or an event handler like onerror=...; the log entry instead contains SQL keywords (UNION, SELECT) and a double-dash comment token. XSS executes in a victim's browser and affects the user session, whereas the observed parameter value is designed to manipulate the database query itself. The presence of SQL syntax in the id parameter, not markup or JavaScript, rules out XSS."}},{"@type":"Answer","text":"Path traversal","comment":{"@type":"Comment","text":"Path traversal attacks manipulate file path references using traversal sequences such as ../../etc/passwd or encoded variants (%2e%2e%2f) to make the application read or include files outside its intended directory. The captured log shows no dot-dot-slash constructs and no file system path; instead, it contains SQL tokens like UNION and SELECT inside the id parameter. These tokens alter database query logic rather than directory resolution, so the artifact is inconsistent with path traversal."}},{"@type":"Answer","text":"Remote file inclusion (RFI)","comment":{"@type":"Comment","text":"Remote file inclusion occurs when an application dynamically includes a file from a URL, commonly seen as parameter values like http://attacker.com/shell.txt or data:// payloads in PHP applications. The log entry's id parameter contains a SQL query fragment, not a URL or file path, meaning the attacker is not trying to load an external resource into server-side code. RFI would leave artifacts of HTTP requests to external hosts or include statements in logs, neither of which appears here."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"You are a forensic investigator responding to a suspected data breach at a financial institution. The incident response team has isolated a Windows 10 workstation used by a former employee. The system","url":"https://courseiva.com/questions/ec-council/ec-chfi/you-are-a-forensic-investigator-responding-to-a-suspected-da-tn9ka","acceptedAnswer":{"@type":"Answer","text":"Capture volatile data using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging","comment":{"@type":"Comment","text":"This is the correct order because volatile data (RAM, running processes, network connections, open files) is lost the instant the system loses power. Using a trusted, write-protected USB tool to capture this data first ensures the most transient evidence is preserved. A graceful shutdown, unlike a hard power-off, allows the OS to flush and close file structures cleanly, reducing the risk of filesystem corruption, and then removing the drive for a forensic imaging workstation yields a defensible disk image without altering the original."}},"suggestedAnswer":[{"@type":"Answer","text":"Use the built-in Windows backup to create a system image to an external drive","comment":{"@type":"Comment","text":"The built-in Windows Backup (e.g., 'Backup and Restore' or 'File History') is a backup utility, not a forensic acquisition tool. It does not create a bit-for-bit copy of the disk; instead, it copies files and system images using Windows' own file system APIs, which can alter access timestamps and fail to capture deleted data, slack space, and unallocated clusters. Running it also writes to the system drive and changes the state of the evidence before any forensic preservation, making it inherently unsound for legal proceedings."}},{"@type":"Answer","text":"Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running","comment":{"@type":"Comment","text":"Booting from a forensic live CD is a common approach for dead acquisition, but doing it *while the system is running* or as a response to a live system is problematic. The boot process itself overwrites RAM (destroying volatile data) and writes temporary files to the disk, changing timestamps and potentially overwriting evidence in unallocated space. Furthermore, if the system is compromised, the live CD may not have a trusted kernel or may be subject to rootkit interference, and imaging a mounted or in-use filesystem can result in an inconsistent, non-forensic image."}},{"@type":"Answer","text":"Immediately pull the power cord to perform a cold acquisition of the hard drive","comment":{"@type":"Comment","text":"While a hard power-off (cold acquisition) is sometimes used to preserve disk state when the system is already off or when malware might destroy evidence, it is not the initial step in a live response. Pulling the power cord instantly terminates all running processes and destroys volatile memory, losing critical evidence such as encryption keys, network connections, and active malware in RAM. It also risks filesystem journaling inconsistencies and may trigger write-caching data loss, potentially leaving the disk in an unclean state that complicates analysis and damages the integrity of the acquired image."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?","url":"https://courseiva.com/questions/ec-council/ec-chfi/refer-to-the-exhibit-an-analyst-recovers-this-binary-log-en-t65ty","acceptedAnswer":{"@type":"Answer","text":"The time the DELETE statement was executed on the MySQL server","comment":{"@type":"Comment","text":"The timestamp in the binary log entry records when the MySQL server executed the DELETE statement, as part of its statement-based or row-based logging. This is the server's authoritative clock at the moment the statement was processed, not when the client sent it or when the file was flushed. MySQL writes this event timestamp into the binary log header for replication and point-in-time recovery, reflecting execution time."}},"suggestedAnswer":[{"@type":"Answer","text":"The time the client sent the query to the server","comment":{"@type":"Comment","text":"The timestamp reflects server-side processing, not the client's send time. Network latency, client-side batching, or queuing can delay the query arrival; the binary log captures when the server actually started executing the statement, after receiving it. So it cannot be used to measure client behavior or network transmission time."}},{"@type":"Answer","text":"The time the binary log file was written to disk","comment":{"@type":"Comment","text":"The binary log file is written as events are generated, but the event timestamp is set at execution time, independent of when the log file is physically flushed to disk. Disk I/O, buffering, and sync settings may cause a delay between event generation and file write. Therefore the timestamp does not indicate the write time to storage."}},{"@type":"Answer","text":"The time the transaction was committed","comment":{"@type":"Comment","text":"For a DELETE statement, particularly in non-transactional storage engines like MyISAM or with autocommit, there is no explicit transaction commit; the statement is immediately durable. Even in InnoDB, the binary log records the statement execution time, not the commit time, as a commit may occur later at the end of the transaction. Thus the timestamp is not about commit timing."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"An analyst is investigating a Linux system that used ext4. The suspect deleted several files and then ran 'fstrim' on the partition. Which of the following best describes the challenge in recovering t","url":"https://courseiva.com/questions/ec-council/ec-chfi/an-analyst-is-investigating-a-linux-system-that-used-ext4-t-0gjde","acceptedAnswer":{"@type":"Answer","text":"The TRIM command instructs the SSD to permanently erase the blocks, and wear leveling may also have moved data","comment":{"@type":"Comment","text":"The TRIM command is an ATA interface primitive that informs the SSD which Logical Block Addresses are no longer in use, allowing the controller to erase the corresponding NAND flash blocks in the background, permanently destroying the data they contain. When an ext4 filesystem is mounted with the discard option or when fstrim is run, all freed blocks are trimmed, including those formerly occupied by deleted files. Additionally, the SSD's wear-leveling algorithm continuously remaps logical to physical blocks, so even if a forensic tool reads the logical LBA, the physical block that originally stored the data may have been relocated during garbage collection. This combination of block erasure and physical address remapping makes traditional file recovery impossible on such systems."}},"suggestedAnswer":[{"@type":"Answer","text":"The ext4 journal will automatically purge the metadata of deleted files","comment":{"@type":"Comment","text":"The ext4 journal is a circular log that records file system metadata changes for crash recovery; it does not perform any kind of metadata purging when a file is deleted. Deleting a file in ext4 involves clearing the directory entry, decrementing the link count, and freeing the inode, but the journal continues to hold historical transaction records. Rather than actively erasing deleted file metadata, journal transactions may preserve remnants of the file's metadata until those log blocks are overwritten by later activity. Thus, the notion of automatic purging by the journal is incorrect."}},{"@type":"Answer","text":"Data recovery is still possible using file carving because fstrim only affects free space","comment":{"@type":"Comment","text":"Data carving after fstrim is not viable because fstrim issues a TRIM command to the SSD for every free block on the filesystem, and deleted file data lives in that free space. The command instructs the SSD controller to discard the underlying NAND blocks, which causes them to be erased and presented as zeroed or unavailable. While fstrim only touches free space, that is exactly the area where unallocated file content would be carved from, so any remnants are destroyed at the physical layer. Allocated files are unaffected, but they are not the target of forensic carving after deletion."}},{"@type":"Answer","text":"The inodes are overwritten immediately, making recovery impossible","comment":{"@type":"Comment","text":"ext4 does not overwrite inode data immediately upon deletion; the inode is simply marked as free in the inode bitmap while its original fields—such as timestamps, ownership, and data block pointers—remain intact until the inode is reused by a new file. The data blocks themselves are likewise not touched and still contain the original file content until overwritten by subsequent writes. Therefore, recovery is possible using tools like debugfs or extundelete if the blocks have not been reused or if TRIM has not been issued. The premise of immediate overwriting is a misunderstanding of ext4's lazy allocation and freeing behavior."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"During a forensic investigation of a Google Cloud Platform (GCP) environment, an analyst reviews Audit Logs and sees a log entry with the method 'storage.objects.list' and a principal email 'attacker@","url":"https://courseiva.com/questions/ec-council/ec-chfi/during-a-forensic-investigation-of-a-google-cloud-platform-go5i0","acceptedAnswer":{"@type":"Answer","text":"An external identity was granted IAM permissions on the bucket, possibly through a misconfigured resource.","comment":{"@type":"Comment","text":"The presence of an external email address in the principal field of the Cloud Audit Log entry indicates that an IAM policy binding grants permissions to an identity outside the organization. This often happens when a bucket has been made public or when a resource-level IAM policy accidentally includes an external user or allUsers/allAuthenticatedUsers. The analyst should examine the bucket's IAM policy using `gcloud iam policies get` or the Cloud Console to identify the exact binding."}},"suggestedAnswer":[{"@type":"Answer","text":"The analyst must immediately shut down the bucket.","comment":{"@type":"Comment","text":"Shutting down the bucket is an incident response action, not a forensic conclusion. The log indicates a potential IAM misconfiguration, but the analyst should first preserve evidence, assess the scope, and determine whether the bucket is actually publicly accessible or if the external identity is authorized. Premature shutdown could destroy ephemeral data and disrupt services without confirming the threat."}},{"@type":"Answer","text":"The attacker spoofed the principal email in the log.","comment":{"@type":"Comment","text":"Cloud Audit Logs in GCP are generated by the authentication layer; the principal email is derived from the authenticated identity token. GCP's Security Command Center and Cloud Audit Logs rely on cryptographically signed credentials, so an attacker cannot simply forge the principal field. A spoofed email would require compromising the identity provider or the service account key, which is a different attack vector than IAM misconfiguration."}},{"@type":"Answer","text":"The log entry is a false positive due to a logging error.","comment":{"@type":"Comment","text":"Cloud Audit Logs are designed to be highly reliable and tamper-evident, with logs streamed to Cloud Storage or BigQuery for retention. A false positive due to a logging error is unlikely because the log entry is generated upon an actual API call that was authenticated and authorized under the given identity. Logging errors typically manifest as missing entries, not fabricated ones with coherent principal and resource fields."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"During a forensic examination of an SSD, the analyst notes that TRIM is enabled. What challenge does TRIM pose for data recovery?","url":"https://courseiva.com/questions/ec-council/ec-chfi/during-a-forensic-examination-of-an-ssd-the-analyst-notes-t-tp2ed","acceptedAnswer":{"@type":"Answer","text":"TRIM permanently erases deleted data at the block level, hindering recovery","comment":{"@type":"Comment","text":"TRIM permanently erases deleted data at the block level by having the OS issue ATA DATASET MANAGEMENT or NVMe Deallocate commands that unmap the blocks containing the deleted file. Once unmapped, the SSD controller no longer preserves the old data and may zero or reuse those physical blocks during garbage collection, so conventional recovery tools cannot locate the file. This is why TRIM-implementing SSDs present a much greater forensic recovery challenge than HDDs or TRIM-disabled SSDs."}},"suggestedAnswer":[{"@type":"Answer","text":"TRIM reduces the lifespan of the SSD by excessive writes","comment":{"@type":"Comment","text":"TRIM is a host-to-device command that marks logical block addresses as no longer containing valid data; it does not write data to the NAND. In fact, TRIM reduces write amplification and helps maintain steady performance by enabling the controller to reclaim erased blocks efficiently. It therefore extends, rather than shortens, SSD lifespan, and it is not a source of excessive write cycles."}},{"@type":"Answer","text":"TRIM compresses data, altering forensic signatures","comment":{"@type":"Comment","text":"TRIM performs no transformation of user data and never compresses it; compression, if applied, is done by the SSD controller's internal data reduction or by the operating system before data reaches the device. The command simply communicates which regions can be discarded, so file contents and their metadata signatures remain unchanged at the logical layer. Consequently, a forensic examiner would not see altered signatures caused by TRIM."}},{"@type":"Answer","text":"TRIM encrypts data, preventing forensic access","comment":{"@type":"Comment","text":"TRIM has no cryptographic function; it is an unmap or discard operation that informs the SSD that previously written data blocks are invalid. Encryption on SSDs is implemented separately through hardware features such as TCG Opal/SED drives with media encryption or through full-disk encryption software like BitLocker. TRIM neither encrypts nor decrypts data, and it does not create a cryptographic barrier preventing forensic access."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"Which of the following is a primary challenge in cloud forensics due to shared infrastructure?","url":"https://courseiva.com/questions/ec-council/ec-chfi/which-of-the-following-is-a-primary-challenge-in-cloud-foren-aouqh","acceptedAnswer":{"@type":"Answer","text":"Multi-tenancy and data comingling","comment":{"@type":"Comment","text":"Multi-tenancy and data comingling are a primary challenge because cloud infrastructure pools resources across many customers on shared physical hardware. When an investigator acquires a forensic image from a virtual disk or memory, the underlying storage may contain remnants or interleaved blocks from other tenants, making it difficult to isolate the target's data without cross-contamination. This threatens chain of custody, requires careful logical isolation verification, and raises significant privacy and legal issues because collecting other tenants' data may violate statutes or service agreements. The shared responsibility model complicates attribution further, as the investigator must prove that the evidence belongs solely to the suspected tenant."}},"suggestedAnswer":[{"@type":"Answer","text":"Slow internet speeds","comment":{"@type":"Comment","text":"Slow internet speeds are a performance metric, not a forensic impediment. Cloud forensic acquisitions depend on API-based access and logical disk snapshots, where bandwidth affects the time to transfer evidence but does not compromise the integrity, admissibility, or legal validity of the data. Even with dial-up speeds, an investigator can still obtain a forensically sound copy, provided the provider's acquisition mechanism is reliable. Thus, this is a minor logistical annoyance, not a primary challenge of cloud forensics."}},{"@type":"Answer","text":"Lack of logging capabilities","comment":{"@type":"Comment","text":"The claim that cloud providers lack logging capabilities is false—providers offer comprehensive logging services such as AWS CloudTrail, Azure Activity Logs, and Google Cloud Audit Logs that record API calls, administrative actions, and security events. The actual forensic challenge is managing the enormous volume of logs, their retention periods, and verifying their integrity when the provider controls the logging infrastructure. Logs can be tampered with or disabled without proper access controls, but they absolutely exist and are a crucial evidence source. Therefore, lack is not the issue; trust and configurability are."}},{"@type":"Answer","text":"Inability to perform network analysis","comment":{"@type":"Comment","text":"Network analysis is indeed possible in cloud environments through tools like VPC Flow Logs (which capture IP traffic metadata), AWS Traffic Mirroring, vTap, and hypervisor-level monitoring. Investigators can install packet capture utilities inside virtual machines and inspect network traffic just as on on-premises systems, limited only by the visibility into the physical network fabric. The distinction is that logical network boundaries and virtual switches may obscure some traffic, but the ability to perform network forensics remains intact. Thus, 'inability' is an incorrect statement—the limitations are about scope and access, not feasibility."}}]},{"@context":"https://schema.org","@type":"Quiz","name":"A security analyst notices repeated entries in an IIS log: 10.0.0.2, -, 05/Feb/2023:08:12:34 +0000, GET /../../windows/system32/config/sam, 404, 0, 532. Which TWO of the following attack types are ind","url":"https://courseiva.com/questions/ec-council/ec-chfi/a-security-analyst-notices-repeated-entries-in-an-iis-log-1-757io","acceptedAnswer":{"@type":"Answer","text":"Directory traversal","comment":{"@type":"Comment","text":"The repeated '../' sequences, often encoded as '%2e%2e%5c' or '%2e%2e/', are classic indicators of directory traversal in IIS logs. An attacker sends these sequences to escape the web root and access sensitive files outside it, such as Windows system files or configuration stores. The log entries show a deliberate attempt to navigate the server's directory hierarchy, which is the defining characteristic of a directory traversal attack."}},"suggestedAnswer":[{"@type":"Answer","text":"SQL injection","comment":{"@type":"Comment","text":"The log entries contain no SQL keywords, operators, or quoted strings that would indicate an injection into database queries. Directory traversal attempts use path manipulation such as '../' or encoded backslashes to navigate the filesystem, not to alter SQL logic. SQL injection typically appears in query string parameters like 'id=1 OR 1=1', while these requests target file paths directly."}},{"@type":"Answer","text":"Denial of service","comment":{"@type":"Comment","text":"A denial of service attack requires overwhelming the server with a high volume of requests to exhaust resources or cause a crash. The log shows only repeated traversal attempts, not a flood of traffic, and these requests are small, low-bandwidth HTTP GETs. DoS would manifest as thousands of requests per second or patterns like SYN floods, not a few path traversal probes."}},{"@type":"Answer","text":"Cross-site scripting","comment":{"@type":"Comment","text":"Cross-site scripting involves injecting executable client-side scripts into web pages that are then rendered to other users, typically via user input reflected or stored in HTML. The IIS log entries show direct file path manipulation with no '
Which Windows Event ID is generated when a new service is installed on a system?
