is wrong because direct knowledge of the case is a requirement for a fact witness, not an expert witness; an expert witness can testify based on hypotheticals or analysis of evidence provided by others, and their testimony is evaluated on methodology, not firsthand involvement. Option C is wrong because while a certification (e.g., CHFI, EnCE) can bolster credibility, it is not a legal prerequisite for admissibility; the court focuses on the reliability of the methods and the analyst's demonstrated expertise, which can be established through experience, training, or education without a specific certification. Option D is wrong because employment by the prosecution does not automatically qualify an analyst as an expert; in fact, it may raise concerns about bias, and the court must independently assess the methodology's acceptance in the forensic community regardless of which party retains the analyst.

677
MCQmedium

An investigator is analyzing an Android device and finds a database file in /data/data/com.whatsapp/databases/msgstore.db. Which type of information is MOST likely stored in this database?

A.WhatsApp chat messages
B.System call logs
C.GPS location history
D.Contact list from the device
AnswerA

WhatsApp chat messages are stored in the app's dedicated SQLite database file named msgstore.db, located in /data/data/com.whatsapp/databases/. This database contains a `messages` table that holds the actual text content, sender/receiver identifiers, timestamps, and message types, making it the primary artefact for recovering chat history. Investigators can also recover deleted messages from free pages of the database file, or from the associated WAL/SHM files if present. Therefore, finding msgstore.db directly indicates WhatsApp chat messages as the relevant data.

Why this answer

The msgstore.db file in the WhatsApp package directory is the primary SQLite database that stores all WhatsApp chat messages, including text messages, media metadata, and message timestamps. This database is located at /data/data/com.whatsapp/databases/msgstore.db on Android devices and is a key artifact for forensic recovery of WhatsApp conversations.

Exam trap

EC-Council often tests the distinction between app-specific databases and system-level databases, and the trap here is that candidates confuse msgstore.db with a general-purpose database that might store contacts or location data, when in fact it is strictly for chat message storage within the WhatsApp application.

How to eliminate wrong answers

Option B is wrong because system call logs are stored in the Linux kernel's ring buffer or in /proc/ and /sys/ filesystem entries, not in an app-specific SQLite database like msgstore.db. Option C is wrong because GPS location history is typically stored in Google Play Services databases (e.g., /data/data/com.google.android.gms/databases/) or in the device's fused location provider, not in WhatsApp's msgstore.db (though WhatsApp may store location-sharing messages as part of chat content, the database itself is not a GPS history store). Option D is wrong because the contact list from the device is stored in the Contacts Provider database (e.g., /data/data/com.android.providers.contacts/databases/contacts2.db) or in WhatsApp's wa.db or axolotl.db, not in msgstore.db, which focuses on message threads.

678
MCQhard

During a forensic examination, an analyst uses the command 'dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt'. What is the primary purpose of including 'hash=sha256' in this command?

A.To split the image into multiple files named with SHA-256 checksums
B.To compute a SHA-256 hash of the input drive and log it to a file for integrity verification
C.To encrypt the output image file using SHA-256
D.To compress the image using SHA-256 compression algorithm
AnswerB

dcfldd computes a SHA-256 hash of the acquired data stream in real time while performing the forensic bit-for-bit image copy, and the `hashlog=` option records that digest to a text file for later verification. This is an integrity control that proves the image matches the source drive at the moment of acquisition. Once the hash is recorded, an examiner can rerun SHA-256 on the image file and compare the outputs to ensure the exhibit has not been modified, which is a core requirement in forensic soundness.

Why this answer

The `hash=sha256` parameter in `dcfldd` instructs the tool to compute a SHA-256 hash of the input device (`/dev/sda`) during the acquisition process. This hash is then logged to the file specified by `hashlog=hash.txt`, providing a verifiable integrity check that the forensic image matches the original source. This is a standard forensic practice to ensure the image has not been altered or corrupted.

Exam trap

The trap here is that candidates confuse hashing with encryption or compression, assuming that `hash=sha256` might secure or shrink the output, when in fact it only generates a fixed-length digest for integrity verification.

How to eliminate wrong answers

Option A is wrong because `dcfldd` uses the `split=` parameter (e.g., `split=2G`) to split an image into multiple files, not the `hash=` parameter, which is solely for hash computation. Option C is wrong because SHA-256 is a cryptographic hash function, not an encryption algorithm; it produces a fixed-size digest, not ciphertext, and cannot encrypt files. Option D is wrong because SHA-256 is a hash function, not a compression algorithm; compression in `dcfldd` is not supported natively, and SHA-256 does not reduce file size.

679
Multi-Selecthard

Which THREE of the following correctly describe the rules of evidence as applied to digital forensics? (Select three.)

Select 3 answers
A.Evidence must be relevant to the case and obtained through lawful means
B.Circumstantial evidence is not allowed in digital forensics cases
C.Hearsay evidence is always inadmissible in court
D.The evidence must be complete and not misleading
E.Evidence must be authentic and its integrity must be verifiable
AnswersA, D, E

Relevance and lawful acquisition are fundamental because evidence must have probative value under Federal Rule of Evidence 401 and be obtained without violating constitutional protections. If evidence is seized via an unlawful search or warrantless procedure, it may be suppressed under the exclusionary rule as 'fruit of the poisonous tree,' even if otherwise probative. This dual requirement ensures that digital forensics examinations do not rely on tainted data that could undermine the integrity of the entire case.

Why this answer

Option A is correct because the fundamental rules of evidence require that any item, including digital artifacts, be both relevant to the matter at hand and collected through lawful means (e.g., valid warrants, consent, or legal exceptions), otherwise it can be excluded. Option D is correct because the evidence must be complete and not misleading — partial or selectively presented data (such as a truncated log or an edited image) can create a false impression and is therefore inadmissible or subject to challenge. Option E is correct because digital evidence must be authentic (shown to be what it purports to be) and its integrity must be verifiable, typically through hash values (e.g., MD5, SHA-256) and a documented chain of custody.

Option B is incorrect because circumstantial evidence is generally admissible in both criminal and civil cases, including digital forensics, and is often used to infer facts when direct evidence is unavailable. Option C is incorrect because hearsay is not always inadmissible; numerous exceptions and exemptions exist (e.g., business records, excited utterances, and machine-generated records), and digital evidence frequently falls under such exceptions.

Exam trap

The CHFI exam often tests the misconception that hearsay evidence is always inadmissible, but in digital forensics, server logs and automated records frequently qualify under hearsay exceptions, making Option C a trap for those who do not know the exceptions.

680
MCQmedium

A Windows system is suspected of having malware that maintains persistence by starting every time a user logs in. Which registry key should be examined FIRST for this persistence mechanism?

A.ShellBags
B.NTUSER.DAT
C.Run keys
D.HKLM\SAM
AnswerC

The Run registry keys, specifically HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, define programs that Windows automatically executes each time a user logs on. Each value name is arbitrary, but the value data is a command line (e.g., C:\Windows\Temp\payload.exe). Malware frequently uses these keys for persistence because they are easy to write, require no elevated privilege for HKCU, and survive a reboot; they are also a primary focus of Autoruns/Windows Defender detections.

Why this answer

The Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) are the most common and straightforward persistence mechanism for malware that executes on user login. These registry keys specify programs that automatically run when a user logs into their account, making them the first place to check for such persistence.

Exam trap

In CHFI, the trap is that candidates might confuse persistence mechanisms like ShellBags (view settings) or SAM (credentials) with startup entries, leading them to pick a wrong answer. The Run keys (HKCU and HKLM) are the standard locations for user logon persistence.

How to eliminate wrong answers

Option A is wrong because ShellBags store folder view settings (size, position, icon layout) for Explorer windows, not executable startup entries. Option B is wrong because NTUSER.DAT is a registry hive file that contains per-user settings, including Run keys, but it is not a specific registry key to examine directly; the question asks for a registry key, not a file. Option D is wrong because HKLM\SAM stores local user account credentials and security account manager data, not startup programs.

681
Multi-Selecteasy

An Android forensic examiner performs a physical acquisition on a device. Which TWO of the following are typical artefacts that can be recovered from the /data/data/ directory on a non-rooted device if the acquisition method allows full file system access?

Select 2 answers
A.Bootloader configuration
B.Recovery mode logs
C.Kernel logs
D.App-specific SQLite databases
E.Shared preferences XML files
AnswersD, E

App-specific SQLite databases are stored in /data/data/<package_name>/databases/ (or /data/user/0/<package>/databases/), making them a primary forensic target for messaging and browsing apps like WhatsApp, Facebook, or Chrome. A physical acquisition of the userdata partition preserves these files even when the app is closed or the device is locked, revealing chat history, contacts, search terms, and timestamps. This is why they are considered a cornerstone of Android mobile evidence.

Why this answer

Option D is correct because /data/data/<package_name>/ is the private sandbox for each installed app, and apps commonly store their structured data in SQLite databases (e.g., /data/data/com.example.app/databases/*.db), which a full file-system acquisition can recover. Option E is correct because Android apps persist key-value settings in SharedPreferences, stored as XML files under /data/data/<package_name>/shared_prefs/*.xml, which are likewise recoverable with full file-system access. Options A, B, and C are not typical artefacts of /data/data/: bootloader configuration resides in bootloader/partition areas (e.g., /misc, /bootloader), recovery mode logs are produced by the recovery partition and typically stored in /cache/recovery/, and kernel logs come from the kernel ring buffer accessed via dmesg or /proc/kmsg, not from the app data directory.

Exam trap

EC-Council often tests the misconception that /data/data/ is inaccessible on non-rooted devices, but a physical acquisition with full file system access (e.g., via JTAG or chip-off) can read the raw NAND flash, allowing recovery of app data regardless of root status.

682
MCQmedium

During dynamic analysis of a malware sample, an analyst uses Process Monitor to monitor file system activity. The malware creates a file named 'C:\Users\Admin\AppData\Roaming\svchost.exe'. What does this likely indicate?

A.The malware is a legitimate Windows update
B.The malware is extracting an archive
C.The malware is cleaning up temporary files
D.The malware is attempting to achieve persistence by placing a copy in a user directory
AnswerD

By copying itself to a user-writable directory such as %APPDATA% or %LOCALAPPDATA% and renaming the copy to svchost.exe, the malware is likely staging itself for persistence — for example, by registering that executable path in a Run registry key or a scheduled task for automatic execution on boot. The AppData location is routinely writable by the unprivileged user, obviating the need for administrator privileges, while the system-process name is designed to evade casual user and security-tool inspection. In the dynamic sandbox, the mere creation of that file is a strong behavioral indicator of persistence planning, especially when followed by registry or task scheduler modifications.

Why this answer

The creation of a file named 'svchost.exe' in the user's AppData\Roaming directory is a classic persistence technique. By placing a copy of itself with the name of a legitimate Windows system process (svchost.exe) in a user-writable location, the malware aims to execute automatically at startup (e.g., via a registry Run key or scheduled task) while evading suspicion. This is not a legitimate Windows update, as system files reside in C:\Windows\System32, not in a user profile directory.

Exam trap

The CHFI exam often tests the misconception that any file named 'svchost.exe' is legitimate, but the key indicator is the path — a system process should never run from a user profile directory like AppData\Roaming.

How to eliminate wrong answers

Option A is wrong because legitimate Windows updates are delivered via Windows Update and stored in C:\Windows\SoftwareDistribution or System32, not created by malware in a user's AppData folder. Option B is wrong because extracting an archive would typically produce multiple files or a temporary extraction folder, not a single executable masquerading as a system process. Option C is wrong because cleaning up temporary files would involve deleting files (e.g., .tmp files) from Temp folders, not creating a new executable in AppData\Roaming.

683
MCQmedium

During a forensic investigation of a MongoDB database, the analyst needs to identify which user executed a particular write operation. Which MongoDB log or feature should the analyst examine?

A.Journal (journal directory)
B.System log (mongod.log)
C.Audit log (auditLog)
D.Oplog (local.oplog.rs)
AnswerC

The audit log (auditLog) is the authoritative forensic source because MongoDB Enterprise's auditing feature, when enabled, emits structured events for user actions including authentication, schema changes, and select CRUD operations. Each audit record contains critical metadata such as the authenticated user (authUser), the exact timestamp, the operation type, and the source IP, enabling precise attribution. Its behavior can be tuned with auditFilter and operationTypes to capture the full scope of actions, making it indispensable for identifying what a user did within the database.

Why this answer

The audit log (auditLog) is the correct source because it is specifically designed to record user authentication and database operations, including which user executed a write operation. MongoDB's audit system captures detailed events such as insert, update, and delete commands along with the authenticated user identity, making it the definitive forensic artifact for user attribution.

Exam trap

EC-Council often tests the misconception that the oplog or system log records user identity, when in fact only the audit log provides authenticated user attribution for database operations.

How to eliminate wrong answers

Option A is wrong because the journal (journal directory) records write-ahead redo logs for crash recovery and durability, not user identity or operation attribution. Option B is wrong because the system log (mongod.log) contains operational messages and errors but does not reliably capture per-operation user context or detailed write command attribution. Option D is wrong because the oplog (local.oplog.rs) is a capped collection used for replication tracking and contains operation details but does not include the authenticated user who executed the write.

684
MCQmedium

A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?

A.The file system is intact and readable
B.The image is an exact bit-for-bit copy of the original drive
C.The drive contains malware
D.The drive was not encrypted
AnswerB

Forensic acquisition tools such as FTK Imager or dd compute a cryptographic hash (typically MD5, SHA-1, or SHA-256) of both the source drive and the resulting image file; when those values match, the image is an exact bit-for-bit replica of the original media. This hash match assures the examiner that no bytes were altered, dropped, or inserted during acquisition, making it admissible and reliable for analysis. It is precisely why hash verification is the cornerstone of forensic soundness.

Why this answer

B is correct because a matching MD5 hash between the image and the original drive confirms that the forensic image is an exact bit-for-bit copy. Hashing algorithms like MD5 produce a unique fixed-size hash value based on the binary content; if two hashes match, the data is identical with no alterations. This validates the integrity of the acquisition process, ensuring that the image is a perfect forensic duplicate.

Exam trap

EC-Council often tests the misconception that a matching hash confirms the drive is readable or free from issues like encryption or malware, when in fact it only confirms bit-for-bit integrity of the acquired image.

How to eliminate wrong answers

Option A is wrong because a matching hash only verifies data integrity, not file system health; a corrupted file system can still produce an identical hash if the corruption existed on the original drive. Option C is wrong because hash matching has no bearing on the presence of malware; malware can be present on both the original and the image without affecting the hash match. Option D is wrong because encryption does not affect the hash comparison; an encrypted drive will produce a hash of the encrypted data, and a matching hash only confirms the image is a copy of that encrypted state.

685
MCQmedium

During a forensic examination of an NTFS drive, an investigator finds that a file 'notes.txt' has an additional data stream named 'hidden.txt' attached. Which feature of NTFS allows this?

