Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 151–225

745 questions total · 10pages · All types, answers revealed

Page 2

Page 3 of 10

Page 4
151
MCQmedium

A security team detects a suspicious process that writes to the Windows registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the MOST likely purpose of this activity?

A.Clearing browser history
B.Establishing persistence for malware
C.Updating system time
D.Configuring firewall rules
AnswerB

Registry Run keys are a classic autostart persistence mechanism: HKCU and HKLM under Software\Microsoft\Windows\CurrentVersion\Run contain command lines that the shell launches immediately after user logon. Malware writes an executable path or PowerShell command into that value to re-establish itself on every reboot or logon attempt. Because the value is executed automatically with the user's or SYSTEM's context, it provides reliable persistence. This is why a process writing to Run keys is strongly indicative of persistence rather than a harmless activity.

Why this answer

The Run key is a common auto-start location used for persistence. Writing to it ensures the process executes at user logon.

152
MCQmedium

A forensic lab manager is setting up a new lab and must decide on the physical security measures. Which of the following is the MOST important to implement first?

A.Construct Faraday cages around the evidence storage area
B.Deploy CCTV cameras covering all entry points
C.Install a gas-based fire suppression system
D.Implement a biometric access control system
AnswerD

Biometric access control authenticates individuals using unique physiological characteristics—such as fingerprints, iris patterns, or facial geometry—making it nearly impossible to lend, steal, or duplicate credentials. This enforces physical access as a preventive control, ensuring only pre-authorized personnel enter evidence storage areas, thereby maintaining chain of custody and legal defensibility. Unlike keys or cards, biometrics provide non-repudiation because each entry attempt is tied to a specific person and can be logged for audit. It directly addresses the foundational risk of unauthorized access, which is the first and most critical security requirement for a forensic lab.

Why this answer

Biometric access control is the most critical first step because it establishes a foundational layer of physical security that authenticates and authorizes personnel before they can access the lab. Without controlling who enters, other measures like CCTV or fire suppression are less effective, as unauthorized individuals could compromise evidence integrity. This aligns with the principle of defense-in-depth, where access control is the primary barrier against tampering or theft.

Exam trap

The trap here is that candidates often prioritize surveillance (CCTV) or evidence preservation (Faraday cages) over the foundational security principle of access control, failing to recognize that without controlling who enters, all other measures are reactive rather than preventive.

How to eliminate wrong answers

Option A is wrong because Faraday cages are specialized for blocking electromagnetic signals (e.g., to prevent remote wiping of mobile devices) and are not a general physical security measure; they should be implemented after basic access controls are in place. Option B is wrong because CCTV cameras are a monitoring/deterrent tool, not a preventive control; they record breaches but do not stop unauthorized access, making them secondary to access control. Option C is wrong because gas-based fire suppression systems protect against fire damage but do not address the immediate threat of unauthorized entry or evidence tampering; they are a safety measure, not a security measure.

153
Multi-Selectmedium

A malware analyst is performing dynamic analysis of a suspicious executable in a Cuckoo Sandbox environment. Which THREE of the following behavioural indicators would be considered suspicious and warrant further investigation?

Select 3 answers
A.Creating a mutex with a hardcoded name
B.Reading registry keys under HKLM\HARDWARE
C.Modifying the hosts file to redirect a domain
D.Writing a temporary file to %TEMP%
E.Connecting to an IP address associated with a known command-and-control server
AnswersA, C, E

A Windows mutex is a kernel synchronization object that malware commonly creates with a fixed, family-specific name to enforce single-instance execution. Because the name is deterministic across samples of the same family, dynamic analysis capturing this API call yields a stable behavioral signature, and analysts can query kernel object namespaces to discover it. Legitimate applications rarely use such distinctive hardcoded mutex names, making this a strong IoC.

Why this answer

Option A is correct because creating a mutex with a hardcoded name is a classic malware behavior used to prevent multiple instances of the same infection from running simultaneously, and the specific name can serve as a host-based indicator of compromise (IOC) for detection and family identification. Option C is correct because modifying the hosts file to redirect a domain is a common technique for DNS hijacking, blocking security vendor updates, or redirecting legitimate traffic to attacker-controlled infrastructure, and it is highly suspicious in a sandbox run. Option E is correct because connecting to an IP address associated with a known command-and-control (C2) server is a direct indicator of malicious beaconing and exfiltration activity, and it is one of the strongest network-level IOCs in dynamic analysis.

Option B is not suspicious because reading registry keys under HKLM\HARDWARE is a routine operation performed by many legitimate applications and drivers to enumerate hardware configuration. Option D is not suspicious because writing a temporary file to %TEMP% is normal behavior for a wide range of benign installers, updaters, and applications, so it does not by itself warrant further investigation.

Exam trap

The CHFI exam often tests the distinction between common benign operations (like reading hardware registry keys or writing to %TEMP%) and truly malicious indicators, so candidates mistakenly flag normal system activities as suspicious without considering context.

154
MCQhard

A forensic analyst is investigating a suspected data exfiltration from a MySQL database. Which log source would be MOST useful to identify the exact SQL queries executed, including SELECT statements that retrieved large volumes of data?

A.MySQL error log
B.MySQL binary log
C.MySQL slow query log
D.MySQL general query log
AnswerD

The MySQL general query log captures every SQL statement received by the server—including SELECT, INSERT, UPDATE, and even malformed queries—along with connection events, regardless of how long each query takes. It provides a complete chronological record that an analyst can replay to spot suspicious patterns, such as repeated large-range SELECTs or queries targeting sensitive columns. With log_output set to TABLE, the log can be queried directly, making it the native MySQL mechanism for uncovering data exfiltration via SELECT.

Why this answer

The MySQL general query log records every SQL statement received from clients, including SELECT queries, making it the most useful source for identifying exact queries executed during a suspected data exfiltration. Unlike other logs, it captures all activity without filtering by error, execution time, or data-change events, so it will show the specific SELECT statements that retrieved large volumes of data.

Exam trap

The binary log only logs data-modifying statements (DML) and not read-only SELECTs, leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because the MySQL error log only records startup/shutdown events, crashes, and critical errors, not the actual SQL queries executed. Option B is wrong because the MySQL binary log (binlog) only logs statements that change data (INSERT, UPDATE, DELETE, etc.) and does not record SELECT queries, which are read-only and thus not captured. Option C is wrong because the MySQL slow query log only records queries that exceed a defined execution time threshold (e.g., long_query_time), and a data-exfiltration SELECT could be fast and still retrieve large volumes, so it would be missed.

155
MCQmedium

An analyst finds the following in an IIS log: 10.0.0.5, -, 02/15/2024, 14:23:56, GET /../../windows/system32/cmd.exe, 404, 0, 0, 0, Mozilla/4.0. Which attack technique does this log entry represent?

A.Cross-site scripting
B.SQL injection
C.Path traversal
D.Remote code execution
AnswerC

Correct because the raw HTTP request includes ../ in the URL path, which is the classic path traversal pattern that, when decoded or normalized by the server, tries to climb above the web root into restricted directories. In IIS, unencoded or URL-encoded traversal sequences such as %2e%2e%5c can expose system files, and even though the server returned 404, the request itself demonstrates a deliberate traversal attempt against the file-system namespace.

Why this answer

The URI contains ../ patterns attempting to access a system file outside the web root, which is path traversal.

156
MCQeasy

Which cloud service's audit logs would an investigator examine to identify who deleted a virtual machine in an Azure subscription?

A.GCP Audit Logs
B.Azure Activity Log
C.Azure AD Sign-in Logs
D.AWS CloudTrail
AnswerB

The Azure Activity Log records subscription-level control-plane operations, including who deleted a virtual machine, when, and from where. It captures the caller identity and operation name, satisfying the investigator's need to attribute the deletion to a specific principal.

Why this answer

Azure Activity Log (formerly known as Audit Logs or Operational Logs) is the platform-level log that records all control-plane operations for Azure resources, including virtual machine creation, modification, and deletion. When a VM is deleted, the Activity Log captures the caller (user or service principal), the timestamp, the operation name (e.g., 'Microsoft.Compute/virtualMachines/delete'), and the status. An investigator would query the Activity Log to identify who initiated the deletion, making option B correct.

Exam trap

EC-CHFI often tests the distinction between control-plane logs (Activity Log) and authentication logs (Azure AD Sign-in Logs), and the trap here is that candidates confuse Azure AD Sign-in Logs (which show who logged in) with the Activity Log (which shows who performed a resource action), leading them to incorrectly choose option C.

How to eliminate wrong answers

Option A is wrong because GCP Audit Logs are specific to Google Cloud Platform, not Microsoft Azure; they cannot log Azure subscription events. Option C is wrong because Azure AD Sign-in Logs record authentication events (user sign-ins) and application usage, not resource-level operations like deleting a virtual machine; they lack the control-plane action details needed. Option D is wrong because AWS CloudTrail is the audit logging service for Amazon Web Services, not for Azure; it captures API calls in AWS accounts, not Azure subscriptions.

157
MCQmedium

A forensic analyst is examining a SQLite database from an iOS device backup. The database contains a table named 'message' with columns 'ROWID', 'text', 'handle_id', and 'date'. This database is MOST likely part of which iOS system database?

A.SMS.db
B.call_history.db
C.Calendar.db
D.AddressBook.db
AnswerA

SMS.db is the iOS SQLite database that stores both SMS text messages and iMessage conversations. The 'message' table contains core evidence such as message text, ROWID, handle_id (linking to the phone number or email), date as Apple epoch nanoseconds, and the 'is_from_me' flag. The 'handle' table maps handles to actual addresses, and the 'service' column distinguishes between iMessage and SMS, making SMS.db the authoritative source for messaging forensics.

Why this answer

The 'message' table with columns 'ROWID', 'text', 'handle_id', and 'date' is the core schema of the SMS.db database on iOS devices. This database stores iMessage and SMS/MMS messages, where 'handle_id' links to the 'handle' table for contact identifiers and 'date' stores the timestamp in Apple's absolute time (seconds since 2001-01-01). The presence of these specific columns confirms it is the SMS/Message database.

Exam trap

The CHFI exam often tests the misconception that 'message' tables are found in AddressBook.db or Calendar.db, but the specific column set (ROWID, text, handle_id, date) is unique to SMS.db in iOS forensics.

How to eliminate wrong answers

Option B is wrong because call_history.db stores call logs with columns like 'Z_PK', 'ZADDRESS', 'ZDATE', and 'ZDURATION', not a 'message' table with 'text' and 'handle_id'. Option C is wrong because Calendar.db uses tables like 'CalendarItem' and 'Recurrence' with columns for event dates and titles, not a 'message' table. Option D is wrong because AddressBook.db (now Contacts.sqlite) uses tables like 'ABPerson' and 'ABMultiValue' for contact data, not a 'message' table for text conversations.

158
MCQhard

During a forensic analysis of a Linux system, the investigator finds that the bash_history file is empty for the root user. However, the system has been used actively. What is the MOST likely explanation?

A.The system was shut down improperly
B.The file is corrupted
C.The user deleted the history
D.The HISTSIZE environment variable is set to 0 or the history file is redirected to /dev/null
AnswerD

When HISTSIZE is set to 0, bash immediately stops appending commands to the in-memory history list, and because the history file is only updated from that list on shell exit or explicit `history -w`, the result is an empty or nonexistent .bash_history. Similarly, configuring HISTFILE to point to /dev/null causes every write to go to a discard device, so no command history survives. Investigators should check the owning user's ~/.bashrc, ~/.bash_profile, and environment for these settings, as they are commonly used in privacy-conscious or automated environments.

Why this answer

The HISTSIZE environment variable controls how many commands are retained in memory during a session. When set to 0, no commands are stored, and the history file (typically ~/.bash_history) remains empty. Alternatively, if HISTFILE is redirected to /dev/null, all history writes are discarded, explaining the empty file despite active use.

Exam trap

Investigators sometimes overlook the possibility that an empty bash_history file may be due to configuration variables like HISTSIZE or HISTFILE, rather than assuming user deletion or corruption.

How to eliminate wrong answers

Option A is wrong because an improper shutdown (e.g., power loss) would not cause the bash_history file to be empty; it might truncate or lose unsaved entries, but the file would still contain previously saved history. Option B is wrong because file corruption typically results in unreadable content or errors, not a perfectly empty file with no error messages. Option C is wrong because if the user deleted the history (e.g., using 'history -c' or manually removing the file), the file would be absent or empty only after deletion; however, the question states the file is empty, not missing, and active use would normally generate new entries unless history recording is disabled.

159
MCQmedium

Which tool is commonly used for timeline analysis in digital forensics, allowing examiners to parse and correlate timestamps from various artifacts?

A.log2timeline
B.Sleuth Kit
C.Nmap
D.Wireshark
AnswerA

log2timeline parses timestamps from disparate artefacts and normalises them into a single super-timeline, letting examiners correlate activity across file system, registry and log sources. This satisfies the requirement to parse and correlate timestamps from various artefacts.

Why this answer

log2timeline (now part of the Plaso framework) is the de facto tool for timeline analysis in digital forensics. It parses a wide range of artifacts (e.g., $MFT, $UsnJrnl, Prefetch, Registry hives, event logs) and correlates their timestamps into a unified, super-timeline, enabling examiners to reconstruct system activity chronologically.

Exam trap

EC-Council CHFI often tests the distinction between file system analysis tools (Sleuth Kit) and timeline correlation tools (log2timeline), so candidates may mistakenly choose Sleuth Kit because it includes mactime, forgetting that log2timeline is the primary tool for building a super-timeline from multiple artifacts.

How to eliminate wrong answers

Option B (Sleuth Kit) is wrong because it is a collection of command-line tools for file system analysis (e.g., fls, icat, mmls) but does not perform timeline correlation or multi-artifact timestamp parsing. Option C (Nmap) is wrong because it is a network scanning tool used for port discovery and service enumeration, not for forensic timeline analysis. Option D (Wireshark) is wrong because it is a network protocol analyzer for capturing and inspecting packets, not a tool for parsing file system or registry timestamps.

160
MCQhard

A forensic analyst examines a Mac system and runs "log show --predicate 'eventMessage contains "disk"' --last 1h" in Terminal. This command extracts Unified Log entries related to disk activity. Which macOS forensic artifact is the analyst MOST likely querying?

A..plist files
B.FSEvents
C.Core Storage logs
D.Apple Unified Logging
AnswerD

Apple Unified Logging is the centralized, high-volume logging architecture built into macOS Sierra and later, aggregating kernel, framework, and app messages into a compact binary format on disk (e.g., in /var/db/diagnostics/). The log show command is the primary interface to filter and extract these entries, accepting predicates for process, subsystem, and time range. This makes it the correct answer because log show exclusively queries the unified logging system, not property lists, filesystem event journals, or Core Storage metadata.

Why this answer

The 'log show' command with --predicate queries the Apple Unified Logging system, which centralizes logs from various subsystems.

161
MCQmedium

A security analyst examines a compromised Windows server and finds a file named 'readme.txt' that appears legitimate. However, using `dir /r`, they discover an alternate data stream named 'readme.txt:hidden.exe'. What is the most likely purpose of this alternate data stream?

A.It is a backup copy of the file
B.It is a symbolic link to another file
C.It is a malicious executable hidden in the file
D.It is a log file generated by the operating system
AnswerC

This is the most plausible finding because NTFS Alternate Data Streams are a well-known technique for concealing malicious payloads on a compromised Windows host. An attacker can write an executable into a stream of a benign file (e.g., `type evil.exe > report.txt:evil.exe`) and execute it using tools like PowerShell or `wmic`, allowing it to evade basic directory scanning and security software that only checks the primary data stream. On a server that is known to be compromised, an unrecognized executable stream is a strong indicator of malware persistence or lateral movement.