A.4624
B.7045
C.4648
D.4720
AnswerB
Event ID 7045 is the Windows System log event emitted by the Service Control Manager whenever a new service is installed or registered on the system. It contains the service name, image path, service type, start type, and the account under which the service runs. This is the definitive event for detecting service installations, although on modern Windows versions event 4697 provides similar service-creation auditing in the Security log.
Why this answer
Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event is generated by the Service Control Manager (SCM) and records details such as the service name, binary path, service type, and start mode, making it a critical artifact for forensic analysis of unauthorized service installations.
Exam trap
The trap here is that candidates confuse Event ID 7045 with Event ID 4697 (service installation in the Security log) or mistakenly associate Event ID 4624 (logon success) with service accounts, but the EC-CHFI exam specifically tests the System log Event ID 7045 for service installation.
How to eliminate wrong answers
Option A is wrong because Event ID 4624 is an account logon success event, not related to service installation. Option C is wrong because Event ID 4648 indicates a logon attempt using explicit credentials (e.g., RunAs), not a service installation. Option D is wrong because Event ID 4720 is generated when a new user account is created in Active Directory, not when a service is installed.
Which TWO of the following are commonly used tools for file carving (recovering files based on file signatures)? (Select TWO.)
Select 2 answers
A.Nmap
B.Foremost
C.Wireshark
D.John the Ripper
E.Scalpel
AnswersB, E
Foremost is a mature file carving tool originally developed by the U.S. Air Force Office of Special Investigations. It scans raw disk images or memory dumps for known file header and footer signatures defined in its configuration file, then extracts contiguous blocks that match those boundaries. This signature-based method allows recovery of files from unallocated clusters without relying on the operating system's file system metadata.
Why this answer
Foremost (B) is a classic file-carving tool originally developed for the U.S. Air Force OSI that scans raw disk images or unallocated space and reconstructs files by matching known file headers, footers, and internal structures defined in its configuration file (foremost.conf). Scalpel (E) is a high-performance carving tool derived from Foremost that uses a configurable header/footer signature database (scalpel.conf) to extract files from disk images, making it a standard choice for signature-based recovery.
Nmap (A) is a network port scanner and host-discovery tool, not a file-carving utility. Wireshark (C) is a network protocol analyzer that captures and inspects packet data, not files on storage media. John the Ripper (D) is a password-cracking tool that tests hashes against wordlists and rules, which is unrelated to recovering files by their signatures.
Exam trap
The CHFI exam often tests the distinction between network analysis tools (Nmap, Wireshark) and forensic recovery tools (Foremost, Scalpel), leading candidates to mistakenly select tools they recognize from other domains.
Which tool is specifically designed for timeline analysis in digital forensics and is the command-line version of the log2timeline framework?
A.Autopsy
B.Sleuth Kit
C.Plaso
D.Wireshark
AnswerC
Plaso, also known as log2timeline, is the command-line tool specifically engineered for timeline analysis. It recursively parses numerous artifact types—such as file system metadata, registry hives, and application logs—to create comprehensive 'super timelines' with unified timestamps. Plaso aggregates and normalizes timestamps into a single, queryable event database (often SQLite or Elasticsearch), making it the de facto standard for advanced timeline construction in forensic investigations.
Why this answer
Plaso (Python Log2Timeline) is the command-line version of the log2timeline framework, specifically engineered for super timeline creation and timeline analysis in digital forensics. It parses multiple log and artifact sources (e.g., Windows Event Logs, Prefetch, Registry hives) into a unified, high-performance timeline database (SQLite or Elasticsearch), enabling examiners to correlate events across time. This makes it the direct answer to a question asking for the CLI tool derived from the log2timeline framework.
Exam trap
EC-Council often tests the distinction between the original Perl-based log2timeline and the Python-based Plaso rewrite, as well as the difference between command-line tools (like Plaso) and GUI tools (like Autopsy, which is based on The Sleuth Kit, not log2timeline).
How to eliminate wrong answers
Option A is wrong because Autopsy is a GUI-based digital forensics platform that provides timeline visualization, but it is not the command-line version of the log2timeline framework; it uses Sleuth Kit and Plaso as backends but is not itself a CLI timeline tool. Option B is wrong because The Sleuth Kit (TSK) is a collection of command-line tools for file system analysis (e.g., fls, icat, mmls) and does not perform timeline analysis or derive from log2timeline; it lacks the log parsing and event correlation engine that Plaso provides. Option D is wrong because Wireshark is a network protocol analyzer for capturing and inspecting packets (e.g., TCP, HTTP, DNS) and has no role in timeline creation from system artifacts; it is unrelated to log2timeline or forensic timeline analysis.
An analyst finds the following string in an IIS log: %3Cscript%3Ealert('XSS')%3C/script%3E. What does this indicate?
A.A cross-site scripting (XSS) attempt
B.A SQL injection attempt
C.A buffer overflow attempt
D.A path traversal attempt
AnswerA
The string 3cscri is a signature of an XSS attempt because 3c is the hexadecimal encoding of the ASCII character '<', and 'scri' is the beginning of the word 'script'. When decoded, this represents the start of an HTML/JavaScript payload such as <script>, which would execute in a victim's browser. IIS logs often capture URL-encoded or hex-encoded characters, so this observed fragment strongly indicates cross-site scripting rather than any other web attack.
Why this answer
The string is URL-encoded HTML/JavaScript (<script>alert('XSS')</script>). It is a typical cross-site scripting payload attempting to execute in a browser.
A forensic examiner is presented with evidence that a suspect's computer was used to commit a fraud. The defense argues that the evidence was obtained without a warrant. Which US Constitutional Amendment is MOST relevant to this argument?
A.Fourth Amendment
B.First Amendment
C.Sixth Amendment
D.Fifth Amendment
AnswerA
The Fourth Amendment prohibits unreasonable searches and seizures and mandates that warrants issue only upon probable cause, describing the place to be searched and items to be seized. In a forensic context, evidence obtained through a warrantless or warrant-invalid search is subject to suppression under the exclusionary rule. Consequently, the Fourth Amendment is the precise constitutional provision that determines whether the defendant's evidence is legally admissible despite potential exceptions such as inevitable discovery.
Why this answer
The Fourth Amendment protects against unreasonable searches and seizures and requires warrants supported by probable cause.
During a malware analysis, an analyst uses a tool to monitor registry changes, file system modifications, and process activity simultaneously. Which tool is BEST suited for this integrated monitoring?
A.Wireshark
B.Process Monitor
C.Regshot
D.Process Explorer
AnswerB
Process Monitor is the correct choice because it uses kernel-mode registry callbacks, a file-system minifilter, and ETW process/thread/network providers to record real-time operations with full paths, operation types, results, durations, and call stacks. It lets an analyst filter by process name, PID, registry key, file path, or operation, and preserve the event timeline in a PML log for detailed malware-behavior reconstruction. This makes it a true dynamic behavioral monitor rather than a packet capture or state-snapshot utility.
Why this answer
Process Monitor (ProcMon) is the correct tool because it integrates real-time monitoring of registry changes, file system modifications, and process/thread activity into a single interface. It combines the legacy tools Regmon (registry) and Filemon (file system) with process monitoring, allowing an analyst to correlate events across all three subsystems simultaneously, which is essential for dynamic malware analysis.
Exam trap
EC-Council often tests the distinction between tools that perform real-time integrated monitoring (Process Monitor) versus tools that offer only snapshot comparisons (Regshot) or specialize in a single subsystem (Process Explorer), leading candidates to confuse Regshot's registry snapshot capability with live monitoring.
How to eliminate wrong answers
Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects network traffic (e.g., packets over Ethernet, Wi-Fi), not registry, file system, or process activity. Option C is wrong because Regshot is a registry comparison tool that takes before-and-after snapshots of the registry and optionally the file system, but it does not monitor process activity or provide real-time, integrated monitoring. Option D is wrong because Process Explorer is a task manager and process analysis tool that shows detailed information about running processes, handles, and DLLs, but it does not monitor registry or file system changes in real time.
Which TWO of the following are Volatility plugins used for process enumeration? (Select two.)
Select 2 answers
A.pslist
B.netscan
C.pstree
D.mftparser
E.hashdump
AnswersA, C
pslist is correct because it enumerates active processes by traversing the doubly linked list of EPROCESS structures anchored at PsActiveProcessHead. This plugin reads each EPROCESS entry directly from kernel memory, extracting the process ID, parent process ID, thread counts, and creation time. It is a fundamental process listing plugin in Volatility, though it can miss processes that have been deliberately unlinked from the list to evade detection.
Why this answer
pslist (A) is a Volatility plugin that walks the active process list from the kernel's EPROCESS linked list (via PsActiveProcessHead) and prints each running process with its PID, PPID, and start time, making it a core process-enumeration plugin. pstree (C) is also a process-enumeration plugin: it uses the same process data but renders it as a parent/child tree based on PPID relationships, which helps reveal process ancestry and hidden or orphaned processes. The other options serve different forensic purposes: netscan (B) enumerates network sockets and connections, mftparser (D) parses the MFT to recover file-system metadata, and hashdump (E) extracts password hashes from the SAM registry hive, so none of them are process-enumeration plugins.
Exam trap
The EC-CHFI exam often tests the distinction between process enumeration plugins (pslist, pstree) and other Volatility plugins that serve different forensic purposes, such as network or file system analysis, to catch candidates who confuse plugin categories.
During a forensic investigation of a compromised web server, an analyst examines the Apache access log and finds the following entry: '192.168.1.10 - - [12/Oct/2024:13:45:22 +0000] "GET /index.php?id=1 UNION SELECT username, password FROM users-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. What type of attack is MOST likely indicated?
A.Cross-site scripting (XSS)
B.SQL injection (SQLi)
C.Path traversal
D.Remote file inclusion (RFI)
AnswerB
The GET request to the id parameter with ' UNION SELECT username,password FROM users -- is a textbook UNION-based SQL injection payload. The single quote closes the original SQL string, UNION SELECT appends attacker-controlled columns to the result set, and the '--' comment sequence comments out the remainder of the original WHERE clause so the query executes exactly as the attacker intends. This causes the application's database to return records (e.g., credentials) that should never be exposed, making SQL injection the correct classification.
Why this answer
The log entry shows a UNION-based SQL injection attempt, where the attacker appends 'UNION SELECT username, password FROM users--' to the 'id' parameter in the GET request. This manipulates the original SQL query to return sensitive data from the 'users' table, which is the hallmark of SQL injection (SQLi). The HTTP 200 response indicates the query executed successfully, confirming the attack vector.
Exam trap
The trap here is that candidates may confuse the 'UNION SELECT' syntax with a path traversal or RFI attack because they see a URL parameter with special characters, but the key indicator is the SQL-specific command structure, not file paths or remote URLs.
How to eliminate wrong answers
Option A is wrong because cross-site scripting (XSS) involves injecting client-side scripts (e.g., JavaScript) into web pages viewed by other users, not manipulating SQL queries via URL parameters; the log shows no script tags or event handlers. Option C is wrong because path traversal attacks use '../' sequences to access files outside the web root (e.g., /etc/passwd), not SQL syntax like 'UNION SELECT'. Option D is wrong because remote file inclusion (RFI) involves including a remote file (e.g., via 'http://evil.com/shell.txt') in a server-side include or function, not injecting SQL commands into a database query.
You are a forensic investigator responding to a suspected data breach at a financial institution. The incident response team has isolated a Windows 10 workstation used by a former employee. The system is still powered on, and the login screen is displayed. Your task is to acquire forensic evidence in a defensible manner. The following actions are available:
A. Immediately pull the power cord to perform a cold acquisition of the hard drive.
B. Capture volatile data (RAM, network connections, running processes) using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging.
C. Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running.
D. Use the built-in Windows backup to create a system image to an external drive.
Which action is the most appropriate first step in this scenario?
A.Use the built-in Windows backup to create a system image to an external drive
B.Capture volatile data using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging
C.Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running
D.Immediately pull the power cord to perform a cold acquisition of the hard drive
AnswerB
This is the correct order because volatile data (RAM, running processes, network connections, open files) is lost the instant the system loses power. Using a trusted, write-protected USB tool to capture this data first ensures the most transient evidence is preserved. A graceful shutdown, unlike a hard power-off, allows the OS to flush and close file structures cleanly, reducing the risk of filesystem corruption, and then removing the drive for a forensic imaging workstation yields a defensible disk image without altering the original.
Why this answer
The system is still powered on with the login screen displayed, meaning volatile data (RAM, network connections, running processes) is present and will be lost if the system is powered off. Capturing this data first using a trusted forensic tool (e.g., FTK Imager or DumpIt) from a write-blocked USB drive preserves critical evidence such as encryption keys, active network connections, and malware in memory. Only after volatile data is secured should the system be shut down normally and the hard drive removed for forensic imaging, ensuring a defensible chain of custody.
Exam trap
EC-Council often tests the misconception that pulling the power cord is the safest method to preserve disk evidence, but the trap here is that it destroys volatile data and can cause filesystem corruption, making it inappropriate when the system is still powered on and volatile data is present.
How to eliminate wrong answers
Option A is wrong because using the built-in Windows backup to create a system image modifies the system (e.g., writes backup metadata, changes registry timestamps) and does not capture volatile data, violating forensic integrity principles. Option C is wrong because booting from a forensic live CD while the system is running can overwrite portions of RAM and disk (e.g., pagefile, unallocated space) and may trigger anti-forensic mechanisms, plus it does not capture the current volatile state before the system is altered. Option D is wrong because immediately pulling the power cord (cold acquisition) destroys all volatile data (RAM, network connections, running processes) that may contain critical evidence like encryption keys or active malware, and can cause filesystem corruption if the disk was in a write state.
Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?
A.The time the DELETE statement was executed on the MySQL server
B.The time the client sent the query to the server
C.The time the binary log file was written to disk
D.The time the transaction was committed
AnswerA
The timestamp in the binary log entry records when the MySQL server executed the DELETE statement, as part of its statement-based or row-based logging. This is the server's authoritative clock at the moment the statement was processed, not when the client sent it or when the file was flushed. MySQL writes this event timestamp into the binary log header for replication and point-in-time recovery, reflecting execution time.
Why this answer
In MySQL binary logs, the timestamp in the 'Query' event header (e.g., '190101 10:00:00') records the server's local time when the statement began executing. This is the time the DELETE statement was actually processed by the MySQL server, not when the client sent it or when the log was written. The binary log captures the exact moment the server starts executing the query, making option A correct.
Exam trap
The CHFI exam often tests the distinction between 'execution time on server' vs 'client send time' or 'commit time', and the trap here is that candidates confuse the binary log event timestamp with the client-side query submission time or the transaction commit time, which are recorded differently in MySQL's binary log format.
How to eliminate wrong answers
Option B is wrong because the timestamp in the binary log event header reflects the server's execution start time, not the client's query send time; client-side timestamps are not recorded in the binary log. Option C is wrong because the binary log file write time is recorded in the file header or as a separate 'Rotate' event, not in the individual query event timestamps. Option D is wrong because the transaction commit time is recorded in a 'Xid' event or 'Query' event with a 'COMMIT' statement, not in the timestamp of a DELETE statement event; the timestamp here marks the start of the statement execution, not the commit.
An analyst is investigating a Linux system that used ext4. The suspect deleted several files and then ran 'fstrim' on the partition. Which of the following best describes the challenge in recovering the deleted data?
A.The ext4 journal will automatically purge the metadata of deleted files
B.Data recovery is still possible using file carving because fstrim only affects free space
C.The inodes are overwritten immediately, making recovery impossible
D.The TRIM command instructs the SSD to permanently erase the blocks, and wear leveling may also have moved data
AnswerD
The TRIM command is an ATA interface primitive that informs the SSD which Logical Block Addresses are no longer in use, allowing the controller to erase the corresponding NAND flash blocks in the background, permanently destroying the data they contain. When an ext4 filesystem is mounted with the discard option or when fstrim is run, all freed blocks are trimmed, including those formerly occupied by deleted files. Additionally, the SSD's wear-leveling algorithm continuously remaps logical to physical blocks, so even if a forensic tool reads the logical LBA, the physical block that originally stored the data may have been relocated during garbage collection. This combination of block erasure and physical address remapping makes traditional file recovery impossible on such systems.
Why this answer
D is correct because the `fstrim` command sends the ATA TRIM (or SCSI UNMAP) command to the SSD, which instructs the drive to physically erase the blocks that are marked as free in the file system. This makes the original data unrecoverable at the block level, as the SSD's firmware permanently discards the data. Additionally, wear leveling may have already moved the data to different physical blocks before the TRIM command, further complicating recovery.