A.USN Journal
B.MFT
C.Alternate Data Streams (ADS)
D.Slack space
AnswerC

Alternate Data Streams (ADS) is a native NTFS capability that allows multiple data streams to be associated with a single file or directory, each identified by a name after a colon (e.g., file.txt:hidden.txt). Data written to an ADS is not shown by typical file size listings or directory views, yet it consumes logical disk space and can contain executables or other arbitrary content. Forensic tools such as `streams` or PowerShell's `Get-Item -Stream *` are required to enumerate and recover ADS, and the Zone.Identifier stream is a legitimate example, while attackers exploit this feature for stealth.

Why this answer

C is correct because NTFS supports Alternate Data Streams (ADS), a feature that allows multiple data streams to be associated with a single file. The 'hidden.txt' stream attached to 'notes.txt' is a classic example of ADS, which can be used to hide data or store metadata without affecting the file's primary content.

Exam trap

The trap here is that candidates confuse ADS with slack space or the MFT, thinking that any hidden data in NTFS must be in slack space or metadata, when ADS is the specific feature for named additional streams.

How to eliminate wrong answers

Option A is wrong because the USN Journal (Update Sequence Number Journal) is a log of changes to files on an NTFS volume, not a mechanism for attaching additional data streams. Option B is wrong because the Master File Table (MFT) is a database that stores metadata about files and directories, but it does not directly enable the attachment of extra data streams; ADS is a separate NTFS feature. Option D is wrong because slack space refers to unused bytes at the end of a file's allocated cluster, which can store hidden data but is not a feature for attaching named data streams like ADS.

686
Multi-Selecthard

A forensic examiner is acquiring a running Linux server that is part of a live incident response. The server hosts a critical database and cannot be taken offline. The examiner needs to capture volatile data in a forensically sound manner. Which TWO of the following actions should the examiner perform? (Choose two.)

Select 2 answers
A.Delete temporary files to free up space for acquisition
B.Use the 'dd' command to create a full disk image of the server's primary drive
C.Capture network connections using the 'netstat' command
D.Run 'fsck' on the primary drive to check for file system inconsistencies
E.Collect the output of the 'ps' command to capture running processes
AnswersC, E

The 'netstat' command displays active network connections, listening ports, and associated processes. This volatile data is crucial for identifying command-and-control channels or data exfiltration. It can be collected quickly without impacting the server's operation, making it a correct action for live volatile data acquisition.

Why this answer

Capturing running processes with 'ps' and network connections with 'netstat' are standard volatile data collection steps that do not disrupt the server. They provide critical information about active threats and can be performed quickly. Full disk imaging and file system checks are either disruptive or irrelevant to volatile data, and deleting files destroys evidence.

Exam trap

The trap here is confusing volatile data acquisition with full disk imaging, or thinking that system maintenance commands like fsck are part of live response.

687
MCQeasy

Which US Constitutional amendment primarily governs the legality of searching and seizing digital devices?

A.Fifth Amendment
B.Fourth Amendment
C.Fourteenth Amendment
D.First Amendment
AnswerB

The Fourth Amendment is the primary constitutional provision governing searches and seizures, establishing the right of the people to be secure against unreasonable searches and seizures and requiring warrants to be supported by probable cause and particularized descriptions. This amendment provides the foundational legal standard for police conduct, including stops, frisks, vehicle searches, and home entries. It also underpins the exclusionary rule, which suppresses evidence obtained through unreasonable searches. Therefore, it is the correct answer for the primary governing amendment.

Why this answer

The Fourth Amendment protects against unreasonable searches and seizures, requiring law enforcement to obtain a warrant based on probable cause before searching or seizing digital devices. This directly governs the legality of accessing data on computers, smartphones, and storage media in forensic investigations.

Exam trap

EC-Council often tests the misconception that the Fifth Amendment (self-incrimination) governs digital searches, but the Fourth Amendment's warrant requirement is the primary constitutional basis for seizing and searching digital devices.

How to eliminate wrong answers

Option A is wrong because the Fifth Amendment protects against self-incrimination and due process, not the legality of searches or seizures of digital devices. Option C is wrong because the Fourteenth Amendment addresses equal protection and due process at the state level, not the specific warrant requirements for searching digital devices. Option D is wrong because the First Amendment protects freedom of speech, religion, press, and assembly, and has no bearing on search and seizure law for digital evidence.

688
MCQeasy

A security analyst is reviewing Windows Security Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this MOST likely indicate?

A.Brute-force password guessing attack
B.Service installation
C.Account lockout policy change
D.Successful account logon
AnswerA

Event ID 4625 is the Windows Security log event for a failed logon attempt. When dozens or hundreds of these events occur from the same source IP or user account within a short window, it strongly indicates a brute-force password guessing attack. Analysts should correlate Sub Status codes (e.g., 0xC000006A for bad password) and Logon Type (e.g., 2 interactive, 3 network) to confirm automated guessing. The rapid repetition of failures with varying passwords is the classic signature of this attack.

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple failures in a short time suggest a brute-force attack against the user account.

689
MCQmedium

An analyst is recovering deleted files from a FAT32 file system. The file system uses a cluster size of 4096 bytes. The first cluster of a deleted file is cluster 100. Which structure contains the chain of clusters for this file?

A.Volume boot record
B.Directory entry
C.File Allocation Table (FAT)
D.Boot sector
AnswerC

The File Allocation Table (FAT) is the core structure for recovering deleted files on a FAT32 filesystem. It contains an array of entries that map each cluster to the next cluster in a file's chain, effectively recording how clusters are linked to form files. When a file is deleted, the directory entry is flagged as deleted, but the FAT entries for the file's clusters are often not immediately cleared, leaving the chain intact and recoverable. An analyst can scan the FAT for orphaned clusters and reconstruct the original file by traversing the cluster linkage, making this option the correct choice.

Why this answer

The File Allocation Table (FAT) is the core structure that stores the chain of clusters for files in FAT32 file systems. When a file is deleted, its directory entry is marked as available, but the FAT entries for its clusters (starting at cluster 100) remain intact until overwritten, allowing recovery by following the cluster chain in the FAT.

Exam trap

EC-CHFI often tests the misconception that the directory entry stores the entire cluster chain, when in fact it only stores the starting cluster number, and the FAT holds the linked list of subsequent clusters.

How to eliminate wrong answers

Option A is wrong because the Volume Boot Record (VBR) contains metadata about the file system (e.g., cluster size, total sectors) and the boot code, but does not store cluster chains for individual files. Option B is wrong because a directory entry holds the file name, attributes, timestamps, and starting cluster number (e.g., cluster 100), but not the chain of subsequent clusters; the chain is stored in the FAT. Option D is wrong because the boot sector is synonymous with the VBR and serves the same purpose—it does not contain cluster allocation information for files.

690
MCQhard

An investigator recovers a file from unallocated space on an NTFS drive using file carving. The file appears to contain alternate data streams (ADS). Which tool can be used to list all ADS associated with a file on a live Windows system?

A.dir /r
B.ls -la
C.attrib
D.fsutil
AnswerA

dir /r is the correct command because the /r switch tells the Windows command interpreter to enumerate all Alternate Data Streams (ADS) associated with each file and directory on an NTFS volume. The output shows each stream in the form filename:streamname:$DATA along with its byte size, allowing the investigator to spot hidden data that normal dir listings omit. This is the native built-in way to reveal ADS without third-party tools.

Why this answer

The `dir /r` command is the correct tool because it is a native Windows command that lists all alternate data streams (ADS) associated with files on an NTFS volume. When used with the `/r` switch, `dir` displays the main file stream along with any named ADS, such as `:Zone.Identifier:$DATA`, which are hidden from standard directory listings. This makes it the most direct and built-in method for an investigator to enumerate ADS on a live Windows system.

Exam trap

EC-Council often tests the distinction between native Windows commands and Unix commands, leading candidates to mistakenly choose `ls -la` because they associate it with listing files, but it cannot reveal NTFS ADS.

How to eliminate wrong answers

Option B is wrong because `ls -la` is a Linux/Unix command that does not exist natively in Windows; even if used via a subsystem like WSL, it does not display NTFS alternate data streams. Option C is wrong because `attrib` is used to view or change file attributes (e.g., read-only, hidden, system) and has no capability to enumerate ADS. Option D is wrong because `fsutil` is a filesystem utility for tasks like managing quotas, hard links, or repair, but it does not have a subcommand to list ADS associated with a specific file.

691
MCQmedium

An analyst is investigating a Linux server running ext4 and needs to recover deleted files that may have been overwritten partially. Which technique is BEST suited for recovering fragments of known file types when the inode metadata is lost?

A.Perform file carving using 'foremost' with custom signatures
B.Use 'dd' to extract the partition and then 'grep' for strings
C.Manually reconstruct the inode table using 'debugfs'
D.Use 'extundelete' to recover files from the journal
AnswerA

File carving with 'foremost' directly scans the raw block device for known file signatures (magic bytes) and reconstructs files based on header/footer patterns, completely bypassing filesystem metadata such as the inode table. Custom signatures extend this to file types not in the default configuration, making it the only viable method when the inode table has been overwritten. Because carving works at the data level, it can still recover fragments of deleted files even when the filesystem structures are corrupted.

Why this answer

When inode metadata is lost, file system-based recovery tools like extundelete cannot function because they rely on that metadata. File carving with foremost uses content-based signatures (magic bytes) to locate and extract file fragments, even from partially overwritten areas of the disk. This makes it the best choice for recovering fragments of known file types when the file system metadata is unavailable.

Exam trap

The trap here is that candidates assume 'extundelete' or 'debugfs' can always recover deleted files, but they fail when inode metadata is lost, whereas carving tools like foremost operate independently of the file system metadata.

How to eliminate wrong answers

Option B is wrong because using 'dd' and 'grep' only recovers plaintext strings, not binary file fragments, and cannot reconstruct file structures. Option C is wrong because manually reconstructing the inode table with 'debugfs' requires that the inode metadata still exists or can be recovered from the file system, which is explicitly stated as lost. Option D is wrong because 'extundelete' relies on the journal and inode metadata to recover files; if the inode metadata is lost, extundelete cannot locate or reconstruct the file fragments.

692
MCQmedium

A cloud forensics investigator is analyzing an incident in AWS. The suspect is alleged to have deleted an S3 bucket. Which AWS service log would contain the DeleteBucket API call details, including the source IP and user identity?

A.AWS CloudTrail
B.VPC Flow Logs
C.Amazon S3 access logs
D.AWS Config
AnswerA

AWS CloudTrail is the correct answer because it is the primary service for logging all API activity in AWS, including management events like DeleteBucket. It records the identity of the principal who made the call, the source IP, the timestamp, and the request parameters, providing a complete audit trail for investigating management-plane incidents. Without CloudTrail, you would lack the forensic evidence of who issued the destructive bucket deletion command.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including management-plane operations like DeleteBucket. Each CloudTrail event contains the source IP address, user identity (IAM user or role ARN), and the exact API action (DeleteBucket), making it the definitive log for investigating S3 bucket deletion incidents.

Exam trap

The CHFI exam often tests the distinction between management-plane logs (CloudTrail) and data-plane logs (S3 access logs), so candidates mistakenly choose S3 access logs thinking they capture bucket deletion, when in fact they only log object-level operations within the bucket.

How to eliminate wrong answers

Option B (VPC Flow Logs) is wrong because they capture network traffic metadata (IP addresses, ports, protocols) at the VPC level, not API-level actions like S3 bucket deletion. Option C (Amazon S3 access logs) is wrong because they record object-level access requests (GET, PUT, DELETE) within a bucket, not the management-plane DeleteBucket API call that removes the bucket itself. Option D (AWS Config) is wrong because it tracks resource configuration changes and compliance over time, but it does not log the source IP or user identity for API calls; it only records the resulting state change.

693
MCQhard

An analyst is examining an NTFS volume and finds that a file's $MFT record indicates it is resident. What does this imply about the file's data?

A.The file is compressed and stored across multiple clusters
B.The file uses alternate data streams to hide data
C.The file's data is stored within the $MFT record itself, suitable for small files
D.The file is a directory junction point
AnswerC

In NTFS, a small file's entire content can be stored directly inside the $MFT record within a resident $DATA attribute, making it immediately accessible without reading additional clusters. This happens when the file's data is small enough to fit in the available space of the file's MFT record, often up to about 700 bytes depending on record size and attribute overhead. Thus, the file is correctly identified as having its data stored within the MFT record itself, which is a standard NTFS optimization.

Why this answer

When a file's $MFT record indicates it is resident, the file's data is stored entirely within the $MFT record itself. This occurs for small files (typically under 512–1024 bytes) to optimize storage and access speed, as the data does not need to be placed in separate clusters on the NTFS volume.

Exam trap

The trap here is that candidates confuse 'resident' with 'compressed' or 'sparse,' or assume resident files always use alternate data streams, when in fact residency simply means the data fits inside the MFT record.

How to eliminate wrong answers

Option A is wrong because a resident file is not compressed and does not span multiple clusters; compression and multi-cluster storage apply to non-resident files. Option B is wrong because alternate data streams (ADS) are a separate NTFS feature that can exist in both resident and non-resident files, but the resident attribute itself does not imply ADS usage. Option D is wrong because a directory junction point is a reparse point, which is unrelated to the resident attribute; junction points involve directory linking, not file data storage within the MFT.

694
MCQmedium

In malware static analysis, a PE file is examined. The section names include '.text', '.rdata', '.data', and '.rsrc'. The entry point is in the .text section. Which tool would be MOST appropriate to identify any packer that might be obfuscating the code?

A.strings
B.Ghidra
C.PEiD
D.IDA Pro
AnswerC

PEiD (Portable Executable Identifier) is purpose-built for static packer/cryptor/compiler detection by matching the file's entry-point bytes, section names, and structural features against a signature database. It identifies common packers like UPX, ASPack, and MEW, along with compilers, which directly answers the question of whether a PE is packed. This makes it the standard artifact triage tool, despite being dated and sometimes evaded by custom/modified packers.

Why this answer

PEiD is specifically designed to detect packers, cryptors, and compilers by scanning PE files for known signatures in the entry point and section headers. Since the question asks for identifying a packer that obfuscates code, PEiD's signature-based detection directly targets this need, unlike general-purpose disassemblers or string extractors.

Exam trap

EC-Council often tests the distinction between tools for packer detection versus general reverse engineering; the trap here is that candidates choose IDA Pro or Ghidra because they are powerful, but the question specifically asks for the *most appropriate* tool to *identify* a packer, not to analyze the unpacked code.

How to eliminate wrong answers

Option A is wrong because `strings` only extracts readable ASCII/Unicode sequences from a file and cannot identify packer signatures or obfuscation algorithms. Option B is wrong because Ghidra is a full reverse-engineering framework focused on disassembly and decompilation, not packer detection; it would require manual analysis to spot packer artifacts. Option D is wrong because IDA Pro is an interactive disassembler/debugger for deep code analysis, but it lacks automated packer signature scanning and is overkill for simply identifying a packer.