Why this answer

Alternate data streams (ADS) in NTFS allow a malicious executable to be hidden within a legitimate file without affecting its visible size or content. The `dir /r` command reveals the ADS 'readme.txt:hidden.exe', indicating that an executable is attached to the file, which is a common technique to evade detection and execute malware.

Exam trap

The CHFI exam often tests the misconception that ADS are used for legitimate system functions like backups or logs, but the key is that ADS are a hiding mechanism for malicious content, not a standard feature for those purposes.

How to eliminate wrong answers

Option A is wrong because ADS are not used for backup copies; backups typically use file extensions or separate directories, not hidden streams. Option B is wrong because symbolic links are separate file system objects created with `mklink`, not hidden within an ADS. Option D is wrong because ADS are not standard log file locations; Windows logs are stored in dedicated directories like `%SystemRoot%\System32\winevt\Logs`.

162
MCQhard

You are imaging a suspect's hard drive using a write blocker and dd command. After imaging, you verify the hash of the original drive and the image file. The original drive hash is SHA1: A1B2C3D4E5..., and the image hash is SHA1: F6G7H8I9J0... What is the most likely cause of the mismatch?

A.The dd command used a different block size
B.The write blocker malfunctioned and allowed writes to the original drive
C.The dd command compressed the output
D.The image file was corrupted during transfer
AnswerB

A write blocker is a dedicated hardware or software mechanism that intercepts and blocks all write commands from the host system to the suspect drive during acquisition. If it malfunctions, the operating system or the acquisition tool may write temporary files, filesystem metadata, or other data onto the original evidence drive. Any such unintended write changes the drive's contents, so when the examiner later computes a hash of the original drive, it will no longer match the hash of the forensic image taken earlier. This is the only option that directly explains how the source itself could be altered, making it the correct cause of the hash discrepancy.

Why this answer

The hash mismatch indicates that the data on the original drive and the image file are not identical. A write blocker malfunction that allowed writes to the original drive during the imaging process would alter the source data after the initial hash was computed, causing the final hash of the original drive to differ from the hash of the image file taken at a different point in time. This is the most direct cause of a hash mismatch because the write blocker's primary purpose is to prevent any modification to the evidence.

Exam trap

EC-Council often tests the misconception that dd's block size or compression affects the hash, but the trap here is that candidates overlook the write blocker's role in preserving evidence integrity and instead focus on technical details of the dd command that do not alter the data content.

How to eliminate wrong answers

Option A is wrong because the dd command's block size affects read/write performance and the number of blocks, but it does not change the underlying data; the hash of the output will match the input regardless of block size as long as the entire drive is read. Option C is wrong because dd does not compress output by default; it performs a bit-for-bit copy, and even if compression were applied (e.g., via piping to gzip), the hash would be computed on the compressed file, not the raw image, but the question states the image file hash is compared, so compression would not cause a mismatch between the original drive hash and the image hash if the image is decompressed correctly. Option D is wrong because corruption during transfer would affect the image file's integrity, but the hash of the original drive would remain unchanged; the mismatch described is between the original drive hash and the image hash, and transfer corruption would only alter the image hash, not the original drive hash.

163
MCQeasy

In mobile forensics, which acquisition method preserves the highest level of data integrity and captures the most data from an iOS device?

A.File system acquisition
B.Physical acquisition
C.Logical acquisition
D.Manual acquisition
AnswerB

Physical acquisition creates a bit-for-bit, forensically sound image of the entire flash memory chip, including unallocated sectors, deleted file fragments, file system slack, and even data remnants from previous partitions. This method is the only approach that preserves the full forensic data set without relying on the device's operating system to filter or sanitize the output. By capturing the complete NAND image, it maximizes data integrity and completeness, making it unequivocally the correct choice for a preservation-focused acquisition.

Why this answer

Physical acquisition is correct because it creates a bit-for-bit copy of the entire flash storage, including unallocated space, deleted files, and system partitions. This method bypasses the iOS file system abstraction, preserving the highest data integrity and capturing all recoverable data, unlike higher-level acquisitions that only retrieve accessible files.

Exam trap

EC-Council often tests the misconception that 'file system acquisition' is the most thorough because it includes system files, but the trap is that physical acquisition alone captures unallocated space and deleted data, which file system acquisition cannot access due to iOS sandboxing and file system abstraction.

How to eliminate wrong answers

Option A is wrong because file system acquisition only copies allocated files and metadata visible through the iOS file system (e.g., via AFC or iTunes backup), missing deleted data and unallocated space, thus providing lower integrity and less data. Option C is wrong because logical acquisition extracts only user-accessible data (e.g., contacts, messages) via APIs like iTunes backup or libimobiledevice, ignoring system files and deleted artifacts, resulting in the least data capture. Option D is wrong because manual acquisition involves physically interacting with the device screen to capture data (e.g., screenshots or notes), which is highly operator-dependent, alters the device state, and cannot recover hidden or deleted data, offering the lowest integrity and data completeness.

164
MCQeasy

Refer to the exhibit. During incident response, a first responder runs 'netstat -ano' on a compromised Windows system. Which connection is most likely to be the command-and-control (C2) channel and should be prioritized for isolation?

A.192.168.1.100:1045 to 203.0.113.5:4444 (ESTABLISHED)
B.192.168.1.100:1047 to 10.0.0.1:22 (ESTABLISHED)
C.192.168.1.100:1046 to 192.168.1.1:443 (ESTABLISHED)
D.192.168.1.100:1048 to 198.51.100.7:80 (TIME_WAIT)
AnswerA

The established connection from the internal host to 203.0.113.5 on TCP port 4444 is a classic command-and-control indicator: port 4444 is the default listener port for Metasploit's Meterpreter reverse shell, and the destination is an external IP address that would not be in any internal allowlist. The ESTABLISHED state confirms an active, ongoing session, meaning the attacker likely already has a foothold and is maintaining control of the host. Moreover, 203.0.113.0/24 is a documentation range (TEST-NET-3), so its appearance in real traffic should immediately raise suspicion.

Why this answer

Shows an established connection from the internal host (192.168.1.100) to an external IP (203.0.113.5) on TCP port 4444, which is commonly associated with Metasploit reverse shells and other C2 frameworks. The ESTABLISHED state indicates an active, ongoing session, making it the highest priority for isolation during incident response.

Exam trap

EC-Council often tests the misconception that any external connection is suspicious, but the trap here is that candidates overlook the significance of the ESTABLISHED state and the specific port 4444, instead focusing on the IP address alone or mistaking a TIME_WAIT connection for an active threat.

How to eliminate wrong answers

Option B is wrong because port 22 is SSH, which is typically used for legitimate remote administration; while it could be abused, it is less likely than a non-standard high port like 4444 to be a C2 channel. Option C is wrong because 192.168.1.1:443 is a local gateway HTTPS connection, likely normal web traffic to the default gateway or a local proxy, not an external C2. Option D is wrong because the connection is in TIME_WAIT state, meaning it has already been closed and is not actively communicating, so it cannot be an active C2 channel.

165
MCQeasy

In network forensics, an analyst captures traffic and sees a large number of ICMP echo requests from 10.0.0.1 to 10.0.0.2 with varying payload sizes. What is the most likely scenario?

A.Network reconnaissance (ping sweep)
B.A man-in-the-middle attack
C.A DoS attack using ICMP floods
D.A DNS amplification attack
AnswerC

A large volume of ICMP echo requests (ping) from a single source to a single destination, especially with varying payload sizes, is a classic signature of an ICMP flood DoS attack. The sheer volume of packets consumes the target's bandwidth and processing resources, and the varied payload sizes are often used to defeat filters that block only fixed-size pings. This pattern is distinct from reconnaissance or protocol-specific abuse because it intentionally overwhelms the victim with raw ICMP traffic.

Why this answer

The scenario describes a single source sending a large number of ICMP echo requests to a single destination with varying payload sizes. This is characteristic of an ICMP flood attack, a type of DoS attack where the attacker overwhelms the target with echo requests, consuming bandwidth and processing resources. The varying payload sizes may be an attempt to evade simple packet filters or to maximize resource consumption.

In contrast, a ping sweep would involve sending requests to multiple destinations to discover live hosts, not a sustained high-volume stream to one host. Therefore, this is most likely a DoS attack, not reconnaissance.

Exam trap

EC-Council often tests the ability to differentiate between reconnaissance and attack by presenting ICMP traffic with varying payloads. Candidates may mistakenly classify a high-volume single-target ICMP flood as a ping sweep (Option A) due to the payload variation, but the key indicator is the single destination and overwhelming volume, which points to a DoS attack.

How to eliminate wrong answers

Option B is wrong because a man-in-the-middle attack typically involves ARP spoofing, DNS spoofing, or session hijacking, not a series of ICMP echo requests with varying payloads. Option C is wrong because a DoS attack using ICMP floods would involve a high volume of packets from potentially multiple sources to overwhelm the target, not a single source sending packets with varying sizes to a single destination, which is too low-volume for denial of service. Option D is wrong because a DNS amplification attack uses spoofed DNS queries with a small request size to generate large responses from open resolvers, targeting a victim with UDP traffic, not ICMP echo requests.

166
MCQhard

In an iOS forensic examination, an analyst extracts an encrypted iTunes backup. The backup contains a file named 'manifest.plist' which lists the backup version and encryption state. Which tool is specifically designed to brute-force the backup password using GPU acceleration?

A.Hashcat
B.Oxygen Forensic Detective
C.Cellebrite UFED
D.GrayKey
AnswerA

Hashcat is the only listed tool designed for GPU-accelerated offline password recovery, and mode 14700 specifically targets iTunes backup password hashes extracted from Manifest.plist. An examiner converts the encrypted backup metadata into a hash format that Hashcat can attack, then uses dictionary, rule-based, or brute-force attacks on GPUs. This makes it uniquely suited for recovering the backup encryption password when the device passcode is unknown or when legal authority permits an offline attack.

Why this answer

Hashcat is the correct tool because it is a password recovery utility that leverages GPU acceleration to perform high-speed brute-force attacks on encrypted iTunes backup passwords. It can directly process the password hash extracted from the 'manifest.plist' file, which contains the backup version and encryption state, allowing efficient cracking of the backup password.

Exam trap

The CHFI exam often tests the distinction between tools used for physical device extraction (like Cellebrite UFED or GrayKey) versus those used for password cracking (like Hashcat), and the trap here is that candidates may confuse GrayKey's passcode bypass capability with backup password cracking, even though GrayKey does not use GPU acceleration for brute-forcing encrypted backups.

How to eliminate wrong answers

Option B (Oxygen Forensic Detective) is wrong because it is a forensic analysis suite for extracting and analyzing mobile device data, not a dedicated password cracking tool with GPU acceleration. Option C (Cellebrite UFED) is wrong because it is a physical extraction and forensic imaging tool for mobile devices, not designed for brute-forcing encrypted backup passwords using GPU acceleration. Option D (GrayKey) is wrong because it is a specialized device for bypassing iOS passcodes via hardware exploits or software vulnerabilities, not for cracking encrypted iTunes backup passwords with GPU-accelerated brute-force attacks.

167
MCQmedium

An incident responder receives an alert that a workstation is beaconing to a known malicious IP address. The responder captures network traffic and analyzes it with Wireshark. Which of the following would be an immediate indicator of compromise (IoC) visible in the traffic capture?

A.Large file transfers during off-hours
B.ARP requests from unknown MAC addresses
C.Encrypted payloads using TLS 1.3
D.Repeated connections to a known malicious IP address on a non-standard port
AnswerD

Repeated connections to a known malicious IP address on a non-standard port is a high-fidelity indicator of compromise because it combines an established threat reputation with observable behavior that matches command-and-control (C2) beaconing. Non-standard ports are often used by malware to evade simple port-based filters, and the recurrence suggests a persistent callback rather than an accidental or one-time connection. This pattern directly aligns with the MITRE ATT&CK technique T1071 for application-layer C2 traffic.

Why this answer

Repeated connections to a known malicious IP address on a non-standard port directly match the definition of a beaconing indicator of compromise (IoC). In network traffic analysis, beaconing is characterized by periodic, outbound connections to a command-and-control (C2) server, often using a non-standard port to evade detection. This pattern is a primary IoC in malware forensics and is immediately visible in Wireshark as a series of TCP SYN packets to the same IP and port at regular intervals.

Exam trap

The CHFI exam often tests the distinction between a direct IoC (like beaconing to a known malicious IP) and secondary indicators (like large file transfers or ARP anomalies) that require additional context to confirm compromise.

How to eliminate wrong answers

Option A is wrong because large file transfers during off-hours may indicate data exfiltration but are not an immediate indicator of beaconing; they are a secondary behavioral anomaly that requires correlation with other evidence. Option B is wrong because ARP requests from unknown MAC addresses indicate local network scanning or spoofing, not beaconing to a remote malicious IP; ARP operates at Layer 2 and does not reveal C2 communication patterns. Option C is wrong because encrypted payloads using TLS 1.3 are not inherently malicious; TLS 1.3 is a standard security protocol used by legitimate services, and its presence alone does not indicate compromise—beaconing is defined by connection patterns, not encryption.

168
MCQmedium

The command used to acquire a disk image resulted in an I/O error. What is the most likely cause?

A.The source disk has bad sectors
B.The output file already exists and is being overwritten
C.The target directory does not have write permissions
D.The target drive is full
AnswerA

The source disk has bad sectors. When the imaging tool issues a raw read to a region containing a physically damaged or unreliable sector, the disk controller cannot return valid data and raises a hardware-level error. The operating system exposes this as an I/O error (EIO) on the read operation, causing the acquisition command to terminate or skip the sector. This is the classic cause of I/O errors during forensic imaging and requires error-handling flags such as 'conv=noerror,sync' in dd to continue.

Why this answer

When a disk imaging tool (e.g., dd, FTK Imager, EnCase) encounters an I/O error during acquisition, the most common cause is physical damage or degradation of the source media, specifically bad sectors. Bad sectors prevent the read head from reliably retrieving data, triggering an I/O error at the operating system or device driver level. This is distinct from logical errors like file system corruption, which typically produce different error messages.

Exam trap

The trap here is that candidates confuse an I/O error (a hardware-level read failure) with logical or permission-based errors, mistakenly attributing the error to the output destination rather than the source media.

How to eliminate wrong answers

Option B is wrong because overwriting an existing output file does not cause an I/O error; it may produce a warning or prompt for confirmation, but the read operation from the source disk proceeds normally. Option C is wrong because a lack of write permissions on the target directory results in a permission denied error, not an I/O error, and the acquisition tool would fail before attempting to read the source. Option D is wrong because a full target drive causes a 'disk full' or 'no space left on device' error, which is a write failure, not a read-related I/O error from the source disk.

169
MCQhard

An incident responder analyzes a compromised system and finds evidence of timestomping: the Modified timestamp of a malicious DLL is earlier than the Creation timestamp. Additionally, the DLL is encrypted with an XOR key. Which anti-forensic techniques are being employed?

A.Timestomping and obfuscation
B.Packer and anti-debugging
C.Rootkit installation and process hiding
D.Log wiping and data hiding
AnswerA

Timestomping is the deliberate modification of file system timestamps (MAC times) to disrupt forensic timeline reconstruction and hide when malware was deployed or accessed. The presence of XOR-encoded strings constitutes obfuscation, a common evasion method used to complicate static signature detection and reverse engineering. Together, these artifacts indicate a deliberate anti-forensic effort to hinder incident response analysis.