Exam trap
EC-Council CHFI often tests the misconception that `fstrim` only affects free space metadata or that file carving can still recover data after a TRIM, when in fact the TRIM command causes the SSD to physically erase the data blocks, making recovery impossible at the file system level.
How to eliminate wrong answers
Option A is wrong because the ext4 journal does not automatically purge metadata of deleted files; it only logs metadata changes for crash recovery, and the journal entries are overwritten in a circular fashion, not purged on deletion. Option B is wrong because file carving relies on data still being present on the storage medium, but `fstrim` on an SSD causes the blocks to be physically erased, so the data is no longer available for carving. Option C is wrong because inodes are not overwritten immediately upon deletion in ext4; they are marked as free but the data blocks remain until overwritten, and the TRIM command is what makes recovery impossible, not immediate inode overwriting.
During a forensic investigation of a Google Cloud Platform (GCP) environment, an analyst reviews Audit Logs and sees a log entry with the method 'storage.objects.list' and a principal email 'attacker@gmail.com'. However, the identity is not from the organization's domain. What should the analyst conclude?
A.The analyst must immediately shut down the bucket.
B.The attacker spoofed the principal email in the log.
C.An external identity was granted IAM permissions on the bucket, possibly through a misconfigured resource.
D.The log entry is a false positive due to a logging error.
AnswerC
The presence of an external email address in the principal field of the Cloud Audit Log entry indicates that an IAM policy binding grants permissions to an identity outside the organization. This often happens when a bucket has been made public or when a resource-level IAM policy accidentally includes an external user or allUsers/allAuthenticatedUsers. The analyst should examine the bucket's IAM policy using `gcloud iam policies get` or the Cloud Console to identify the exact binding.
Why this answer
In GCP, Audit Logs record the actual identity used to authenticate the API call. The presence of 'attacker@gmail.com' as the principal email indicates that an external Google account (not part of the organization's domain) was granted IAM permissions on the bucket, likely through a misconfigured resource policy (e.g., a bucket-level IAM policy that allows allUsers or a specific external user). This is a common cloud security misconfiguration where overly permissive IAM bindings are applied.
Exam trap
EC-Council often tests the misconception that Audit Logs can be spoofed or that external identities cannot appear in logs unless there is a logging error, but the correct understanding is that GCP Audit Logs faithfully record the authenticated identity, and an external email indicates a real IAM permission grant.
How to eliminate wrong answers
Option A is wrong because immediately shutting down the bucket is a reactive, non-forensic action that could destroy evidence; the analyst should first verify the scope of the misconfiguration and preserve logs. Option B is wrong because GCP Audit Logs are generated by the Cloud Audit Logs service and the principal email is extracted from the authenticated identity token (OAuth 2.0 or JWT) — spoofing the principal email would require compromising the authentication mechanism, which is not feasible for an external attacker. Option D is wrong because Audit Logs are tamper-proof and generated by the GCP infrastructure; a logging error that introduces a specific external email is extremely unlikely and would be a systemic issue, not a one-off false positive.
D.TRIM permanently erases deleted data at the block level, hindering recovery
AnswerD
TRIM permanently erases deleted data at the block level by having the OS issue ATA DATASET MANAGEMENT or NVMe Deallocate commands that unmap the blocks containing the deleted file. Once unmapped, the SSD controller no longer preserves the old data and may zero or reuse those physical blocks during garbage collection, so conventional recovery tools cannot locate the file. This is why TRIM-implementing SSDs present a much greater forensic recovery challenge than HDDs or TRIM-disabled SSDs.
Why this answer
TRIM is an ATA command that allows the operating system to inform the SSD which data blocks are no longer in use. When TRIM is enabled, the SSD's garbage collection process immediately erases these blocks at the physical level, making the data permanently unrecoverable through conventional forensic tools. This directly hinders data recovery because the deleted data is physically zeroed or marked as invalid before any forensic acquisition can occur.
Exam trap
The trap here is that candidates confuse TRIM with wear-leveling or encryption, assuming it protects data rather than permanently destroying it, leading them to choose options that describe unrelated SSD features.
How to eliminate wrong answers
Option A is wrong because TRIM does not reduce SSD lifespan; in fact, it reduces write amplification and extends lifespan by preventing unnecessary rewrite cycles. Option B is wrong because TRIM does not compress data; it simply marks blocks as invalid for erasure, and compression is a separate file system or OS feature that does not alter forensic signatures in the context of TRIM. Option C is wrong because TRIM does not encrypt data; encryption is handled by separate mechanisms like BitLocker or hardware encryption, and TRIM operates independently of encryption.
Which of the following is a primary challenge in cloud forensics due to shared infrastructure?
A.Slow internet speeds
B.Multi-tenancy and data comingling
C.Lack of logging capabilities
D.Inability to perform network analysis
AnswerB
Multi-tenancy and data comingling are a primary challenge because cloud infrastructure pools resources across many customers on shared physical hardware. When an investigator acquires a forensic image from a virtual disk or memory, the underlying storage may contain remnants or interleaved blocks from other tenants, making it difficult to isolate the target's data without cross-contamination. This threatens chain of custody, requires careful logical isolation verification, and raises significant privacy and legal issues because collecting other tenants' data may violate statutes or service agreements. The shared responsibility model complicates attribution further, as the investigator must prove that the evidence belongs solely to the suspected tenant.
Why this answer
Multi-tenancy means multiple customers share the same physical resources. This complicates evidence isolation and can lead to data comingling, making forensic acquisition difficult.
A security analyst notices repeated entries in an IIS log: 10.0.0.2, -, 05/Feb/2023:08:12:34 +0000, GET /../../windows/system32/config/sam, 404, 0, 532. Which TWO of the following attack types are indicated by this log entry?
Select 2 answers
A.SQL injection
B.Directory traversal
C.Privilege escalation attempt
D.Denial of service
E.Cross-site scripting
AnswersB, C
The repeated '../' sequences, often encoded as '%2e%2e%5c' or '%2e%2e/', are classic indicators of directory traversal in IIS logs. An attacker sends these sequences to escape the web root and access sensitive files outside it, such as Windows system files or configuration stores. The log entries show a deliberate attempt to navigate the server's directory hierarchy, which is the defining characteristic of a directory traversal attack.
Why this answer
The use of '../' indicates path traversal, and the target file (SAM) is a common target for privilege escalation.
A forensic analyst is creating a forensic image of a suspect's hard drive using a write blocker. Which of the following BEST describes the purpose of using a hardware write blocker?
A.To ensure that no data is written to the source drive during imaging
B.To increase the speed of data acquisition
C.To encrypt the forensic image for secure storage
D.To allow the suspect drive to be booted without altering data
AnswerA
A hardware write blocker sits between the suspect drive and the forensic workstation, intercepting every ATA/SCSI/NVMe command and allowing only read-only commands (e.g., READ SECTOR, IDENTIFY) to pass through while suppressing destructive commands like WRITE and DELETE. This preserves the bit-for-bit original state, so hash values calculated on the source remain valid and the evidence is admissible in court.
Why this answer
A hardware write blocker is a device placed between the suspect drive and the forensic workstation that intercepts and blocks any write commands from the operating system or imaging software. Its primary purpose is to guarantee that the source drive remains completely unaltered during acquisition, preserving the integrity of the evidence for legal and forensic purposes. This is achieved by allowing only read commands to pass through, while all write commands are physically or logically blocked at the hardware level.
Exam trap
The CHFI exam often tests the misconception that a write blocker's purpose is to protect the destination drive or to speed up imaging, rather than its core function of write-protecting the source drive to maintain forensic integrity.
How to eliminate wrong answers
Option B is wrong because a write blocker does not increase acquisition speed; in fact, it may introduce a slight overhead due to command filtering and does not affect the transfer rate of the drive interface. Option C is wrong because encryption of the forensic image is a separate process performed by imaging software (e.g., FTK Imager, dd with encryption) or hardware encryptors, not by a write blocker. Option D is wrong because booting a suspect drive would inherently write temporary system files, logs, and swap data to the drive, which a write blocker is designed to prevent; a write blocker cannot allow booting without altering data because the operating system must write to the drive during boot.
During a forensic investigation, an examiner wants to recover deleted files from a FAT32 file system. Which structure is most critical for file recovery?
A.File Allocation Table (FAT)
B.Master File Table (MFT)
C.Journal
D.Inode table
AnswerA
The File Allocation Table is the core metadata structure of FAT32, storing a linked list of cluster numbers (cluster chains) for every file. When a file is deleted, its directory entry is marked with byte 0xE5 but the associated FAT cluster chain is often left intact until those clusters are reused, and the directory entry still contains the starting cluster and file size. By reading the starting cluster and following the FAT chain to the end-of-chain marker, forensic tools can reassemble the deleted file's data clusters back into a contiguous stream for recovery.
Why this answer
In FAT32, the File Allocation Table (FAT) is the primary structure that tracks cluster allocation chains for files. When a file is deleted, the directory entry is marked as available, but the FAT entries (cluster chains) often remain intact until overwritten, making the FAT the most critical structure for recovering deleted files by reconstructing their cluster sequences.
Exam trap
The CHFI exam often tests the misconception that all file systems use a similar metadata structure (like MFT or inode tables), leading candidates to confuse FAT32 with NTFS or ext-based systems, when in fact FAT32 relies solely on the File Allocation Table for cluster chain recovery.
How to eliminate wrong answers
Option B (Master File Table) is wrong because MFT is specific to NTFS, not FAT32; FAT32 uses directory entries and the FAT, not an MFT. Option C (Journal) is wrong because FAT32 does not have a journaling feature; journaling is found in NTFS (USN journal) or ext3/ext4, not in FAT32. Option D (Inode table) is wrong because inode tables are used in Unix/Linux file systems like ext2/ext3/ext4, not in FAT32.
An analyst captures network traffic during an incident and wants to extract files transferred over HTTP. Which Wireshark feature is BEST suited for this task?
A.Follow TCP Stream
B.Statistics > HTTP
C.Export Objects > HTTP
D.Analyze > Expert Info
AnswerC
Export Objects > HTTP is the correct method: Wireshark parses the HTTP conversations in the capture, reassembles the response bodies, handles chunked transfer-encoding and content-encoding, and then presents each recovered object as an individual file ready to be saved. This directly recovers binaries, documents, images, or any other file that was transferred over HTTP, providing the actual artifact for forensic analysis and hash comparison.
Why this answer
Wireshark's 'Export Objects > HTTP' feature is specifically designed to extract files (e.g., images, documents, executables) transferred over HTTP by reassembling the TCP streams and parsing the HTTP response bodies. This feature automates the extraction process, saving the analyst from manually reconstructing each file from raw packets.
Exam trap
The trap here is that candidates confuse 'Follow TCP Stream' (which shows raw data) with a file extraction tool, not realizing that 'Export Objects > HTTP' is the dedicated feature for extracting files from HTTP traffic in Wireshark.
How to eliminate wrong answers
Option A is wrong because 'Follow TCP Stream' only displays the raw ASCII or hex dump of a single TCP session's payload, requiring manual extraction and reconstruction of files from the stream data, which is inefficient for multiple files. Option B is wrong because 'Statistics > HTTP' provides aggregate metrics like request/response counts, methods, and hostnames, but does not extract or export file content. Option D is wrong because 'Analyze > Expert Info' highlights protocol anomalies, errors, or warnings (e.g., malformed packets, retransmissions) and is not designed for file extraction.
During a forensic investigation, an analyst discovers that the suspect's hard drive was encrypted using BitLocker. The analyst has obtained the recovery key. Which of the following is the best next step to ensure data integrity?
A.Decrypt the drive using the recovery key and then create a forensic image.
B.Run a live analysis tool to extract encryption keys from memory.
C.Create a forensic image of the encrypted drive, then decrypt the image.
D.Boot the suspect computer and copy files to an external drive.
AnswerC
Creating a bit-for-bit forensic image of the encrypted drive before any decryption preserves the original evidence in its native state, capturing the full encrypted volume, partition table, free space, and deleted data remnants. The analyst can then decrypt that image on a write-protected or isolated forensic workstation using the known recovery key or extracted keys, leaving the original exhibit untouched and maintaining chain of custody. This workflow is the accepted standard for full-disk-encrypted evidence because it separates acquisition from decryption and permits multiple independent analyses.
Why this answer
Creating a forensic image of the encrypted drive before decryption preserves the original evidence in its pristine, unaltered state. Decrypting the image later using the recovery key ensures that the original encrypted data remains intact and verifiable, maintaining data integrity throughout the investigation.
Exam trap
EC-Council often tests the principle that forensic imaging must occur before any decryption or analysis to preserve evidence integrity, and candidates mistakenly believe decryption first is acceptable because they have the key.
How to eliminate wrong answers
Option A is wrong because decrypting the drive directly on the original hardware modifies the data and metadata, breaking the chain of custody and potentially altering evidence. Option B is wrong because running a live analysis tool to extract encryption keys from memory is unnecessary when the recovery key is already obtained, and live acquisition risks modifying the system state and compromising integrity. Option D is wrong because booting the suspect computer and copying files to an external drive alters the original media and does not create a bit-for-bit forensic image, violating forensic best practices.
During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. Which of the following is the PRIMARY reason for using a write blocker?
A.To allow the suspect drive to be mounted as read-write for analysis
B.To decrypt the drive automatically without the key
C.To prevent any modification to the suspect drive during acquisition
D.To speed up the imaging process by caching writes
AnswerC
A hardware write blocker intercepts and blocks write commands at the interface level, so the drive remains unaltered while the analyst images it. This preserves evidential integrity, satisfying the forensic requirement that acquisition never modify the suspect drive's original content.
Why this answer
The primary reason for using a hardware write blocker is to ensure that the suspect drive is connected in a read-only manner, preventing any write operations from the forensic workstation from reaching the drive. This preserves the integrity of the evidence by guaranteeing that no data is altered, added, or deleted during the acquisition process, which is a fundamental requirement for admissibility in legal proceedings.
Exam trap
EC-Council often tests the misconception that write blockers are used to speed up imaging or that they provide some form of decryption, when in fact their sole purpose is write prevention for evidence integrity.
How to eliminate wrong answers
Option A is wrong because a write blocker forces the drive to be read-only, not read-write; mounting as read-write would risk modifying evidence. Option B is wrong because write blockers do not perform decryption; they only block write commands at the hardware level and have no capability to decrypt drives without the key. Option D is wrong because write blockers do not cache writes or speed up imaging; in fact, they add a slight overhead by intercepting and blocking write commands, and caching writes would contradict the goal of preventing modification.
A forensic analyst is examining a Docker container that was used to launch a DDoS attack. Which layer of a Docker image is most likely to contain the attacker's malicious scripts?
A.The overlay filesystem layer
B.The topmost writable container layer
C.The volume mounted from the host
D.The base image layer
AnswerB
The topmost writable container layer, also called the 'container layer' or 'upperdir' in overlayfs terms, is where all runtime modifications are recorded. When a container creates, deletes, or alters files, those changes are written here using copy-on-write, making it the primary location for malicious scripts planted during execution. This layer is ephemeral and typically destroyed with the container unless it is explicitly preserved via docker commit or docker export, so forensic collection must target this layer for runtime tampering.
Why this answer
Docker images consist of read-only layers. The topmost writable layer (container layer) holds changes made at runtime, such as installing tools or scripts. The attack scripts would be in this layer.
A security analyst discovers a suspicious registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate. The key points to a file in AppData. What is the most likely purpose of this registry key?
A.It logs the user's keystrokes
B.It ensures the malware runs every time the user logs in
C.It is a legitimate Windows update configuration
D.It stores the malware's configuration settings
AnswerB
HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard per-user autostart location. When a user signs in, the Winlogon/userinit process reads every value under this key and executes the associated command line. Malware writes a value pointing to its executable in AppData so the payload is relaunched automatically on every successful login, establishing persistence.
Why this answer
The registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard Windows autostart location. Malware commonly adds an entry here to achieve persistence, ensuring it executes every time the user logs in. The suspicious name 'WindowsUpdate' is a common masquerade tactic to hide malicious intent.
Exam trap
The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and actual malware functionality; the trap here is assuming the key name 'WindowsUpdate' implies legitimate system behavior, when in fact it is a classic masquerade technique.
How to eliminate wrong answers
Option A is wrong because keystroke logging is a specific function of malware, not a property of the Run registry key itself; the key only specifies an executable to launch. Option C is wrong because legitimate Windows Update configuration is stored in system-level registry paths (e.g., HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate) and never in HKCU\...\Run. Option D is wrong because the Run key stores a command line to execute a program, not configuration settings; malware configuration is typically stored in separate files or other registry keys.
During a forensic investigation, an analyst creates a forensic image using `dcfldd` with the command: `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=10M`. What is the purpose of the `hashwindow` parameter?
A.It limits the total amount of data to hash to 10 MB
B.It creates a hash for every 10 MB block of data
C.It sets the hash algorithm to SHA-256
D.It enables error correction for every 10 MB
AnswerB
With `hashwindow=10M`, dcfldd computes an independent hash value for every 10 MB block of input, allowing the analyst to verify each segment individually rather than relying solely on a single whole-file digest. This block-wise hashing is crucial for large forensic images because it pinpoints exactly which 10 MB region has changed or become corrupted, enabling targeted re-acquisition or analysis. It does not alter the total data processed, and the root hash over the entire stream may still be generated simultaneously if requested.