695
MCQeasy

A forensic investigator is examining a suspicious file and wants to determine its true file type regardless of its extension. The investigator runs the 'file' command on the file and receives the output 'PE32 executable (GUI) Intel 80386, for MS Windows'. However, the file has a .txt extension. What is the most likely explanation for this discrepancy?

A.The file is a Windows executable that has been renamed with a .txt extension to evade detection or confuse users.
B.The file is a shortcut file (.lnk) that has been renamed to .txt, but the 'file' command misidentifies it as an executable.
C.The file is a text file that has been mistakenly identified by the 'file' command due to its content.
D.The file is a polyglot file that is both a valid text file and a valid executable.
AnswerA

Malware often uses misleading file extensions to disguise executables. The 'file' command correctly identifies the file as a PE32 executable based on its header, despite the .txt extension. This indicates deliberate renaming, a common tactic to bypass security controls that rely on extension-based filtering or to trick users into opening the file. The investigator should treat it as an executable.

Why this answer

The 'file' command identifies file types by examining their content, particularly magic numbers. A PE32 executable header indicates a Windows executable, regardless of the file extension. Renaming an executable with a .txt extension is a common malware tactic to evade detection and trick users.

The investigator should recognize this discrepancy as suspicious and handle the file accordingly.

Exam trap

The trap here is trusting the file extension over the actual file content, which can lead to misclassification of malicious files.

696
MCQmedium

In malware forensics, which of the following is an indicator of compromise (IoC) that can be used to detect a specific malware strain across multiple systems?

A.The file's size in bytes reported by the filesystem
B.The file's MD5 hash computed from its binary contents
C.The file's copyright metadata embedded in the PE header
D.The file's creation timestamp as recorded by the operating system
AnswerB

An MD5 hash is computed from the exact binary contents of the file, producing a fixed-length digest that acts as a fingerprint for that specific byte sequence; changing even a single bit results in a completely different digest. In malware forensics, matching a sample's MD5 against a threat intelligence database identifies a known malicious file with high confidence because the digest is directly derived from the bytes, not from mutable metadata. Although MD5 has known collision vulnerabilities, for identifying a particular captured sample it is still a standard and reliable indicator, with SHA-256 preferred for stronger assurance.

Why this answer

The MD5 hash of a file's binary contents is a unique cryptographic fingerprint that remains consistent across all copies of the exact same malware strain, regardless of where it is stored or what metadata the filesystem assigns. This makes it a reliable indicator of compromise (IoC) for identifying a specific malware sample across multiple systems, as the hash will match even if file names, sizes, or timestamps differ.

Exam trap

EC-Council often tests the misconception that file metadata like timestamps or sizes are reliable IoCs, when in fact they are easily altered or inconsistent across systems, whereas a cryptographic hash of the binary content provides a deterministic and verifiable identifier.

How to eliminate wrong answers

Option A is wrong because the file's size in bytes can vary due to padding, compression, or different file system cluster sizes, and multiple distinct malware strains can have identical file sizes, making it non-unique and unreliable as a specific IoC. Option C is wrong because copyright metadata embedded in the PE header is optional, easily stripped or modified by malware authors, and is not a consistent or trustworthy identifier across different samples of the same strain. Option D is wrong because the file's creation timestamp is set by the operating system at the time of file extraction or download, which varies per system and can be manipulated via timestomping, so it cannot uniquely identify a specific malware strain across multiple environments.

697
Multi-Selectmedium

Which TWO of the following are valid methods for hiding data on an NTFS volume without using third-party tools? (Select 2)

Select 2 answers
A.Creating a symbolic link to a hidden file
B.Encrypting the file with EFS
C.Slack space (file slack or volume slack)
D.Alternate Data Streams (ADS)
E.Using the $Recycle.bin folder
AnswersC, D

Slack space arises because files are stored in fixed-size clusters, and a file rarely fills the final cluster completely, leaving unused bytes (file slack) or gaps between allocated clusters (volume slack). These residual areas can be overwritten with hidden data without altering the file's apparent size or its directory entry, since the OS does not touch slack during normal operations. This creates a covert storage location that persists until the cluster is reused, making it a standard technique for hiding forensic evidence.

Why this answer

Option C is correct because NTFS allocates disk space in clusters, and when a file's logical size is smaller than the allocated cluster(s), the unused bytes form file slack (and unused clusters at the end of the volume form volume slack); data written into that slack is not visible through normal file reads and requires no third-party tool—just native OS utilities. Option D is correct because NTFS natively supports Alternate Data Streams, allowing extra data to be attached to a file via syntax like 'type secret > file.txt:stream', and this stream is not shown by default in Explorer or a standard 'dir' listing, making it a built-in hiding method. Option A is not a hiding method—a symbolic link is simply a reparse point that redirects to a target, and the link itself is visible; it does not conceal data.

Option B, EFS encryption, protects confidentiality but does not hide the file's existence, as the file and its metadata remain visible. Option E, the $Recycle.bin folder, is a normal system folder for deleted items and does not provide a native concealment mechanism beyond ordinary file attributes.

Exam trap

The trap here is that candidates often confuse data hiding with data protection or access control, incorrectly selecting EFS (encryption) or symbolic links as hiding methods, when the CHFI exam specifically tests native NTFS features that conceal data from normal file system views without altering file attributes or permissions.

698
MCQhard

A forensic investigator uses FTK Imager to create a forensic image of a suspect's laptop. The acquisition generates both an E01 file and a corresponding hash file. Which statement accurately describes the integrity verification process in FTK Imager?

A.The hash is computed only when the image is mounted for analysis, not during acquisition
B.FTK Imager does not support hash verification; a separate tool must be used
C.The hash is compared to a known-good hash from the manufacturer's database
D.The image file includes embedded hash values that can be verified later to ensure data integrity
AnswerD

Expert Witness Format (E01) images embed CRC32 checksums for each chunk and MD5/SHA1 hashes for the entire file, allowing later verification without access to the original drive. When the investigator re-opens the image, FTK Imager recomputes these values and compares them to the stored values to detect any alteration or corruption. Because the embedded hash values are stored inside the image file itself, they provide an independent integrity check even after the source is no longer available.

Why this answer

FTK Imager embeds hash values (MD5 and SHA1) directly into the E01 file during acquisition. These embedded hashes can be verified later by FTK Imager or compatible tools to confirm that the image has not been altered, ensuring data integrity without relying on an external hash file.

Exam trap

The trap here is that candidates often assume hash verification requires an external file or separate tool, but FTK Imager embeds the hash directly in the E01 file, making verification a built-in feature that does not rely on external databases or post-acquisition computation.

How to eliminate wrong answers

Option A is wrong because FTK Imager computes the hash during acquisition, not when the image is mounted for analysis; the hash is calculated in real-time as data is read from the source. Option B is wrong because FTK Imager fully supports hash verification; it can verify the embedded hash against the acquired data and also allows verification of separate hash files (e.g., .txt or .md5). Option C is wrong because FTK Imager does not compare hashes to a manufacturer's database; it compares the computed hash of the acquired image to the hash value embedded in the E01 file or provided separately, ensuring the image matches the original source.

699
MCQhard

During a forensic examination of an NTFS drive, an analyst runs 'fsutil usn readjournal C:' and observes a large number of USN journal entries for a specific file after a certain date. The file's $MFT record shows a last modified timestamp far earlier than the journal entries. What does this discrepancy suggest?

A.The file's metadata was modified without changing its content, possibly using timestomping or ADS manipulation
B.The file is a system file that is excluded from USN journaling
C.The file system is corrupted and the MFT is not updating correctly
D.The file was accessed via a mounted volume shadow copy, which does not update MFT
AnswerA

A recorded USN journal entry that does not correspond to an observable MFT timestamp change indicates that metadata was altered without updating the file's content. Attackers commonly use timestomping to directly modify $STANDARD_INFORMATION or $FILE_NAME timestamps in the MFT, bypassing the normal NTFS APIs that would trigger a journaled update; alternatively, ADS manipulation can change attribute-level metadata while leaving the main file data untouched. The consistency of the journal and MFT in this case makes accidental or corrupted behavior unlikely, pointing to deliberate anti-forensic action.

Why this answer

The USN journal records all changes to files and directories on an NTFS volume, including metadata modifications. When the USN journal shows numerous entries after a date but the $MFT record's last modified timestamp is earlier, it indicates that the file's metadata (e.g., timestamps, ADS) was altered without updating the $MFT's last modified field—a classic sign of timestomping or ADS manipulation. This discrepancy arises because timestomping tools can directly modify $MFT attributes while the USN journal still logs the change event.

Exam trap

The trap here is that candidates assume the USN journal only tracks data content changes, not metadata changes, leading them to incorrectly attribute the discrepancy to corruption or shadow copies instead of recognizing it as evidence of timestomping.

How to eliminate wrong answers

Option B is wrong because system files are not excluded from USN journaling; the USN journal records changes for all files on an NTFS volume, including system files, unless specifically filtered by the analyst. Option C is wrong because file system corruption would typically cause inconsistent or missing entries across both the USN journal and $MFT, not a clean discrepancy where the journal is updated but the $MFT timestamp is not. Option D is wrong because accessing a file via a mounted volume shadow copy does not update the live $MFT record at all, but the USN journal entries in this scenario are on the live volume, not the shadow copy; shadow copies have their own separate $MFT and USN journal.

700
MCQmedium

You are a first responder for a medium-sized enterprise. The Help Desk received multiple reports that users cannot access the company's internal web application (app.example.com) hosted on a Windows Server 2019 VM. The server is also running a MySQL database and an FTP service for file transfers. You remote into the server and find that the web server (IIS) is still running, but the application pool is stopped. The event logs show multiple failed logon attempts from an external IP address (198.51.100.23) for the local administrator account around the time the issues started. The FTP service log shows successful anonymous logins from the same IP minutes before the web app failure. The MySQL log shows a query 'DROP TABLE users;' executed at 03:15 AM. The current time is 04:00 AM. What immediate action should you take?

A.Capture a memory dump of the server, then disconnect the network cable, and then image the hard drive.
B.Disconnect the server from the network and then restore the database from the last clean backup.
C.Immediately shut down the server to prevent further damage and then create a forensic image of the hard drive.
D.Run a full antivirus scan, then try to restart the application pool to restore service quickly.
AnswerA

Capture a memory dump first because RAM holds the most volatile evidence—running processes, open network sockets, loaded kernel modules, and decrypted data—all of which vanish on power loss. Disconnecting the network cable immediately after memory acquisition cuts off remote attacker access and prevents further tampering with disk evidence. Finally, imaging the hard drive preserves the static data in a forensically sound, bit-for-bit copy for later analysis. The strict ordering follows the volatility hierarchy, ensuring no evidence layer is destroyed before it is captured.

Why this answer

The server is actively compromised — the attacker gained access via anonymous FTP, executed a destructive SQL query, and performed lateral movement. Capturing a memory dump preserves volatile evidence (e.g., running processes, network connections, and in-memory malware), disconnecting the network cable prevents further data exfiltration or remote control, and imaging the hard drive captures persistent evidence. This follows the CHFI first responder priority: preserve volatile data first, then isolate, then acquire non-volatile evidence.

Exam trap

EC-Council often tests the first responder's priority order — candidates mistakenly choose to shut down or restore services first, forgetting that volatile evidence (memory, network connections) is lost on power-off and that isolation must precede any remediation.

How to eliminate wrong answers

Option B is wrong because restoring the database from backup destroys volatile evidence (e.g., memory-resident malware, active network connections) and may re-infect the system if the backup is compromised; isolation must precede restoration. Option C is wrong because shutting down the server destroys volatile data (e.g., running processes, network connections, encryption keys in memory) and may trigger anti-forensic mechanisms; the correct order is memory capture before power-off. Option D is wrong because running an antivirus scan modifies the system state (e.g., file access times, quarantine actions) and may alert the attacker if they have remote access; service restoration is premature before forensic preservation.

701
Multi-Selecthard

Which THREE of the following are challenges specific to container forensics?

Select 3 answers
A.Ephemeral nature of containers: containers are often short-lived and can be deleted quickly
B.Containers cannot be imaged using standard forensic tools
C.Container logs are always stored in a centralized location
D.Multiple layers in a container image require analysis of each layer for forensic artifacts
E.Containers share the host kernel, so kernel-level artifacts are not available
AnswersA, D, E

Containers are designed to be short-lived and disposable, often existing for seconds or minutes during automated builds, batch jobs, or scaled-out microservices. Unlike VMs that persist as files on disk, a container's writable layer is typically deleted when the container stops, so forensic acquisition must occur live or immediately after the incident before the container is removed by orchestrators or cleanup daemons. Even the container ID, PID, and filesystem may vanish, making time-sensitive triage critical.

Why this answer

Option A is correct because containers are frequently ephemeral—they can be stopped, deleted, or replaced in seconds—so volatile evidence such as running processes, memory, and writable layer data may disappear before acquisition, making timely capture critical. Option D is correct because a container image is built from stacked layers (e.g., in OCI/Docker format), and each layer may contain distinct artifacts, deleted files, or modifications, so investigators must analyze every layer rather than just the final filesystem view. Option E is correct because containers share the host's kernel via namespaces and cgroups rather than running their own kernel, so kernel-level artifacts (e.g., kernel modules, some syscalls, and host-level kernel logs) are not isolated within the container and must be examined on the host instead.

Option B is not correct because containers and their images can be imaged or exported using standard tools such as docker export, docker save, or dd on the underlying storage, so this is not an inherent limitation. Option C is not correct because container logs are not always centralized; by default they are stored locally on the host (e.g., under /var/lib/docker/containers or via the configured logging driver), and centralization only occurs if a logging driver or aggregation system is explicitly configured.

Exam trap

A common misconception in CHFI is that containers are completely un-imageable with standard tools, but in reality, `docker export` and `docker save` produce standard archives that can be ingested by forensic suites.

702
Multi-Selectmedium

During a Linux forensic investigation, an analyst examines the file /var/log/auth.log and finds repeated entries with 'Failed password for root from 192.168.1.200 port 22 ssh2'. Which TWO conclusions can the analyst draw from this evidence?

Select 2 answers
A.The source IP 192.168.1.200 belongs to a local subnet
B.The system is experiencing a brute-force attack on SSH
C.The SSH service is enabled and listening on port 22
D.The attacker attempted to exploit a vulnerability in the SSH version
E.An unauthorized user successfully logged in as root
AnswersB, C

The log pattern shows multiple 'Failed password' events for SSH from the same source IP within a short window, which is the classic indicator of an automated brute-force attack. Attackers cycle through username/password combinations hoping for a match, generating a high volume of authentication failures. This does not require any vulnerability in SSH itself; it merely targets weak credentials.