Why this answer

Timestomping is confirmed because the Modified timestamp (which tracks file content changes) is earlier than the Creation timestamp, which is logically impossible under normal file system operations—this indicates an attacker deliberately set the Modified timestamp backward to evade timeline analysis. The XOR encryption of the DLL is a form of obfuscation, a technique used to hide the true content of the file from static analysis tools and signature-based detection. Together, these two actions represent the anti-forensic techniques of timestomping and obfuscation.

Exam trap

EC-Council often tests the distinction between obfuscation (e.g., XOR encryption) and packing (e.g., UPX compression), where candidates mistakenly equate any encryption with a packer, but a packer specifically alters the PE structure and includes a decompression stub, while XOR obfuscation is a simpler, non-structural transformation.

How to eliminate wrong answers

Option B is wrong because a packer compresses or encrypts an executable to reduce size or evade signature detection, but it does not alter timestamps, and anti-debugging techniques (e.g., IsDebuggerPresent API calls) are runtime defenses, not file-level obfuscation or timestamp manipulation. Option C is wrong because rootkit installation involves modifying the OS kernel or system calls to hide processes or files, and process hiding is a runtime concealment method—neither directly relates to timestamp manipulation or XOR encryption of a single DLL. Option D is wrong because log wiping targets system or application logs (e.g., clearing Event Logs or /var/log files), and data hiding typically refers to steganography or alternate data streams, not XOR encryption of a DLL.

170
MCQeasy

In a macOS forensic investigation, which log system stores high-level events such as application launches and authentication attempts in a binary format, and can be queried using the 'log' command?

A.system.log
B.Audit log
C.FSEvents
D.Unified logging
AnswerD

Unified logging is the current logging architecture in macOS, introduced in Sierra, and aggregates system and user messages into a high-performance, structured, binary trace database stored under /var/db/diagnostics. It supports advanced querying via the `log` command, captures multiple log levels and activities, and is the authoritative source for modern forensic analysis of system and application behavior.

Why this answer

Unified logging is the correct answer because macOS stores high-level events like application launches and authentication attempts in a binary format within the unified log system (stored in /var/db/diagnostics/ and /var/db/uuidtext/). The 'log' command is the native tool to query these logs, using predicates and options such as 'log show' or 'log stream', making it the only option that matches both the binary format and the query method described.

Exam trap

EC-Council often tests the misconception that all macOS logs are plain-text files, leading candidates to choose system.log, when in fact modern macOS uses the binary unified log system that requires the 'log' command for querying.

How to eliminate wrong answers

Option A is wrong because system.log is a legacy plain-text log file (located at /var/log/system.log) that stores syslog-style messages, not a binary format, and is not queried with the 'log' command. Option B is wrong because the Audit log (managed by the auditd daemon, stored in /var/audit/) records security-relevant events in BSM (Basic Security Module) binary format, but it is queried using the 'praudit' or 'auditreduce' commands, not the 'log' command. Option C is wrong because FSEvents (File System Events) logs file system changes in a binary format (stored in /.fseventsd/), but it does not store application launches or authentication attempts, and it is queried using the 'fs_usage' or 'fseventer' tools, not the 'log' command.

171
MCQhard

An investigator images an SSD that has TRIM enabled. Which of the following challenges will MOST likely affect the recovery of deleted files from this SSD?

A.The SSD uses a different partition table scheme
B.TRIM causes the SSD to zero out freed blocks, preventing recovery
C.The SSD firmware encrypts all data, requiring a decryption key
D.Wear leveling spreads data across blocks, complicating recovery
AnswerB

TRIM is an ATA command that tells the SSD which logical blocks belonging to a deleted file are no longer in use, causing the controller to immediately discard or erase that data at the flash level. As a result, the original content is physically removed or marked for garbage collection before a forensic image is taken, so common recovery tools cannot reconstruct the file. This direct erasure is what makes deleted data unrecoverable on a TRIM-enabled SSD.

Why this answer

When TRIM is enabled on an SSD, the operating system notifies the drive which blocks are no longer in use. The SSD's firmware then immediately zeroes out or internally marks those blocks as free, physically erasing the data. This prevents forensic tools from recovering deleted files because the underlying data is no longer present on the NAND flash cells.

Exam trap

The trap here is that candidates often confuse wear leveling with TRIM, assuming that wear leveling itself causes data loss, when in fact TRIM is the specific command that actively erases freed blocks on SSDs.

How to eliminate wrong answers

Option A is wrong because the partition table scheme (e.g., MBR vs. GPT) does not affect the ability to recover deleted files from an SSD with TRIM; TRIM operates at the block level, independent of the partition layout. Option C is wrong because while some SSDs support hardware encryption, it is not a default or universal feature, and TRIM itself does not cause encryption; the question specifically states TRIM is enabled, not that the drive is encrypted.

Option D is wrong because wear leveling spreads writes across blocks to extend the drive's lifespan, but it does not actively erase or zero out freed blocks; TRIM is the mechanism that causes data loss, not wear leveling.

172
MCQmedium

During a Linux forensic investigation, you find a suspicious cron job in /etc/cron.d/malware that runs every 5 minutes as root. Which persistence mechanism is being used?

A.Bash history
B.Systemd service
C.Cron job
D.Init script
AnswerC

Cron job is correct because /etc/cron.d/ contains cron schedule files that the cron daemon parses and executes at predefined time intervals using the standard 'minute hour day month weekday' syntax. These jobs run as the specified user and can be set to execute arbitrary commands, making them a common mechanism attackers use for scheduled persistence. The file's presence in /etc/cron.d/ with a valid time specification directly indicates a cron job rather than any other startup or logging mechanism.

Why this answer

The cron daemon reads job definitions from files in /etc/cron.d/ and executes them according to the schedule specified. Finding a file named 'malware' in /etc/cron.d/ that runs every 5 minutes as root directly indicates a cron job persistence mechanism, as this is the standard location for system-wide cron entries.

Exam trap

EC-CHFI often tests the distinction between cron jobs and systemd timers or init scripts, and the trap here is that candidates may confuse the /etc/cron.d/ directory with init scripts or systemd unit files, not realizing that cron is a separate scheduler with its own file format and location.

How to eliminate wrong answers

Option A is wrong because Bash history (~/.bash_history) records user commands but does not automatically execute them at intervals; it is a log, not a persistence mechanism. Option B is wrong because a systemd service uses unit files (e.g., .service files in /etc/systemd/system/) and is managed by systemctl, not by entries in /etc/cron.d/. Option D is wrong because init scripts are stored in /etc/init.d/ and are used by SysV init or Upstart, not by cron, and they run at system startup or shutdown, not on a scheduled interval.

173
MCQmedium

A forensic analyst is examining a Windows 10 system and finds suspicious activity. Which registry hive contains user-specific configuration data that can reveal evidence of recent file access through ShellBags, UserAssist, and MRU lists?

A.HKLM\SYSTEM
B.HKLM\SAM
C.HKLM\SOFTWARE
D.NTUSER.DAT
AnswerD

NTUSER.DAT is the per-user registry hive loaded as HKEY_CURRENT_USER at logon. It contains explorer shell bag state, UserAssist execution counts and last-run timestamps, RecentDocs MRU, and many user-profile settings. For Windows 10 analysis, this hive is the primary registry file for reconstructing a user's activity and program execution.

Why this answer

The NTUSER.DAT file is the registry hive that stores user-specific configuration data for each user profile on a Windows 10 system. It contains the ShellBags keys (for folder view settings and recent folder access), UserAssist keys (tracking GUI-based program executions via the ROT13-encoded count and timestamp), and MRU (Most Recently Used) lists (for recently opened files and applications). These artifacts are critical for forensic analysis of user activity, and they are not stored in any of the HKLM hives, which are machine-wide.

Exam trap

A common misconception is that user-specific artifacts like ShellBags and UserAssist are stored in the HKLM\SOFTWARE hive because it contains application-related settings, but in reality, these are per-user and reside in the NTUSER.DAT hive (loaded as HKCU).

How to eliminate wrong answers

Option A is wrong because HKLM\SYSTEM stores system-wide configuration data such as device drivers, services, and boot settings, not user-specific ShellBags, UserAssist, or MRU lists. Option B is wrong because HKLM\SAM contains the Security Account Manager database with local user account hashes and group memberships, not user activity artifacts like file access logs. Option C is wrong because HKLM\SOFTWARE holds machine-wide software settings and application configurations, but user-specific data like ShellBags and UserAssist are stored per-user in NTUSER.DAT, not in this hive.

174
MCQeasy

Which Windows Registry hive is primarily used to store user-specific application settings and recently accessed files?

A.HKU\.DEFAULT
B.HKLM\SYSTEM
C.HKLM\SAM
D.NTUSER.DAT
AnswerD

NTUSER.DAT is the registry hive loaded into HKCU when a user logs on, and it contains that user's personal settings, application preferences, environment variables, desktop appearance, and recent documents. It is stored in the user's profile directory (e.g., C:\Users\Username\NTUSER.DAT) and is a key artifact for forensic analysis of user activity and configuration. The question's 'user' is best answered by NTUSER.DAT because HKCU itself is not a file, but NTUSER.DAT is the physical hive that backs it.

Why this answer

NTUSER.DAT is the correct answer because it is the registry hive file that stores per-user settings, including application configurations and recently accessed files (e.g., MRU lists). When a user logs on, Windows loads NTUSER.DAT into HKEY_CURRENT_USER (HKCU), making it the primary repository for user-specific data.

Exam trap

EC-Council often tests the misconception that HKCU is a separate hive file, when in fact it is a dynamic view of NTUSER.DAT loaded from the user's profile directory.

How to eliminate wrong answers

Option A is wrong because HKU\.DEFAULT contains the profile settings for the LocalSystem account (used by services), not for interactive users, and does not store per-user application settings or recent files. Option B is wrong because HKLM\SYSTEM stores system-wide configuration, boot parameters, and driver settings, not user-specific data. Option C is wrong because HKLM\SAM holds the Security Account Manager database (user and group credentials), not application settings or recent file lists.

175
MCQeasy

In cloud forensics, one of the major challenges is that data may be stored in multiple jurisdictions with different legal requirements. This challenge is known as:

A.Multi-tenancy
B.Chain of custody
C.Volatile evidence
D.Data jurisdiction
AnswerD

Data jurisdiction is the correct answer because cloud providers routinely replicate and store customer data across multiple geographic regions and legal jurisdictions, often without precise knowledge of the physical location at a given moment. This forces investigators to navigate conflicting national laws, data sovereignty rules, and international legal assistance processes—unlike traditional on-premises forensics where location is fixed. Legal authority to access data may depend on the data's physical or controlling jurisdiction, making this the central challenge in cloud forensics.

Why this answer

Data jurisdiction refers to the legal and regulatory issues that arise when data is stored or processed across different geographic locations with varying laws.

176
Multi-Selectmedium

A forensic analyst is investigating a Windows system for evidence of malware persistence. Which TWO registry locations are commonly used by malware to automatically execute on system startup?

Select 2 answers
A.HKLM\SAM
B.C:\Windows\Prefetch
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellBags
D.HKLM\SYSTEM\CurrentControlSet\Services
E.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AnswersD, E

HKLM\SYSTEM\CurrentControlSet\Services satisfies the persistence requirement because Windows loads service entries here at boot via the Service Control Manager, before user logon. Malware registers a malicious driver or service to achieve SYSTEM-level autostart, making this a core location for forensic examination of startup persistence.

Why this answer

Option D, HKLM\SYSTEM\CurrentControlSet\Services, is correct because this registry hive stores service configurations, including the Start value that determines whether a service (or malicious driver/service) launches automatically at boot, making it a classic autostart persistence location. Option E, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is correct because the per-user Run key causes listed programs to execute automatically when that user logs on, a very common malware persistence mechanism. Option A, HKLM\SAM, is not an autostart location; it stores local account and security database information.

Option B, C:\Windows\Prefetch, is a filesystem artifact used for execution evidence and performance, not a registry startup key. Option C, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellBags, records folder view settings and is useful for user activity forensics, not automatic execution.

Exam trap

The trap here is that candidates confuse registry locations used for user-specific startup (like HKCU\...\Run) with system-wide persistence mechanisms, or they mistakenly think non-startup keys like SAM or ShellBags are relevant to auto-execution.

177
MCQmedium

An analyst is examining a hard drive that was seized from a suspect. The drive is detected as a smaller capacity than listed on the label. Which of the following is the MOST likely explanation?

A.The drive has been partitioned with a GPT table, which does not use the full capacity
B.The file system is FAT32, which has a 2 TB limit
C.The drive controller has a firmware bug reporting incorrect size
D.The drive has a Host Protected Area (HPA) that hides sectors from the OS
AnswerD

A Host Protected Area (HPA) is an ATA feature that allows the maximum LBA address to be set to a value lower than the drive's physical limit, effectively hiding the sectors beyond that point from the operating system. This is performed with the SET MAX ADDRESS command, and the hidden area can contain data deliberately hidden from normal access. Forensic examiners can determine the true native capacity using ATA commands and, with proper write-blocking, remove the HPA to image the entire disk, making this the correct explanation for the observed discrepancy.

Why this answer

A Host Protected Area (HPA) is a reserved region on an ATA/ATAPI hard drive that can hide sectors from the operating system, making the drive appear smaller than its physical capacity. This is a common anti-forensics technique used to conceal data, and it can be detected and removed using tools like hdparm or ATA Security commands.

Exam trap

The trap here is that candidates may confuse file system limits (like FAT32's 2 TB cap) with raw drive capacity reporting, or assume partitioning schemes like GPT inherently reduce capacity, when in fact HPA is the deliberate, forensically significant mechanism for hiding sectors.

How to eliminate wrong answers

Option A is wrong because GPT (GUID Partition Table) actually supports drives larger than 2 TB and uses the full capacity; it does not hide sectors or reduce usable space. Option B is wrong because FAT32 has a 2 TB volume size limit, but this applies to the file system, not the raw drive capacity detected by the BIOS or OS; the drive would still report its full physical size. Option C is wrong while firmware bugs can cause incorrect size reporting, they are rare and not the most likely explanation in a forensic context; HPA is a deliberate, common mechanism for hiding data.

178
Multi-Selecthard

Which THREE of the following are best practices for a first responder when arriving at a computer crime scene?

Select 3 answers
A.Photograph the entire scene, including the computer screen and connections
B.Disconnect the computer from the network to prevent remote tampering
C.Turn off the computer immediately to prevent remote access
D.Boot the computer from a forensic CD to preview the hard drive
E.Collect volatile data such as RAM if the computer is on
AnswersA, B, E

Photographing the entire scene before touching anything creates a permanent visual record of the computer's physical location, orientation, visible screen contents, LEDs, and all cable connections to peripherals and the network. This documentation preserves transient configuration details that can never be recreated later, and it supports chain-of-custody by showing exactly the state in which the device was found. Thorough scene photography is a foundational first-responder step.

Why this answer

Option A is correct because photographing the entire scene—including the screen contents, cable connections, and peripheral devices—creates an accurate, tamper-evident visual record of the original state before anything is touched, which is essential for later legal admissibility. Option B is correct because disconnecting the computer from the network (e.g., unplugging the Ethernet cable or disabling Wi-Fi) prevents remote tampering, malware propagation, or remote wipe commands while preserving the local system state. Option E is correct because volatile data such as RAM contents, running processes, network connections, and open files are lost on shutdown, so a first responder should capture this evidence first using accepted order-of-volatility principles.