Why this answer
The `hashwindow` parameter in `dcfldd` specifies the size of the data chunks for which individual hash values are computed. With `hashwindow=10M`, the tool generates a SHA-256 hash for every 10 MB block of the input data, allowing verification of integrity on a per-block basis rather than only a single hash for the entire image. This is useful for detecting corruption or tampering in specific segments of large forensic images.
Exam trap
EC-Council often tests the distinction between parameters that set the hash algorithm (`hash=`) versus those that control hash granularity (`hashwindow`), leading candidates to confuse `hashwindow` with limiting the total data or enabling error correction.
How to eliminate wrong answers
Option A is wrong because `hashwindow` does not limit the total amount of data to hash; it defines the block size for per-block hashing, and the entire input is still processed. Option C is wrong because the hash algorithm is set by the `hash=sha256` parameter, not by `hashwindow`. Option D is wrong because `hashwindow` does not enable error correction; it only controls the granularity of hash computation, and `dcfldd` does not provide built-in error correction for data blocks.
During a forensic investigation of a compromised web server, you find the following entry in the IIS log: 192.168.2.50, -, 10/Jan/2023, 14:32:15, W3SVC1, WEB01, 192.168.2.10, 80, POST, /uploads/shell.aspx, 200, 0, 0, 513, 0, Mozilla/4.0. Which action should the investigator prioritize?
A.Rebuild the web server from a clean backup
B.Analyze the uploaded shell.aspx file for malicious content
C.Delete the shell.aspx file immediately
D.Check the web server's firewall logs for the attacker's IP
AnswerB
Analyzing the uploaded shell.aspx file is the most direct and probative step because it's an active web shell that confirms a successful exploitation and defines the attacker's capabilities. Static analysis (e.g., extracting strings, decoding obfuscated payloads) and dynamic analysis in a sandbox reveal command-and-control channels, file exfiltration methods, and any additional backdoors the shell installs. This knowledge is essential for both attribution and full remediation.
Why this answer
The IIS log entry shows a successful POST (HTTP 200) to /uploads/shell.aspx, which is a classic indicator of a web shell upload. The investigator's priority is to analyze the uploaded file to determine its capabilities, persistence mechanisms, and any data exfiltration or lateral movement it may have enabled. This aligns with forensic best practices: preserve and examine the artifact before taking remediation steps.
Exam trap
EC-Council often tests the misconception that immediate remediation (deletion or rebuild) is the correct first step, but forensic methodology demands artifact preservation and analysis before any destructive action.
How to eliminate wrong answers
Option A is wrong because rebuilding the server from a clean backup destroys volatile evidence (e.g., the shell.aspx file, memory artifacts, and recent log entries) before analysis is complete, violating forensic preservation principles. Option C is wrong because deleting the shell.aspx file immediately destroys the primary artifact needed for attribution, reverse engineering, and understanding the attacker's methods; it also does not address potential persistence mechanisms like scheduled tasks or registry modifications. Option D is wrong because the attacker's IP (192.168.2.50) is already present in the IIS log, and firewall logs may not provide additional actionable information at this stage; the priority is to analyze the uploaded payload, not to chase an IP that could be spoofed or a proxy.
File slack, also known as cluster slack, is exactly the unused portion of the last cluster assigned to a file. When a file's logical size is not an exact multiple of the cluster size, the file system allocates a full cluster but only writes data up to the end of the file, leaving the remaining bytes in that cluster uninitialized. This residual space is significant in digital forensics because it may contain remnants of previously deleted files or other data that were not overwritten by the current file's content.
Why this answer
Slack space is the unused portion of the last cluster allocated to a file. When a file does not exactly fill its final cluster, the remaining bytes in that cluster are slack space, which can contain remnants of previously deleted data. This is a critical area in file system forensics because it may hold hidden evidence.
Exam trap
EC-Council often tests the distinction between slack space and unallocated space; the trap is that candidates confuse the unused portion of a file's last cluster (slack) with free space on the disk (unallocated), leading them to pick Option D.
How to eliminate wrong answers
Option A is wrong because the file system journal (e.g., NTFS $LogFile or ext3/4 journal) is a dedicated area for metadata changes and transaction logs, not the unused tail of a file's last cluster. Option C is wrong because the Master Boot Record (MBR) occupies the first 512 bytes of a disk (sector 0) and is a boot structure, not related to cluster-level slack. Option D is wrong because space between partitions is called partition gap or unallocated space, which exists at the disk level, not within a file's allocated cluster.
Which tool is specifically designed to analyze email headers and track the path of an email across multiple servers?
A.Aid4Mail
B.EmailTracker
C.Wireshark
D.FTK Imager
AnswerB
EmailTracker is a purpose-built utility for parsing email message headers and reconstructing the delivery path from sender to recipient. It extracts each Received: header, maps the originating IP address, identifies intermediary mail servers and time zones, and surfaces anomalies such as forged headers or mismatches among SPF, DKIM, and DMARC results. This automated route visualization is exactly what 'analyzing email headers' means in an investigative context.
Why this answer
EmailTracker is a web-based tool that parses email headers and visualizes the route. Aid4Mail is for forensic acquisition/analysis. Wireshark captures network packets.
An organization suspects a stealthy malware infection on a critical server. Traditional antivirus and EDR solutions have not detected anything. Which forensic approach would be most effective in identifying the malware, given that it likely resides only in memory?
A.Perform a full disk scan with updated antivirus signatures
B.Acquire a memory dump and perform memory forensics with tools like Volatility
C.Conduct a live analysis using built-in Windows tools like Task Manager
D.Analyze network traffic for anomalies using a NetFlow analyzer
AnswerB
Acquiring a memory dump and analyzing it with Volatility is the correct approach because it preserves the volatile state where fileless malware resides, capturing the actual code, injected processes, and hooked kernel structures. Memory forensics allows investigators to enumerate running processes, inspect process memory and VAD trees, and extract indicators that would be lost on reboot, providing the most direct evidence of the infection.
Why this answer
The malware resides only in memory, making it invisible to disk-based scans. Memory forensics with tools like Volatility allows investigators to analyze RAM artifacts (e.g., processes, network connections, injected code) to detect stealthy malware that never writes to disk.
Exam trap
The CHFI exam often tests the misconception that live analysis tools (like Task Manager or Process Explorer) are sufficient for detecting memory-resident malware, but they fail to reveal hidden or injected code that only memory forensics can uncover.
How to eliminate wrong answers
Option A is wrong because a full disk scan with updated antivirus signatures targets files on disk, but the malware is memory-resident and never written to disk, so it will not be detected. Option C is wrong because live analysis using built-in Windows tools like Task Manager provides only a high-level view of processes and cannot reveal hidden or injected code, rootkits, or kernel-level artifacts that require deep memory structure parsing. Option D is wrong because analyzing network traffic with a NetFlow analyzer can show anomalous communication patterns but cannot directly identify malware that resides only in memory; it lacks the ability to inspect process memory, loaded modules, or code injection.
An analyst is preparing to analyze a RAID 5 array of three disks. The analyst wants to reconstruct the logical volume for file system analysis. Which THREE steps are essential in this process?
Select 3 answers
A.Use a tool like `mdadm` (Linux) or RAID reconstructor (Windows) to assemble the array
B.Zero out the first sector of each disk to remove remnants of previous arrays
C.Determine the disk order and stripe size
D.Identify the parity rotation method (left-symmetric, etc.)
E.Run `chkdsk` on each individual disk before reconstruction
AnswersA, C, D
RAID 5 forensic analysis requires rebuilding the logical volume from the member disk images; `mdadm` can assemble the array by reading on-disk superblocks, while tools like RAID Reconstructor automate the cross-drive stripe and parity calculation. Simply imaging each disk separately leaves the filesystem fragmented across all three drives, so the examiner must first combine the disks into a coherent logical device before mounting or parsing the filesystem for evidence.
Why this answer
The essential first step is to assemble the RAID 5 set from the member disks using a tool such as mdadm on Linux or a RAID reconstructor on Windows, because the logical volume must be presented to the OS before file system analysis can occur (A). Before assembly, the analyst must determine the disk order and stripe (chunk) size, since RAID 5 distributes data across all members in a specific sequence and wrong parameters yield an unreadable volume (C). The analyst must also identify the parity rotation method (e.g., left-symmetric, right-asymmetric), because parity placement determines how each stripe's data and parity blocks are arranged and must match the original configuration (D).
Zeroing the first sector (B) is destructive and unnecessary, as it would erase metadata needed for reconstruction, and running chkdsk on individual member disks (E) is invalid because each disk holds only fragments of the file system, not a complete volume.
Exam trap
EC-Council often tests the misconception that you must run file system repair tools (like `chkdsk`) on individual disks before reconstruction, but this is incorrect because those tools require a logical volume and can corrupt the RAID metadata.
A security analyst detects that a system's 'SeDebugPrivilege' is enabled for a suspicious process. Which technique is the malware MOST likely attempting to use?
A.Persistence through service
B.Anti-debugging
C.Network sniffing
D.Process injection
AnswerD
SeDebugPrivilege is a high-impact privilege that permits a process to obtain full access to other processes, including those running at higher integrity levels. Attackers commonly use it to enable process injection: with this privilege, they can call OpenProcess(PROCESS_ALL_ACCESS) on a victim process, then use WriteProcessMemory and CreateRemoteThread to inject and execute malicious code. The privilege is often present in admin or SYSTEM token but disabled by default, meaning the attacker must call AdjustTokenPrivileges to enable it before injection. This requirement directly explains why a security analyst would observe SeDebugPrivilege being manipulated in conjunction with process injection.
Why this answer
SeDebugPrivilege allows a process to debug other processes, including accessing and modifying their memory. Malware often enables this privilege to perform process injection, where malicious code is written into the memory of a legitimate process (e.g., via WriteProcessMemory and CreateRemoteThread) to evade detection and execute under the target process's context.
Exam trap
EC-Council often tests the misconception that SeDebugPrivilege is only for debugging or anti-debugging, but the exam trap is that it directly enables process injection and memory manipulation, not just debugging tools.
How to eliminate wrong answers
Option A is wrong because persistence through service typically involves creating or modifying Windows services (e.g., via sc.exe or registry keys like HKLM\SYSTEM\CurrentControlSet\Services), not enabling SeDebugPrivilege. Option B is wrong because anti-debugging techniques (e.g., IsDebuggerPresent, NtQueryInformationProcess) aim to prevent analysis, not leverage a debug privilege for code execution. Option C is wrong because network sniffing requires raw socket access or WinPcap/Npcap, not SeDebugPrivilege, which is a security privilege for process debugging.
A forensic investigator is analyzing a USB drive formatted with FAT32 and finds that a deleted file's directory entry still exists but the first character of the filename is replaced with 0xE5. What does this indicate?
A.The file is marked as hidden
B.The file has been deleted
C.The file is encrypted
D.The file is fragmented
AnswerB
When a file is deleted in a FAT file system, the first character of its 8.3 directory entry is overwritten with 0xE5, which is the standard deletion marker. This byte serves as a tombstone so the operating system knows the entry is free for new file allocation while the remaining cluster chain and directory fields stay intact until reused. Forensic analysts rely on this marker to identify deleted files and recover data by parsing the rest of the entry, including the starting cluster value and file size, making 0xE5 a direct indicator of prior deletion.
Why this answer
In FAT32 file systems, when a file is deleted, the first byte of its directory entry's filename is replaced with the hexadecimal value 0xE5 (which displays as a lowercase sigma 'σ' in some viewers). This is the standard deletion marker for FAT file systems, indicating that the file's directory entry is available for reuse. The presence of 0xE5 in the first character position specifically signifies deletion, not any other attribute or state.
Exam trap
Candidates often confuse the 0xE5 deletion marker with file attribute flags (e.g., hidden, system). In FAT32, 0xE5 in the first character of the filename indicates deletion, not a file attribute. Attribute bytes are separate in the directory entry.
How to eliminate wrong answers
Option A is wrong because the hidden attribute is controlled by a specific bit in the file attribute byte (bit 1, value 0x02) within the directory entry, not by overwriting the first character of the filename with 0xE5. Option C is wrong because FAT32 does not support native file encryption; encryption would be handled by an external tool or the OS (e.g., EFS on NTFS) and would not be indicated by a 0xE5 marker. Option D is wrong because fragmentation is a condition where a file's clusters are non-contiguous, tracked in the FAT table via cluster chains, and is not indicated by the 0xE5 byte in the directory entry.
During static analysis of a PE file, an analyst uses PEiD and detects the signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What should the analyst do next?
A.The file is clean; no further analysis needed
B.Unpack the file using a UPX unpacker or manual unpacking
C.Delete the file as it is definitely malware
D.Run the file in a sandbox immediately
AnswerB
Because UPX modifies the PE structure and replaces the original entry point with an unpacking stub, the file must first be unpacked to recover the original code for static analysis. If the sample retains a standard UPX header, running `upx -d` can restore it; otherwise, manual unpacking (e.g., OEP tracing via the pushad/popad pair, memory dump, and import reconstruction with Scylla or ImportREC) is required. Only then can strings, imports, and code logic be truly analyzed.
Why this answer
The signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' indicates the file is packed with UPX (Ultimate Packer for eXecutables). Packing is a common technique used by malware authors to obfuscate the original code and evade signature-based detection. The analyst must unpack the file using a UPX unpacker or manual unpacking to reveal the actual executable code for further static or dynamic analysis.
Exam trap
The CHFI exam often tests the misconception that a packer signature automatically indicates malware, when in fact packing is a legitimate software distribution technique and the analyst must unpack the file to determine its true nature.
How to eliminate wrong answers
Option A is wrong because the presence of a packer signature like UPX does not mean the file is clean; packing is often used to hide malicious code. Option C is wrong because deleting the file without analysis destroys potential evidence and may be premature—packed files can be legitimate software, and the analyst must verify. Option D is wrong because running a packed file in a sandbox may not reveal the true behavior, as the unpacking routine must execute first; static unpacking is the proper next step to obtain the unpacked binary for analysis.
A forensic analyst is examining a Windows 10 system and needs to view the Master File Table ($MFT) to identify recently deleted files. Which tool is most appropriate for parsing the $MFT directly?
A.Wireshark
B.John the Ripper
C.EnCase
D.Nmap
AnswerC
EnCase is a full forensic suite that acquires bit-for-bit images and exposes the underlying NTFS structures, including the Master File Table ($MFT), $LogFile, and $UsnJrnl, so an examiner can recover active and deleted files along with their timestamps, sizes, and parent paths. It performs file carving and signature analysis to reconstruct data from unallocated clusters, and it parses $MFT resident and non-resident data attributes to reassemble fragmented or partially overwritten records. This makes EnCase the appropriate choice when the goal is to examine and recover deleted artifacts from a Windows 10 system.
Why this answer
EnCase is a forensic suite that includes a dedicated parser for the Master File Table ($MFT) on NTFS volumes. It can directly read the raw $MFT file to recover metadata of deleted files, including their names, timestamps, and data runs, even after the directory entry is removed. This makes it the correct choice for examining the $MFT to identify recently deleted files.
Exam trap
EC-CHFI often tests the distinction between network analysis tools (Wireshark, Nmap) and password crackers (John the Ripper) versus forensic file system parsers, leading candidates to pick a familiar tool name without considering its actual function.
How to eliminate wrong answers
Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects packets on a network interface; it has no capability to parse local file system structures like the $MFT. Option B is wrong because John the Ripper is a password cracking tool that operates on hash files (e.g., /etc/shadow or LM/NT hashes), not on file system metadata or the $MFT. Option D is wrong because Nmap is a network scanning utility used for host discovery and port enumeration; it cannot read or interpret the $MFT on a local drive.
An investigator recovers a suspicious file from a compromised system. Using PEiD, the file is detected as 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What is the MOST appropriate next step in the analysis?
A.Delete the file as it is likely a false positive from a legitimate UPX-packed application.
B.Unpack the file using the UPX tool or manual unpacking to obtain the original executable.
C.Submit the packed file to VirusTotal to obtain a hash-based detection report.
D.Run the file in a sandbox without unpacking to observe dynamic behavior.
AnswerB
Unpacking is the correct next step because UPX is a reversible packer: the `upx -d` command can usually reconstruct the original executable, exposing the real code, import table, and resources for static analysis. Even if the UPX header is intentionally malformed or modified to resist automatic unpacking, a manual unpacking approach—using memory dumps, Scylla or ImpRec for import reconstruction—can recover the original logic. Analyzing the unpacked binary allows the investigator to identify malicious behavior without executing it, which is critical for understanding the threat and preserving integrity. This approach directly addresses the core investigative need to analyze the true payload, not just the packing stub.