Why this answer

Option B is correct because repeated 'Failed password for root' entries in /var/log/auth.log indicate multiple unsuccessful SSH authentication attempts against the root account, which is the classic signature of an SSH brute-force attack. Option C is correct because the log entries show connections to port 22 with the ssh2 protocol, meaning the SSH daemon (sshd) is running and accepting connections on TCP port 22. Option A is not supported: 192.168.1.200 is a private RFC 1918 address, but that alone does not prove it is on the same local subnet as the examined host.

Option D is wrong because failed password entries reflect authentication failures, not exploitation of an SSH software vulnerability. Option E is wrong because 'Failed password' explicitly indicates the login attempts did not succeed.

Exam trap

EC-Council CHFI often tests the distinction between failed authentication attempts (indicating a brute-force attack) and successful logins or vulnerability exploitation, leading candidates to incorrectly assume a successful breach or a software exploit from mere failure logs.

703
MCQmedium

A forensic investigator is analyzing a Linux ext4 file system. They suspect a file was deleted but its inode may still be intact. Which tool can be used to recover the file by referencing the inode?

A.dd
B.scalpel
C.foremost
D.debugfs
AnswerD

debugfs is a filesystem debugger built specifically for ext2/ext3/ext4 that provides direct access to the on-disk inode structures. Commands such as `lsdel` list unlinked inodes and `cat <inode>` display file content by inode number, allowing targeted recovery of deleted files when the inode is still valid. Unlike carving tools, debugfs leverages the filesystem metadata itself, making it the correct choice for inode-based recovery.

Why this answer

debugfs is an interactive file system debugger for ext2/ext3/ext4 that allows direct manipulation of inode structures. When a file is deleted but its inode remains intact, debugfs can recover the file by using the `lsdel` command to list deleted inodes and the `dump` command to extract the file contents by referencing the inode number.

Exam trap

The CHFI exam often tests the distinction between file carving tools (scalpel, foremost) and file system forensic tools (debugfs), expecting candidates to know that carving ignores metadata while debugfs leverages the inode structure for recovery.

How to eliminate wrong answers

Option A is wrong because `dd` is a low-level disk cloning tool that copies raw data block by block; it cannot interpret file system metadata or recover files by inode. Option B is wrong because `scalpel` is a file carving tool that relies on file headers and footers, not inode structures, making it ineffective when the inode is intact but the file content is not contiguous. Option C is wrong because `foremost` is also a file carver that uses header/footer signatures for recovery, not file system metadata like inodes.

704
Multi-Selecthard

Which THREE of the following are challenges specific to forensic analysis of solid-state drives (SSDs) compared to traditional hard disk drives (HDDs)? (Select three.)

Select 3 answers
A.The TRIM command can permanently erase deleted data
B.SSDs have higher latency for read operations
C.Wear leveling algorithms move data unpredictably
D.Built-in hardware encryption may prevent data access
E.Bad block remapping is more frequent on SSDs
AnswersA, C, D

The TRIM command tells an SSD to wipe the physical blocks that hold deleted file data by sending an ATA command that removes the mapping and allows garbage collection to zero the cells. Once TRIM is issued, the original data is permanently erased and cannot be recovered by software or even sophisticated laboratory techniques. This is a flash-specific obstacle because HDDs do not have TRIM; on a hard disk, deleted files remain in place until overwritten.

Why this answer

Option A is correct because the ATA TRIM command (and SCSI UNMAP) tells the SSD controller that blocks are no longer in use, allowing the drive to erase them via garbage collection, which can permanently destroy deleted data before an examiner images the drive. Option C is correct because wear leveling and garbage collection relocate logical blocks to different physical NAND pages transparently, so logical-to-physical mapping changes constantly and traditional file-carving based on physical offsets becomes unreliable. Option D is correct because many SSDs implement hardware-based full-disk encryption (e.g., OPAL/TCG or proprietary SED encryption) tied to the controller, and without the credential or a powered-on unlocked state the data is inaccessible even after chip-off.

Option B is wrong because SSDs generally have lower, not higher, read latency than HDDs since there is no seek or rotational delay. Option E is wrong because bad-block remapping exists on both HDDs and SSDs and is not a challenge specific to SSD forensics.

Exam trap

EC-Council often tests the misconception that SSDs have higher read latency due to their electronic nature, but in reality, SSDs have much lower latency than HDDs because they lack moving parts; the trap is to confuse latency with the unpredictability of wear leveling or garbage collection delays.

705
MCQeasy

Which Linux log file is the PRIMARY source for authentication-related events such as user logins, sudo usage, and failed authentication attempts?

A./var/log/kern.log
B./var/log/syslog
C./var/log/boot.log
D./var/log/auth.log
AnswerD

/var/log/auth.log records PAM and sudo authentication events on Debian-based systems, capturing successful logins, failed password attempts, and privilege escalation via sudo. This directly satisfies the stem's requirement for a primary authentication source covering logins, sudo usage, and failures, unlike general system or kernel logs.

Why this answer

/var/log/auth.log is the primary log file on Linux systems (especially Debian/Ubuntu) that records authentication-related events, including user logins (via sshd, login, su), sudo command executions, and failed authentication attempts. This log is generated by the authpriv facility in syslog and is specifically designed to capture security and authentication messages, making it the go-to source for forensic analysis of user access and privilege escalation.

Exam trap

In EC-CHFI, candidates often confuse /var/log/syslog with /var/log/auth.log, thinking syslog captures all system events. However, authentication events are specifically routed to a separate file (auth.log or secure) for security isolation and forensic analysis of user access.

How to eliminate wrong answers

Option A is wrong because /var/log/kern.log contains kernel messages (e.g., driver errors, hardware events) and does not log user authentication or sudo usage. Option B is wrong because /var/log/syslog captures general system messages (e.g., daemon logs, cron jobs) but not the authpriv facility by default; authentication events are typically excluded from syslog to separate security-relevant data. Option C is wrong because /var/log/boot.log records boot-time messages from the init system (e.g., systemd or SysV) and has no relation to runtime authentication events like logins or sudo.

706
MCQhard

An investigator notes that a file on an NTFS volume has a resident data size of 900 bytes, but the $DATA attribute lists an allocated size of 1024 bytes. What does this indicate?

A.The file is compressed using NTFS compression
B.The file has slack space that may contain remnants of previously deleted data
C.The file's data is stored in the MFT as a resident attribute
D.The file is stored in an alternate data stream
AnswerB

File slack occurs because NTFS allocates disk space in fixed-size clusters, while a file's logical size is measured in bytes. If the final cluster is only partially used, the remaining bytes from the end of the file to the end of that cluster are not initialized by the filesystem, so they may still contain data from a previously deleted file or from an earlier, larger version of the current file. This residual data is a common forensic target because it survives normal file deletion and can be carved during analysis. The observed discrepancy between allocated size and logical size directly indicates that such slack space exists.

Why this answer

On an NTFS volume, when a file's data is stored as a resident attribute within the MFT, the $DATA attribute's allocated size is typically 0 because the data occupies space only within the MFT record itself. Here, the allocated size is 1024 bytes, which is larger than the resident data size of 900 bytes. This indicates that the file is stored non-resident (i.e., in clusters outside the MFT), and the allocated size reflects the cluster size (e.g., 1024 bytes per cluster).

The difference between the allocated size (1024 bytes) and the actual data size (900 bytes) is slack space, which may contain remnants of previously deleted data.

Exam trap

A common misconception is that a resident data size smaller than allocated size implies the file is resident in the MFT, but in reality, resident files have an allocated size of 0, and a non-zero allocated size indicates non-resident storage with potential slack space.

How to eliminate wrong answers

Option A is wrong because NTFS compression would typically result in an allocated size smaller than the uncompressed data size, not larger; compression reduces cluster usage, but here the allocated size (1024 bytes) is larger than the data size (900 bytes), which is inconsistent with compression. Option C is wrong because if the file's data were stored as a resident attribute in the MFT, the allocated size would be 0 (since no clusters are allocated), not 1024 bytes. Option D is wrong because an alternate data stream (ADS) would have its own $DATA attribute with its own allocated size; the scenario describes a single $DATA attribute with a specific allocated size, not the presence of multiple streams.

707
MCQmedium

A forensic analyst is testifying in court as an expert witness. What is the PRIMARY role of an expert witness in digital forensics?

A.To represent the interests of the party that hired them.
B.To determine the guilt or innocence of the defendant.
C.To offer an opinion on the technical facts and assist the trier of fact.
D.To present factual findings only, without interpretation.
AnswerC

Under Federal Rule of Evidence 702, a properly qualified expert may testify in the form of an opinion if specialized knowledge will help the trier of fact understand the evidence or determine a fact in issue, provided the opinion is based on sufficient facts or data, reliable principles and methods, and the expert has reliably applied those methods to the case. This role allows the expert to interpret technical findings—such as disk forensic artifacts, network logs, or malware analysis—and draw conclusions from patterns that a lay witness cannot, while remaining impartial and not advocating for either side.

Why this answer

The primary role of an expert witness in digital forensics is to provide an impartial opinion on technical facts, helping the trier of fact (judge or jury) understand complex digital evidence. Unlike a lay witness, an expert is permitted to offer interpretations and conclusions based on their specialized knowledge, as defined under Federal Rule of Evidence 702. This opinion must be based on sufficient facts or data, reliable principles and methods, and a reliable application of those methods to the case.

Exam trap

The CHFI exam often tests the distinction between a fact witness and an expert witness, trapping candidates who think an expert can only present raw facts (Option D) rather than offering technical opinions.

How to eliminate wrong answers

Option A is wrong because an expert witness must remain impartial and objective, not advocate for the hiring party; their duty is to the court, not to the client. Option B is wrong because determining guilt or innocence is the sole responsibility of the trier of fact (judge or jury), not the expert witness, who only provides technical analysis and opinions. Option D is wrong because while factual findings are foundational, an expert witness is specifically allowed to offer interpretations and opinions on those facts, which is what distinguishes them from a fact witness.

708
Multi-Selecthard

An analyst is reviewing a Linux system for signs of a rootkit. Which THREE of the following are common indicators of a rootkit infection? (Select THREE.)

Select 3 answers
A.Incorrect file permissions on /etc/passwd
B.Anomalies in the /proc filesystem
C.Large number of failed SSH login attempts
D.Suspicious loadable kernel modules
E.Modified system binaries like ls and ps
AnswersB, D, E

Anomalies in the /proc filesystem are a strong rootkit indicator because /proc is a virtual filesystem that reflects kernel data structures, including the live process list and network sockets. Kernel-level rootkits often hook the /proc handler routines or hide their own PIDs and associated entries, so comparing output of ps and netstat against /proc directly can reveal hidden processes or mismatched connection tables. For example, a rootkit may unlink its process from the task list while left visible in /proc's pid directory, or vice versa, and an examiner should inspect /proc/<pid>/cmdline and /proc/net/tcp for subtle inconsistencies.

Why this answer

Option B is correct because a rootkit often hooks or hides processes, files, and network sockets by tampering with the kernel's virtual /proc filesystem, so discrepancies between /proc entries and tools like ps or ls, or missing PIDs, are a classic anomaly. Option D is correct because rootkits frequently install malicious loadable kernel modules (LKMs) to intercept syscalls and conceal their presence, so unexpected or unsigned modules in lsmod//proc/modules are a strong indicator. Option E is correct because rootkits commonly replace or trojanize core system binaries such as ls, ps, netstat, and top so they omit the attacker's processes and files, which can be detected via package verification (rpm -V, debsums) or checksum comparison.

Option A is not a typical rootkit indicator, since incorrect permissions on /etc/passwd usually reflect misconfiguration or a separate privilege/account issue rather than kernel-level concealment. Option C is also not specific to rootkits, as a high volume of failed SSH logins indicates brute-force or credential-stuffing attempts, not the stealth mechanisms a rootkit employs.

Exam trap

EC-Council often tests the distinction between network-based attack indicators (like failed SSH logins) and host-based rootkit artifacts (like /proc anomalies or modified binaries), leading candidates to confuse brute-force activity with kernel-level compromise.

709
MCQmedium

During an investigation of a compromised system, the analyst discovers that the suspect used steganography to hide data within image files. Which forensic tool is BEST suited for detecting hidden data in images through statistical analysis?

A.Binwalk
B.Wireshark
C.Foremost
D.Stegdetect
AnswerD

Stegdetect is the correct tool because it performs automated statistical steganalysis designed to detect hidden messages in JPEG images. It uses quantitative tests, including chi-square analysis and other frequency-domain tests, to identify anomalies in the distribution of DCT coefficients that are characteristic of tools like JSteg, OutGuess, and F5. This makes Stegdetect a purpose-built steganography detection tool, unlike general-purpose file analyzers or network sniffers.

Why this answer

Stegdetect is specifically designed to detect hidden data in images by applying statistical analysis to identify anomalies in pixel distributions that indicate steganographic embedding. It uses techniques like chi-square analysis and RS analysis to detect LSB (Least Significant Bit) steganography, making it the best choice for this task.

Exam trap

The trap here is that candidates often confuse file carving tools (like Foremost) with steganography detection, or assume network analysis tools (like Wireshark) can be repurposed for image analysis, when the question specifically requires statistical analysis of image data.

How to eliminate wrong answers

Option A (Binwalk) is wrong because it is a firmware analysis tool that scans for embedded files and signatures in binary blobs, not for statistical steganography detection in images. Option B (Wireshark) is wrong because it is a network protocol analyzer for capturing and inspecting packets, with no capability for image steganography detection. Option C (Foremost) is wrong because it is a file carving tool that recovers deleted files based on headers and footers, not a tool for statistical analysis of steganographic content.

710
Multi-Selecthard

A security team is analyzing a compromised Linux server. Indicators suggest the attacker used a web shell. Which THREE of the following are common persistence mechanisms that may be found on the system? (Select THREE.)

Select 3 answers
A.Adding an SSH public key to /root/.ssh/authorized_keys
B.Cron jobs added to /etc/crontab
C.Modification of the NTUSER.DAT registry hive
D.Prefetch file creation
E.A systemd service in /etc/systemd/system/
AnswersA, B, E

An attacker who gains root access can append a public key to /root/.ssh/authorized_keys, enabling passwordless SSH logins as root indefinitely. This is a low-effort, high-impact persistence mechanism because the legitimate key file already exists and may not trigger immediate alarms. Even if the web shell is patched, the SSH key provides a clean, encrypted backdoor that bypasses normal authentication. Removing it requires auditing the authorized_keys file for unexpected entries.

Why this answer

Option A is correct because appending an attacker-controlled public key to /root/.ssh/authorized_keys grants passwordless SSH access as root, a classic Linux persistence technique. Option B is correct because entries added to /etc/crontab (or /etc/cron.d, user crontabs) cause malicious commands or reverse shells to execute on a schedule, surviving reboots. Option E is correct because a malicious unit file placed in /etc/systemd/system/ and enabled with systemctl enable will start the attacker's payload automatically at boot.