Option C is not appropriate because powering off the machine destroys volatile evidence and can trigger encryption or anti-forensic routines, and it contradicts the need to preserve RAM. Option D is not appropriate for a first responder because booting from a forensic CD alters the system state and is a later laboratory or examiner step, not an initial scene-response action.

Exam trap

EC-Council often tests the misconception that immediately powering off a computer is a safe first step, when in fact it destroys volatile evidence and can corrupt the file system, making forensic recovery harder.

179
Multi-Selectmedium

Which TWO of the following are essential components of a proper chain of custody documentation? (Select TWO.)

Select 2 answers
A.The name of the suspect
B.Date and time of each evidence transfer
C.Signature of each person who handled the evidence
D.The operating system version of the suspect's computer
E.The IP address of the forensic workstation
AnswersB, C

Recording the date and time of every evidence transfer establishes an auditable timeline proving continuous custody from seizure to presentation. This satisfies the chain of custody requirement by demonstrating that no unaccounted gap permitted tampering.

Why this answer

Option B is correct because chain of custody documentation must record the date and time of every transfer of evidence, establishing an auditable timeline that proves the evidence was continuously accounted for from seizure to presentation. Option C is correct because each person who handled or transferred the evidence must sign for it, creating individual accountability and showing an unbroken sequence of custody. Together, these entries let investigators demonstrate that the evidence was not tampered with or substituted.

Option A is not essential to the chain of custody itself, since the suspect's identity does not establish who controlled the evidence. Option D is irrelevant because the OS version of the suspect's computer is a technical artifact detail, not a custody record. Option E is likewise irrelevant, as the forensic workstation's IP address does not document the handling or transfer of evidence.

Exam trap

EC-Council often tests the misconception that technical details about the evidence (like OS version or IP address) are part of chain of custody, when in fact the chain only tracks who handled the evidence and when, not the evidence's configuration.

180
MCQmedium

During the initial response to a suspected data breach, a first responder discovers a live system with active network connections. The responder needs to preserve evidence while minimizing alteration. Which of the following is the MOST appropriate first step?

A.Use a memory acquisition tool to capture the contents of RAM.
B.Run a full disk imaging tool to capture the hard drive contents.
C.Disconnect the network cable to isolate the system from the network.
D.Immediately shut down the system by pulling the power cord.
AnswerA

A memory acquisition tool (e.g., WinPmem, DumpIt, or FTK Imager's memory capture) preserves the volatile data that defines the system's live state: running processes, loaded kernel modules, open network sockets, unencrypted credentials, and memory-resident malware. This is the first step in RFC 3227's volatility order because every subsequent action—including disk imaging, network isolation, or powering off—will alter or destroy these transient artifacts, leaving the investigation without the most probative evidence of the breach.

Why this answer

A is correct because in a live system with active network connections, the most volatile evidence is in RAM (e.g., running processes, network connections, encryption keys). Using a memory acquisition tool (like FTK Imager or WinPmem) captures this volatile data before any other action, preserving evidence that would be lost on shutdown or disconnection. This aligns with the order of volatility (RFC 3227), which prioritizes memory over disk.

Exam trap

The CHFI exam often tests the misconception that disconnecting the network or shutting down is the safest first step, but the trap here is that volatile memory is the most critical evidence and must be captured before any action that could alter or destroy it.

How to eliminate wrong answers

Option B is wrong because running a full disk imaging tool first would overwrite unallocated space and modify system metadata (e.g., last access times), altering evidence; it also ignores the higher volatility of RAM. Option C is wrong because disconnecting the network cable may terminate active connections and cause the system to lose volatile data (e.g., network state, encryption keys), and it can trigger anti-forensic scripts that wipe evidence. Option D is wrong because immediately shutting down by pulling the power cord destroys all volatile memory (RAM), including running processes and network connections, and can corrupt disk data due to unclean shutdown.

181
Multi-Selectmedium

Which TWO Windows artifacts can be used to identify recently accessed files or folders on a system? (Select the two best answers.)

Select 2 answers
A.Event ID 4624
B.SAM hive
C.Prefetch files
D.LNK files
E.ShellBags
AnswersD, E

LNK files (Windows shortcuts) are automatically created when a user accesses a file or folder, particularly in locations like the Recent folder (%AppData%\Microsoft\Windows\Recent), desktop, or Start Menu. These shortcut files embed the target path, creation timestamp, last written timestamp, and even the volume serial number of the drive, making them excellent evidence of recently opened documents. Forensic tools can parse LNK metadata to reconstruct user file access activity, even if the original file has been deleted.

Why this answer

LNK files (option D) are Windows shortcut files that store a reference to the original target file or folder, including its path, volume information, and timestamps, and they are created or updated when a user opens a document or folder, making them a direct indicator of recent access. ShellBags (option E) are registry entries (in NTUSER.DAT under HKCU\Software\Microsoft\Windows\Shell) that record folder view settings and paths the user has browsed in Explorer, so they reveal folders that were accessed even if the folder no longer exists. Event ID 4624 (option A) is a Security log entry for successful logon events and does not record file or folder access.

The SAM hive (option B) stores local user account and password hash data, not file access history. Prefetch files (option C) record execution of applications to speed up subsequent launches, not the opening of individual files or folders.

Exam trap

The CHFI exam often tests the distinction between artifacts that record file/folder access (LNK, ShellBags) versus artifacts that record program execution (Prefetch) or system-level events (Event IDs), leading candidates to mistakenly select Prefetch files or Event ID 4624.

182
MCQmedium

A network forensic analyst captures packets and sees a TCP SYN packet sent to port 80, followed by a SYN-ACK, then an ACK, and then an HTTP GET request. What can be concluded?

A.The session was hijacked after the handshake
B.A TCP half-open scan was performed
C.The TCP connection was successfully established
D.The connection was refused by the server
AnswerC

The presence of all three handshake packets—SYN, SYN-ACK, and ACK—in the capture, with the ACK carrying a valid sequence number that acknowledges the server's SYN-ACK, confirms that the TCP connection reached the ESTABLISHED state. This is further corroborated by data segments following the handshake, where the payload-bearing packets use the negotiated sequence and acknowledgment numbers to advance the byte stream. In forensic packet analysis, a completed handshake with subsequent payload indicates a successful connection.

Why this answer

The TCP three-way handshake (SYN, SYN-ACK, ACK) completes successfully, establishing a connection. The subsequent HTTP GET request confirms the connection is fully open and usable for application-layer data transfer. This is the standard sequence for a normal TCP connection establishment.

Exam trap

EC-Council CHFI exams often test the distinction between a completed TCP handshake (SYN, SYN-ACK, ACK) and a half-open scan (SYN only, no final ACK). Candidates may mistakenly think any SYN followed by SYN-ACK indicates a scan, but the presence of the final ACK and data proves the connection was fully established.

How to eliminate wrong answers

Option A is wrong because session hijacking would require injecting packets with forged sequence numbers after the handshake, not the normal completion of the handshake and a legitimate HTTP GET. Option B is wrong because a TCP half-open scan (e.g., using nmap -sS) sends only a SYN and never completes the handshake with an ACK; the presence of a full handshake and an HTTP GET indicates a completed connection, not a scan. Option D is wrong because a connection refused would result in a RST packet from the server in response to the SYN, not a SYN-ACK and subsequent data transfer.

183
Multi-Selectmedium

An analyst is examining a Windows 10 system and suspects the use of NTFS alternate data streams (ADS) to hide malicious executables. Which THREE methods can the analyst use to detect hidden ADS on the system?

Select 3 answers
A.Checking the $MFT for $DATA attributes where the attribute name is not empty
B.Using `Sysinternals streams.exe` to enumerate streams on the drive
C.Comparing file sizes from `dir` output with raw disk sector counts
D.Running `sfc /scannow` to verify system file integrity
E.Running `dir /r` in the command prompt to list files with alternate streams
AnswersA, B, E

In NTFS, every file has a default, unnamed $DATA attribute that holds the primary file content; any additional $DATA attribute must have a non-empty name and constitutes an alternate data stream (ADS). Parsing the MFT directly, using forensic tools or a custom parser, reveals these named $DATA attributes even when the file system APIs hide them from normal directory listings. This method is definitive because it reads the raw on-disk structures rather than relying on OS-level enumeration, and it can expose ADS that were deliberately created with names mimicking legitimate files.

Why this answer

Option A is correct because NTFS alternate data streams are stored as additional $DATA attributes within a file's MFT record, so parsing the $MFT and looking for $DATA attributes whose name field is non-empty directly reveals the existence of named streams. Option B is correct because Sysinternals streams.exe is purpose-built to enumerate NTFS alternate data streams on files, directories, or entire drives, making it a standard forensic and administrative detection tool. Option E is correct because the Windows `dir /r` switch displays alternate data streams associated with files, listing each stream name and its size alongside the normal file listing.

Option C is not a reliable detection method because `dir` reports the logical file size while raw sector counts include allocation and metadata differences, so discrepancies do not specifically indicate ADS. Option D is incorrect because `sfc /scannow` only verifies and repairs the integrity of protected Windows system files and does not enumerate or report alternate data streams.

Exam trap

Candidates often mistakenly believe that `dir /r` is only available in PowerShell or is not a valid method. In reality, `dir /r` works in the standard Windows Command Prompt (cmd.exe) and is a legitimate way to list alternate data streams.

184
MCQmedium

During a mobile forensic investigation, an analyst uses Cellebrite UFED to extract data from a locked iOS device. The extraction successfully retrieves the device's passcode, call logs, SMS messages, and application data. Which extraction method did the analyst MOST likely use?

A.File system extraction
B.Physical extraction
C.Advanced logical extraction
D.Logical extraction
AnswerC

Advanced logical extraction, as performed by tools such as Cellebrite UFED, leverages bootload-level exploits like Checkm8 to temporarily bypass the lock screen and prompt the device to trust the forensic workstation. This grants access to keychain items, including passcode hashes, and permits extraction of app data by reading the encrypted filesystem with the user's decryption keys while the device is powered. It is the correct answer because it is specifically designed to recover passcode-related and application data from locked iOS devices in a non-invasive manner, preserving data integrity without needing a full chip image.

Why this answer

C is correct because Advanced Logical Extraction (ALE) on Cellebrite UFED leverages a combination of file system parsing, agent-based extraction, and exploit techniques to retrieve the device passcode, call logs, SMS messages, and application data from a locked iOS device without requiring a full physical dump. This method bypasses the logical extraction limitations by using a custom agent or AFC (Apple File Conduit) to access protected data, making it the most likely method for the described successful extraction.

Exam trap

The CHFI exam often tests the misconception that 'physical extraction' is the most powerful method for locked iOS devices, but the trap here is that physical extraction is rarely achievable on modern iOS due to hardware encryption, whereas Advanced Logical Extraction is the practical method used by tools like Cellebrite UFED to retrieve passcodes and application data from locked devices.

How to eliminate wrong answers

Option A is wrong because file system extraction typically requires the device to be jailbroken or have an unlocked state to mount the file system and retrieve raw files; it does not inherently retrieve the passcode from a locked device. Option B is wrong because physical extraction on iOS devices is extremely limited due to hardware encryption and secure enclave protections, and it rarely succeeds on locked devices without advanced bootrom exploits (e.g., checkm8), which are not standard in Cellebrite UFED for passcode retrieval. Option D is wrong because logical extraction only retrieves data that the device's operating system exposes via standard APIs (e.g., iTunes backup), which does not include the passcode or deep application data from a locked device.

185
MCQmedium

A Linux system uses the ext4 filesystem. A forensic analyst needs to recover a recently deleted file. Which of the following methods is MOST likely to succeed if the file's inode has not been reallocated?

A.Mount the filesystem with `mount -o ro,noatime` and browse
B.Use `dd` to copy the entire partition and search for the file signature
C.Use `ls -la` to view deleted file entries
D.Run `extundelete /dev/sda1 --restore-file /path/to/file`
AnswerD

Running extundelete /dev/sda1 --restore-file /path/to/file is correct because extundelete is specifically built to recover deleted files from ext3/ext4 filesystems by scanning inode tables, block bitmaps, and the journal to locate the inode and reconstruct the file's data blocks. It can operate on a live mounted partition, but safest practice is to unmount first, and it restores the original filename in a dedicated output directory if the inode is still present and not overwritten. This targeted approach aligns with ext4's metadata structures, unlike simple browsing or blind carving.

Why this answer

`extundelete` is a dedicated tool designed to recover deleted files from ext3/ext4 filesystems by leveraging the filesystem's journal and inode data. If the inode has not been reallocated, the tool can directly restore the file using its path, making it the most targeted and efficient method.

Exam trap

EC-Council often tests the misconception that deleted files remain visible in directory listings or can be recovered by simply mounting the filesystem, when in fact specialized tools like `extundelete` are required to access the filesystem's metadata structures.

How to eliminate wrong answers

Option A is wrong because mounting with `-o ro,noatime` only provides read-only access and prevents access time updates, but does not recover deleted files; deleted files are not visible through normal directory browsing. Option B is wrong because using `dd` to image the partition and then searching for a file signature is a brute-force, time-consuming method that relies on file content being contiguous and unoverwritten, and it is less reliable than using filesystem metadata. Option C is wrong because `ls -la` only lists current directory entries and cannot show deleted file entries; deleted files are not listed in the directory structure.

186
Multi-Selectmedium

During a mobile forensic investigation, an examiner wants to recover deleted WhatsApp messages from an Android device. Which of the following artefacts should the examiner examine? (Select TWO.)

Select 2 answers
A./data/media/0/Android/data/com.whatsapp/
B./data/data/com.android.providers.telephony/databases/mmssms.db
C./data/data/com.whatsapp/databases/msgstore.db
D./data/data/com.whatsapp/files/Avatars/
E./data/data/com.google.android.gms/databases/
AnswersA, C

This path is the app-specific external storage directory for WhatsApp on shared storage, exposed via FUSE and sometimes accessible to forensic tools even without root. It holds user-visible artifacts such as transmitted images, videos, voice notes, and document files, and may also contain encrypted database backups (e.g., msgstore.db.crypt14) that, when credentialed or decrypted, can reveal message history. In a logical acquisition, this location is a priority because it often survives app data clearing and can corroborate messages recovered from the internal database. It is correct because it is a designated app-owned location on external media where WhatsApp materializes attachments with metadata like file names and timestamps.

Why this answer

WhatsApp stores media files (images, videos, voice notes) in the external app-specific directory `/data/media/0/Android/data/com.whatsapp/`. Even after a message is deleted from the chat, the media file may remain in this directory if it was not explicitly removed, allowing recovery. Option C is correct because the primary SQLite database `msgstore.db` in `/data/data/com.whatsapp/databases/` contains the chat messages, including deleted entries that are often only marked as deleted but not physically removed until a vacuum operation.

Exam trap

The CHFI exam often tests the distinction between the app-specific data directory (`/data/data/`) and the external media directory (`/data/media/0/`), tricking candidates into thinking only the internal database holds deleted messages, while media files in the external directory are also recoverable artefacts.

187
MCQmedium

During a forensic investigation, an analyst acquires a hard drive using a hardware write blocker. Which of the following is the PRIMARY reason for using a hardware write blocker?