Why this answer
The PEiD detection of 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' confirms the file is packed with UPX (Ultimate Packer for eXecutables). Packing obfuscates the original code and often evades static analysis. The most appropriate next step is to unpack the file using the UPX tool (with the -d switch) or manual unpacking to recover the original executable for deeper static and dynamic analysis.
Exam trap
EC-Council often tests the misconception that a packer detection alone indicates a false positive or that dynamic analysis without unpacking is sufficient, when in fact unpacking is the foundational step to reveal the true executable for both static and dynamic analysis.
How to eliminate wrong answers
Option A is wrong because deleting the file based solely on a UPX packer detection is premature; UPX is commonly used by malware to compress and obfuscate code, and a legitimate application does not preclude malicious intent. Option C is wrong because submitting the packed file to VirusTotal may yield a hash that differs from the unpacked malware, potentially missing detection signatures that rely on the unpacked code. Option D is wrong because running the packed file in a sandbox without unpacking may cause the unpacking stub to execute and then the malware to run, but the packed state prevents proper static analysis and may not trigger all dynamic behaviors if the unpacking fails or is environment-aware.
A security analyst is reviewing the output from a forensic tool examining an iOS Keychain. The analyst finds an entry with the attribute 'kSecAttrAccessible' set to 'kSecAttrAccessibleWhenUnlockedThisDeviceOnly'. What does this indicate?
A.The item is backed up to iCloud and can be restored to another device
B.The item is accessible even when the device is locked
C.The item is only accessible when the device is unlocked and is not backed up to iCloud
D.The item is stored in the Secure Enclave and cannot be extracted
AnswerC
This is the accurate reading of kSecAttrAccessibleWhenUnlockedThisDeviceOnly: it couples a time-based access gate (only after device unlock) with a device-scoped protection boundary (no iCloud backup and no restoration to another device). Keychain items with this attribute are available to apps only while the user has unlocked the device, and they do not appear in encrypted backups. A forensic examiner needs the unlocked device or the passcode to obtain the item.
Why this answer
The attribute 'kSecAttrAccessibleWhenUnlockedThisDeviceOnly' in iOS Keychain indicates that the item can only be accessed when the device is unlocked and is not included in any backup (iCloud or iTunes). This is because the 'ThisDeviceOnly' suffix ties the encryption key to the device's UID, preventing migration to another device or restoration from backup. Option C correctly captures both conditions: accessibility only when unlocked and exclusion from backups.
Exam trap
EC-Council often tests the misconception that 'ThisDeviceOnly' only affects backup behavior, when in fact it also prevents restoration to another device, and candidates may confuse 'WhenUnlocked' with 'AfterFirstUnlock' or 'Always', which have different lock-state requirements.
How to eliminate wrong answers
Option A is wrong because 'ThisDeviceOnly' explicitly prevents the item from being backed up to iCloud or restored to another device; only items without that suffix can be migrated. Option B is wrong because 'WhenUnlocked' means the item is only accessible when the device is unlocked, not when locked; the 'kSecAttrAccessibleWhenUnlocked' class requires the device to be unlocked for decryption. Option D is wrong because the Keychain item is encrypted with a key derived from the device's UID and the user's passcode, but it is not stored in the Secure Enclave; the Secure Enclave handles cryptographic operations but does not store Keychain items directly.
An analyst examining an Outlook PST file wants to recover deleted emails that are no longer visible in the Deleted Items folder. Which technique is MOST effective?
A.Convert the PST to an EDB file and mount it
B.Repair the PST file using Scanpst.exe
C.Reconstruct the PST from the Exchange server backup
D.Use a forensic tool to carve for deleted items within the PST
AnswerD
Forensic carving scans the raw PST byte stream for known message property tags, signature patterns, and header structures that remain in unallocated blocks after logical deletion. Because deleting an item typically only marks its B-tree entries as free rather than scrubbing the underlying data, tools can reassemble deleted emails directly from the PST's free space and slack. This bypasses the file's logical index, which is exactly why it is the only listed option capable of recovering permanently deleted items.
Why this answer
Deleted emails in PST files are often not immediately overwritten. Using forensic tools to scan the PST file for unallocated space or deleted items can recover them.
A security analyst is investigating a phishing email and notices the DKIM-Signature header is present but fails validation. Which TWO actions should the analyst take?
Select 2 answers
A.Ignore the DKIM failure as it is not important
B.Check the DKIM DNS record for the signing domain
C.Reply to the sender to verify authenticity
D.Examine the Received headers for spoofing clues
E.Delete the email immediately
AnswersB, D
The correct forensic step is to query the DNS TXT record for the selector and signing domain using tools like dig or nslookup, then use that public key to cryptographically verify the DKIM signature in the email headers. If the key is missing, expired, or does not match, this confirms the failure is due to a real spoofing attempt or misconfiguration. This validation is objective and reproducible, unlike replying or deleting evidence.
Why this answer
DKIM failure indicates the email may be forged or tampered with. Checking the domain's DKIM DNS record and examining the email headers for other spoofing indicators are appropriate steps.
Which THREE of the following are common indicators of a web shell on a compromised web server? (Select THREE.)
Select 3 answers
A.Presence of .htaccess files with rewrite rules
B.Files with obfuscated code (e.g., base64 encoded strings)
C.Files located in web-accessible directories (e.g., /uploads) with execute permissions
D.High number of 404 errors in access logs
E.Unusual HTTP POST requests with large payloads to a single script
AnswersB, C, E
Files containing obfuscated code, such as base64-encoded strings wrapped in eval(), gzinflate(), or str_rot13(), are a strong indicator of a web shell because legitimate web applications rarely need to obscure their logic. Obfuscation is deliberately used to hide malicious payloads from static signature-based scanners and to complicate manual inspection. The presence of such encoding in an unexpected file under a web-accessible directory—especially in upload folders—strongly suggests an attacker is trying to evade detection and maintain remote access.
Why this answer
Option B is correct because web shells are frequently hidden by obfuscating their PHP/JSP/ASP code with base64-encoded strings, gzinflate, eval, or similar encoding tricks to evade signature-based detection. Option C is correct because attackers commonly drop web shell files into writable, web-accessible directories such as /uploads or /images and set execute permissions so the web server can run them via HTTP. Option E is correct because a web shell typically receives commands through HTTP POST requests carrying unusually large or repeated payloads to a single script, which is a strong behavioral indicator in access logs.
Option A is not a reliable indicator, since .htaccess files with rewrite rules are a normal, legitimate part of Apache configuration and are used for many benign purposes. Option D is not a reliable indicator either, because a high number of 404 errors usually reflects broken links, scanning noise, or misconfiguration rather than a web shell specifically.
Exam trap
A common trap is to view .htaccess rewrite rules as inherently malicious, but they are a standard Apache feature; the trap is confusing legitimate configuration with attack indicators, leading candidates to select Option A incorrectly.
Which Windows Event ID is generated when a new service is installed on a system, and is often used by malware to establish persistence?
A.4624
B.4648
C.7045
D.4720
AnswerC
Event 7045 is the correct event because it is the Service Control Manager (SCM) event logged in the System event log whenever a new service is installed on the system. This event captures critical persistence indicators, including the service name, image file path, service type, and start type, making it a primary focus for forensic analysts investigating malware that establishes persistence by registering itself as a service. Unlike the Security log events in the other options, 7045 directly maps to the act of creating a service and appears during both legitimate software installs and malicious service creation.
Why this answer
Event ID 7045 is generated by the Windows Service Control Manager (SCM) when a new service is installed on the system. Malware often uses this event to establish persistence by creating a service that automatically starts, and forensic analysts look for 7045 events to detect unauthorized service installations.
Exam trap
The EC-CHFI exam often tests the distinction between Event IDs related to authentication (4624, 4648) and those related to system configuration changes (7045), so candidates may confuse logon events with service installation events.
How to eliminate wrong answers
Option A is wrong because Event ID 4624 indicates a successful logon to the system, not a service installation. Option B is wrong because Event ID 4648 logs explicit credential usage (e.g., RunAs), not service creation. Option D is wrong because Event ID 4720 tracks user account creation in Active Directory, not service installation.
Which Windows registry hive stores user-specific configuration and is loaded when a user logs in, containing artifacts such as recently accessed files and application settings?
A.SECURITY
B.NTUSER.DAT
C.HKLM\SAM
D.SYSTEM
AnswerB
Each user profile has a NTUSER.DAT file that is loaded into the registry's HKEY_CURRENT_USER hive upon user logon. It stores registry keys and values specific to that user, such as desktop settings, environment variables, application preferences, and many forensic artifacts like recently used files, typed URLs, and application-specific data. This is exactly the per-user configuration store.
Why this answer
NTUSER.DAT is the registry hive that contains user-specific settings and is loaded into HKEY_CURRENT_USER upon logon. It includes UserAssist, MRU lists, and other user activity artifacts.
A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?
A.Photograph the scene and secure the area
B.Connect a write blocker and create a forensic image immediately
C.Immediately shut down the computer to prevent data alteration
D.Pull the power cord to ensure the system does not shut down normally
AnswerA
Documenting the scene through photographs and establishing a secure perimeter is the mandatory first step in digital forensics, as it creates a verifiable record of the original state of the computer, cables, and peripherals before any interaction. Securing the area prevents unauthorized personnel from touching the machine, which could alter timestamps, memory contents, or other volatile evidence. This step also grounds the chain of custody by showing exactly what was present when first responders arrived, and it should precede any hardware or software actions on the system.
Why this answer
The first priority at a live crime scene is to preserve the integrity of the scene and all potential evidence. Standard forensic procedure (e.g., from NIST SP 800-86 and ACPO guidelines) mandates that the first responder must photograph the scene to document the state of the computer (including screen contents, cables, and peripherals) and secure the area to prevent unauthorized access or tampering. Only after this documentation and scene stabilization can the responder proceed to handle the live system, such as capturing volatile data or creating a forensic image.
Exam trap
The trap here is that candidates often confuse the urgency of preserving volatile data with the need to immediately perform a live acquisition or shut down the system, forgetting that scene documentation and security are the foundational first steps in any forensic investigation.
How to eliminate wrong answers
Option B is wrong because connecting a write blocker and creating a forensic image immediately is a later step in the forensic process; the first responder must first document the scene and secure it to preserve the chain of custody and prevent evidence contamination. Option C is wrong because immediately shutting down the computer can destroy volatile data (e.g., RAM contents, network connections, running processes) and may trigger anti-forensic mechanisms or cause file system corruption; proper live acquisition should be performed first if the system is running. Option D is wrong because pulling the power cord (hard power-off) can cause data loss, file system corruption, and loss of volatile memory, and it bypasses the need to document the system state and capture live data; it should only be considered as a last resort when the system is actively being used to destroy evidence.
You are a forensic investigator responding to a data breach at a mid-sized company. The company uses a hybrid cloud environment with AWS for production workloads and on-premises servers for legacy applications. The breach was detected when an internal monitoring system flagged unusual outbound traffic from an AWS EC2 instance (i-0a1b2c3d4e5f) to an external IP address (198.51.100.20) on TCP port 4444 during off-hours. The EC2 instance runs a Linux-based web server. The security team has already isolated the instance by removing its security group rules and stopping the instance. You have been provided with the following: (1) AWS CloudTrail logs for the past 72 hours, (2) VPC Flow Logs for the same period, (3) a snapshot of the instance’s root volume (EBS), and (4) the instance metadata log from the AWS console. The company’s incident response policy requires preservation of all volatile data before powering off the instance. Which of the following steps should you take FIRST to ensure a forensically sound investigation?
A.Acquire a memory dump from the stopped instance by re-attaching the root volume to a forensic workstation.
B.Review the instance metadata log to identify the user who launched the instance.
C.Create a forensic copy of the EBS snapshot and attach it to a separate analysis EC2 instance in a different AWS account to avoid altering evidence.
D.Analyze the VPC Flow Logs to determine if other instances communicated with the same external IP.
AnswerC
Creating a forensic copy of the EBS snapshot and attaching that copy to a separate EC2 instance in a different AWS account is the correct first preservation step because the snapshot is the only durable disk evidence of the compromised instance. Attaching the original snapshot to an analysis instance—even read-only—risks unwitting writes from filesystem journal replay, and operating in the same account risks accidental modification or deletion. A copied snapshot in an isolated account grants a clean, authority-controlled workspace where forensic tools cannot alter the original evidence.
Why this answer
The first step in a forensically sound investigation is to create a forensic copy (bit-for-bit) of the EBS snapshot before any analysis. This preserves the original evidence integrity, as required by the order of volatility and chain of custody. Attaching the copy to a separate analysis EC2 instance in a different AWS account prevents accidental modification of the original snapshot and isolates the forensic environment from the compromised production account.
Exam trap
The trap here is that candidates confuse volatile data preservation with the need to acquire memory from a stopped instance (Option A), not realizing that stopping the instance already destroys RAM, and the snapshot only captures disk data.
How to eliminate wrong answers
Option A is wrong because the instance is already stopped, so volatile data (memory) is lost; re-attaching the root volume to a forensic workstation would not recover memory, and the snapshot is of the root volume, not RAM. Option B is wrong because reviewing the instance metadata log to identify the user who launched the instance is a non-forensic administrative step that does not preserve or acquire evidence; it should be done after securing the evidence. Option D is wrong because analyzing VPC Flow Logs is a valid investigative step, but it is not the first priority; the immediate need is to preserve the EBS snapshot evidence before any analysis that might alter or overlook the original data.
An analyst is examining a PCAP file in Wireshark and notices a series of TCP SYN packets sent to multiple ports on a single IP address, with no subsequent SYN-ACK replies. What type of network activity does this indicate?
A.A denial of service attack
B.A man-in-the-middle attack
C.A TCP handshake for normal connection establishment
D.A port scan attempting to identify open ports
AnswerD
This is a classic TCP SYN (half-open) scan, in which a scanner sends a SYN packet to each port and determines that a port is open if it receives a SYN-ACK response, while a RST indicates closed or filtered. Because the scanner immediately responds with an RST (or simply ignores the SYN-ACK) rather than completing the three-way handshake with an ACK, no full TCP connection is established, making this a quick and stealthy method for mapping open services. The pcap will show many SYN → SYN-ACK → RST sequences, with the scanner never sending the final ACK that would complete a legitimate connection.
Why this answer
Sending SYN packets to many ports without receiving SYN-ACKs indicates a port scan, likely a TCP SYN scan, to discover open ports.
A forensic investigator is documenting evidence for a case. What is the PRIMARY purpose of maintaining an unbroken chain of custody for digital evidence?
A.To track the storage location of the evidence.
B.To prove that the evidence has not been altered or tampered with.
C.To speed up the investigation process.
D.To assign responsibility for the evidence to a single individual.
AnswerB
An unbroken chain of custody records every transfer, handler and storage location of the evidence from seizure to court. This documentation proves the evidence has not been altered or tampered with, satisfying the requirement to demonstrate its integrity and admissibility throughout the investigation.
Why this answer
The primary purpose of maintaining an unbroken chain of custody is to establish the integrity and authenticity of digital evidence by documenting every person who handled it, every transfer, and every access event. This documentation allows the court to verify that the evidence has not been altered, tampered with, or corrupted from the moment of seizure through analysis and presentation. Without a provable chain of custody, the evidence may be deemed inadmissible under rules like Federal Rule of Evidence 901 or similar standards in other jurisdictions.
Exam trap
EC-Council often tests the distinction between the operational benefit (tracking location) and the legal purpose (proving integrity), so candidates mistakenly choose Option A because they focus on the logistical aspect rather than the evidentiary admissibility requirement.
How to eliminate wrong answers
Option A is wrong because tracking the storage location is only a secondary benefit of chain-of-custody documentation, not its primary legal purpose; the core goal is to prove integrity, not merely to log physical or logical locations. Option C is wrong because maintaining a rigorous chain of custody often slows down the investigation process due to required documentation, logging, and verification steps; it is designed for legal admissibility, not speed. Option D is wrong because chain of custody does not assign responsibility to a single individual; it documents every individual who handled the evidence, ensuring multiple points of accountability and preventing a single point of failure or bias.
A forensics investigator finds a suspicious LNK file on a Windows system that points to a script located on a remote share. What is the PRIMARY forensic significance of this LNK file?
A.It is evidence of USB device insertion.
B.It may be part of a lateral movement technique using remote execution.
C.It shows the user's recently accessed files.
D.It is a prefetch artifact indicating the script was executed.
AnswerB
This is the correct interpretation: an .lnk file that points to a remote share or contains a UNC path (e.g., \\attacker-server\payload\.scr) is a recognized lateral movement technique. Attackers use LNK shortcuts as bootstrap payloads delivered through PsExec, scheduled tasks, or WMI, where the shortcut is written to a target host and triggers remote execution of a malicious script or binary. The shortcut's TargetPath and Arguments fields are the forensic keys to identifying this behavior.
Why this answer
An LNK file pointing to a remote share is a classic indicator of lateral movement, often used in techniques like SMB-based remote execution or PsExec. The LNK file itself does not execute code, but when opened, it triggers the Windows shell to connect to the remote share and run the script, allowing an attacker to move from one system to another without dropping a binary on the target. This is a key forensic artifact for identifying network-based propagation in attacks such as ransomware or APT intrusions.