Option C is incorrect because NTUSER.DAT is a Windows registry hive and does not exist on Linux. Option D is incorrect because Prefetch files are a Windows artifact created by the OS for performance, not a Linux persistence mechanism.

Exam trap

EC-Council often tests cross-platform knowledge by including Windows-specific artifacts (like NTUSER.DAT or Prefetch) in Linux-focused questions, hoping candidates overlook the operating system context and select them out of familiarity.

711
MCQmedium

During a forensic investigation of an Android device, the examiner uses ADB to extract data. Which command would create a full backup of the device's data partition, including app data and shared storage?

A.adb backup -f backup.ab -apk -shared -all
B.adb shell dd if=/dev/block/mmcblk0 of=/data/backup.img
C.adb pull /data/data/
D.adb restore backup.ab
AnswerA

The `adb backup -f backup.ab -apk -shared -all` command invokes Android's Backup Manager over ADB to create a non-root full logical backup, writing an Android Backup (AB) archive that contains installed APKs (-apk), shared/sdcard data (-shared), and all application data (-all). In forensic triage, this is the correct method to capture user-visible app data without altering the device's system partition, although it cannot retrieve protected app-private files from apps that disable backup or obtain deleted data. The resulting backup.ab can later be parsed with tools like Android Backup Extractor (abe) to reconstruct app content for analysis.

Why this answer

The `adb backup -f backup.ab -apk -shared -all` command creates a full Android backup that includes all apps and their data (via `-all`), includes APK files (via `-apk`), and includes shared storage (via `-shared`), outputting a single `.ab` file. This is the standard ADB method for non-rooted devices to capture a comprehensive logical backup of app data and shared storage.

Exam trap

The CHFI exam often tests the distinction between backup creation (`adb backup`) and restoration (`adb restore`), or between logical backups (ADB backup) and physical imaging (`dd`), leading candidates to confuse the purpose of each command.

How to eliminate wrong answers

Option B is wrong because `adb shell dd if=/dev/block/mmcblk0 of=/data/backup.img` attempts to create a raw block-level image of the entire device (mmcblk0), which requires root access and is not a standard ADB backup command; it also writes to a path that may not be writable without root. Option C is wrong because `adb pull /data/data/` only copies the app-specific data directory, missing shared storage and system data, and typically requires root access on modern Android devices due to permissions. Option D is wrong because `adb restore backup.ab` is used to restore a backup, not to create one, and thus does not extract data from the device.

712
MCQmedium

A forensic analyst is examining an SSD that may have had deleted files. The analyst is concerned about the TRIM command. What effect does TRIM have on forensic recovery of deleted files?

A.TRIM increases the chance of recovering deleted files
B.TRIM causes wear leveling that spreads data across blocks, aiding recovery
C.TRIM invalidates deleted data blocks, making them unreadable and unrecoverable
D.TRIM has no effect on forensic analysis
AnswerC

TRIM is an ATA command by which the operating system informs the SSD controller that specific logical block addresses are no longer in use. The controller marks those mappings as invalid, after which reads to those LBAs return zeros and the physical NAND pages are scheduled for erasure during garbage collection. This active invalidation means the original file data is not accessible through normal forensic acquisition tools, and often the cells are fully erased, leaving no recoverable remnants on the device.

Why this answer

The TRIM command allows the operating system to inform the SSD which data blocks are no longer in use. The SSD then internally marks those blocks as invalid and may immediately erase them or add them to its free pool for garbage collection. This process physically removes the data, making it unreadable and unrecoverable through standard forensic tools, which is why option C is correct.

Exam trap

The trap here is that candidates confuse TRIM with wear leveling or assume that deleted files on SSDs behave like those on HDDs, where data persists until overwritten, leading them to pick option B or D.

How to eliminate wrong answers

Option A is wrong because TRIM does not increase recovery chances; it actively destroys the data by instructing the SSD to erase the blocks. Option B is wrong because wear leveling is a separate process that distributes writes across NAND cells to extend drive life, not a mechanism that aids recovery; TRIM does not spread data for recovery purposes. Option D is wrong because TRIM has a profound effect on forensic analysis by making deleted files permanently unrecoverable from the SSD's user-accessible area.

713
MCQmedium

In a memory forensics investigation using Volatility, an analyst wants to see a list of processes that were active at the time of acquisition, including hidden processes. Which Volatility command should be used?

A.pslist
B.pstree
C.netscan
D.psscan
AnswerD

psscan bypasses the linked list entirely by scanning physical memory for EPROCESS pool tags (typically 'Pro' and 'Proc') using Volatility's pool scanner. This allows it to find hidden processes that have been unlinked from PsActiveProcessHead, as well as processes in less obvious states. It is the recommended plugin when checking for DKOM-based rootkits or when pslist/pstree results seem incomplete.

Why this answer

Psscan, because it scans the physical memory for _EPROCESS structures, allowing it to detect processes that are hidden from the standard linked list used by pslist. This makes psscan the appropriate command for identifying hidden or unlinked processes that were active at the time of acquisition.

Exam trap

The trap here is that candidates often confuse pslist (which lists only linked processes) with psscan (which finds hidden processes), mistakenly believing pslist can detect all active processes because it is the most commonly used command.

How to eliminate wrong answers

Option A is wrong because pslist enumerates processes by walking the doubly linked list of _EPROCESS structures, which can be manipulated by rootkits to hide processes, so it cannot detect hidden processes. Option B is wrong because pstree also relies on the same linked list as pslist and simply displays the parent-child relationship; it does not perform a pool scan to find hidden processes. Option C is wrong because netscan is used to display network connections (TCP/UDP endpoints) from memory, not to list active processes.

714
MCQeasy

Which of the following partition table types uses a protective MBR and a GPT header, and is recommended for disks larger than 2 TB?

A.MBR
B.Dynamic disk
C.GPT
D.APM (Apple Partition Map)
AnswerC

GPT (GUID Partition Table) is a modern partition table standard that includes a protective MBR at the first logical block; this MBR contains a single partition entry of type 0xEE that spans the entire disk to prevent legacy BIOS utilities from misinterpreting the disk as unpartitioned. This protective MBR enables GPT to support disks larger than 2 TiB while maintaining compatibility with older tools.

Why this answer

GPT (GUID Partition Table) is the correct answer because it uses a protective MBR at the first sector (LBA 0) to prevent legacy tools from misidentifying the disk as unformatted, followed by the GPT header at LBA 1. This structure is specifically designed to support disks larger than 2 TB by using 64-bit logical block addresses, overcoming the 2 TB limit of MBR’s 32-bit addressing.

Exam trap

Candidates often mistake Dynamic disk as a partition table type, but it is actually a logical volume manager that can sit on top of either MBR or GPT, so it does not inherently use a protective MBR or GPT header.

How to eliminate wrong answers

Option A is wrong because MBR (Master Boot Record) uses 32-bit logical block addressing, which limits the maximum addressable disk size to 2 TB (with 512-byte sectors), and it does not include a protective MBR or GPT header. Option B is wrong because Dynamic disk is a Windows volume management scheme that can use either MBR or GPT as the underlying partition table; it is not a partition table type itself and does not inherently use a protective MBR or GPT header. Option D is wrong because APM (Apple Partition Map) is a legacy partition scheme used by older PowerPC-based Macs, which does not include a protective MBR or GPT header and is not recommended for disks larger than 2 TB.

715
MCQmedium

During an iOS forensic analysis, an examiner recovers the Keychain data from a backup. Which type of information is commonly stored in the iOS Keychain and can be extracted during analysis?

A.Text message content and attachments
B.Call log timestamps and durations
C.Contact photos and thumbnails
D.Wi-Fi passwords and website login credentials
AnswerD

Wi-Fi passwords and website login credentials are exactly the kind of secrets the iOS Keychain is designed to protect, stored as generic passwords and internet passwords in encrypted keychain databases. Each Keychain item includes metadata such as the service name, account name, and access group, and is encrypted with a key hierarchy that ties to the device's passcode via the Secure Enclave. During forensic acquisition, an examiner can use tools to decrypt the keychain or extract keychain plists from a file system image, which is why these credentials are the correct item to associate with Keychain analysis.

Why this answer

The iOS Keychain is a secure, encrypted database designed to store sensitive user credentials and secrets. Wi-Fi passwords and website login credentials are explicitly stored in the Keychain to protect them from unauthorized access, making them recoverable during forensic analysis of a backup.

Exam trap

The CHFI exam often tests the misconception that the Keychain stores all app data or media, when in fact it is strictly limited to credentials, tokens, and secrets, while other data types reside in separate databases.

How to eliminate wrong answers

Option A is wrong because text message content and attachments are stored in the SMS/MMS SQLite database (sms.db) and the attachments directory, not in the Keychain. Option B is wrong because call log timestamps and durations are stored in the CallHistory.storedata SQLite database, not in the Keychain. Option C is wrong because contact photos and thumbnails are stored in the AddressBook framework's SQLite database (AddressBook.sqlitedb) and the filesystem, not in the Keychain.

716
MCQmedium

An Android device is seized as evidence. The screen is locked with a PIN. Which tool or method is MOST appropriate for acquiring a physical image of the device without bypassing the lock screen, assuming the device is rooted?

A.Boot into recovery mode and use ADB to dd the userdata partition
B.Use Cellebrite UFED with a lock screen bypass exploit
C.Remove the microSD card and image it separately
D.Perform an ADB backup to obtain app data only
AnswerA

Booting into recovery mode bypasses the Android OS and its lock screen, so ADB access does not require user authorization, screen unlock, or USB debugging approval. With a rooted device already granting elevated privileges, issuing dd against the /dev/block/.../userdata path performs a block-level physical acquisition of the entire internal userdata partition, including encrypted blobs or files, which is exactly what the question requires. This method is correct because it captures the full internal storage image without needing to unlock the screen or install any bypass, and it preserves deleted data blocks for forensic analysis.

Why this answer

Booting into recovery mode on a rooted Android device allows you to use ADB to execute the `dd` command, which can create a bit-for-bit physical image of the userdata partition without needing to bypass the lock screen. Since the device is rooted, you have the necessary privileges to read the raw block device, and recovery mode ensures the filesystem is not mounted, preventing data corruption during acquisition.

Exam trap

EC-Council often tests the distinction between physical and logical acquisition methods, and the trap here is that candidates may choose ADB backup (Option D) thinking it is a valid physical acquisition, when in fact it only captures a logical subset of data and cannot recover deleted or system-level artifacts.

How to eliminate wrong answers

Option B is wrong because Cellebrite UFED with a lock screen bypass exploit is designed to bypass the lock screen, which contradicts the question's requirement of not bypassing the lock screen; additionally, such exploits may not be available or reliable for all devices. Option C is wrong because removing the microSD card and imaging it separately only captures external storage, not the internal userdata partition where the majority of forensic evidence (e.g., app data, messages) resides, and it does not acquire a physical image of the device's internal storage. Option D is wrong because an ADB backup only extracts app data via Android's backup mechanism, which is a logical acquisition that does not capture deleted data, system files, or the full physical image of the userdata partition.

717
MCQeasy

A security analyst is reviewing Apache access logs and finds the entry: 192.168.1.100 - - [10/Mar/2025:08:12:34 +0000] "GET /search?q=test' OR '1'='1 HTTP/1.1" 200 532. Which attack does this log entry most likely indicate?

A.Cross-site scripting (XSS)
B.Remote file inclusion (RFI)
C.SQL injection (SQLi)
D.Path traversal
AnswerC

The presence of a lone single quote followed by OR '1'='1 is a classic SQL injection signature because it breaks out of the string literal and makes the WHERE clause always true, potentially returning every record or bypassing authentication. If the application concatenates this input directly into a SELECT or login query, the attacker controls query logic beyond the intended parameter. The exact syntax is meaningful only in the context of SQL parsing, making SQLi the correct classification.

Why this answer

The presence of ' OR '1'='1 in the query string is a classic SQL injection attempt, designed to bypass authentication or extract data.

718
MCQeasy

During a forensic investigation, an analyst examines a hard disk and notices that the partition table uses a 64-bit scheme with a maximum of 128 partitions. Which partition table type is in use?

A.MBR
B.LDM
C.APM
D.GPT
AnswerD

The GUID Partition Table (GPT) is the correct partition table scheme, as it uses 64-bit logical block addressing and, per the UEFI specification, a default of 128 partition entries in the 16 KB partition-entry area (each entry is 128 bytes). This allows GPT to support up to 128 primary partitions without the need for extended partitions. Additionally, GPT stores a protective MBR at LBA 0 for compatibility, and duplicates both the header and partition table at the end of the disk for redundancy, which is exactly the 64-bit structure the question describes.

Why this answer

GPT (GUID Partition Table) uses a 64-bit scheme for logical block addressing and supports up to 128 partitions by default in its standard header layout. This matches the description of a 64-bit partition table with a maximum of 128 partitions, making D the correct answer.

Exam trap

The trap here is that candidates confuse LDM (a dynamic disk volume manager) with a partition table type, or mistakenly think MBR supports more than 4 primary partitions via extended partitions, but the question explicitly specifies a 64-bit scheme with 128 partitions, which only GPT satisfies.

How to eliminate wrong answers

Option A is wrong because MBR (Master Boot Record) uses a 32-bit scheme and supports a maximum of 4 primary partitions (or 3 primary plus an extended partition), not 128 partitions. Option B is wrong because LDM (Logical Disk Manager) is a dynamic disk management system used by Windows, not a partition table type; it relies on MBR or GPT underneath and does not define a 64-bit partition scheme with 128 partitions. Option C is wrong because APM (Apple Partition Map) uses a 32-bit scheme and supports up to 15 partitions, not 128, and was used in older Mac systems before Intel transition.

719
MCQeasy

Which tool is specifically designed for performing physical extraction of iOS devices and is widely used by law enforcement for bypassing passcode restrictions on modern iPhones?

A.Cellebrite UFED
B.GrayKey
C.Magnet AXIOM
D.Oxygen Forensic Detective
AnswerB

GrayKey is a purpose-built hardware/software appliance engineered exclusively for iOS forensic physical extraction and passcode bypass. It connects to the device's Lightning port and performs automated brute-force attacks against the passcode, including techniques that leverage the device's secure enclave vulnerabilities to allow full filesystem acquisition. This focused capability, combined with high success rates on passcode-protected iPhones, is precisely why law enforcement agencies deploy GrayKey rather than general-purpose mobile tools for physical extraction.

Why this answer

GrayKey is specifically designed for physical extraction of iOS devices, leveraging advanced techniques to bypass passcode restrictions on modern iPhones, including those with Secure Enclave and full-disk encryption. It is widely adopted by law enforcement for its ability to perform brute-force attacks on the device's passcode without triggering the auto-wipe feature, making it the correct answer.