A.To increase the transfer speed of the imaging process.
B.To bypass the drive's password protection.
C.To compress the data during imaging.
D.To ensure that the operating system does not mount the drive as writable.
AnswerD

The forensic purpose of a write blocker is to prevent the host operating system from mounting the evidence drive with write access. Without a write blocker, merely connecting a drive to a forensic workstation can cause the OS to automatically mount it read-write, creating files, updating last-accessed timestamps, or writing to the filesystem journal—all of which modify the evidence and invalidate its cryptographic hash. A hardware write blocker sits between the drive and the host and intercepts ATA/SCSI commands, allowing read commands to pass while blocking write commands at the firmware level. This guarantees that the original evidence drive remains bit-for-bit unchanged, preserving its forensic integrity and admissibility in court.

Why this answer

The primary reason for using a hardware write blocker is to physically intercept the SATA/IDE bus between the suspect drive and the forensic workstation, ensuring that only read commands (e.g., ATA READ DMA) are passed through while blocking any write commands (e.g., ATA WRITE DMA). This prevents the operating system from mounting the drive as writable, which would otherwise cause automatic writes (e.g., timestamp updates, journaling, or prefetch creation) that alter evidence and break the chain of custody.

Exam trap

The trap here is that candidates confuse the write blocker's purpose with performance features (speed, compression) or assume it can bypass security mechanisms, when in fact its sole forensic function is to guarantee read-only access at the hardware interface level.

How to eliminate wrong answers

Option A is wrong because hardware write blockers do not increase transfer speed; they operate at the bus speed and may even introduce slight latency due to filtering logic. Option B is wrong because bypassing drive password protection is not a function of a write blocker; that requires specialized tools like forensic drive unlockers or ATA security commands. Option C is wrong because compression is a software feature of imaging tools (e.g., dd with gzip, FTK Imager, EnCase) and is unrelated to the hardware write blocker's role of write prevention.

188
MCQmedium

A forensic investigator is examining a Windows 10 workstation that was seized after a suspected data exfiltration. The user claims they only used legitimate cloud storage. The investigator wants to determine which USB mass storage devices were previously connected to the system by examining the Windows registry. Which registry location should the investigator examine to find the device instance IDs and associated volume serial numbers of previously connected USB storage devices?

A.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
B.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
C.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
D.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBHUB\Enum
AnswerA

The USBSTOR key under the SYSTEM hive stores information about USB mass storage devices that have been connected. Each subkey represents a device instance and contains details such as the device serial number, friendly name, and sometimes the volume serial number. This is the primary location for tracing USB storage device history on Windows systems.

Why this answer

The USBSTOR registry key under the SYSTEM hive is specifically designed to track USB mass storage devices. It records device instance IDs, which include the vendor ID, product ID, and serial number, allowing investigators to identify unique devices. This key persists even after the device is removed, making it a reliable source for determining previous USB storage connections.

Exam trap

The trap here is confusing MountPoints2 with USBSTOR, as both can show USB usage but only USBSTOR stores the device instance IDs and serial numbers needed for definitive identification.

189
Multi-Selecteasy

Which TWO of the following are common challenges specific to cloud forensics?

Select 2 answers
A.Multi-tenancy issues
B.Data jurisdiction
C.Inability to create disk images
D.Permanent data deletion recovery
E.Lack of forensic tools
AnswersA, B

In cloud environments, physical servers host virtual machines from multiple customers simultaneously, meaning forensic investigators must retrieve evidence from shared infrastructure without compromising other tenants' data. A logical volume snapshot or hypervisor memory capture may inadvertently include artifacts from co-resident workloads, creating legal and ethical isolation problems. This challenge is cloud-specific because in traditional on-premise forensics the media belongs exclusively to the subject organization, whereas cloud providers enforce isolation only through software boundaries like virtual LANs and hypervisor controls.

Why this answer

Multi-tenancy complicates data isolation, and data jurisdiction affects legal access to data across regions.

190
Multi-Selecthard

In the context of e-discovery, which THREE of the following are key steps in the Electronic Discovery Reference Model (EDRM)? (Select THREE)

Select 3 answers
A.Preservation
B.Production
C.Collection
D.Prosecution
E.Investigation
AnswersA, B, C

In the EDRM, preservation is the planned, proactive act of placing a litigation hold on all potentially relevant electronically stored information (ESI) once legal action is reasonably anticipated. It ensures that data remains intact and unaltered, thereby preventing spoliation and associated sanctions. Preservation is distinct from collection in that it imposes a legal duty to maintain the status quo, rather than performing the physical extraction of data.

Why this answer

Preservation (A) is a core EDRM step that focuses on safeguarding potentially relevant electronically stored information (ESI) once a duty to preserve is triggered, preventing spoliation before collection occurs. Production (B) is the EDRM phase in which responsive, non-privileged ESI is delivered to the requesting party in an agreed-upon format, often with load files and metadata, completing the exchange. Collection (C) is the EDRM step that gathers the identified and preserved ESI using forensically sound methods so that its integrity and chain of custody are maintained for later processing and review.

The other options do not belong: Prosecution (D) is a legal litigation activity, not an EDRM phase, and Investigation (E) is a general fact-finding process that is not one of the nine EDRM stages (Identification, Preservation, Collection, Processing, Review, Analysis, Production, Presentation, and Information Governance).

Exam trap

The CHFI exam often tests the distinction between 'Preservation' and 'Collection' as separate steps, and candidates mistakenly think 'Investigation' or 'Prosecution' are part of the EDRM when they are actually post-discovery legal actions.

191
MCQmedium

An investigator is analyzing cloud storage logs and finds an entry showing that a file was accessed using the root credentials from an IP address in a different geographic region. The organization has strict policies against root usage. What should the investigator do FIRST?

A.Check if the activity correlates with a known vulnerability or authorized task
B.Contact law enforcement for cybercrime investigation
C.Change the password of the root account
D.Immediately revoke the root access keys
AnswerA

Correlating the observed access against logged change tickets, vulnerability scanners (e.g., CVE data), and scheduled maintenance windows is the correct initial triage step. It lets you determine whether the activity is a false positive or expected administrative behavior before taking any action that would be disruptive or destructive. Cross-referencing source IP, user agent, and API call pattern against known vulnerability signatures or authorized task records preserves evidential integrity while filtering out benign anomalies.

Why this answer

The first step in any forensic investigation is to correlate the suspicious activity with known events, such as authorized tasks or vulnerabilities, to avoid false positives. Root access from an unfamiliar IP could be legitimate if tied to a scheduled maintenance window or a known vulnerability exploitation attempt that requires verification. Prematurely changing credentials or contacting law enforcement could destroy evidence or alert an attacker before the scope is understood.

Exam trap

The trap here is that candidates panic and choose a reactive security action (like revoking keys or changing passwords) instead of following forensic best practice: preserve and validate before acting.

How to eliminate wrong answers

Option B is wrong because contacting law enforcement is a premature escalation step that should only occur after internal validation and evidence preservation, not as the first action. Option C is wrong because changing the root password could alert an active attacker and destroy volatile evidence such as active sessions or memory artifacts. Option D is wrong because immediately revoking root access keys could disrupt legitimate operations and also destroy evidence; the investigator must first verify the activity's legitimacy and preserve logs.

192
MCQhard

A forensic analyst is using Plaso (log2timeline) to create a super timeline from a compromised Windows system. Which of the following is the PRIMARY advantage of using Plaso over manual timeline creation?

A.It automatically correlates events from different sources and provides a unified timeline
B.It can detect malware by signature scanning
C.It generates a timeline only from Windows Event Logs
D.It encrypts the timeline for secure storage
AnswerA

Plaso log2timeline ingests data from filesystem metadata, application logs, and artifact parsers, then normalizes and correlates timestamped events into a single timeline. This unified super-timeline allows an analyst to visualize and sequence activity across email, web, and file transactions. Consequently, it enables efficient analysis of event sequences rather than per-source inspection.

Why this answer

Plaso (log2timeline) is designed to automatically parse and correlate artifacts from multiple sources—such as Windows Event Logs, Registry hives, Prefetch files, and USN journals—into a single, unified super timeline. This eliminates the need for manual correlation across disparate log files, which is error-prone and time-consuming, making automated correlation the primary advantage over manual timeline creation.

Exam trap

In EC-CHFI exams, candidates often confuse Plaso's automated correlation with other security functions like malware detection or encryption, leading to incorrect choices.

How to eliminate wrong answers

Option B is wrong because Plaso does not perform signature-based malware detection; it is a timeline creation and forensic artifact parsing tool, not an antivirus or intrusion detection system. Option C is wrong because Plaso generates timelines from a wide range of forensic artifacts (e.g., Registry, file system metadata, browser history), not exclusively from Windows Event Logs. Option D is wrong because Plaso does not encrypt timelines; encryption is a separate storage or transport concern, not a core feature of the timeline generation process.

193
MCQmedium

An analyst is performing malware analysis and executes a suspicious binary in a sandbox. The sandbox reports that the binary creates a mutex named 'Global\DRIVER_UPDATE_MTX' before attempting to connect to 'http://malicious.com/update'. Which tool would BEST capture the network traffic during dynamic analysis?

A.Regshot
B.Wireshark
C.Process Explorer
D.Process Monitor
AnswerB

Wireshark is a full-featured network protocol analyzer that captures raw frames on a network interface and decodes hundreds of protocols, from Ethernet through application layers. For malware analysis, it is the standard tool for observing live command-and-control (C2) sessions, exfiltration attempts, or scanning activity. Analysts can filter for suspicious IPs, follow TCP streams to reconstruct payloads, and read pre-recorded packet capture (PCAP) files, making it ideal for this scenario.

Why this answer

Wireshark is the correct tool because it captures and analyzes network packets at the protocol level, allowing the analyst to inspect the HTTP request to 'http://malicious.com/update', including headers, payload, and any subsequent data exfiltration. Dynamic analysis of malware requires monitoring network traffic to identify command-and-control (C2) communications, and Wireshark provides full packet capture (PCAP) for this purpose.

Exam trap

EC-Council often tests the distinction between host-based monitoring tools (like Process Monitor and Process Explorer) and network-based capture tools (like Wireshark), leading candidates to choose a host-based tool when the question explicitly asks for network traffic capture.

How to eliminate wrong answers

Option A is wrong because Regshot is a registry and file system snapshot comparison tool, not a network traffic capture tool; it cannot capture HTTP or TCP/IP packets. Option C is wrong because Process Explorer is a process management and analysis utility that shows handles, DLLs, and threads, but it does not capture network traffic at the packet level. Option D is wrong because Process Monitor monitors file system, registry, and process/thread activity in real time, but it does not capture raw network packets or HTTP traffic.

194
MCQeasy

Which of the following is an example of an indicator of compromise (IoC) that can be used to detect malware on a network?

A.A mutex name
B.A known malicious IP address
C.A registry key modification
D.A file's MD5 hash
AnswerB

A known malicious IP address is a network-based indicator of compromise because it is observed in network telemetry, such as connections to a command-and-control (C2) server, phishing infrastructure, or malware distribution points. Analysts identify it through flow logs, DNS queries, or proxy logs, and it reflects external communication from the victim environment. Because it is a network artifact rather than an endpoint artifact, it is the correct answer for a network-level IoC.

Why this answer

A known malicious IP address is a classic indicator of compromise (IoC) because it directly identifies a command-and-control (C2) server or a source of malicious traffic. Network monitoring tools can match outbound or inbound connections against threat intelligence feeds of known bad IPs, triggering an alert. This is a network-based IoC that requires no host-level analysis, making it ideal for initial detection.

Exam trap

EC-Council often tests the distinction between network-based and host-based IoCs, and the trap here is that candidates mistakenly classify host-level artifacts (mutex, registry, hash) as network IoCs because they are common in malware analysis, but the question explicitly asks for an indicator 'on a network'.

How to eliminate wrong answers

Option A is wrong because a mutex name is a host-based artifact used to detect malware on an infected system (e.g., ensuring only one instance runs), not a network-based IoC. Option C is wrong because a registry key modification is a host-based forensic artifact indicating persistence or configuration changes on a Windows system, not a network-level indicator. Option D is wrong because a file's MD5 hash is a host-based file integrity check or malware signature, used to identify known malicious files on disk, not to detect malware on the network.

195
MCQhard

During a forensic examination, an analyst uses the command 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync'. What is the primary purpose of the 'conv=noerror,sync' option in this context?

A.To split the image into multiple smaller files
B.To skip bad sectors and continue imaging, padding the output with zeros
C.To compress the output image file
D.To verify the image integrity using a hash
AnswerB

The `noerror` flag lets dd continue past read errors instead of aborting, while `sync` pads each failed block with zero bytes so block alignment and offsets stay intact. This satisfies the forensic requirement of acquiring a complete, verifiable image from a failing drive without losing positional correspondence to the source.

Why this answer

The 'conv=noerror,sync' option tells dd to continue reading even when it encounters read errors (noerror) and to pad the output with zeros (sync) to maintain the correct offset alignment, ensuring the image remains a bit-for-bit copy of the source drive despite bad sectors. This is critical in forensic imaging to preserve the integrity of the data stream and avoid truncation or corruption of the output file.

Exam trap

The trap here is that candidates often confuse 'conv=noerror,sync' with error correction or data recovery, when in fact it simply allows the imaging to proceed past bad sectors by padding with zeros, not by recovering the lost data.

How to eliminate wrong answers

Option A is wrong because splitting an image into multiple files is achieved with options like 'split' or 'bs' combined with 'count', not with 'conv=noerror,sync'. Option C is wrong because compression is not a function of dd's conv parameter; compression requires piping through gzip or using a separate tool. Option D is wrong because hash verification is done with separate commands like 'md5sum' or 'sha256sum', not with the conv parameter of dd.

196
MCQhard

During a memory forensics analysis using Volatility, an examiner runs 'python vol.py -f memory.dmp pslist' and sees a suspicious process named 'expl0rer.exe' with a PPID of 4. What does a PPID of 4 indicate, and what should the examiner do next?

A.The process is probably a hidden or injected process; run 'psxview' and 'malfind' to detect anomalies
B.The process is a child of the System process, indicating it is a legitimate system process; no further action needed
C.The process is a child of the System Idle Process, which is normal; ignore it
D.The process has been injected into the System process and is likely a rootkit; run 'psscan' to verify
AnswerA

In Volatility, a process whose parent PID is 4 (System) is anomalous because the System kernel process rarely creates user-mode children; this pattern often appears when malware uses parent PID spoofing or when a process is hidden from the normal active process list. Run 'psxview' to cross-reference process listings from multiple sources (e.g., PsActiveProcessHead, PspCidTable, and CSRSS) to uncover hidden processes, and 'malfind' to locate executable pages containing injected shellcode such as an MZ header. These steps will confirm whether the process is truly malicious or merely unusual, making this the correct investigative action.

Why this answer

In Windows memory forensics, a PPID of 4 indicates the parent process is the System process (PID 4), which is the kernel-mode process responsible for starting system services and drivers. A suspicious process like 'expl0rer.exe' with PPID 4 is highly anomalous because legitimate user-mode processes are rarely direct children of the System process; the most notable legitimate exception is smss.exe. The examiner should run 'psxview' to check for hidden processes and 'malfind' to detect code injection, as this PPID can indicate a process masquerading as a system component or whose parent PID has been manipulated.

Exam trap

The CHFI exam often tests the misconception that PPID 4 always means a legitimate system process, but the trap is that the System process (PID 4) rarely has direct user-mode children, and any suspicious name warrants further analysis with 'psxview' and 'malfind'.