Exam trap
The trap here is that candidates confuse LNK files with Prefetch artifacts or assume all LNK files indicate user activity, when in fact an LNK targeting a remote share is a strong signal of lateral movement via SMB/remote execution, not local execution or USB history.
How to eliminate wrong answers
Option A is wrong because LNK files are not specific to USB insertion; USB device insertion is typically evidenced by USBSTOR registry keys, setupapi.dev.log, or PnP events, not by the presence of an LNK file pointing to a remote share. Option C is wrong because LNK files can indicate recently accessed files only if they are in the user's Recent folder (e.g., %APPDATA%\Microsoft\Windows\Recent), but this LNK points to a remote share, not a local file, and its primary significance is not user access history but potential malicious remote execution. Option D is wrong because Prefetch files (.pf) are created when an executable runs locally, not when a script is launched via an LNK file; the LNK file itself is not a Prefetch artifact, and execution of the script would generate a Prefetch for the script host (e.g., wscript.exe or cmd.exe) only if it runs locally, not from a remote share.
During a forensic investigation of a compromised Linux server, you find the following entry in /var/log/auth.log: 'Mar 10 03:14:15 server sshd[1234]: Accepted publickey for root from 10.0.0.5 port 54321 ssh2: RSA SHA256:AbCdEf123456'. Which artifact should you examine next to determine if unauthorized key-based access occurred?
A./var/log/syslog
B./etc/ssh/sshd_config
C.~/.ssh/authorized_keys
D./etc/passwd
AnswerC
~/.ssh/authorized_keys is a per-user file that stores the public keys (one key per line) that are permitted to log in as that user via SSH. When an attacker compromises a Linux server, a common persistence technique is to append their own public key to /root/.ssh/authorized_keys or another user's authorized_keys file, enabling silent passwordless access at any time. Checking this file for unrecognized keys — and correlating key hashes or comments with known legitimate admins — is direct evidence of key-based backdoor access, making it the correct file to examine in this scenario.
Why this answer
The log entry shows a successful public key authentication from root. To determine if this key-based access was unauthorized, you must examine the ~/.ssh/authorized_keys file for the root user. This file contains the public keys that are authorized to log in as root; if the key fingerprint SHA256:AbCdEf123456 is present, the access was legitimate; if absent, it indicates an unauthorized key was added by an attacker.
Exam trap
The trap here is that candidates may focus on the log entry itself or server configuration (sshd_config) instead of realizing that the authorized_keys file is the only place that records which keys are permitted, making it the direct source for verifying whether the key used was pre-authorized.
How to eliminate wrong answers
Option A is wrong because /var/log/syslog is a general system log that may contain similar entries but does not store the authorized public keys themselves; it would only duplicate the auth.log information without providing the key validation data. Option B is wrong because /etc/ssh/sshd_config controls SSH server settings (e.g., PermitRootLogin, PubkeyAuthentication) but does not list which specific keys are authorized; it cannot confirm whether a particular key was pre-authorized. Option D is wrong because /etc/passwd stores user account information (UID, GID, home directory, shell) but has no relation to SSH public key fingerprints or authorized_keys content.
You are investigating a network breach at a financial institution. The organization uses a network-based intrusion detection system (NIDS) and maintains full packet capture (PCAP) for critical segments. The incident allegedly started with a spear-phishing email that delivered a remote access trojan (RAT). The security team has isolated the infected host and provided you with a disk image of the host and a PCAP file covering the network traffic from the host for the 24-hour period before isolation. In the PCAP, you see a series of TCP connections from the host to an external IP address on port 443 (HTTPS). The external IP is known to be associated with a command-and-control (C2) server. However, the disk image shows no evidence of the RAT binary or any malicious files. The host's antivirus logs are clean. Which of the following is the most likely explanation for the lack of evidence on the disk?
A.The antivirus software deleted the malicious files before the image was taken
B.The hard drive was reimaged before the forensic image was taken
C.The RAT uses a rootkit to hide its files
D.The malware was fileless and only resided in memory
AnswerD
Fileless malware executes in volatile memory only, using legitimate tools like PowerShell, WMI, or .NET code, and never writes a persistent payload to the hard drive. Therefore a standard disk image, even a forensically sound one, will not contain the malicious code, as it lives entirely in RAM. To identify it, the investigator must capture and analyze memory (RAM) before the system is powered off; the absence of on-disk artifacts is the hallmark of this approach.
Why this answer
The absence of the RAT binary and any malicious files on the disk, combined with clean antivirus logs and active C2 traffic over HTTPS, strongly indicates a fileless malware infection. Fileless malware operates entirely in memory (RAM), never writing its payload to disk, which explains why the disk image shows no artifacts and why traditional file-scanning antivirus did not detect it. The TCP connections to the C2 server on port 443 are consistent with a memory-resident RAT that loads directly into a legitimate process (e.g., PowerShell, WMI, or a script interpreter) and communicates over encrypted HTTPS to evade network inspection.
Exam trap
EC-Council often tests the distinction between file-based and fileless malware, and the trap here is assuming that a rootkit (Option C) is the only way to hide files, when in fact fileless malware never writes files to disk at all, making rootkits unnecessary for evasion.
How to eliminate wrong answers
Option A is wrong because antivirus software typically quarantines or logs deleted files, and the scenario states antivirus logs are clean — if deletion had occurred, the logs would show a detection event. Option B is wrong because the question explicitly states the security team isolated the infected host and provided a disk image; if the drive had been reimaged, there would be no disk image to analyze, and the scenario would mention a reimage event. Option C is wrong because while rootkits can hide files from the operating system, they still leave traces on disk (e.g., in the Master File Table or alternate data streams) that forensic tools can detect, and the question says there is no evidence of any malicious files — not just hidden files.
An investigator is analyzing email headers and notices the following: The 'Received' headers show a path through multiple servers, the 'DKIM-Signature' domain matches the sender domain, and 'X-Originating-IP' is present. Which TWO pieces of information are MOST useful to trace the original sender's IP address? (Choose two.)
Select 2 answers
A.The 'Message-ID' header
B.The 'From' header email address
C.The DKIM-Signature's 'd=' domain
D.The X-Originating-IP header value
E.The last (bottommost) Received header's IP
AnswersD, E
The X-Originating-IP header records the IP the sending client supplied at submission, often surviving forwarding that rewrites Received chains. Where present and unspoofed, it exposes the originating host directly, satisfying the stem's need to trace the original sender's IP rather than intermediate relays.
Why this answer
The X-Originating-IP header (D) is the most direct artifact for tracing the sender, because it is typically inserted by the originating webmail or client and records the actual public IP address from which the message was submitted. The bottommost Received header (E) is also critical, since Received headers are prepended as the message traverses each hop, so the last (bottommost) entry reflects the earliest server that accepted the message and its connecting IP, which is closest to the true origin. Together, D and E let an investigator correlate the claimed client IP with the first-hop server's observed source address.
The Message-ID (A) is only a unique identifier generated by the sending system and contains no routable IP information. The From header (B) is trivially spoofable and only shows a claimed address, not the transmission source. The DKIM-Signature d= domain (C) identifies the signing domain for authentication but does not reveal the sender's IP address.
Exam trap
EC-Council CHFI often tests the distinction between headers that contain routing information (Received, X-Originating-IP) and those that contain metadata or authentication data (Message-ID, From, DKIM), leading candidates to mistakenly choose headers that are easily forged or unrelated to IP tracing.
An analyst is performing dynamic analysis of a malware sample in Cuckoo Sandbox. Which TWO of the following are typical indicators of command and control (C2) communication?
Select 2 answers
A.The malware creates a registry run key for persistence
B.The malware performs DNS queries to a domain that resolves to a known malicious IP
C.The malware modifies system files in C:\Windows\System32
D.The malware creates a mutex named 'Global\MyMutex'
E.The malware makes HTTP POST requests to a domain registered 2 days ago
AnswersB, E
DNS queries to a domain that resolves to a known malicious IP are a classic C2 beaconing signature because the malware must resolve the hostname of its command-and-control server before establishing a session. During dynamic analysis, repeated DNS lookups to a domain tied to a malicious address indicate that the sample is attempting to reach infrastructure controlled by the attacker. The reputation correlation of the resolved IP raises the confidence that this is C2 communication rather than unrelated background traffic.
Why this answer
Option B is correct because DNS queries to a domain resolving to a known malicious IP are a classic C2 indicator: the malware must locate its controller, and threat-intel feeds flag such resolutions as beaconing to adversary infrastructure. Option E is correct because HTTP POST requests to a newly registered domain (2 days old) fit the C2 profile of exfiltrating victim data or receiving tasking over web protocols, and domain age is a strong reputation signal for malicious infrastructure. Option A is not a C2 indicator but a persistence technique via the Registry Run key.
Option C describes system file modification, which indicates tampering or defense evasion rather than network C2. Option D describes mutex creation, which is typically used for single-instance checks or host-based sandbox-evasion markers, not command-and-control traffic.
Exam trap
EC-Council often tests the distinction between local host artifacts (persistence, mutexes, file modifications) and network-based C2 indicators, tricking candidates into selecting any suspicious behavior rather than focusing specifically on outbound communication patterns.
A malware analyst is analyzing a suspicious executable. Which THREE of the following are valid indicators of compromise (IoCs) that can be extracted from static analysis of the PE file? (Select THREE)
Select 3 answers
A.IP addresses from embedded strings
B.Registry keys modified during execution
C.MD5 hash of the file
D.File paths created during execution
E.List of imported DLLs and functions
AnswersA, C, E
IP addresses embedded in the binary are static indicators because a strings extraction (e.g., `strings` or `floss`) can reveal them directly from the file bytes without executing the sample. These addresses often point to hardcoded command-and-control servers, and can be correlated with threat-intel feeds or observed network traffic. The malware analyst can triage the sample purely from static artifacts, making this a valid static IoC.
Why this answer
Option A is correct because static analysis of a PE file routinely includes extracting embedded strings, and hardcoded IP addresses or URLs found in the binary are classic network-based IoCs that can be used for blocking and detection. Option C is correct because the MD5 hash of the file is a cryptographic file-based IoC computed directly from the sample without executing it, allowing analysts to pivot in threat-intelligence platforms and write hash-based detection rules. Option E is correct because the PE import table is parsed statically, and the list of imported DLLs and functions (e.g., CreateRemoteThread, VirtualAllocEx, WinINet APIs) reveals capabilities and is a valid host/behavioral IoC used in YARA and hunting rules.
Option B is not correct because registry keys modified during execution can only be observed through dynamic analysis (e.g., Procmon, Regshot), not from static inspection of the PE file. Option D is not correct because file paths created during execution are also runtime artifacts revealed by dynamic analysis or sandboxing, not extractable from the static structure of the executable.
Exam trap
EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse runtime artifacts (like registry or file system changes) with data extractable from the PE file itself without execution.
A forensic analyst is examining Azure Activity Logs for signs of privilege escalation. Which TWO of the following activities would be MOST indicative of an attacker attempting to escalate privileges? (Choose two.)
Select 2 answers
A.A user updating their own password
B.Deleting a resource group
C.Creation of a custom RBAC role with Owner permissions
D.Adding a user to the Global Administrator role
E.A user accessing a storage account they own
AnswersC, D
Creating a custom RBAC role with Owner permissions lets an attacker define a bespoke role carrying full control, bypassing detection tuned to built-in role assignments. The Activity Log records the role definition write, revealing deliberate privilege escalation rather than legitimate administrative change.
Why this answer
Option C is correct because creating a custom RBAC role that includes Owner-level permissions (for example, wildcard actions like "*" or "Microsoft.Authorization/*/write") is a classic privilege-escalation technique — the attacker grants themselves or an accomplice full control over a scope without using a built-in role, which is exactly the kind of activity a forensic analyst should flag. Option D is correct because adding a user to the Global Administrator role is a direct, high-impact elevation to the highest privileged directory role in Microsoft Entra ID, granting full control over all Azure subscriptions and tenant resources, and is one of the most reliable indicators of attempted privilege escalation. Option A is not indicative because users changing their own password is a routine self-service action that does not change their authorization level.
Option B is not indicative because deleting a resource group is a destructive/impact action, not an escalation of privileges. Option E is not indicative because accessing a storage account the user already owns is normal, authorized activity within their existing permissions.
Exam trap
EC-Council often tests the distinction between actions that are destructive (like deleting a resource group) versus actions that actually elevate privilege levels (like creating a custom role or adding a user to a high-privilege directory role).
During an iOS forensic examination, an analyst extracts the SMS.db file from an iTunes backup. Which table within this database contains the actual message content and associated metadata such as timestamps and sender/recipient information?
A.chat
B.message
C.attachment
D.handle
AnswerB
The 'message' table is the core target because each row represents a single SMS or iMessage, with columns such as 'text' (the message body), 'date' (absolute Unix time), 'is_from_me', and 'handle_id' linking to the sender. Logical forensic extraction typically includes this table to recover the actual words exchanged. Even when attachments or group metadata are involved, the text originates here, making it the correct choice.
Why this answer
The `message` table in SMS.db stores the actual message content (the `text` field) along with critical metadata such as `date` (Unix timestamp), `is_from_me` (sender/recipient indicator), and `handle_id` (foreign key to the `handle` table). This is the primary table for message body and timestamp data in iOS SMS/MMS forensics.
Exam trap
EC-Council often tests the distinction between the `message` table (content + timestamps) and the `handle` table (contact identifiers), leading candidates to confuse the `handle` table as containing message data when it only stores address book references.
How to eliminate wrong answers
Option A is wrong because the `chat` table stores conversation groupings (chat rooms) and references to messages via the `chat_message_join` table, not the message content itself. Option C is wrong because the `attachment` table stores metadata about file attachments (e.g., filename, MIME type, transfer state) but not the text content of messages. Option D is wrong because the `handle` table stores contact identifiers (phone numbers, email addresses) and their service types (iMessage, SMS), not the message body or timestamps.
A forensic examiner is analyzing a potentially malicious Portable Executable (PE) file recovered from a compromised host. The examiner uses PEStudio to inspect the file and notices that the Import Address Table (IAT) contains only two functions: LoadLibraryA and GetProcAddress. Which of the following does this most likely indicate?
A.The file is a legitimate system component that relies on dynamic linking for performance optimization.
B.The malware uses dynamic API resolution to hide its true capabilities from static analysis tools.
C.The malware is written in a high-level language such as C#, which compiles to a .NET assembly and has a minimal IAT.
D.The file is packed with a commercial packer, which automatically reduces the import table to these two functions.
AnswerB
When a PE file imports only LoadLibraryA and GetProcAddress, it indicates that the malware resolves other API functions at runtime. This technique, known as dynamic API resolution, evades static analysis because the actual functions used are not listed in the import table. Analysts must then resort to dynamic analysis or manual unpacking to uncover the full behavior of the sample.
Why this answer
A PE file that imports only LoadLibraryA and GetProcAddress is highly suspicious because it suggests the malware dynamically resolves other API calls at runtime. This technique hides the true functionality from static analysis, as the actual functions used are not visible in the import table. Investigators must use dynamic analysis or memory forensics to reveal the full behavior.
This is a common evasion tactic in malware.
Exam trap
The trap here is assuming that a minimal import table is due to packing or a legitimate optimization, when it specifically indicates dynamic API resolution.
A Docker container is suspected of malicious activity. Which THREE data sources should the investigator collect for forensic analysis?
Select 3 answers
A.Network packet captures from the container's virtual interface
B.Host system audit logs
C.Docker image layer files
D.Container logs (stdout/stderr)
E.The Dockerfile used to build the image
AnswersB, C, D
Host system audit logs, such as those from auditd, systemd journal, or syslog, are the strongest artifact because the host kernel records container process activity in a way that survives container removal. These logs commonly capture container-ID-tagged process executions, file access, syscalls, and seccomp/AppArmor denials, allowing an investigator to reconstruct the container's interactions with the host. Unlike in-container logs, an attacker who deletes or overwrites files inside the container cannot easily erase the host-side audit trail.
Why this answer
Container logs, image layers, and host system logs are key sources in Docker forensics.
A first responder arrives at a scene where a computer is turned on and a user is logged in. What is the FIRST action the responder should take to preserve volatile evidence?
A.Photograph the screen and then shut down the system normally
B.Immediately unplug the power cord to prevent data alteration
C.Remove the hard drive immediately for forensic imaging
D.Collect volatile data such as RAM contents and running processes
AnswerD
Volatile data, by definition, vanishes the instant power is lost, so it must be captured first—RAM contents, running processes, active network connections, open files, and logged-on users. A responder should use statically linked, trusted forensic tools from внешней media to dump memory to a forensically sound image, record output, and preserve the system state in a documented chain of custody before any power-down or disk removal.
Why this answer
Volatile data (e.g., RAM contents, running processes, network connections) is lost when power is removed. The first responder must collect this data before any shutdown or hardware removal, following the order of volatility (RFC 3227). This preserves critical evidence that cannot be recovered later.