Exam trap

The CHFI exam often tests the distinction between general-purpose forensic suites (like Cellebrite UFED or Magnet AXIOM) and specialized hardware tools (like GrayKey) that are purpose-built for iOS passcode bypass, leading candidates to choose a familiar name like Cellebrite instead of the correct specialized tool.

How to eliminate wrong answers

Option A is wrong because Cellebrite UFED is a versatile forensic tool that supports both physical and logical extraction across many mobile platforms, but it is not specifically designed for iOS physical extraction and does not specialize in bypassing passcode restrictions on modern iPhones as GrayKey does. Option C is wrong because Magnet AXIOM is a comprehensive digital forensic platform for analyzing data from computers, mobile devices, and cloud sources, but it relies on third-party tools for physical extraction and does not directly perform hardware-level passcode bypass on iOS devices. Option D is wrong because Oxygen Forensic Detective is a mobile forensic tool that supports logical and file system extractions, but it lacks the specialized hardware and software capabilities for brute-forcing iOS passcodes on modern iPhones with Secure Enclave protection.

720
MCQmedium

Based on the exhibit, what is the most likely indication of malware persistence?

A.services.exe PID 4321 is a known malware process
B.Windows Defender service is stopped, allowing malware to run
C.services.exe is listening on TCP port 4444, indicating possible code injection
D.svchost.exe hosting BFE and MpsSvc indicates a firewall bypass
AnswerC

services.exe is the Windows Service Control Manager and should never expose listening TCP endpoints on its own; its normal IPC is via a named pipe used by subprocesses, not a network socket. Port 4444 is a well-known default payload port for Metasploit's meterpreter and is frequently used by backdoors, so an established listening socket on services.exe is a classic sign of injected shellcode. Because services.exe runs as SYSTEM, attackers often inject code into it to steal its high privileges and evade detection.

Why this answer

Services.exe (the Service Control Manager) should not normally listen on any TCP port. When it is found listening on TCP port 4444—a port commonly associated with Metasploit and reverse shells—it strongly indicates that malware has injected code into the legitimate services.exe process, hijacking it to establish a persistent backdoor listener. This is a classic sign of process hollowing or reflective DLL injection, where the malware hides its network activity under a trusted system process.

Exam trap

EC-Council often tests the misconception that any process named 'services.exe' or 'svchost.exe' is automatically malicious, when in fact the key indicator is abnormal behavior (like listening on a non-standard port) that deviates from the process's legitimate function.

How to eliminate wrong answers

Option A is wrong because services.exe is a legitimate Windows system process (the Service Control Manager), and PID 4321 alone does not indicate malware; malware often uses process names like svchost.exe or services.exe to blend in, so the PID itself is not a known malware identifier. Option B is wrong because while a stopped Windows Defender service could allow malware to run, the exhibit shows no evidence that Defender is stopped; the question asks for the most likely indication of persistence based on the exhibit, and a stopped service is a condition, not a direct indicator of persistence. Option D is wrong because svchost.exe hosting BFE (Base Filtering Engine) and MpsSvc (Windows Firewall) is normal behavior; these services are part of the Windows Firewall and do not indicate a bypass—in fact, they are the firewall itself, and their presence in svchost.exe is expected.

721
MCQeasy

Which tool is commonly used in timeline analysis for digital forensics to parse various artifacts and create a super timeline?

A.Volatility
B.Wireshark
C.Sleuth Kit
D.log2timeline / Plaso
AnswerD

log2timeline (now evolved into Plaso) is the definitive open-source tool for digital forensics timeline analysis. It recursively parses a disk image or collection of files, using numerous parsers to extract timestamps from file system metadata, operating system logs, application traces, browser history, registry keys, and many other artifact types. All parsed timestamps are normalized into a unified SQLite database, enabling the investigator to generate a 'super timeline' that correlates events across multiple sources for temporal reconstruction. This comprehensive multi-source approach is exactly what timeline analysis demands, making it the correct answer.

Why this answer

log2timeline (now part of the Plaso framework) is specifically designed to parse a wide variety of digital forensic artifacts—such as Windows Event Logs, Prefetch files, registry hives, and browser history—and aggregate them into a single, unified super timeline. This super timeline allows investigators to correlate events across different data sources and identify sequences of activity with precise timestamps, which is essential for timeline analysis in OS and network forensics.

Exam trap

EC-Council often tests the distinction between low-level filesystem tools (like Sleuth Kit) and high-level artifact parsing tools (like log2timeline/Plaso), leading candidates to mistakenly choose Sleuth Kit because they associate 'timeline analysis' with file timestamps (MAC times) rather than the comprehensive super timeline that aggregates multiple artifact types.

How to eliminate wrong answers

Option A is wrong because Volatility is a memory forensics framework used for analyzing RAM dumps (e.g., processes, network connections, registry hives in memory), not for parsing filesystem artifacts to build a super timeline. Option B is wrong because Wireshark is a network packet analyzer that captures and inspects live or recorded network traffic (e.g., TCP/IP packets), not a tool for parsing local OS artifacts or generating timelines. Option C is wrong because Sleuth Kit (TSK) provides low-level filesystem analysis tools (e.g., fls, icat, mmls) and can extract file metadata and recover deleted files, but it does not natively parse high-level application artifacts or produce a unified super timeline; that requires additional scripting or integration with tools like log2timeline.

722
MCQhard

A forensic analyst is investigating a Docker container that was used to launch a network attack. The container has been stopped but not removed. Which action should the analyst take FIRST to preserve volatile evidence?

A.Restart the container and use 'docker exec' to collect evidence
B.Use 'docker inspect' to view container metadata only
C.Use 'docker save' to export the container as a tar file
D.Use 'docker commit' to create an image of the container
AnswerD

'docker commit' captures the container's current writable layer into a new image, preserving the filesystem state at a defined moment without modifying the original container's content. By default, Docker pauses the container during the commit, giving a point-in-time consistent snapshot that can be exported with 'docker save' and analyzed in a sandbox. This method is the best option listed because it preserves the container's filesystem evidence in a non-destructive way, although it does not capture live memory or active network connections.

Why this answer

Preserving the container's file system and logs is key. 'docker commit' creates an image from the container's current state. 'docker export' exports the filesystem as a tar archive. 'docker logs' retrieves logs. 'docker inspect' shows metadata. The container is stopped, so 'docker exec' won't work without starting it, which alters state. 'docker save' saves images, not containers. The best first step is to create an image or export the filesystem.

723
MCQhard

An investigator acquires an SSD from a laptop that has been turned off for 24 hours. The suspect recently deleted several incriminating files. Using a forensic imager, the investigator creates a bit-for-bit copy. However, when analyzing the image, the deleted files' data appears to be zeros. What is the MOST likely cause?

A.The files were stored in the paging file, which is volatile
B.The SSD controller performed wear leveling, moving data to unallocated blocks
C.The imaging tool incorrectly interpreted the data due to encryption
D.The TRIM command was issued, causing the SSD to erase the freed blocks
AnswerD

SSDs with TRIM enabled erase freed blocks at the controller level, so deleted file data is zeroed rather than left recoverable. After 24 hours powered off, garbage collection has completed, meaning the bit-for-bit image captures only zeros where the incriminating files once resided.

Why this answer

The TRIM command is an ATA command that allows an operating system to inform an SSD which data blocks are no longer in use and can be wiped internally. When the suspect deleted the files, the OS likely issued a TRIM command to the SSD, causing the controller to erase the freed physical blocks. Since the laptop was off for 24 hours, the SSD had ample time to complete the garbage collection process, resulting in the deleted files' data appearing as zeros in the forensic image.

Exam trap

The EC-CHFI exam often tests the misconception that wear leveling (Option B) causes data loss, but wear leveling only relocates data to balance write cycles; it does not erase the original data—TRIM and garbage collection are the mechanisms that actively zero out freed blocks on SSDs.

How to eliminate wrong answers

Option A is wrong because the paging file (pagefile.sys) is stored on the SSD, not in volatile memory, and while it can contain remnants of data, it is not inherently volatile; the issue here is that the deleted files' data is zeros, not that it was never written to disk. Option B is wrong because wear leveling moves data to different physical blocks to extend the SSD's lifespan, but it does not erase the original data; the data would still exist in the moved location unless explicitly erased by TRIM or garbage collection. Option C is wrong because encryption would make the data appear as ciphertext, not zeros; the imaging tool would still capture the encrypted data, and the question states the data appears as zeros, not as unreadable encrypted content.

724
MCQmedium

An organization uses Azure. A security analyst needs to investigate a suspicious login event. Which Azure log contains details about user sign-ins, including IP address, timestamp, and success/failure status?

A.Azure Monitor Metrics
B.Azure AD Sign-in logs
C.Azure Activity Logs
D.Azure Security Center alerts
AnswerB

Azure AD Sign-in logs are the canonical record of user authentication events in Azure Active Directory. Each entry contains the user principal name, IP address, client application, timestamp, location, conditional access policies applied, and the sign-in status (success, failure, or interrupted). These logs cover interactive and non-interactive sign-ins and are accessible via the Azure portal, Microsoft Graph API, or by streaming to a SIEM. They provide the granular evidence needed to trace exactly when, from where, and how an account was accessed.

Why this answer

Azure AD Sign-in logs (Option B) are the correct source because they specifically capture user authentication events, including the IP address of the client, the exact timestamp of the sign-in attempt, and the success or failure status (e.g., 'Success', 'Failure', 'Interrupted'). This log is part of Azure Active Directory's monitoring suite and is designed for identity-related forensic investigations, unlike infrastructure or resource-level logs.

Exam trap

The trap here is that candidates often confuse Azure Activity Logs (control-plane) with Azure AD Sign-in logs (identity-plane), mistakenly thinking that resource-level logs capture user authentication events.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Metrics stores numerical performance data (e.g., CPU usage, request counts) and does not contain user sign-in details like IP addresses or success/failure status. Option C is wrong because Azure Activity Logs record control-plane operations on Azure resources (e.g., creating a VM, modifying a network security group) and do not include user authentication events. Option D is wrong because Azure Security Center alerts provide security threat notifications (e.g., detected malware, suspicious network activity) but do not serve as a raw log of sign-in events with IP and timestamp details.

725
MCQmedium

A security analyst detects a sudden spike in failed logon events with Event ID 4625 on a Windows domain controller. The source IP addresses are random and from various external subnets. Which type of attack is MOST likely occurring?

A.Pass‑the‑hash attack
B.Kerberos ticket forgery (Golden Ticket)
C.Insider threat with compromised credentials
D.Brute‑force attack
AnswerD

Each 4625 event explicitly records an authentication failure with logon type, source IP, and username, so a sudden spike from many different source addresses targeting the same accounts is the hallmark of a distributed password-guessing attack. The attacker submits candidate passwords over RDP, SMB, or VPN until one succeeds, which is exactly why the failed-logon count spikes before eventual access. The varied external IPs and volume distinguish this from credential misuse or ticket-forging attacks.

Why this answer

Event ID 4625 indicates a failed logon attempt. A sudden spike from random, external source IPs is characteristic of a brute-force attack, where an attacker systematically tries many username/password combinations against the domain controller. This pattern does not match the stealthier or more targeted nature of the other attack types.

Exam trap

EC-Council often tests the distinction between a brute-force attack (many failed logons from varied IPs) and a pass-the-hash attack (which uses a valid hash and does not generate failed logon events), leading candidates to confuse the two when they see Event ID 4625.

How to eliminate wrong answers

Option A is wrong because a pass-the-hash attack uses captured NTLM hashes to authenticate without needing the plaintext password, and it typically originates from a compromised internal host, not from random external IPs. Option B is wrong because Kerberos ticket forgery (Golden Ticket) involves forging a Kerberos TGT using the KRBTGT hash, which does not generate a spike in failed logon events (Event ID 4625) from external sources. Option C is wrong because an insider threat with compromised credentials would likely show successful logons or a targeted pattern, not a high volume of failed attempts from many random external subnets.

726
MCQmedium

During a forensic examination, the analyst encounters a file that is not automatically readable by forensic tools. The analyst suspects the file contains contraband images. Which of the following is the BEST approach to handle this evidence in accordance with the rules of evidence?

A.Delete the file to prevent accidental distribution.
B.Create a forensic copy and use a write blocker to access the copy with appropriate software.
C.Ignore the file because it cannot be easily read.
D.Open the file using the original application on the suspect's computer.
AnswerB

Create a forensic copy by using a hardware write blocker between the original media and the forensic workstation, then acquire a bit-for-bit image (e.g., in E01 or raw format) with a tool like FTK Imager or dd. Verify the integrity of both the original and the copy by recording cryptographic hashes (SHA-256 or MD5) before and after acquisition, ensuring they match. Only after that should you access the copy with appropriate forensic software (e.g., EnCase, Autopsy, X-Ways) to parse the file, leaving the original media untouched and forensically pristine.

Why this answer

Forensic best practices require creating a bit-for-bit forensic copy of the original evidence and using a write blocker to prevent any alteration to the original. The analyst can then use specialized software (e.g., a hex editor, file carving tools, or a viewer that supports the file's raw format) to access the copy and extract contraband images without violating the integrity of the evidence, which is essential for admissibility under rules of evidence such as the Federal Rules of Evidence (FRE) 901.

Exam trap

EC-Council CHFI often tests the misconception that you can safely open a file on the suspect's computer if you are careful, but the trap is that any direct access to the original evidence violates the forensic principle of non-alteration and can invalidate the entire investigation.

How to eliminate wrong answers

Option A is wrong because deleting the file destroys potential evidence and violates the principle of evidence preservation, which could lead to spoliation sanctions and inadmissibility. Option C is wrong because ignoring the file is a failure to investigate; forensic tools may not automatically read the file due to encryption, corruption, or an unknown format, but the analyst must attempt to recover or interpret it using alternative methods (e.g., file carving, decryption, or manual hex analysis). Option D is wrong because opening the file with the original application on the suspect's computer risks modifying the file's metadata, timestamps, or content, and may trigger anti-forensic mechanisms, thereby compromising the chain of custody and evidence integrity.

727
MCQmedium

A security analyst reviews Windows Security event logs and finds Event ID 4625 with Logon Type 10. What does this indicate?

A.Failed remote interactive logon (e.g., RDP)
B.Failed service logon attempt
C.Successful network logon
D.Successful local logon
AnswerA

Event ID 4625 is the Windows security event for failed authentication, and Logon Type 10 (RemoteInteractive) is assigned specifically when the attempt occurs via a remote interactive protocol such as RDP. A 4625 event with Logon Type 10 therefore precisely indicates a failed remote interactive logon, commonly seen in RDP brute-force attacks. The combination of the failure code (4625) and the remote interactive logon type (10) leaves no ambiguity about the attempt's outcome and origin.