How to eliminate wrong answers

Option B is wrong because while PPID 4 does indicate the System process, a suspiciously named process like 'expl0rer.exe' is not a legitimate system process; system processes have standard names (e.g., smss.exe, csrss.exe) and are not direct children of PID 4. Option C is wrong because PPID 4 refers to the System process, not the System Idle Process (PID 0); the System Idle Process has PID 0, and a PPID of 4 does not indicate an idle or normal process. Option D is wrong because while injection is possible, a PPID of 4 does not necessarily mean the process has been injected into the System process; it means the process is a child of the System process, and 'psscan' is used to find terminated or hidden processes, not specifically to verify injection; 'malfind' is the appropriate tool for detecting injected code.

197
MCQeasy

Which of the following is the PRIMARY purpose of using a write blocker in computer forensics?

A.To speed up the imaging process by caching writes.
B.To convert the hard drive interface from SATA to USB.
C.To encrypt the forensic image for secure transport.
D.To prevent any modification to the original evidence drive during acquisition.
AnswerD

A hardware write blocker's primary purpose is to preserve the forensic integrity of the original evidence drive by intercepting the command stream between the host computer and the suspect drive, filtering out any write, erase, or reset commands while allowing read-only access. This ensures that the acquisition process does not alter data, timestamps, or metadata, allowing the resulting forensic image to match the original bit-for-bit and be verified via hashing. By enforcing read-only access at the hardware interface level, it provides a court-defensible mechanism for evidence preservation.

Why this answer

A write blocker ensures that no data is written to the original evidence drive during acquisition, maintaining its integrity.

198
Multi-Selecthard

Which THREE of the following are common challenges specific to cloud forensics? (Select THREE)

Select 3 answers
A.Data jurisdiction and legal compliance across regions
B.Volatility of evidence due to auto-scaling and ephemeral instances
C.Inability to acquire physical hard drives
D.Lack of standardized log formats
E.High cost of forensic tools
AnswersA, B, C

Cloud data resides in provider-controlled regions, so forensic acquisition must satisfy differing disclosure, privacy and data-protection laws. This legal fragmentation across jurisdictions directly constrains where evidence can be collected and how it may be transferred, satisfying the cross-region compliance challenge named in the stem.

Why this answer

Option A is correct because cloud data is stored in provider regions worldwide, so investigators must navigate differing data-protection laws (e.g., GDPR), cross-border legal processes, and jurisdictional conflicts over where evidence resides and who controls it. Option B is correct because auto-scaling, serverless functions, and ephemeral instances can be terminated or recycled at any time, destroying volatile evidence such as RAM contents, running processes, and temporary logs before acquisition can occur. Option C is correct because in cloud environments the customer has no physical access to the underlying hardware; forensic acquisition must rely on provider-mediated methods like VM snapshots, EBS volume copies, or APIs rather than seizing physical hard drives.

Option D is not a cloud-specific challenge, since inconsistent log formats are a general logging issue across on-premises and cloud systems rather than unique to cloud forensics. Option E is not a cloud-specific challenge either, as the cost of forensic tools applies broadly to all digital investigations and is not an inherent characteristic of cloud computing.

Exam trap

EC-Council often tests the distinction between general forensic challenges and those that are unique to cloud environments, so candidates mistakenly select 'Lack of standardized log formats' or 'High cost of forensic tools' because they are real issues, but they are not specific to cloud forensics.

199
Multi-Selecteasy

Which TWO of the following are common Linux log files that can be used for forensic analysis?

Select 2 answers
A./etc/passwd
B./var/log/syslog
C./var/log/auth.log
D./etc/shadow
E./proc/cpuinfo
AnswersB, C

/var/log/syslog is the primary, centralized system log on Debian-based distributions like Ubuntu, written by the rsyslog daemon. It aggregates high-level kernel messages, service start and stop events, hardware errors, cron activity, and other system-level notifications from software that uses the syslog(3) API. This file is essential for troubleshooting and forensic timeline reconstruction because it captures a broad chronological record of system behavior, though it deliberately excludes authentication events.

Why this answer

/var/log/syslog (B) is correct because it is the standard system log on many Linux distributions (Debian/Ubuntu and others), recording kernel messages, daemon activity, service events, and general system errors that are valuable for reconstructing a timeline during forensic analysis. /var/log/auth.log (C) is also correct because it captures authentication-related events such as logins, sudo usage, su attempts, and PAM/SSH authentication failures or successes, which are essential for investigating unauthorized access. The unmarked options do not belong: /etc/passwd (A) and /etc/shadow (D) are account database files, not log files, even though they are useful for reviewing user accounts and password hashes, and /proc/cpuinfo (E) is a virtual file exposing CPU details, not a log of system or security events.

Exam trap

The exam highly tests the distinction between configuration files (like /etc/passwd and /etc/shadow) and dynamic log files, leading candidates to mistakenly select static system files as sources of forensic evidence.

200
MCQmedium

A network forensics analyst captures traffic and sees a series of TCP SYN packets sent to multiple ports on a target, with no corresponding SYN-ACK replies. What type of activity is MOST likely indicated?

A.A denial-of-service (DoS) flood
B.A port scan reconnaissance
C.A man-in-the-middle attack
D.Normal web browsing traffic
AnswerB

This pattern is the classic signature of a TCP SYN scan, a common port scanning technique. The attacker sends a SYN packet to each port on a target; if the port is open, the target responds with a SYN-ACK, while closed ports trigger an RST or no reply. Observing multiple SYN packets to different ports without complete handshakes indicates systematic probing to enumerate which services are listening, exactly what a port scan reconnaissance does.

Why this answer

The observation of TCP SYN packets sent to multiple ports without any SYN-ACK replies indicates a port scan, specifically a SYN scan (half-open scan). In a SYN scan, the attacker sends a SYN packet to each port; if the port is open, the target responds with a SYN-ACK, but the attacker never completes the handshake. The absence of any SYN-ACK replies suggests that either all scanned ports are closed (RST responses would be expected) or the target is filtering traffic, but the pattern of multiple SYN packets to different ports is the hallmark of reconnaissance, not a denial-of-service attack.

Exam trap

A common trap is confusing a SYN scan (reconnaissance) with a SYN flood (DoS attack); the key differentiator is the lack of SYN-ACK replies combined with scanning multiple ports, indicating reconnaissance rather than an attempt to overwhelm the target.

How to eliminate wrong answers

Option A is wrong because a denial-of-service (DoS) flood typically involves a high volume of traffic (e.g., SYN flood) to overwhelm a target, often with spoofed source IPs, and would generate SYN-ACK replies from the target if ports are open; the absence of SYN-ACK replies here suggests a scan, not an attack. Option C is wrong because a man-in-the-middle attack requires intercepting and potentially modifying communications between two parties, which is not indicated by a series of SYN packets to multiple ports with no replies. Option D is wrong because normal web browsing traffic involves completing the TCP three-way handshake (SYN, SYN-ACK, ACK) and then exchanging HTTP data, not sending SYN packets to multiple ports without receiving SYN-ACK replies.

201
MCQeasy

According to Locard's exchange principle, which of the following is MOST relevant to digital forensics?

A.The chain of custody must be maintained for all evidence
B.When a person interacts with a digital device, they leave digital traces that can be recovered
C.Every crime scene contains at least one latent fingerprint
D.Digital evidence is always stored in non-volatile memory
AnswerB

This is the direct digital adaptation of Locard's exchange principle: every interaction with a digital device leaves residual traces, such as file metadata changes, prefetch cache entries, registry modification times, network connection logs, or remnants in RAM. Those traces may be volatile or persistent, but their existence is the foundational premise of digital forensics. Because user actions necessarily alter the device's state, examiners can reconstruct activity by identifying and analyzing these digital footprints. Therefore, this statement accurately reflects how Locard's principle applies to digital investigations.

Why this answer

Locard's exchange principle states that every contact leaves a trace. In digital forensics, this translates to the fact that when a person interacts with a digital device (e.g., opening a file, browsing a website, or typing a command), they leave digital traces such as log entries, metadata, temporary files, or registry artifacts. These traces can be recovered and analyzed to reconstruct user activity, making option B the most relevant application of the principle in this context.

Exam trap

The CHFI exam often tests the misconception that Locard's exchange principle applies only to physical evidence (like fingerprints or DNA), leading candidates to incorrectly choose option C, when in fact the principle is equally valid for digital traces such as log entries, file metadata, and memory artifacts.

How to eliminate wrong answers

Option A is wrong because the chain of custody is a procedural requirement for evidence admissibility, not a direct application of Locard's exchange principle, which focuses on the transfer of traces rather than documentation. Option C is wrong because Locard's principle does not guarantee that every crime scene contains a latent fingerprint; it states that every contact leaves a trace, but the trace may be digital, biological, or physical, and not necessarily a fingerprint. Option D is wrong because digital evidence is not always stored in non-volatile memory; volatile memory (RAM) contains evidence such as running processes, network connections, and encryption keys, which are lost on power loss, and Locard's principle applies to both volatile and non-volatile traces.

202
MCQhard

A forensic tool outputs a timeline of file system events. The analyst needs to correlate registry modifications with file creation times. Which tool is specifically designed for super timeline creation from multiple sources?

A.Plaso
B.Autopsy
C.Volatility
D.Sleuth Kit
AnswerA

Plaso (formerly log2timeline) is an open-source Python framework purpose-built for super timeline generation. It parses dozens of artifact types—file system metadata (MACB timestamps), log files, registry hives, browser history, and more—and outputs unified timelines in formats like SQLite, CSV, or Elasticsearch. It is the tool most directly associated with 'outputs a timeline of file system events' because it aggregates evidence from multiple sources into a single chronological narrative.

Why this answer

Plaso (log2timeline) is specifically designed to create super timelines by aggregating and correlating events from multiple sources, including file system metadata, registry hives, and event logs. It parses artifacts like NTFS $MFT, USN journal, and registry keys (e.g., NTUSER.DAT) to produce a unified timeline, enabling the analyst to correlate registry modifications with file creation times.

Exam trap

EC-Council often tests the distinction between tools that perform low-level file system analysis (Sleuth Kit) and those that aggregate multiple artifact sources into a unified timeline (Plaso), leading candidates to confuse Sleuth Kit's 'fls' output with a super timeline.

How to eliminate wrong answers

Option B (Autopsy) is wrong because it is a GUI-based digital forensics platform that relies on The Sleuth Kit for analysis and does not natively generate super timelines from multiple sources; it focuses on file carving and keyword search rather than timeline correlation. Option C (Volatility) is wrong because it is a memory forensics framework designed to analyze RAM dumps (e.g., processes, network connections) and does not parse file system or registry artifacts for timeline creation. Option D (Sleuth Kit) is wrong because it is a command-line toolkit for low-level file system analysis (e.g., mmls, fls) but lacks the multi-source aggregation and timeline synthesis capabilities of Plaso.

203
Multi-Selecthard

A malware analyst is performing static analysis on a packed executable. Which THREE techniques are effective for unpacking or analyzing packed malware? (Select THREE.)

Select 3 answers
A.Renaming the file to .txt
B.Performing strings analysis on the packed binary
C.Running PEiD to identify the packer
D.Executing the sample in Cuckoo Sandbox
E.Using OllyDbg to step through the unpacking routine
AnswersB, C, E

Strings may reveal embedded data or unpacked code regions.

Why this answer

Performing strings analysis on a packed binary can reveal embedded strings, such as import hints, configuration data, or the original entry point (OEP), which may survive packing. While packing obfuscates many strings, some packers leave remnants that static analysis tools like `strings` can extract, providing initial clues about the malware's functionality without execution.

Exam trap

The trap is that candidates may assume the question only allows static analysis techniques, but dynamic methods like using a debugger (OllyDbg) are also effective for unpacking. Do not exclude valid dynamic options just because they involve execution.

204
MCQmedium

In an ext4 file system, a forensic analyst needs to examine the journal to recover recently deleted files. Where is the journal typically stored?

A.In a reserved area after the superblock
B.In the superblock
C.In a special inode (inode 8)
D.In the group descriptor table
AnswerC

In ext4, the default journal is stored as a special inode, typically inode 8. This inode is allocated when the filesystem is created with a journal, and it contains the journal blocks that record metadata and data changes for recovery. The superblock's s_journal_inum field points to this inode number, confirming its role. The journal inode is not a regular file; it is marked as a special filesystem object, and its data blocks are used exclusively for journaling.

Why this answer

In ext4, the journal is stored as a regular file associated with a special inode, typically inode 8. This design allows the journal to be managed by the file system's standard inode and block allocation mechanisms, rather than being placed in a fixed reserved area. When a file is deleted, its data blocks may still be referenced in the journal until they are overwritten, enabling recovery by replaying or analyzing journal entries.

Exam trap

The CHFI exam often tests the misconception that the journal is stored in a fixed reserved area (like after the superblock) rather than as a file associated with a special inode, leading candidates to choose Option A.

How to eliminate wrong answers

Option A is wrong because the reserved area after the superblock is used for the block group descriptors and backup superblocks, not for the journal; the journal is not stored in a fixed reserved area but as a file. Option B is wrong because the superblock contains metadata about the file system (e.g., block size, inode count) but does not store the journal itself; the journal is a separate data structure. Option D is wrong because the group descriptor table contains per-block-group metadata (e.g., block and inode bitmaps) and does not hold journal data; the journal is managed via a special inode.

205
MCQmedium

An analyst discovers a suspicious file named 'cmd.aspx' in the uploads directory of an IIS web server. Analysis reveals the file contains code to execute system commands. What is this file most likely?

A.A log file
B.A benign configuration file
C.A web shell
D.A backup of a legitimate page
AnswerC

A file placed in a web-accessible upload directory that executes system commands is a web shell, giving the attacker remote command execution through HTTP requests. The .aspx extension confirms it runs under IIS via ASP.NET, matching the scenario's server.

Why this answer

A web shell is a malicious script uploaded to a web server (like IIS) that allows an attacker to execute arbitrary system commands through the web interface. The file 'cmd.aspx' is an ASP.NET page, and its ability to execute system commands is the hallmark of a web shell, often used for post-exploitation persistence and remote access.

Exam trap

EC-Council often tests the misconception that any .aspx file in an uploads directory is legitimate, but the key differentiator is the presence of code that executes system commands, which is unique to a web shell.

How to eliminate wrong answers

Option A is wrong because a log file records events or errors and does not contain executable code to run system commands. Option B is wrong because a benign configuration file (e.g., web.config) defines server settings and does not include command execution logic. Option D is wrong because a backup of a legitimate page would preserve original functionality, not introduce command execution capabilities.

206
MCQmedium

During a forensic investigation, you encounter a Windows system with an NTFS volume. The suspect claims they never used the recycle bin, but you find files in the $Recycle.bin folder. Which artifact can help you determine the original file path and deletion time?

A.The USN journal
B.The file slack space
C.The $I file in the $Recycle.bin folder
D.The $MFT entry for the deleted file
AnswerC

When Windows moves a file to the Recycle Bin, it creates an $I file (paired with an $R content file) in the $Recycle.Bin folder. The $I file contains a header including the file size, the deletion timestamp in Windows FILETIME format, and the original full path stored as UTF-16LE. This makes the $I file the authoritative source for determining the original path and deletion time, even if the $R file's content has been overwritten.

Why this answer

The $I file in the $Recycle.bin folder stores metadata about the deleted file, including its original file path and the deletion timestamp. When a file is moved to the Recycle Bin, Windows creates an $I file (e.g., $I<random>.dat) containing this information, which can be parsed to recover the original location and deletion time. This makes it the direct artifact for the investigator's needs.