Exam trap
EC-Council often tests the order of volatility (RFC 3227) and the misconception that immediate shutdown or hardware removal is safer, when in fact the priority is capturing volatile data first to avoid permanent loss.
How to eliminate wrong answers
Option A is wrong because shutting down the system normally allows the OS to write data to disk (e.g., pagefile.sys, temporary files), potentially overwriting evidence, and destroys volatile data. Option B is wrong because immediately unplugging the power cord causes an abrupt loss of all volatile data (RAM, network state) and may corrupt the file system, making forensic analysis harder. Option C is wrong because removing the hard drive without first capturing volatile data loses all RAM-based evidence, and hot-swapping a running system can cause data corruption or loss of encryption keys in memory.
During a forensic analysis of a compromised Linux system, you notice that the /proc filesystem contains a suspicious entry /proc/12345/exe pointing to /tmp/.hidden/malware. What conclusion can you draw?
A.The system was rebooted recently
B.The malware is a kernel module
C.A process with PID 12345 is running the malware
D.The malware was executed via a cron job
AnswerC
The /proc/[pid]/exe entry is a symlink to the exact on-disk binary that process 12345 is currently executing. If that link resolves to a deleted or hidden location, such as '/path/to/evil (deleted)', it indicates the process is running malware that was opened and unlinked to evade detection. This is a strong and direct indicator that PID 12345 is executing the malicious code.
Why this answer
The /proc filesystem is a virtual filesystem that provides process information. The entry /proc/12345/exe is a symbolic link pointing to the executable file that started the process with PID 12345. Since this link exists and points to /tmp/.hidden/malware, it confirms that a process with PID 12345 is currently running that malware binary.
Exam trap
A common misconception in forensic analysis is that /proc entries persist across reboots or that a symlink in /proc indicates a kernel module. However, /proc/[pid]/exe points to the user-space binary that started the process, confirming a running process.
How to eliminate wrong answers
Option A is wrong because the existence of /proc/12345/exe indicates the process is currently running; a reboot would clear all /proc entries, so this entry would not exist after a reboot. Option B is wrong because kernel modules are typically loaded via insmod/modprobe and do not have entries in /proc/[pid]/exe; they are listed under /proc/modules or via lsmod. Option D is wrong because while a cron job could have launched the malware, the /proc entry alone does not indicate the launch mechanism; it only shows the current running state, not the scheduling method.
A first responder arrives at a workstation suspected of being compromised by malware that is still running. The user is logged in and a suspicious process is active. The responder needs to capture volatile data before shutting down. Which command should be used first to capture the contents of RAM to a file?
A.winpmem.exe -o memory.raw
B.volatility -f memory.raw imageinfo
C.ftk imager --capture-memory
D.dd if=/dev/mem of=memory.raw
AnswerA
winpmem is a Windows memory acquisition tool that captures physical memory to a raw file. Running it first preserves volatile data before any shutdown or further changes. It is specifically designed for forensic imaging of RAM on live Windows systems and is a standard first-responder tool. Capturing memory with winpmem before other actions aligns with order of volatility principles.
Why this answer
The order of volatility dictates that RAM contents should be captured before any other action. winpmem is a reliable Windows memory acquisition tool that outputs a raw memory file. The other options are either for a different OS, incorrect syntax, or analysis rather than acquisition. Capturing memory first ensures critical volatile evidence such as running processes and network connections is preserved.
Exam trap
The trap here is assuming that analysis tools like Volatility can acquire memory or that Linux commands work on Windows, when acquisition must be done with a dedicated Windows memory capture utility first.
During an investigation of a web application breach, an analyst reviews IIS logs and finds numerous entries with status code '200' and URIs containing '?cmd=' followed by encoded strings. The analyst also notices that some requests have a 'User-Agent' string resembling 'Microsoft-CryptoAPI/10.0'. What is the MOST likely conclusion?
A.The logs indicate a successful SQL injection attack
B.The logs show a cross-site scripting (XSS) attack targeting administrators
C.The server is infected with ransomware, encrypting files
D.A webshell is being used to execute commands on the server
AnswerD
The logs indicate a webshell is in use because the HTTP requests contain a cmd parameter whose values are operating-system commands, a classic hallmark of server-side web shells such as China Chopper or b374k. The non-standard User-Agent further suggests a customized or automated attacker tool, and the consistent use of this parameter across requests shows persistent remote access. This behavior is the result of a command injection vulnerability, where the web application fails to sanitize user input before passing it to the system shell, allowing the attacker to execute arbitrary commands directly against the server.
Why this answer
The presence of numerous HTTP 200 (success) responses with URIs containing '?cmd=' followed by encoded strings indicates that an attacker is sending command execution requests to a webshell on the server. The unusual User-Agent string 'Microsoft-CryptoAPI/10.0' is a known evasion technique used by webshell tools (e.g., China Chopper variants) to blend in with legitimate Windows update traffic. Successful command execution returns a 200 status, confirming the webshell is active and under attacker control.
Exam trap
The trap here is that candidates see '200 OK' and assume success of an attack like SQL injection, but the '?cmd=' parameter is the definitive indicator of a command execution webshell. EC-CHFI emphasizes recognizing webshell indicators such as encoded command parameters and unusual User-Agent strings.
How to eliminate wrong answers
Option A is wrong because SQL injection typically results in error codes (e.g., 500) or modified database responses, not consistent 200s with '?cmd=' parameters; the '?cmd=' pattern is characteristic of command execution, not SQL queries. Option B is wrong because XSS attacks inject client-side scripts into web pages and do not produce server-side command execution logs with '?cmd=' URIs; XSS would appear as reflected or stored script payloads in parameters like '?q=' or '?search='. Option C is wrong because ransomware encrypts files locally and communicates with C2 servers, but it does not generate repeated HTTP 200 responses with '?cmd=' in IIS logs; ransomware activity would show unusual file access patterns or encryption API calls, not webshell command execution.
Which THREE of the following are indicators of a webshell in web server logs? (Select THREE)
Select 3 answers
A.Multiple GET requests to /index.html
B.POST requests to a script file with large payloads
C.Consistent 304 Not Modified responses
D.Requests to unusual script files like cmd.aspx or shell.php
E.A high number of requests from a single IP to a single script
AnswersB, D, E
POST requests to a script file with large payloads strongly suggest webshell activity because attackers use the HTTP body to hide command strings, encoded scripts, or file-upload content from URL-based logging and detection. A legitimate script receiving a large POST body is uncommon, and when combined with an executable extension (.php, .aspx, .jsp), it indicates the attacker is sending instructions or data to be processed by the shell. The large payload size also corresponds to obfuscated command blocks or base64-encoded data, making it a crucial behavioral indicator.
Why this answer
Webshells are indicated by anomalous script files being accessed, POST requests to script files, and high request rates to a single script. These patterns suggest remote access and command execution.
Which TWO of the following are valid methods to hide data on an NTFS file system without using external tools?
Select 2 answers
A.Embedding data in file slack space
B.Storing data in the NTFS file system journal ($LogFile)
C.Using the $Volume attribute in the MFT
D.Encrypting data with EFS
E.Using Alternate Data Streams (ADS)
AnswersA, E
File slack is unused space at the end of a cluster that can be filled with data.
Why this answer
A is correct because file slack space is the unused bytes between the end of a file's logical data and the end of its allocated cluster. On NTFS, when a file does not fill its last cluster, the remaining bytes (RAM slack and drive slack) can be written to without affecting the file's visible content. This is a native hiding method that requires no external tools, as the data is simply written to the slack region using standard file I/O operations.
Exam trap
EC-CHFI often tests the misconception that NTFS journals or MFT attributes can be used for data hiding without external tools, but only slack space and Alternate Data Streams (ADS) are native, supported mechanisms that do not require third-party utilities.
An investigator is analyzing a FAT32 drive and notices that a deleted file's directory entry still exists, but the first byte of the filename is changed to 0xE5. What does this indicate about the file?
A.The file is fragmented
B.The file is marked as deleted but its data clusters may still be intact
C.The file has been securely overwritten
D.The file is encrypted
AnswerB
In FAT32, a file deletion changes the first byte of its directory entry to 0xE5, signaling that the entry is available for reuse, while the clusters linked in the FAT are marked as free. The actual data bytes remain in the volume until overwritten by new writes, so deleted files can often be recovered using forensic carving or FAT chain analysis. This makes 0xE5 a critical artifact for identifying recoverable evidence.
Why this answer
In FAT32 file systems, a deleted file's directory entry is marked by replacing the first byte of the filename with 0xE5. This indicates the file is logically deleted, but the data clusters referenced in the directory entry remain intact until overwritten by new data. Option B is correct because the 0xE5 marker is the standard FAT deletion marker, and the clusters are not erased.
Exam trap
The trap here is that candidates may confuse the 0xE5 deletion marker with fragmentation or assume the data is securely erased, when in fact the marker only indicates logical deletion and the clusters remain intact.
How to eliminate wrong answers
Option A is wrong because fragmentation is indicated by the FAT chain entries showing non-contiguous cluster numbers, not by the 0xE5 byte in the directory entry. Option C is wrong because secure overwriting would zero out or randomize the data clusters, but the 0xE5 marker only indicates logical deletion without modifying cluster content. Option D is wrong because encryption is a property of the file's data content or metadata, not indicated by the first byte of the filename being changed to 0xE5.
What is the primary goal of the chain of custody in a digital forensic investigation?
A.To maintain the integrity and admissibility of evidence
B.To encrypt the evidence during transport
C.To speed up the forensic analysis process
D.To ensure that the forensic tools used are properly licensed
AnswerA
Documenting every transfer, handler and access point creates an unbroken audit trail proving the evidence was not altered or contaminated. This preserved integrity is what allows the artefact to be admitted as reliable in court or disciplinary proceedings.
Why this answer
The chain of custody is a documented chronological record that tracks the seizure, custody, control, transfer, analysis, and disposition of digital evidence. Its primary goal is to maintain the integrity and admissibility of evidence by proving that the evidence has not been tampered with or altered from the moment it was collected until it is presented in court. This is critical because any break in the chain can lead to evidence being deemed inadmissible under rules like the Federal Rules of Evidence (FRE) or the Daubert standard.
Exam trap
EC-Council often tests the misconception that chain of custody is about physical security or tool licensing, when in fact it is solely about maintaining a verifiable, unbroken record of evidence handling to ensure legal admissibility.
How to eliminate wrong answers
Option B is wrong because encrypting evidence during transport is a security measure to protect confidentiality, not a goal of the chain of custody, which focuses on integrity and accountability through documentation. Option C is wrong because the chain of custody does not speed up analysis; in fact, it adds procedural steps that can slow the process but are necessary for legal admissibility. Option D is wrong because ensuring forensic tools are properly licensed is a matter of tool validation and legal compliance, unrelated to the chain of custody's purpose of tracking evidence handling.
A security analyst reviews Apache access logs and finds the following entry: `192.168.1.10 - - [12/Jul/2024:10:15:30 -0400] "GET /search.php?q=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 5321 "-" "Mozilla/5.0"`. Which attack technique is most likely being attempted?
A.Remote file inclusion
B.SQL injection
C.Cross-site scripting (XSS)
D.Directory traversal
AnswerB
The presence of UNION SELECT in a query parameter is a classic, definitive indicator of in-band SQL injection. An attacker appends a UNION-based query to the original SQL statement that the application executes against the backend database; if the attacker correctly matches the number and data types of the original query's columns, the database returns the attacker's chosen rows alongside the legitimate results, enabling data exfiltration. This technique operates entirely within the database engine and does not involve remote file loading, client-side script execution, or filesystem path traversal, making the log evidence fully consistent with an automated SQL injection probe.
Why this answer
The log entry shows a GET request to `/search.php?q=1' UNION SELECT username,password FROM users--`. The single quote (`'`) breaks out of the SQL string context, and the `UNION SELECT` clause attempts to retrieve data from the `users` table. This is a classic SQL injection (SQLi) attack targeting the backend database, as the injected SQL syntax is designed to manipulate the query executed by the application.
Exam trap
The trap here is that candidates may confuse the `UNION SELECT` SQL syntax with a file inclusion or XSS payload, but the presence of a single quote and SQL keywords specifically indicates SQL injection, not other web attacks.
How to eliminate wrong answers
Option A is wrong because remote file inclusion (RFI) involves injecting a URL to include a remote file (e.g., via `http://` in a parameter), not SQL syntax like `UNION SELECT`. Option C is wrong because cross-site scripting (XSS) injects client-side scripts (e.g., `<script>`) into the response to execute in a browser, not SQL commands against the database. Option D is wrong because directory traversal uses path sequences like `../` to access files outside the web root, not SQL keywords or quotes.
During a Linux forensic investigation, you find the following entry in /var/log/auth.log: "Accepted publickey for root from 203.0.113.5 port 54321 ssh2: RSA SHA256:abc...". The user claims they never connect from that IP. Which forensic artifact should you examine next to confirm unauthorized access?
A.bash_history for suspicious commands
B./etc/shadow for recent modifications
C.~/.ssh/authorized_keys for unauthorized keys
D./var/log/syslog for cron job entries
AnswerC
The ~/.ssh/authorized_keys file for each user is the authoritative list of public keys allowed to log in as that account via SSH. Attackers commonly append a single base64-encoded line containing their public key, often with command= or from= restrictions to evade detection, enabling silent passwordless access independent of any password change. Comparing every entry against known administrative keys—while verifying file ownership, permissions, and the account's shell—is the direct method to locate such an implanted credential.
Why this answer
The log entry shows a successful SSH authentication using a public key from an unknown IP. The most direct way to confirm unauthorized access is to check ~/.ssh/authorized_keys for any rogue public keys that were added without the user's knowledge, as this file controls which keys are permitted to authenticate as that user. If an attacker added their own public key here, they could log in without a password, making this the primary artifact to examine.
Exam trap
EC-Council often tests the distinction between authentication artifacts (authorized_keys) and post-authentication artifacts (bash_history), leading candidates to mistakenly focus on what the attacker did after login rather than how they got in.
How to eliminate wrong answers
Option A is wrong because bash_history only shows commands executed after login, not the authentication method or key used; it would not reveal how the attacker gained access. Option B is wrong because /etc/shadow stores password hashes and is not involved in public key authentication; modifying it would not enable key-based SSH access. Option D is wrong because /var/log/syslog contains general system messages and cron job entries, but the SSH authentication event is already captured in auth.log; cron jobs are unrelated to the public key authentication method used here.
During a malware analysis session, an analyst uses Process Monitor (Procmon) to observe a suspicious executable. Which of the following behavioral indicators would MOST strongly suggest the malware is attempting to establish persistence?
A.Making outbound TCP connections to an IP address
B.Creating a named mutex
C.Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run
D.Creating files in the %TEMP% directory
AnswerC
Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence technique because entries under this key are executed automatically each time the logged-in user starts a Windows session. This location is attractive to malware since it requires no elevated privileges to modify and survives reboots, allowing the malicious payload to re-launch on every user logon. Removing the registry value eliminates the persistence, which is why it is monitored by tools like Sysinternals Autoruns.
Why this answer
Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism because Windows automatically launches programs listed in this registry key at user logon. Process Monitor capturing a write to this key directly indicates the malware is configuring itself to run on startup, which is the strongest evidence of persistence among the options.
Exam trap
EC-Council often tests the distinction between runtime indicators (network connections, mutexes, temp files) and persistence mechanisms (registry Run keys, scheduled tasks, startup folders), so candidates mistakenly pick outbound connections or mutexes as persistence when they are not.
How to eliminate wrong answers
Option A is wrong because making outbound TCP connections indicates network communication (e.g., C2 beaconing), not persistence. Option B is wrong because creating a named mutex is a synchronization primitive used to prevent multiple instances of a process, not a persistence mechanism. Option D is wrong because creating files in %TEMP% is typical for temporary data extraction or staging, but does not ensure the malware runs again after reboot.
An analyst discovers that a Windows system has hidden data in the Host Protected Area (HPA) of the hard drive. Which tool or method can be used to detect and access the HPA?
A.Using the Windows Disk Management utility
B.Using the hdparm command in Linux with the -N flag
C.Using the Volatility framework
D.Using the chkdsk command
AnswerB
hdparm -N /dev/sda shows the user-accessible capacity vs. native capacity, revealing HPA.
Why this answer
The Host Protected Area (HPA) is a reserved region on ATA/ATAPI hard drives that is not visible to the operating system's standard disk utilities. The `hdparm` command in Linux with the `-N` flag is specifically designed to detect and modify the HPA by querying the drive's native max address, revealing hidden sectors. Windows Disk Management and other OS-level tools cannot access the HPA because it is hidden at the firmware level via the ATA SET MAX ADDRESS command.
Exam trap
The trap here is that candidates assume standard Windows utilities like Disk Management can see all drive areas, but the HPA is hidden at the firmware level and requires ATA command-level tools like hdparm to access.