Why this answer

Event ID 4625 with Logon Type 10 specifically indicates a failed Remote Interactive logon attempt, which is characteristic of Remote Desktop Protocol (RDP) connections. Logon Type 10 is defined in Windows security auditing as 'RemoteInteractive' and is triggered when an authentication attempt fails over a remote desktop session, typically using RDP (port 3389). This event is critical for detecting brute-force or unauthorized RDP access attempts.

Exam trap

The trap here is that candidates often confuse Logon Type 10 with Logon Type 2 (interactive) or Logon Type 3 (network), failing to recognize that Type 10 is specifically for remote interactive (RDP) logons, and that Event ID 4625 always indicates failure, not success.

How to eliminate wrong answers

Option B is wrong because a failed service logon attempt is represented by Logon Type 5, not Logon Type 10, and involves scheduled tasks or services running under a specific account. Option C is wrong because Event ID 4625 is explicitly a failure event (the '5' in 4625 denotes failure), whereas successful network logons are logged as Event ID 4624 with Logon Type 3 (network logon). Option D is wrong because a successful local logon is Event ID 4624 with Logon Type 2 (interactive), not a failure event, and Logon Type 10 is specifically for remote interactive sessions, not local console logons.

728
MCQhard

During a Mac forensic investigation, you examine the unified log for process execution around the time of an incident. Which command-line tool is used to query the macOS unified log?

A.log
B.journalctl
C.dmesg
D.syslog
AnswerA

The unified log is queried with the log command (e.g., log show --last 1h --predicate 'process == "Finder"' --info --debug). It reads the structured, privacy-redacted binary store under /var/db/diagnostics, applying predicates to return timestamps, process metadata, and persistence flags. In forensic triage you typically run log collect to aggregate entries while preserving causality and before volatile data is lost.

Why this answer

The `log` command is the native macOS tool for querying the unified log system, which consolidates kernel, driver, and application logs into a single, high-performance data store. It supports filtering by process, time range, and subsystem, making it essential for forensic timeline reconstruction on macOS. Unlike traditional syslog, the unified log uses a binary format that only `log` can efficiently parse.

Exam trap

EC-Council often tests the distinction between Linux and macOS logging tools, expecting candidates to know that `journalctl` is Linux-specific and that macOS uses its own `log` command, not legacy syslog utilities.

How to eliminate wrong answers

Option B (journalctl) is wrong because it is the query tool for systemd's journal on Linux, not for macOS's unified log. Option C (dmesg) is wrong because it prints kernel ring buffer messages, which is a legacy Linux/Unix utility and does not access the macOS unified log store. Option D (syslog) is wrong because it refers to the legacy syslog protocol and daemon (e.g., syslogd), which macOS replaced with the unified log system in OS X Yosemite (10.10); the `syslog` command is deprecated and cannot query the modern binary log store.

729
MCQeasy

Which cloud forensic challenge refers to the inability to physically access the storage media where data resides?

A.Data jurisdiction
B.Lack of physical access
C.Multi-tenancy
D.Volatility of evidence
AnswerB

Lack of physical access means investigators cannot directly seize or image the underlying magnetic media or solid-state drives that store cloud data, because those devices reside in provider-managed data centers. This forces reliance on logical acquisition through provider APIs or legal processes, making it difficult to verify the integrity and chain of custody of the evidence. It is the core forensic challenge that distinguishes cloud investigations from traditional on-premises computer forensics.

Why this answer

Cloud forensics often involves data stored on remote servers managed by a cloud service provider (CSP). Forensic investigators cannot physically seize or access the hard drives or SSDs due to the CSP's infrastructure and security policies, making physical access impossible. This lack of physical access is a fundamental challenge that distinguishes cloud forensics from traditional digital forensics, where the media can be physically acquired and imaged.

Exam trap

EC-Council CHFI exam often tests the distinction between 'lack of physical access' and 'multi-tenancy' by presenting multi-tenancy as a plausible answer, but the key is that multi-tenancy is about resource sharing, not the inability to physically touch the storage media.

How to eliminate wrong answers

Option A is wrong because data jurisdiction refers to legal and regulatory issues regarding where data is stored geographically, not the physical inability to access storage media. Option C is wrong because multi-tenancy describes the sharing of physical resources among multiple tenants, which introduces data separation and privacy concerns, but it does not directly address the inability to physically access the storage media. Option D is wrong because volatility of evidence concerns the ephemeral nature of data in memory or temporary storage that can be lost quickly, not the physical inaccessibility of persistent storage media.

730
MCQmedium

In cloud forensics, which AWS service provides a centralized log of API calls made by users and services, often used to investigate unauthorized access or configuration changes?

A.AWS CloudWatch
B.AWS CloudTrail
C.AWS Config
D.AWS VPC Flow Logs
AnswerB

CloudTrail is the correct AWS service because it continuously records API activity across your account, capturing each call's identity, source IP, timestamp, request parameters, and response elements. It delivers immutable event history to S3 for long-term retention and enables centralized, cross-region and cross-account trails, making it the primary evidence source for reconstructing attacker actions during forensic investigations.

Why this answer

AWS CloudTrail records all API calls for governance, compliance, and operational auditing, making it essential for forensic investigations in AWS.

731
MCQmedium

A security analyst receives an image of a hard drive with a GPT partition table. Which of the following is a key difference between GPT and MBR that the analyst should consider?

A.GPT stores partition information only in the first sector of the disk
B.GPT uses a protective MBR to prevent legacy tools from misinterpreting the disk
C.GPT supports up to 4 primary partitions; MBR supports up to 128
D.MBR uses a GUID partition table; GPT uses a simple table at sector 0
AnswerB

GPT deliberately places a legacy MBR at LBA 0 containing a single protective partition of type 0xEE that claims the whole disk. This makes traditional MBR-only utilities recognize the disk as already partitioned and belonging to an unknown OS, preventing them from misinterpreting the GPT layout and overwriting data while still allowing UEFI firmware to locate the real GPT header.

Why this answer

GPT uses a protective MBR (Master Boot Record) at sector 0 of the disk to maintain backward compatibility with legacy BIOS-based tools that expect an MBR. This protective MBR contains a single partition entry of type 0xEE that covers the entire disk (or up to 2 TiB), preventing older utilities from misinterpreting the GPT disk as unformatted or overwriting GPT structures. This is a key architectural difference from MBR, which has no such protective mechanism.

Exam trap

The trap here is that candidates often confuse the protective MBR with a regular MBR partition table, thinking GPT has no MBR at all, or they mistakenly believe GPT stores all partition data only in the first sector, when in fact the protective MBR is a distinct compatibility layer that does not contain the actual GPT partition entries.

How to eliminate wrong answers

Option A is wrong because GPT stores partition information in multiple locations: the primary GPT header and partition entries at the beginning of the disk (LBA 1–33) and a secondary (backup) copy at the end of the disk, not only in the first sector. Option C is wrong because it reverses the limits: MBR supports up to 4 primary partitions (or 3 primary + 1 extended), while GPT supports up to 128 primary partitions by default (and can be extended). Option D is wrong because MBR uses a simple partition table at sector 0 (LBA 0) with a 64-byte partition table, while GPT uses a GUID Partition Table with a primary header at LBA 1 and partition entries starting at LBA 2, not a simple table at sector 0.

732
MCQmedium

During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?

A.AWS CloudTrail
B.Amazon S3 server access logs
C.AWS Config
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the primary forensic source because it records management events in the S3 control plane, including the DeleteBucket API call that removes a bucket. Each event captures the calling user's IAM identity or federated principal, source IP address, event time, and request parameters, enabling attribution. CloudTrail is enabled by default for management events, preserving this evidence without pre-provisioning.

Why this answer

AWS CloudTrail records API calls made to AWS services, including S3 bucket deletion, along with the identity of the caller.

733
MCQhard

An analyst reviews proxy logs and sees repeated requests to a known malicious domain from multiple internal hosts, each using a different User-Agent string. The requests are all GET requests for /images/icon.png. What technique is most likely being used to evade detection?

A.User-Agent randomization
B.HTTPS tunneling
C.IP spoofing
D.Domain generation algorithm (DGA)
AnswerA

Repeated requests containing randomized User-Agent strings strongly indicate the client is deliberately changing that header on every request. User-Agent randomization is a standard anti-detection technique because unmodified command-line tools with absent or malformed User-Agents are easily filtered by security appliances, while frequent switching between browser-like values makes traffic appear to come from diverse legitimate clients. In proxy logs, varied User-Agents from the same source IP defeat naive signature matching, but the high rotation rate itself remains a suspicious behavioral pattern.

Why this answer

The repeated GET requests for the same resource (/images/icon.png) from multiple internal hosts, each with a different User-Agent string, is a classic indicator of User-Agent randomization. This technique is used by malware to evade signature-based detection that relies on static User-Agent values, making the traffic appear to originate from diverse browsers or devices.

Exam trap

EC-Council often tests the distinction between techniques that modify request headers (User-Agent randomization) versus those that change the destination (DGA) or transport (HTTPS tunneling), so candidates may confuse User-Agent randomization with DGA because both are used for evasion.

How to eliminate wrong answers

Option B (HTTPS tunneling) is wrong because the logs show plain HTTP GET requests, not encrypted tunnel traffic; HTTPS tunneling would obscure the request content, not randomize User-Agent headers. Option C (IP spoofing) is wrong because IP spoofing would forge source IP addresses, but the logs show requests from multiple internal hosts (real IPs), and spoofed IPs would not receive responses for TCP-based HTTP. Option D (Domain generation algorithm (DGA)) is wrong because DGA is used to generate new domain names to evade domain blocklists, not to randomize User-Agent strings; the requests here target a single known malicious domain.

734
Multi-Selectmedium

Which TWO pieces of information can be obtained from an email's Received headers to help trace the email's origin? (Select TWO)

Select 2 answers
A.The DKIM signature hash
B.The sender's email client version
C.The IP address of the originating mail server
D.The subject line of the email
E.The timestamp when the email was processed by each server
AnswersC, E

The first Received header in an email contains the originating IP address of the server, or sometimes the actual client, that connected to the first hop MTA. For example, a trace line like 'Received: from [192.0.2.15] (unknown [192.0.2.15])' exposes the source IP as observed by the receiving server. This IP is fundamental to source attribution because it identifies the initial relay point in the message's path, even if the envelope sender is forged.

Why this answer

Option C is correct because Received headers record the connecting host's IP address (typically in the form 'Received: from mail.example.com ([192.0.2.1]) by ...'), which lets an investigator identify the originating mail server and trace the message's path back toward its source. Option E is correct because each Received header includes a date/time stamp showing when that hop processed the message, allowing analysts to reconstruct the chronological relay chain and spot delays or anomalies. The unmarked options do not belong: the DKIM signature hash (A) appears in the DKIM-Signature header, not Received; the sender's email client version (B) is not a standard Received field (it may appear in User-Agent or X-Mailer headers); and the subject line (D) is carried in the Subject header, which is unrelated to routing information.

Exam trap

The EC-CHFI exam often tests the misconception that the DKIM signature hash or subject line is part of the Received headers, when in fact Received headers only contain routing information (IPs, hostnames, timestamps) and not message content or cryptographic signatures.

735
MCQhard

A forensic analyst is reviewing the syslog from a compromised Linux server. Based on the exhibit, what does the 'orphan inode deleted' message indicate?

A.A hidden file was permanently removed from the filesystem.
B.A file was deleted while still open, and the filesystem has cleaned up the orphan inode.
C.A rootkit has attempted to hide files by marking them as orphan inodes.
D.A critical system file has been deleted, and the filesystem is warning the administrator.
AnswerB

When a file is unlinked but a process still holds its file descriptor, the inode remains allocated until the descriptor closes, resulting in an orphan inode. On a journaling filesystem such as ext4, that inode is recorded in the orphan list during the transaction, and after an unclean shutdown or during mount, the filesystem deletes it to reclaim space and logs 'orphan inode' messages. This is expected lifecycle behavior, not a sign of an attack or corruption.

Why this answer

The 'orphan inode deleted' message in syslog indicates that a file was deleted while it was still open by a process. The kernel's inode cleanup mechanism (part of the VFS layer) detected the orphaned inode—an inode with no directory entry but still referenced by an open file descriptor—and removed it after the last file descriptor was closed. This is standard behavior in Linux filesystems (e.g., ext4) and is not indicative of hidden files, rootkits, or critical system file alerts.

Exam trap

EC-Council often tests the misconception that 'orphan inode deleted' is a security alert or sign of malicious activity, when in fact it is a normal filesystem housekeeping message that occurs whenever a file is deleted while still open by a process.

How to eliminate wrong answers

Option A is wrong because 'orphan inode deleted' does not imply a hidden file; hidden files (dot files) are simply files with names starting with a period and are not related to orphan inodes. Option C is wrong because rootkits may hide files by manipulating directory entries or using kernel modules, but they do not mark files as orphan inodes—orphan inodes are a natural consequence of deleting an open file, not a hiding technique. Option D is wrong because the message is a routine informational log from the filesystem cleanup process, not a warning about critical system file deletion; it does not indicate administrator action is required.

736
MCQeasy

Which of the following email authentication protocols uses a digital signature to verify the sender's domain and that the email has not been tampered with?

A.DMARC
B.DKIM
C.SPF
D.STARTTLS
AnswerB

DKIM (DomainKeys Identified Mail) is the protocol that adds a digital signature to email headers, specifically a DKIM-Signature header containing a base64-encoded signature. The signing domain uses its private key to sign selected header fields and the message body, while the receiving MTA retrieves the public key via a TXT record in DNS (e.g., selector._domainkey.example.com) and verifies the signature. This cryptographically ties the message to the domain and ensures the signed content was not altered in transit.

Why this answer

DKIM (DomainKeys Identified Mail) is the correct answer because it uses a digital signature (an encrypted hash) added to the email header, which is verified against a public key published in the sender's DNS TXT record. This cryptographic process confirms that the email originated from the claimed domain and that the message body and key headers have not been altered in transit, ensuring integrity and authenticity.

Exam trap

A common trap in the EC-CHFI exam is that candidates confuse STARTTLS's transport-layer encryption with message-level authentication, leading them to pick D instead of the correct digital signature protocol.

How to eliminate wrong answers

Option A (DMARC) is wrong because DMARC is a policy framework that uses SPF and DKIM results to instruct receivers on how to handle unauthenticated mail (e.g., quarantine or reject); it does not itself create or verify digital signatures. Option C (SPF) is wrong because SPF only checks the envelope sender (Return-Path) against a list of authorized IP addresses in DNS; it provides no cryptographic integrity or tamper detection. Option D (STARTTLS) is wrong because STARTTLS is a protocol command (defined in RFC 3207) that upgrades an existing plaintext SMTP connection to an encrypted TLS session; it protects the channel but does not authenticate the sender's domain or verify message integrity after delivery.

737
MCQmedium

Which Azure log source should an investigator query to identify who deleted a virtual machine and when?