Exam trap

The CHFI exam often tests the misconception that the $MFT entry retains deletion metadata, but in NTFS, the $MFT entry for a deleted file is marked as free and its attributes are often cleared or reused, whereas the $I file in $Recycle.bin is the persistent artifact for original path and deletion time.

How to eliminate wrong answers

Option A is wrong because the USN journal records changes to files and directories (e.g., creation, deletion, renaming) but does not store the original file path or deletion time in a directly retrievable format for Recycle Bin items; it only logs the update sequence number and basic operation type. Option B is wrong because file slack space contains residual data from previous file allocations (e.g., RAM or partial file fragments) but does not store metadata like original file paths or deletion times. Option D is wrong because the $MFT entry for the deleted file is typically marked as free and its attributes (like $FILENAME) may be overwritten or cleared, so it cannot reliably provide the original path or deletion time after the file is moved to the Recycle Bin.

207
MCQmedium

A forensic lab in a shared office building must protect evidence against unauthorized physical access, environmental damage, and electromagnetic interference. The lab manager is documenting the physical controls for an accreditation audit. Which control best addresses the risk of an intruder removing a seized hard drive from the evidence room?

A.A locked evidence locker with a keypad entry log and tamper-evident seals on each evidence bag
B.A UPS connected to the forensic workstation to prevent power loss during imaging
C.An antistatic wrist strap worn by the examiner while handling the drive
D.A Faraday bag used to store mobile phones during transport
AnswerA

A locked evidence locker with logged keypad entry and tamper-evident seals directly prevents and detects unauthorized removal of a seized drive. The entry log creates an auditable record of who accessed the evidence room, while the seals reveal any attempt to open an evidence bag after seizure. Together they satisfy the physical security and chain-of-custody expectations for a forensics lab.

Why this answer

The scenario asks for a control against unauthorized physical removal of evidence. Only a locked evidence locker with logged keypad access and tamper-evident seals both restricts entry and provides detection if a bag is opened. The other choices protect power continuity, block wireless signals, or prevent electrostatic damage, none of which stop an intruder from taking a drive.

Exam trap

The trap here is confusing environmental or handling safeguards such as UPS units and wrist straps with actual physical access controls that restrict who can reach the evidence.

208
Multi-Selecthard

Which TWO of the following are challenges in SSD forensics compared to traditional HDD forensics? (Choose two.)

Select 2 answers
A.SSDs are not compatible with forensic imaging tools
B.Wear leveling distributes data across blocks, making it harder to recover specific files
C.TRIM command causes deleted data to be erased quickly
D.SSDs have larger storage capacity than HDDs
E.SSDs are more resistant to physical damage
AnswersB, C

In order to prolong NAND flash lifespan, the SSD’s firmware uses wear leveling to dynamically remap logical block addresses across different physical memory cells, so a file's sectors are not stored contiguously or predictably in physical flash. Since the Flash Translation Layer hides the current physical location of each logical block, forensic carving tools that reconstruct files based on contiguous clusters or expected sector order are often defeated. Additionally, wear leveling may copy data to new blocks while the old block is erased, further destroying remnants of previously deleted files before the examiner ever acquires the drive.

Why this answer

Option B is correct because wear leveling is an SSD controller function that deliberately writes data to different physical NAND blocks to spread erase cycles evenly, so logical addresses no longer map predictably to physical locations and file fragments become scattered, making recovery of specific files far harder than on an HDD where LBAs map directly to fixed platters/sectors. Option C is correct because the TRIM command, issued by the OS (e.g., via ATA DATA SET MANAGEMENT or SCSI UNMAP), tells the SSD controller that deleted blocks are no longer needed, allowing garbage collection to erase them almost immediately, which destroys residual data that would otherwise remain recoverable on an HDD until overwritten. Option A is wrong because SSDs are fully compatible with standard forensic imaging tools such as dd, FTK Imager, and EnCase; the challenge is write-blocking and controller behavior, not tool compatibility.

Option D is wrong because capacity is not a forensic challenge unique to SSDs, and SSDs are not inherently larger than HDDs. Option E is wrong because physical damage resistance is not a recognized forensic challenge distinguishing SSDs from HDDs in this context.

Exam trap

EC-Council often tests the misconception that TRIM is a challenge only for deleted data recovery, but candidates must also recognize wear leveling as a separate, equally critical challenge that affects the forensic recovery of both deleted and existing files.

209
Multi-Selecthard

A security analyst observes a process making repeated network connections to an IP address 192.168.1.100 on TCP port 4444, and the process writes a DLL file to C:\Users\Public\. Which THREE actions should the analyst take immediately as part of dynamic analysis?

Select 3 answers
A.Isolate the host from the network to prevent further C2 communication
B.Capture a memory dump using FTK Imager or similar
C.Delete the DLL file to stop the malware
D.Monitor process creation and file system activity with Process Monitor
E.Reimage the hard drive to remove the malware
AnswersA, B, D

Network isolation is the immediate containment step that severs the host's ability to reach the C2 infrastructure, cutting off incoming commands and blocking on-going data exfiltration. It also prevents the malware from propagating to adjacent systems via SMB, RDP, or other protocols. However, isolation must be performed in a way that preserves volatile evidence for later collection.

Why this answer

Option A is correct because the repeated TCP connections to 192.168.1.100 on port 4444 strongly indicate command-and-control (C2) traffic, and isolating the host from the network immediately contains the incident and prevents further data exfiltration or remote instructions. Option B is correct because capturing a memory dump with FTK Imager (or an equivalent tool like WinPmem or DumpIt) preserves volatile evidence such as injected code, running processes, network connections, and encryption keys that would be lost on shutdown or reboot. Option D is correct because Process Monitor (Procmon) provides real-time visibility into process creation, file system writes (such as the DLL dropped in C:\Users\Public\), registry changes, and network activity, which is essential for dynamic analysis of the malware's behavior.

Option C is not appropriate because deleting the DLL destroys forensic evidence and may not stop the running process, which could simply re-drop the file; the analyst should preserve and analyze it first. Option E is not appropriate at this stage because reimaging the hard drive destroys all volatile and non-volatile evidence needed for dynamic and forensic analysis, and should only occur after evidence collection and containment.

Exam trap

EC-Council often tests the distinction between immediate dynamic analysis actions (containment, monitoring, memory capture) versus destructive or premature remediation steps (deleting files, reimaging), and the trap here is that candidates mistakenly choose to delete the DLL or reimage the drive, thinking it will stop the malware, when in fact it destroys evidence and bypasses the forensic process.

210
Multi-Selectmedium

Which TWO of the following are challenges specific to SSD forensics compared to traditional HDD forensics?

Select 2 answers
A.Bad sectors
B.Wear leveling
C.File fragmentation
D.TRIM command
E.Slack space
AnswersB, D

Wear levelling spreads writes across NAND blocks and relocates data transparently, so logical block addresses no longer map predictably to physical locations. This defeats the contiguous, sequential imaging assumptions that traditional HDD forensics relies upon.

Why this answer

Wear leveling (B) is a challenge specific to SSD forensics because SSDs use a flash translation layer (FTL) to remap logical block addresses (LBAs) to physical NAND pages, so the same LBA can point to different physical locations over time and data may be spread across multiple dies, making it difficult to reconstruct the true physical layout or recover prior versions of data. The TRIM command (D) is also SSD-specific: when the OS issues TRIM (e.g., via ATA DATA SET MANAGEMENT or SCSI UNMAP), the drive marks deleted LBAs as invalid and may erase or garbage-collect those blocks, so deleted data can be unrecoverable and the drive's contents change even without user activity, complicating imaging and timeline analysis. By contrast, bad sectors (A), file fragmentation (C), and slack space (E) are challenges common to traditional HDD forensics as well, since they arise from magnetic platter media, file-system allocation behavior, and cluster-level storage rather than from SSD flash management.

Exam trap

A common misconception is that TRIM is the only SSD-specific challenge, but wear leveling is equally critical because it affects data recovery of both deleted and existing files by altering physical storage locations.

211
MCQmedium

A network analyst is reviewing a packet capture and sees a large number of TCP SYN packets sent to various ports on a single host from multiple source IPs. This pattern is most indicative of which type of attack?

A.ARP spoofing
B.SYN flood
C.DNS amplification
D.Ping of death
AnswerB

A SYN flood is a transport-layer denial-of-service attack that exploits the TCP three-way handshake by sending a massive number of SYN packets with spoofed or non-responsive source IP addresses. The server allocates a transmission control block (TCB) and memory for each half-open connection, then replies with SYN-ACK packets that are never answered, causing the listen backlog to fill and preventing legitimate clients from completing handshakes. This matches the capture of many SYN packets and represents a direct, stateful DoS mechanism.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IPs to a target host. The target allocates resources for each half-open connection, exhausting its backlog queue and preventing legitimate connections. The pattern of many SYN packets from multiple IPs to various ports matches this attack's signature.

Exam trap

EC-Council often tests the distinction between a SYN flood (which uses TCP SYN packets to exhaust connection resources) and a DDoS reflection attack like DNS amplification, where candidates mistakenly focus on the 'multiple source IPs' aspect without recognizing the TCP handshake exploitation.

How to eliminate wrong answers

Option A is wrong because ARP spoofing involves sending forged ARP replies to associate the attacker's MAC address with a legitimate IP, not a flood of TCP SYN packets from multiple sources. Option C is wrong because a DNS amplification attack uses small DNS queries with spoofed source IPs to cause large responses directed at the victim, relying on UDP and reflection, not TCP SYN floods. Option D is wrong because the Ping of Death involves sending oversized ICMP packets that cause buffer overflows, not a high volume of TCP SYN packets.

212
Multi-Selectmedium

Which THREE of the following are Windows Event IDs that are particularly useful for investigating account logon activities?

Select 3 answers
A.4625 - An account failed to log on
B.4648 - A logon was attempted using explicit credentials
C.4624 - An account was successfully logged on
D.4656 - A handle to an object was requested
E.7045 - A service was installed in the system
AnswersA, B, C

Event ID 4625 is generated on the domain controller or local machine whenever a logon attempt fails, regardless of whether the failure was due to a bad password, a nonexistent account, or a locked-out account. The event contains critical forensic details such as the account name, the source network address, logon type, and the specific sub-status code (e.g., 0xC000006A for bad password). Analysts rely on 4625 spikes to detect password spraying or brute-force attacks, and correlating this ID with successful logons (4624) for the same account shortly afterward can reveal successful credential compromise after repeated failures.

Why this answer

Option A (4625 - An account failed to log on) is correct because it records failed authentication attempts in the Security log, which is essential for detecting brute-force, password-spraying, or unauthorized access attempts. Option B (4648 - A logon was attempted using explicit credentials) is correct because it captures scenarios where a process or user supplies alternate credentials (e.g., RunAs, scheduled tasks, or lateral movement with explicit creds), which is critical for tracing credential misuse. Option C (4624 - An account was successfully logged on) is correct because it documents successful logons, including logon type (2 interactive, 3 network, 10 RDP, etc.), enabling investigators to establish a timeline of legitimate or suspicious access.

Option D (4656 - A handle to an object was requested) is not a logon event; it relates to object access auditing and handle requests, so it does not directly evidence account logon activity. Option E (7045 - A service was installed in the system) is a System log event about service installation (persistence), not an account logon event, so it is not relevant to investigating logon activities.

Exam trap

EC-Council often tests the distinction between logon-specific events (4624, 4625, 4648) and other security events like object access (4656) or system changes (7045), so candidates must remember that only events in the 462x series directly track account logon attempts.

213
MCQeasy

An email forensic analyst receives a suspicious email and wants to trace its origin. Which email header field provides the most reliable information about the IP address of the sending SMTP server?

A.Return-Path
B.Received
C.DKIM-Signature
D.X-Originating-IP
AnswerB

The Received header is the standard, reliable source for tracing the sending server's IP address in email forensics. Each SMTP server that handles the message adds a Received header that records the IP address (and often the hostname) of the server from which it received the message, along with a timestamp. The first Received header (reading from the bottom of the message) identifies the original sender's server, while each subsequent header documents each hop in the delivery chain. These headers are added automatically by mail servers and are much more difficult to spoof than user-controlled headers, making them the primary evidence for IP identification.

Why this answer

The 'Received' header is the most reliable source for tracing the origin of an email because each SMTP server that handles the message adds a new 'Received' header at the top, recording the IP address of the sending server (from the HELO/EHLO handshake) and the receiving server. The bottommost 'Received' header typically contains the IP address of the original sending SMTP server, as it is added by the first receiving MTA. This field is standardized in RFC 5321 and is the primary forensic artifact for email source identification.

Exam trap

The EC-Council CHFI exam often tests the misconception that X-Originating-IP is the most reliable source because it appears to directly show the sender's IP, but candidates must remember it is a non-standard header that can be easily forged or omitted, whereas the 'Received' header chain is a mandatory, traceable part of the SMTP protocol.

How to eliminate wrong answers

Option A is wrong because the Return-Path header (RFC 5321) contains the envelope sender (bounce address), not the IP address of the sending server; it is set by the Mail User Agent or the final MTA and can be forged. Option C is wrong because the DKIM-Signature header (RFC 6376) contains a cryptographic signature and the selector domain (d=), but it does not directly reveal the sending SMTP server's IP address; it only indicates the domain claiming responsibility for the message. Option D is wrong because X-Originating-IP is a non-standard, proprietary header often added by webmail services (e.g., Hotmail, Yahoo) to log the client's IP, but it is not universally present, not part of the SMTP protocol, and can be omitted or spoofed by the originating server.

214
Multi-Selectmedium

Which TWO of the following are valid artifacts for determining program execution on a Windows system? (Select TWO.)

Select 2 answers
A.Pagefile.sys
B.System Restore points
C.Jump Lists
D.Prefetch files
E.Windows Error Reporting logs
AnswersC, D

Jump Lists record recently and frequently accessed files and applications per user, including entries created when programs launch. They therefore evidence program execution on Windows, satisfying the requirement for a valid execution artifact alongside Prefetch and similar records.

Why this answer

Jump Lists (C) are valid artifacts because they are stored per-user in the AutomaticDestinations and CustomDestinations folders under %AppData%\Microsoft\Windows\Recent, and they record recently or frequently accessed files and applications, providing direct evidence of program execution. Prefetch files (D) are also valid because Windows creates a .pf file in C:\Windows\Prefetch for each executed application, containing the executable name, run count, and last-run timestamps, which directly demonstrates program execution. Pagefile.sys (A) is a virtual memory swap file, not an execution artifact, and System Restore points (B) are snapshots of system state used for rollback rather than proof of program execution.

Windows Error Reporting logs (E) record crash and error telemetry, so they may indicate a program ran but are not a reliable or standard artifact for determining execution.

Exam trap

EC-Council often tests the distinction between artifacts that record normal execution (Prefetch, Jump Lists) versus those that capture system state or errors (Pagefile, Restore Points, WER logs), leading candidates to overestimate the forensic value of Pagefile.sys or System Restore points.

215
MCQmedium

An examiner is analyzing an Android device using Cellebrite UFED. The device is locked with a PIN, and the examiner has no PIN. Which acquisition type should the examiner attempt FIRST to maximize data recovery without destroying evidence?

A.Logical extraction via ADB backup
B.Manual extraction by photographing the screen
C.File system extraction via ADB root shell
D.Physical extraction using a bootloader exploit
AnswerA

ADB backup is a logical extraction that communicates with the Android system over USB to create a tar archive of app data and shared storage. Because it works through the running OS rather than requiring physical access to the flash chip, it can succeed on a locked device if USB debugging has already been enabled and the computer's RSA key is authorized. It does not require root, preserves the device's original state, and is a non-invasive first step before attempting more intrusive acquisition.