How to eliminate wrong answers
Option A is wrong because Windows Disk Management only shows partitions visible to the OS and cannot detect the HPA, which is hidden at the ATA command level. Option C is wrong because the Volatility framework is a memory forensics tool for analyzing RAM dumps, not for low-level hard drive regions like the HPA. Option D is wrong because chkdsk checks file system integrity on visible partitions and has no capability to interact with ATA commands that control the HPA.
A security analyst reviews Windows Security Event Log and notices multiple Event ID 4625 entries for a single user account from various IP addresses within a short time frame. What is the MOST likely attack being attempted?
A.Brute-force password attack
B.Kerberos golden ticket attack
C.ARP spoofing attack
D.Pass-the-hash attack
AnswerA
A brute-force password attack is characterized by a high volume of Event ID 4625 (failed logon) entries, often from multiple source IPs or workstations, as the attacker cycles through password dictionaries or guesses. The systematic nature of these failures—repeated attempts against one or more accounts—is the definitive signature, which aligns with the observed 'multiple failed logons from different sources' in the security log.
Why this answer
Event ID 4625 indicates a failed logon attempt. Multiple such events for a single user account from various IP addresses within a short time frame is the classic signature of a brute-force password attack, where an attacker tries many passwords against one account from multiple source IPs to evade rate-limiting or IP-based blocking.
Exam trap
The trap here is that candidates may confuse Event ID 4625 with other attack types like pass-the-hash (which typically produces 4624 success events) or assume any authentication failure indicates a Kerberos attack, but the key differentiator is the pattern of multiple failure attempts from varied IPs targeting a single account.
How to eliminate wrong answers
Option B is wrong because a Kerberos golden ticket attack involves forging a Ticket Granting Ticket (TGT) using the KRBTGT account hash, which does not generate multiple 4625 failure events from different IPs; it would instead produce successful logon events (4624) with unusual ticket attributes. Option C is wrong because ARP spoofing is a Layer 2 attack that manipulates ARP tables to intercept traffic on a local network segment; it does not generate Windows Security Event ID 4625 entries, which are specific to authentication attempts at the application or OS level. Option D is wrong because a pass-the-hash attack uses stolen NTLM hashes to authenticate without knowing the plaintext password, typically resulting in successful logon events (4624) rather than repeated failure events (4625) from multiple IPs.
During an iOS forensics investigation, an examiner extracts an iTunes backup and finds the SQLite database files. Which TWO of the following databases are LEAST likely to contain forensically relevant artefacts for a communication analysis?
Select 2 answers
A.SMS.db
B.data_ark.db
C.AddressBook.db
D.tmp.db
E.call_history.db
AnswersB, D
Not a standard iOS backup database; likely not present or relevant.
Why this answer
B is correct because data_ark.db is not a standard iOS SQLite database; it does not exist in typical iOS backups or file systems. The name suggests a fabricated or non-standard artefact, making it least likely to contain forensically relevant communication data. In contrast, databases like SMS.db and call_history.db are well-documented repositories for SMS messages and call logs, respectively.
Exam trap
EC-Council often tests candidates' familiarity with standard iOS database filenames, and the trap here is that 'data_ark.db' sounds plausible (like an 'ark' for data) but is not a real iOS database, leading examinees to overlook it as a distractor.
A forensic investigator recovers a hard drive from a suspect's computer. The drive is detected as 120 GB in BIOS, but forensic tools report only 100 GB of addressable space. Which data hiding technique is MOST likely being used?
A.Device Configuration Overlay (DCO)
B.Volume slack
C.Host Protected Area (HPA)
D.Alternate Data Streams (ADS)
AnswerC
Host Protected Area (HPA) is an ATA feature that uses the SET MAX ADDRESS command to lower the drive's reported maximum address, causing all sectors beyond that boundary to become inaccessible to the operating system and BIOS. This effectively hides data in the protected area at the end of the physical disk, which is exactly the kind of capacity mismatch that forensic acquisition tools detect by comparing the native maximum address against the current maximum. HPA is the correct answer because it directly addresses the hardware-level capacity reduction described.
Why this answer
The Host Protected Area (HPA) is a region on a hard drive that is hidden from the operating system by using the ATA SET MAX ADDRESS command to reduce the reported addressable space. Since the BIOS detects the full 120 GB but forensic tools see only 100 GB, the HPA is the most likely technique, as it creates a hidden area beyond the reported maximum LBA that is not visible to standard forensic acquisition tools unless specifically addressed.
Exam trap
The trap here is that candidates confuse HPA with DCO, but the key differentiator is that DCO hides space from the BIOS as well, while HPA allows the BIOS to see the full drive but hides space from the OS and forensic tools.
How to eliminate wrong answers
Option A is wrong because Device Configuration Overlay (DCO) is a feature that allows the drive manufacturer to hide the entire drive or a portion of it from the BIOS and OS, but here the BIOS correctly detects 120 GB, ruling out DCO. Option B is wrong because volume slack refers to unused space at the end of a volume that is not part of any partition, but it does not reduce the total addressable space reported by forensic tools; it is a byproduct of partition alignment, not a deliberate hiding technique. Option D is wrong because Alternate Data Streams (ADS) are a feature of NTFS that allow data to be hidden within a file's metadata, but they do not affect the total addressable space of a hard drive; they operate at the file system level, not the disk geometry level.
An investigator needs to analyze the contents of the Windows Recycle Bin on a system running Windows 10. Which artifact(s) should the investigator examine to determine the original location and deletion time of a file in the Recycle Bin?
A.The 'System Volume Information' folder
B.The '$I' and '$R' files in the $Recycle.Bin\<SID> folder
C.The 'INFO2' file in the Recycled folder
D.The 'desktop.ini' file in the Recycle Bin
AnswerB
In Windows 10, deleted files are stored under C:\$Recycle.Bin\<UserSID> as a pair of files with a shared random suffix: the $I file contains a binary structure—8-byte header, original file size, 64-bit FILETIME deletion timestamp, UTF-16 original path length, and the original absolute path—while the $R file retains the raw contents of the deleted object. Because the visible $R filename is a generated suffix, parsing the $I metadata is the only way to recover the original name and location; both files together allow full forensic reconstruction of the deletion.
Why this answer
In Windows 10, the Recycle Bin is implemented as the `$Recycle.Bin` folder, with each user having a subfolder identified by their Security Identifier (SID). When a file is deleted, it is renamed to an `$R` file (the actual data) and an `$I` file (metadata including original path and deletion timestamp) is created. Examining these `$I` and `$R` files allows the investigator to determine the original location and deletion time of the file.
Exam trap
EC-Council often tests the distinction between Windows 10's `$Recycle.Bin` folder with `$I`/`$R` files and the legacy `Recycled` folder with `INFO2` file, so candidates mistakenly choose the `INFO2` option for modern Windows systems.
How to eliminate wrong answers
Option A is wrong because the 'System Volume Information' folder contains system restore points and volume shadow copies, not Recycle Bin metadata. Option C is wrong because the 'INFO2' file is used in older Windows versions (Windows 2000/XP) for Recycle Bin metadata, not in Windows 10. Option D is wrong because 'desktop.ini' is a configuration file that controls folder appearance (e.g., icon layout), not a forensic artifact for file deletion details.
A forensic analyst is examining a network packet capture for signs of data exfiltration. Which THREE of the following are common indicators of data exfiltration over DNS? (Select three.)
Select 3 answers
A.Low TTL values in DNS responses
B.DNS queries sent to multiple different DNS servers
C.DNS responses with unusually large payloads (e.g., TXT records)
D.High volume of DNS queries to a single domain
E.DNS queries for random-looking subdomains
AnswersC, D, E
In normal operation, DNS TXT records are used for verifiable text like SPF policies or domain ownership tokens and are rarely larger than a few hundred bytes; an attacker exfiltrating data will pad or encode payloads into TXT answers, causing response sizes to exceed typical benign traffic. Since a standard UDP DNS response without EDNS0 is limited to 512 bytes, responses that push against or exceed that limit (and require TCP fallback) are a solid anomaly. These oversized TXT responses, combined with a queried domain that also receives many random subdomain queries, are a hallmark of DNS tunneling.
Why this answer
Option C is correct because DNS tunneling tools such as iodine and dnscat2 encode stolen data in TXT, NULL, or CNAME records, producing responses far larger than the typical 512-byte UDP DNS limit and thus a strong exfiltration indicator. Option D is correct because exfiltration over DNS requires many queries to carry data out, so a high volume of queries to a single domain (often thousands per hour) stands out against normal resolver traffic. Option E is correct because the encoded payload is placed in the leftmost label, generating long, random-looking subdomains such as 'aGVsbG8.evil.com' that are characteristic of DNS tunneling.
Option A is not a reliable indicator: low TTLs are common in fast-flux and load-balancing setups and are not specific to exfiltration. Option B is also not specific, since clients legitimately query multiple configured or fallback DNS servers during normal resolution.
Exam trap
The CHFI exam often tests the misconception that low TTL values are a definitive sign of exfiltration, but TTL manipulation is rarely used in DNS tunneling and is more commonly associated with legitimate DNS optimization or fast-flux networks.
A forensic analyst is examining a USB drive formatted with FAT32. A suspect claims they deleted a file several weeks ago. The analyst uses a carving tool but cannot recover the file. What is the MOST likely reason for the failed recovery?
A.The file was encrypted and cannot be carved
B.FAT32 does not support file carving
C.The file was stored in the MFT, which is only present in NTFS
D.The file clusters were overwritten by new data
AnswerD
File carving succeeds only when the original data content still physically exists on the media, typically in unallocated space. If the drive continued to be used after the file was deleted, the clusters that once held the file may have been reallocated and overwritten with new data. Overwriting destroys the original byte pattern, so there is nothing left for carving algorithms to recover. This is the correct reason a file may be un-carveable even though carving itself remains possible.
Why this answer
File carving relies on finding the file's content clusters on disk, typically by scanning for file headers and footers. If the suspect deleted the file weeks ago, the clusters that held the file's data were likely marked as free in the FAT32 file allocation table and subsequently overwritten by new data written to the drive. This is the most common reason for carving failure on a FAT32 volume that has been in active use after deletion.
Exam trap
EC-Council often tests the misconception that file carving depends on file system metadata (like MFT or directory entries), when in fact carving works at the raw data level and fails primarily due to data overwriting.
How to eliminate wrong answers
Option A is wrong because encryption does not prevent file carving; carving recovers raw data clusters regardless of encryption, though the recovered data would be unreadable without the key. Option B is wrong because FAT32 fully supports file carving; carving tools work at the raw sector level and are file-system agnostic, relying on file signatures rather than file system metadata. Option C is wrong because the MFT (Master File Table) is a metadata structure specific to NTFS, not FAT32; FAT32 uses directory entries and FAT tables, not an MFT, so the file's metadata would be in a directory entry, not the MFT.
Which TWO of the following are forensic artifacts found on macOS systems that can help reconstruct user activity?
Select 2 answers
A..plist files
B.Unified logging
C.Prefetch files (*.pf)
D.Registry hive files
E.Event ID 4624
AnswersA, B
Property list files on macOS are structured XML or binary files that store per-app preferences, recent item lists, window states, and other persistent configuration data. In forensic examinations, they are critical for attributing user activity because they often contain timestamps and device-specific identifiers, and can be decoded with `plutil` or `strings`. They serve as the macOS counterpart to the Windows Registry for configuration and usage artifacts.
Why this answer
Option A (.plist files) is correct because macOS stores application and system preferences, recent items, and user-activity metadata in property list files (often binary or XML) under ~/Library/Preferences and /Library/Preferences, which investigators can parse with plutil or plist editors to reconstruct user behavior. Option B (Unified logging) is correct because macOS's Unified Logging system (introduced in 10.12, accessed via the log command or log show) records detailed system, application, and user events in .tracev3 files under /var/db/diagnostics, providing a rich timeline of activity. Option C (Prefetch files) is incorrect because *.pf Prefetch files are a Windows artifact (C:\Windows\Prefetch) that does not exist on macOS.
Option D (Registry hive files) is incorrect because the Windows Registry (e.g., NTUSER.DAT, SYSTEM, SAM) is not present on macOS, which uses plists and other stores instead. Option E (Event ID 4624) is incorrect because that is a Windows Security event log identifier for a successful logon, not a macOS forensic artifact.
Exam trap
This question tests the distinction between Windows and macOS forensic artifacts. The trap is that candidates familiar with Windows forensics may incorrectly assume Prefetch files or Registry hives exist on macOS, or that Event ID 4624 has a macOS equivalent.
An analyst receives an alert indicating a suspicious process (PID 3342) is making outbound connections on port 443 to an unknown IP. The system is a Windows 10 workstation. Which first responder action is MOST appropriate?
A.Capture a full memory dump using a tool like FTK Imager (Memory Capture) or DumpIt.
B.Immediately disconnect the system from the network to contain the threat.
C.Check the Windows Event Logs for related entries.
D.Reboot the system to clear any malicious processes from memory.
AnswerA
Capturing a full memory dump with FTK Imager (Memory Capture) or DumpIt preserves the entire contents of RAM, including running processes, loaded drivers, active network sockets, decrypted data, and injected code that exist only in volatile memory at that instant. This adheres to the order of volatility and allows analysis of the live system state without altering or destroying it. Memory imaging is the highest-priority step because many advanced threats operate solely in memory and leave minimal traces on disk.
Why this answer
Capturing a full memory dump (option A) is the most appropriate first responder action because it preserves the volatile state of the suspicious process (PID 3342) and its associated artifacts (e.g., network connections, loaded DLLs, encryption keys) before any further system changes occur. This allows forensic analysis to identify the malware's behavior, such as command-and-control (C2) communication over port 443 (HTTPS), without altering evidence. Tools like FTK Imager (Memory Capture) or DumpIt acquire a raw .mem file that can be analyzed with Volatility or Rekall to extract process details, network sockets, and injected code.
Exam trap
EC-Council often tests the principle that volatile data (memory) must be captured before any containment or analysis steps, and the trap here is that candidates mistakenly prioritize network containment (option B) over evidence preservation, forgetting that disconnecting the network can destroy critical volatile artifacts like active connections and encryption keys.
How to eliminate wrong answers
Option B is wrong because immediately disconnecting the system from the network may destroy volatile evidence (e.g., active TCP connections, ARP cache, and network session data) and could alert the attacker, potentially triggering anti-forensic measures like process termination or data encryption. Option C is wrong because checking Windows Event Logs is a secondary step that should occur after memory capture; event logs may not contain real-time process details (e.g., memory-resident code) and can be tampered with or cleared by the malware. Option D is wrong because rebooting the system destroys all volatile memory (RAM), including the suspicious process (PID 3342), network connections, and any decrypted payloads, making forensic recovery of the attack impossible.
In email forensics, which TWO of the following headers are most useful for identifying the true origin of an email? (Select TWO.)
Select 2 answers
A.Message-ID
B.DKIM-Signature
C.X-Originating-IP
D.Received
E.MIME-Version
AnswersC, D
X-Originating-IP is a non-standard header inserted by certain email clients, such as Microsoft Outlook/Exchange, when a message is composed and sent; it contains the raw IP address of the client machine that actually sent the message before it reached a mail server. This header is a direct, valuable starting point in an investigation because it points to the sender's own network connection. However, its presence is client-dependent and it can be absent or forged if the client or a malicious user chooses to omit or modify it.
Why this answer
Received headers show the path and each server's IP, while X-Originating-IP may contain the sender's IP. DKIM verifies integrity but not origin IP. Message-ID is just an identifier.
Which THREE of the following are indicators of a webshell compromise on a web server?
Select 3 answers
A.High CPU usage from web server processes
B.Regular successful logins to the server with correct credentials
C.Presence of files with extensions like .php, .asp, or .jsp in web directories that are not part of the original application
D.Unexpected outbound connections from the web server to unknown IP addresses
E.Decrease in network traffic
AnswersA, C, D
Webshell activity spawns unexpected processes under the web server's user context, driving sustained CPU consumption from httpd, w3wp, or similar. This resource anomaly reflects attacker commands executing through the shell, distinguishing it from normal request-driven load spikes.
Why this answer
Option A is correct because webshells often execute resource-intensive commands (cryptomining, brute-forcing, scanning, or reverse shells) through the web server's worker processes, so sustained high CPU usage by httpd/nginx/w3wp or their child processes is a common indicator. Option C is correct because attackers typically drop or upload webshell files into web-accessible directories, so unexpected .php, .asp, .aspx, or .jsp files that are not part of the original application are a strong sign of compromise. Option D is correct because a webshell commonly establishes command-and-control or exfiltration channels, producing unexpected outbound connections from the web server to unknown external IP addresses on unusual ports.
Option B does not belong because legitimate successful logins with valid credentials are normal activity and are not, by themselves, an indicator of a webshell. Option E does not belong because a decrease in network traffic is not characteristic of webshell activity, which typically generates additional traffic rather than reducing it.
Exam trap
Candidates often mistake normal administrative behavior (Option B) for suspicious activity, but webshells bypass authentication entirely, making regular successful logins irrelevant as indicators.