A.Azure Activity Log
B.Azure Active Directory sign-in logs
C.Azure Diagnostic Settings for the VM
D.Network Security Group flow logs
AnswerA

Azure Activity Log records control-plane operations on subscriptions, including the identity that issued a virtual machine deletion and its timestamp. It satisfies the requirement to attribute the deletion to a specific principal, unlike data-plane or guest OS logs, which capture runtime events rather than management actions.

Why this answer

The Azure Activity Log (formerly known as Audit Logs) is the subscription-level log that records all control-plane operations on Azure resources, including virtual machine creation, deletion, and modification. When a VM is deleted, the Activity Log captures the operation name (e.g., 'Microsoft.Compute/virtualMachines/delete'), the caller's identity (user or service principal), the timestamp, and the status of the operation. This makes it the authoritative source for answering 'who deleted a VM and when'.

Exam trap

Candidates often confuse authentication logs (such as sign-in logs) with resource operation logs (such as activity logs). Authentication logs only show login events, not the actions performed after login. To determine who deleted a VM, you need the activity log that records control-plane operations.

How to eliminate wrong answers

Option B is wrong because Azure AD sign-in logs track authentication events (user logins, MFA challenges, token issuance) but do not record resource-level operations like VM deletion; they are identity-focused, not resource-focused. Option C is wrong because Azure Diagnostic Settings for a VM collect guest OS-level logs (e.g., event logs, performance counters, IIS logs) and are not aware of control-plane operations such as VM deletion, which occur at the Azure Resource Manager layer. Option D is wrong because Network Security Group flow logs capture IP traffic flows (source/destination IP, port, protocol) through NSGs and are used for network forensics, not for tracking who performed a resource management action like deleting a VM.

738
MCQhard

A forensic analyst is examining a RAID 5 array consisting of three disks. One disk has failed and has been replaced. The array is rebuilt automatically. However, the analyst needs to recover deleted files that existed before the rebuild. What is the MOST significant challenge in this scenario?

A.File carving techniques do not work on RAID volumes
B.The rebuild process may overwrite data in slack space and previously unallocated clusters
C.The file system becomes corrupted after rebuild
D.The RAID controller encrypts data, preventing direct disk access
AnswerB

Rebuilding RAID 5 writes new parity and data, overwriting free space and slack.

Why this answer

When a RAID 5 array with a failed disk is rebuilt, the controller reconstructs data using parity information and writes it to the replacement disk. This rebuild process writes to all previously unallocated clusters and slack space across the array, potentially overwriting the very data the analyst hopes to recover. Deleted files that existed before the rebuild are at high risk of being overwritten during this automatic reconstruction, making recovery extremely difficult or impossible.

Exam trap

The trap here is that candidates may think the rebuild only affects the failed disk's data, but in reality, the rebuild process writes to all disks in the array, overwriting unallocated space and slack space across the entire volume.

How to eliminate wrong answers

Option A is wrong because file carving techniques can work on RAID volumes; they search for file signatures in raw data and are not inherently blocked by RAID structures, though they may need to account for striping. Option C is wrong because a properly executed RAID 5 rebuild does not corrupt the file system; the array remains logically consistent after reconstruction, though data in previously unallocated areas may be lost. Option D is wrong because RAID controllers do not encrypt data by default; encryption is a separate feature (e.g., self-encrypting drives or software encryption) and is not an inherent property of RAID 5.

739
MCQhard

Refer to the exhibit. A database administrator finds the above error log entries when attempting to start the MySQL service. The server was working fine yesterday. What is the most likely cause of this issue?

A.The MySQL user does not have write permissions to the data directory.
B.The binary log is full and cannot be rotated.
C.The server ran out of memory due to high innodb_buffer_pool_size.
D.The InnoDB system tablespace file (ibdata1) is corrupted.
AnswerD

The InnoDB system tablespace file (ibdata1) holds the data dictionary, rollback segments, and undo tablespaces; its first page contains a header that InnoDB validates at startup. If that header or any critical internal page is corrupted, InnoDB cannot initialize its storage engine and aborts with errors such as 'Database page corruption' or 'Cannot open datafile'. This matches the administrator's exhibit, making corruption of ibdata1 the correct explanation; recovery requires restoring the tablespace from backup or rebuilding it with new setup.

Why this answer

The error log entries indicate that InnoDB is unable to open or read the system tablespace file (ibdata1), which is the core file storing the InnoDB data dictionary, undo logs, and doublewrite buffer. A corrupted ibdata1 prevents MySQL from starting because the storage engine cannot initialize its internal structures, even if the server was operational the previous day. This matches the symptom of a sudden failure without prior configuration changes.

Exam trap

EC-Council often tests the distinction between permission errors, disk-full errors, memory errors, and corruption errors, so the trap here is that candidates may confuse a 'cannot start' error with a permission issue or memory exhaustion, rather than recognizing the specific InnoDB corruption signature in the log.

How to eliminate wrong answers

Option A is wrong because if the MySQL user lacked write permissions to the data directory, the error would typically be 'Permission denied' or 'Can't create/write to file', not a corruption-related InnoDB error about ibdata1. Option B is wrong because a full binary log that cannot be rotated would cause a 'Binary log disk full' or 'Could not write to binlog' error, not an InnoDB system tablespace corruption error. Option C is wrong because running out of memory due to high innodb_buffer_pool_size would manifest as an out-of-memory (OOM) kill or allocation failure, not a specific corruption error for ibdata1.

740
MCQmedium

An investigator examines an iPhone backup file. Inside the backup manifest, they find a file path 'AppDomainGroup-group.com.example.app'. This indicates the data belongs to which type of app container?

A.System container for iOS system apps
B.The app's sandbox container
C.A shared container for multiple apps from the same developer
D.Temporary container for app data
AnswerC

The 'AppDomainGroup-' prefix in an iOS backup identifies a shared container that is part of an app group, which allows multiple apps from the same developer to access common files and preferences. These groups are declared via the com.apple.security.application-groups entitlement, and the container is stored outside each app's individual sandbox. Therefore, when an investigator sees this prefix, it correctly means a shared container for multiple apps from the same developer.

Why this answer

The file path 'AppDomainGroup-group.com.example.app' indicates a shared container used by App Groups, a feature that allows multiple apps from the same developer to share data. This is not a sandbox container for a single app, nor is it a system or temporary container. The 'group' prefix and the bundle identifier pattern confirm it belongs to a shared app group container.

Exam trap

EC-Council often tests the distinction between 'AppDomain-' (single app sandbox) and 'AppDomainGroup-' (shared container), and candidates mistakenly pick the sandbox container option because they overlook the 'group' keyword in the path.

How to eliminate wrong answers

Option A is wrong because system containers for iOS system apps use paths like '/System/Library' or '/var/containers/Bundle/System', not 'AppDomainGroup-'. Option B is wrong because an app's sandbox container uses the 'AppDomain-' prefix (e.g., 'AppDomain-com.example.app'), not 'AppDomainGroup-'. Option D is wrong because temporary containers use paths like 'tmp/' or 'Caches/' within the app's sandbox, not a dedicated 'AppDomainGroup-' domain.

741
MCQmedium

In Mac forensics, which artifact stores system-wide and per-user application preferences, often used to determine configured settings and recently accessed files?

A.Unified logging
B..plist files
C.Sqlite databases
D.FSEvents
AnswerB

Property list files encode application preferences as key-value pairs, storing both system-wide settings in /Library/Preferences and per-user settings in ~/Library/Preferences. This satisfies the stem's requirement to determine configured settings and recently accessed files, since plists also record recent items, window states and document history.

Why this answer

In macOS, application and system preferences are stored in property list (.plist) files. These XML or binary files contain key-value pairs that define configured settings, default values, and recently accessed files (e.g., NSRecentDocuments). Forensic examiners parse .plist files to recover user behavior, application usage, and system configuration.

Exam trap

EC-Council often tests the distinction between preference storage (.plist) and logging (Unified logging) or file system change tracking (FSEvents), leading candidates to confuse operational logs with persistent configuration artifacts.

How to eliminate wrong answers

Option A is wrong because Unified logging (os_log) captures system and application log messages, not persistent preference settings or recently accessed file lists. Option C is wrong because SQLite databases store structured data like contacts, messages, or browser history, but they are not the primary artifact for system-wide or per-user application preferences; .plist files serve that role. Option D is wrong because FSEvents records file system changes (creation, modification, deletion) for Time Machine and Spotlight, not application preferences or configured settings.

742
MCQeasy

A security team needs to preserve network evidence for a potential legal case. What is the BEST practice for capturing volatile network data?

A.Wait until normal business hours to capture traffic
B.Only record summary logs from the firewall
C.Perform packet capture using a portable tool and store the capture with a cryptographic hash
D.Use a dedicated forensic workstation with a write blocker
AnswerC

Performing packet capture with a portable tool such as tcpdump or dumpcap on a mirror port preserves the live, volatile network state while minimizing footprint, and a cryptographic hash (like SHA-256) computed at acquisition time provides integrity verification for later evidence examination. The captured PCAP stores both headers and payloads, allowing protocol analysis and stream reassembly. Store the capture on write-protected media and record the hash in the chain-of-custody documentation to prove tamper-resistance.

Why this answer

Capturing volatile network data requires immediate acquisition of live traffic before it is lost, and using a portable tool (e.g., tcpdump, Wireshark) allows rapid deployment. Storing the capture with a cryptographic hash (e.g., SHA-256) ensures data integrity and chain of custody, which is essential for admissibility in legal proceedings. This approach preserves the most volatile evidence (packet contents) while providing verifiable proof that the data has not been altered.

Exam trap

EC-Council often tests the distinction between volatile and non-volatile evidence; the trap here is that candidates confuse the write blocker (used for disk forensics) with network capture tools, incorrectly assuming that a write blocker can somehow preserve network traffic.

How to eliminate wrong answers

Option A is wrong because waiting until normal business hours introduces unacceptable delay; volatile network data (e.g., active sessions, real-time traffic) is lost the moment it passes, and delaying capture risks losing critical evidence. Option B is wrong because recording only summary logs from the firewall discards the full packet payload and metadata (e.g., TCP sequence numbers, application-layer data), which are often necessary for reconstructing incidents and proving intent. Option D is wrong because a dedicated forensic workstation with a write blocker is designed for acquiring non-volatile storage media (e.g., hard drives, SSDs) to prevent writes; network traffic is volatile and cannot be captured via a write blocker, which has no role in live network packet capture.

743
Multi-Selectmedium

Which TWO of the following tools are commonly used for file carving during forensic investigations?

Select 2 answers
A.Sleuth Kit
B.WinPmem
C.Foremost
D.Volatility
E.PhotoRec
AnswersC, E

Foremost is a well-known file carver that performs signature-based recovery by scanning raw image files for headers and footers defined in its configuration file, foremost.conf. It recovers files by content, not metadata, making it effective after formatting or file-system damage. Foremost supports many common file types and is a standard tool in Linux forensic distributions for recovering deleted files.

Why this answer

Foremost (C) is correct because it is a classic file-carving tool that scans raw disk images or unallocated space and reconstructs files by matching known headers, footers, and internal structures defined in its configuration file. PhotoRec (E) is also correct because it performs signature-based carving to recover deleted files from disk images, memory cards, and other media, ignoring the filesystem to extract data by content type. Sleuth Kit (A) is a forensic analysis toolkit for examining filesystem metadata and timelines rather than a dedicated carving tool, WinPmem (B) is a memory acquisition tool for capturing RAM images, and Volatility (D) is a memory forensics framework for analyzing RAM dumps, so none of these are primarily used for file carving.

Exam trap

EC-Council often tests the distinction between file carving tools (Foremost, PhotoRec) and memory analysis tools (Volatility, WinPmem) or file system analysis tools (Sleuth Kit), expecting candidates to recognize that carving operates on raw disk data without file system metadata.

744
MCQmedium

During a forensic examination of a Windows 10 system, an investigator runs the following command: 'fsutil usn readjournal C: > usn_output.txt'. What is the primary purpose of this action?

A.To recover deleted files from the Recycle Bin
B.To analyze the Update Sequence Number (USN) journal for file system activity
C.To check the integrity of the NTFS file system
D.To extract the Master File Table ($MFT) from the volume
AnswerB

The fsutil usn readjournal command reads the Update Sequence Number (USN) journal, a Microsoft NTFS feature that records a high-level log of all file and directory changes, including creation, deletion, and attribute updates. This makes it an excellent source for identifying file system activity during a forensic investigation, as the journal entry contains the file reference, change reason, and timestamp. Using the optional /v (verbose) flag reveals additional detail about each USN_RECORD, such as the file name and the actual reason flags set for the change.

Why this answer

The `fsutil usn readjournal` command reads the Update Sequence Number (USN) journal, which is a change journal that records all modifications to files and directories on an NTFS volume. This is the primary purpose of the command, as it allows an investigator to analyze file system activity, including file creations, deletions, and modifications, which is critical for forensic timeline reconstruction.

Exam trap

The CHFI exam often tests the distinction between the USN journal (which logs changes) and the $MFT (which stores file metadata), causing candidates to confuse reading the journal with extracting the MFT.

How to eliminate wrong answers

Option A is wrong because recovering deleted files from the Recycle Bin is not the function of the USN journal; the USN journal records metadata about changes but does not store file content or facilitate recovery from the Recycle Bin. Option C is wrong because checking the integrity of the NTFS file system is performed by commands like `chkdsk` or `fsutil dirty query`, not by reading the USN journal. Option D is wrong because extracting the Master File Table ($MFT) is done using specialized forensic tools or commands like `fsutil mft` or direct disk reading, not by reading the USN journal, which is a separate NTFS metadata structure.

745
Multi-Selecthard

A forensic analyst is investigating a malware incident on a Windows system and suspects that the malware uses process injection to execute malicious code within a legitimate process. The analyst has acquired a memory dump of the system. Which two of the following techniques should the analyst use to detect and analyze process injection? (Choose two.)

Select 2 answers
A.Analyze network traffic captures for signs of data exfiltration from the injected process.
B.Check the Windows event logs for process creation events with unusual parent-child relationships.
C.Use the Volatility command malfind to identify hidden or injected code in process memory.
D.Run a full antivirus scan on the memory dump file to detect known malware signatures.
E.Examine the memory dump for discrepancies between the executable sections on disk and those in memory.
AnswersC, E

The Volatility plugin malfind is designed to detect hidden or injected code in process memory by scanning for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk. It is a standard tool for memory forensics and can reveal injected code from techniques like process hollowing or DLL injection. This directly addresses the scenario.

Why this answer

Detecting process injection from a memory dump requires techniques that directly examine process memory. Comparing on-disk and in-memory executable sections reveals modifications, while the Volatility malfind plugin scans for suspicious memory regions indicative of injected code. These two methods are specifically designed to uncover injection artifacts and are standard in memory forensics.

Exam trap

The trap here is relying on signature-based scanning or network logs, which do not directly reveal process injection in memory.

Page 9

Page 10 of 10

All pages