Why this answer

When an Android device is locked with a PIN and no PIN is known, a logical extraction via ADB backup is the safest first step. ADB backup (adb backup) can capture app data and system settings without requiring root or unlocking the bootloader, and it does not modify the device state, preserving evidence integrity. This method works if USB debugging was previously enabled, which is common in forensic acquisitions, and it avoids the risk of triggering lockout or data wiping that physical methods might cause.

Exam trap

EC-Council often tests the misconception that physical extraction is always the best first step for locked devices, but the trap here is that bootloader exploits or physical methods can trigger data wiping or require unlocking, whereas ADB backup is a non-invasive logical method that preserves evidence integrity when USB debugging is enabled.

How to eliminate wrong answers

Option B is wrong because manual extraction by photographing the screen is a non-acquisition technique that only captures visible content, not underlying data like deleted files or app databases, and it is not a standard forensic acquisition method for maximizing data recovery. Option C is wrong because file system extraction via ADB root shell requires root access, which is not available on a locked device without a PIN; attempting to root the device could modify system partitions and destroy evidence. Option D is wrong because physical extraction using a bootloader exploit often requires unlocking the bootloader, which wipes the device (factory reset) as a security measure, destroying all user data and making it unsuitable as a first attempt.

216
MCQeasy

Which of the following is the BEST definition of computer forensics?

A.The application of investigative and analytical techniques to gather and preserve evidence from digital devices suitable for presentation in a court of law.
B.The use of software tools to scan for malware on a computer system.
C.The process of recovering deleted files from a hard drive.
D.The process of securing a computer network from unauthorized access.
AnswerA

The application of investigative and analytical techniques to gather and preserve evidence from digital devices suitable for presentation in a court of law is the full-scope definition. It encompasses the entire forensic process: identification, acquisition, preservation, analysis, and documentation while maintaining a strict chain of custody. Every action must be reproducible and defensible in legal proceedings, ensuring that the evidence is authentic, unaltered, and admissible. This distinguishes computer forensics from unrelated practices like malware scanning or network hardening.

Why this answer

Computer forensics is fundamentally the application of investigative and analytical techniques to collect, preserve, and analyze digital evidence in a manner that maintains its integrity and admissibility in a court of law. This definition encompasses the entire forensic process, from acquisition through chain of custody to presentation, aligning with the CHFI framework's emphasis on legal and procedural rigor.

Exam trap

EC-Council often tests the distinction between a narrow technical task (like file recovery or malware scanning) and the full legal and procedural scope of computer forensics, causing candidates to confuse a single step with the entire discipline.

How to eliminate wrong answers

Option B is wrong because it describes malware scanning, which is a security or incident response task, not the comprehensive legal and investigative process of computer forensics. Option C is wrong because it focuses solely on file recovery, which is only one small technical step within the broader forensic methodology, ignoring evidence preservation, analysis, and legal presentation. Option D is wrong because it defines network security (e.g., firewalls, access controls), not the post-incident forensic examination of digital evidence for legal proceedings.

217
Multi-Selectmedium

Which TWO tools are commonly used for static analysis of malware binaries?

Select 2 answers
A.Cuckoo Sandbox
B.Wireshark
C.IDA Pro
D.Ghidra
E.Process Monitor
AnswersC, D

IDA Pro is a disassembler and debugger for static analysis.

Why this answer

IDA Pro is a leading interactive disassembler and debugger used for static analysis of malware binaries. It allows analysts to examine executable code without executing it, by disassembling machine code into assembly language and providing cross-references, function graphs, and decompilation capabilities. This makes it essential for reverse engineering malicious software to understand its logic, embedded strings, and control flow.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse tools that monitor live behavior (like Cuckoo Sandbox or Process Monitor) with those that analyze code without execution, leading them to select dynamic analysis tools for a static analysis question.

218
MCQmedium

A security analyst is investigating a containerized application running on a Docker host. The analyst needs to collect forensic evidence from a stopped container without starting it. Which of the following Docker commands should be used to export the container's filesystem as a tar archive?

A.docker commit
B.docker export
C.docker cp
D.docker save
AnswerB

docker export is the correct command because it streams the container's entire filesystem into a flat tar archive, exactly the kind of backup or migration artifact the analyst would need. It captures the full root filesystem as the container sees it, including all runtime changes, but intentionally omits image metadata and layer history. This tar can be piped to a file or imported later with docker import to reconstruct a filesystem as an image.

Why this answer

The `docker export` command creates a tar archive of a container's filesystem, even if the container is stopped, without starting it. This is the correct tool for extracting forensic evidence from a stopped container's filesystem as a single archive file.

Exam trap

The trap here is confusing `docker export` (container filesystem to tar) with `docker save` (image layers to tar), as both produce tar archives but target different objects (container vs. image).

How to eliminate wrong answers

Option A is wrong because `docker commit` creates a new image from a container's changes, not a tar archive of the filesystem, and it requires the container to be running. Option C is wrong because `docker cp` copies files or directories between a container and the host filesystem, but it does not export the entire filesystem as a tar archive and requires the container to be running. Option D is wrong because `docker save` exports one or more Docker images (not containers) as a tar archive, including metadata and layers, which is used for image migration, not container filesystem extraction.

219
MCQhard

During an investigation, an analyst uses `dd if=/dev/sdb of=evidence.img bs=4k conv=noerror,sync`. What is the purpose of the `conv=noerror,sync` option?

A.It hashes each block to verify integrity.
B.It enables synchronous writing to ensure data integrity.
C.It compresses the output image to save space.
D.It skips read errors and pads the output with zeros to maintain block alignment.
AnswerD

When used as conv=noerror,sync, dd will continue reading a source device after encountering bad sectors because noerror suppresses the usual abort-on-error behavior, while sync pads each incomplete or unreadable block with zeros up to the full input block size. This zero-filling preserves the original logical block offsets and keeps the image's partition layout aligned, which is critical for later forensic analysis. The result is a complete-sized image in which damaged areas are marked as zero-filled blocks rather than causing the output to shrink or lose alignment.

Why this answer

The `conv=noerror,sync` option in `dd` instructs the tool to continue processing even when a read error is encountered (`noerror`) and to pad the output block with zeros (`sync`) to maintain the original block alignment. This ensures that the resulting image file remains the same size as the source device, preserving the forensic integrity of the data layout despite hardware-level read failures.

Exam trap

EC-Council often tests the misconception that `sync` in `conv=noerror,sync` refers to synchronous I/O or write caching, when in fact it means padding output blocks with zeros to maintain alignment after read errors.

How to eliminate wrong answers

Option A is wrong because `conv=noerror,sync` does not perform hashing; hashing is done separately with options like `hash=md5` or via a pipe to `sha256sum`. Option B is wrong because synchronous writing is controlled by the `oflag=sync` or `conv=fsync` option, not `conv=noerror,sync`; the `sync` in `conv` refers to padding with zeros, not write synchronization. Option C is wrong because `dd` does not compress data; compression requires piping through `gzip` or using `conv=lz4` or similar, and `conv=noerror,sync` has no compression effect.

220
MCQhard

An organization in the UK suspects an employee of data theft. The IT manager wants to search the employee's company-issued laptop without consent. Which law primarily governs this action?

A.Police and Criminal Evidence Act 1984 (PACE)
B.Computer Misuse Act 1990
C.GDPR (General Data Protection Regulation)
D.Human Rights Act 1998
AnswerC

GDPR (General Data Protection Regulation) covers data protection and privacy, but it is not the primary law governing the act of searching a laptop without consent in this context.

Why this answer

The primary law governing an employer's search of an employee's company-issued laptop without consent is the GDPR/UK Data Protection Act, as the search involves processing the employee's personal data and workplace privacy. The Computer Misuse Act 1990 primarily addresses unauthorized access to computer systems; it is not the most applicable law when the IT manager is acting with the employer's authority on company-owned equipment. PACE 1984 applies to police searches, and the Human Rights Act 1998 sets out broader privacy principles but is not the primary law for this internal employer action.

221
MCQhard

A forensic investigator is analyzing a compromised web server. In the Apache access logs, the investigator finds the following request: 'GET /images/../../../etc/passwd HTTP/1.1' with a 200 status code. Which of the following is the MOST likely reason the server returned a 200 (OK) response?

A.The server redirected the request to the root directory and returned the index page
B.The server has a custom 404 page that returns a 200 status code
C.The request was blocked by a web application firewall (WAF) which returned a 200 status
D.The server is vulnerable to directory traversal and returned the contents of /etc/passwd
AnswerD

A 200 OK status in response to a directory traversal payload—such as a URL containing ../../etc/passwd—strongly indicates that the server successfully accessed and returned the specified file. In a vulnerable web server, improper path sanitization allows the attacker to escape the web root and retrieve sensitive system files, with the response body containing the file's contents (e.g., root:x:0:0:root:/root:/bin/bash). This is the classic signature of a path traversal vulnerability, as the server processes the '../' sequences and serves the requested file. The combination of the traversal payload and a 200 status, along with the file content in the response, confirms successful exploitation.

Why this answer

A 200 response to a path traversal request indicates that the server executed the request and returned the file content, meaning the directory traversal attack succeeded.

222
MCQhard

A forensic examiner is analyzing a RAID 5 array consisting of three disks. One disk has failed and is not available. The remaining two disks contain data and parity. Which technique can be used to reconstruct the missing disk's data and recover the original data?

A.Replace the failed disk and rebuild the array using the controller's rebuild function
B.Use dd to image the two disks, then perform a XOR operation on the data stripes to reconstruct the third disk's data
C.Use FTK Imager to create a logical image of each disk and merge them
D.Simply image the two disks and use file carving tools to extract files
AnswerB

RAID 5 stores parity as the XOR of the data stripes across all member disks. Imaging the two surviving disks with dd, then XORing corresponding stripes, regenerates the missing disk's data, since parity XOR remaining data yields the absent block.

Why this answer

In a RAID 5 array with three disks, data and parity are striped across all disks. When one disk fails, the missing data can be reconstructed by performing an XOR operation on the corresponding stripes from the remaining two disks. This is because RAID 5 uses distributed parity where the parity block is the XOR of the data blocks in the same stripe, so XORing the surviving data and parity stripes recovers the lost data.

Exam trap

The CHFI exam often tests the misconception that RAID 5 can tolerate two disk failures or that simple imaging of surviving disks yields complete data without reconstruction, leading candidates to choose file carving or logical imaging options.

How to eliminate wrong answers

Option A is wrong because replacing the failed disk and using the controller's rebuild function is a hardware/administrative recovery method, not a forensic technique for reconstructing data from the remaining two disks when the failed disk is unavailable. Option C is wrong because FTK Imager's logical imaging merges file system metadata, not raw stripe-level data, and cannot reconstruct missing RAID 5 data without understanding the stripe layout and parity. Option D is wrong because simply imaging two disks and using file carving tools will only recover files that are contiguous and not split across stripes, and cannot reconstruct data that was solely on the failed disk.

223
MCQeasy

Which tool is specifically designed for dynamic analysis of malware by executing it in a controlled, isolated environment and logging its behavior?

A.PEiD
B.IDA Pro
C.Ghidra
D.Cuckoo Sandbox
AnswerD

Cuckoo Sandbox is a dedicated automated malware analysis system that executes suspicious files in isolated virtual machines and records low-level API calls, file system modifications, registry changes, and network activity during runtime. It is explicitly designed for dynamic analysis, enabling analysts to observe a sample's real behavior without infecting a production host.

Why this answer

Cuckoo Sandbox is the correct answer because it is an open-source automated malware analysis system specifically designed to execute suspicious files in a controlled, isolated environment (a sandbox) and log their behavior, including system calls, file system changes, network traffic, and memory dumps. Unlike static analysis tools, Cuckoo performs dynamic analysis by actually running the malware and observing its runtime actions.

Exam trap

The CHFI exam often tests the distinction between static analysis tools (like PEiD, IDA Pro, Ghidra) and dynamic analysis tools (like Cuckoo Sandbox), trapping candidates who confuse reverse engineering with automated behavioral analysis in a sandbox.

How to eliminate wrong answers

Option A is wrong because PEiD is a static analysis tool that detects packers, cryptors, and compilers in PE files by scanning file signatures; it does not execute malware or log runtime behavior. Option B is wrong because IDA Pro is a disassembler and debugger used for static and interactive reverse engineering of binary code, not for automated dynamic analysis in an isolated sandbox environment. Option C is wrong because Ghidra is a reverse engineering framework developed by the NSA that focuses on static analysis and decompilation, lacking the sandboxed execution and behavior logging capabilities of a dedicated dynamic analysis tool like Cuckoo.

224
Multi-Selectmedium

A forensic investigator is analyzing a Linux system that was compromised. The investigator needs to examine the file system for evidence of unauthorized access. The system uses the ext4 file system. Which TWO of the following file system artifacts can provide evidence of file creation, modification, or access times? (Choose two.)

Select 2 answers
A.File allocation table (FAT)
B.File system journal (ext4 journal)
C.Inode timestamps (atime, mtime, ctime)
D.Directory entry (dentry) cache
E.Extended attributes (xattrs)
AnswersB, C

The ext4 journal records metadata transactions and can be used to reconstruct recent file system changes. It may contain records of file creation, deletion, and modification, even if the inode timestamps are altered or lost. Analyzing the journal can reveal evidence of file operations that occurred before the system was powered off.

Why this answer

Inode timestamps (atime, mtime, ctime) directly record when a file was accessed, modified, or its metadata changed, providing a timeline of activity. The ext4 journal logs metadata transactions and can be analyzed to reconstruct recent file operations, including creation and deletion. Together, these artifacts offer valuable evidence of unauthorized file activity on the compromised system.

Exam trap

The trap here is assuming that extended attributes or dentry cache hold timestamp information, but they serve different purposes: xattrs store security labels, and dentry cache is volatile memory, not persistent storage.

225
MCQeasy

A security analyst reviews Windows Event Logs and sees Event ID 4625 multiple times for a single user account from a remote IP address within a short time frame. What is the MOST likely interpretation?

A.The user successfully logged on from multiple locations
B.An attacker is attempting to brute-force the user's password
C.The system is experiencing a denial-of-service attack
D.A service installed itself on the system
AnswerB

An attacker is attempting to brute-force the user's password is correct because a rapid series of Event ID 4625 entries from the same source IP against the same username is the classic signature of a brute-force or password-spraying attack. Each 4625 event includes metadata such as Logon Type (e.g., 3 for network or 10 for RDP), Sub Status codes (e.g., 0xC000006A for a bad password), and the source network address. The repeated failures followed by no corresponding 4624 success indicate the attacker has not yet guessed valid credentials, reinforcing the brute-force conclusion.

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple occurrences for the same user from a single remote IP within a short timeframe is the classic signature of a brute-force attack, where an attacker systematically tries different passwords against that account.

Exam trap

EC-Council often tests the distinction between success (4624) and failure (4625) event IDs, and the trap here is that candidates may misread 4625 as a successful logon or confuse it with a DoS attack because of the high frequency of events.

How to eliminate wrong answers

Option A is wrong because Event ID 4625 is a failure event, not a success; successful logons generate Event ID 4624. Option C is wrong because a denial-of-service attack would typically flood the system with traffic or cause resource exhaustion, not generate repeated failed logon attempts for a single user. Option D is wrong because a service installation would generate different event IDs (e.g., 4697 or 7045) and would not produce repeated 4625 failures from a remote IP.

Page 2

Page 3 of 10

Page 4

All pages