Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 226–300

745 questions total · 10pages · All types, answers revealed

Page 3

Page 4 of 10

Page 5
226
MCQeasy

Which file system uses a Master File Table ($MFT) as its central catalog for file metadata?

A.FAT32
B.APFS
C.ext4
D.NTFS
AnswerD

NTFS is the correct answer because it uses the Master File Table (MFT) as its central metadata repository. The MFT is a special file containing at least one record for every file and directory, storing attributes, security descriptors, timestamps, and data runs. This central table allows NTFS to efficiently locate and manage all filesystem objects, and it is a defining feature of NTFS.

Why this answer

NTFS (New Technology File System) uses the Master File Table ($MFT) as its central catalog to store metadata about every file and directory on the volume. Each file or directory has at least one record in the $MFT, which contains attributes such as timestamps, security descriptors, data runs, and the file's name. This design is fundamental to NTFS's ability to support advanced features like journaling, hard links, and alternate data streams.

Exam trap

EC-CHFI often tests the misconception that FAT32 or ext4 uses a Master File Table because they also have file allocation tables or inode tables, but the $MFT is a unique NTFS structure with a specific on-disk format and record-based architecture.

How to eliminate wrong answers

Option A is wrong because FAT32 uses a File Allocation Table (FAT) and directory entries, not a Master File Table; it stores file metadata in 32-byte directory entries within clusters. Option B is wrong because APFS (Apple File System) uses a B-tree based container structure with object maps and snapshots, not an $MFT; its metadata is managed through a catalog file and extent reference tree. Option C is wrong because ext4 uses inodes and block groups to store file metadata, with a superblock and group descriptors, not a Master File Table; the inode table is the central metadata structure.

227
MCQeasy

Which Linux log file is the primary source for authentication-related events, including SSH login attempts and sudo usage?

A./var/log/kern.log
B./var/log/syslog
C./var/log/auth.log
D./var/log/messages
AnswerC

This is the primary authentication log on Debian-based Linux distributions, recording events from the auth and authpriv syslog facilities. It captures successful and failed logins, sudo usage, SSH public-key and password authentication, user account changes, cron jobs run with authentication, and PAM module activity. As the central repository for authentication-related messages, forensic examiners look here first for evidence of unauthorized access or identity-related events.

Why this answer

/var/log/auth.log is the dedicated Linux log file for authentication-related events, including SSH login attempts (via PAM and sshd), sudo usage, and user authentication failures. This file is managed by the syslog daemon and is the primary source for forensic analysis of authentication activity on Debian-based systems.

Exam trap

The CHFI exam often tests the distinction between distribution-specific log files, so the trap here is that candidates familiar with Red Hat-based systems (where /var/log/secure is the auth log) may incorrectly choose /var/log/messages or /var/log/syslog, not realizing that CHFI focuses on Debian/Ubuntu conventions where /var/log/auth.log is the standard.

How to eliminate wrong answers

Option A is wrong because /var/log/kern.log records kernel messages, such as hardware errors and driver issues, not authentication events. Option B is wrong because /var/log/syslog captures general system logs (e.g., daemon messages, cron jobs) but does not specifically isolate authentication events; it may contain some auth entries only if the syslog configuration merges them, but it is not the primary source. Option D is wrong because /var/log/messages is a generic log file on some distributions (like Red Hat/CentOS) that stores non-critical system messages, but it is not the dedicated authentication log; on Debian systems, it often does not exist or is a symlink, and on RHEL-based systems, authentication events go to /var/log/secure, not /var/log/messages.

228
MCQhard

During an Android forensic examination, the analyst uses ADB to run 'adb shell dumpsys batterystats --reset' before acquiring data. What is the MOST likely purpose of this command?

A.To clear battery logs that may contain evidence of app activity
B.This command is not recommended in forensic acquisition as it may destroy potential evidence
C.To ensure the device is in a low-power state for safe extraction
D.To optimize device performance during imaging
AnswerB

In Android forensic acquisition, state-changing commands such as `adb shell dumpsys batterystats --reset` are strictly avoided because they permanently delete historical battery and wake-lock data that may corroborate user behavior, malware activity, or spyware persistence. Sound methodology requires read-only or write-protected acquisition, and any command that writes to system files risks spoliation and breaks the chain of custody. Since resetting battery stats has no legitimate role in a defensible acquisition workflow, this command must not be recommended.

Why this answer

The 'adb shell dumpsys batterystats --reset' command clears the battery statistics logs on the device. In forensic acquisition, any command that modifies or deletes data on the device is considered destructive to evidence. The reset operation removes historical battery data that may contain timestamps and app usage patterns, which could be critical evidence.

Therefore, this command is not recommended in forensic acquisition as it may destroy potential evidence.

Exam trap

EC-Council often tests the misconception that clearing logs is a benign or preparatory step, when in fact any command that modifies device state during acquisition violates forensic best practices and may be considered evidence spoliation.

How to eliminate wrong answers

Option A is wrong because clearing battery logs is precisely what the command does, and while those logs may contain evidence of app activity, the purpose of the command is to reset them, not to preserve them; the question asks for the 'most likely purpose' in a forensic context, which is that it is destructive. Option C is wrong because the command does not affect the device's power state; it only resets battery statistics data, and ensuring a low-power state is achieved through other means like disabling radios or using airplane mode. Option D is wrong because the command does not optimize device performance during imaging; it only clears battery stats, and performance optimization is irrelevant to forensic acquisition.

229
MCQmedium

An investigator needs to testify in court as an expert witness. Which of the following qualifications is MOST important for the court to accept their testimony?

A.They have a certification in computer forensics.
B.They have published articles in peer-reviewed journals on digital forensics.
C.They can demonstrate knowledge, skill, experience, training, or education that will assist the trier of fact.
D.They have been employed as a forensic analyst for over 10 years.
AnswerC

This option reflects the exact language of Federal Rule of Evidence 702, which establishes that a witness may qualify as an expert by virtue of knowledge, skill, experience, training, or education, provided the testimony will assist the trier of fact. The court serves as a gatekeeper and must determine that the proposed expert's qualifications are directly relevant to the technical or scientific issues in dispute and that their testimony is both reliable and helpful to the jury. This standard is deliberately broad and flexible, allowing the court to consider practical experience, formal education, certifications, and publications collectively rather than relying on any single credential.

Why this answer

Under the Federal Rules of Evidence (FRE) Rule 702, a witness qualified as an expert by knowledge, skill, experience, training, or education may testify if their specialized knowledge will assist the trier of fact. Option C directly mirrors this legal standard, making it the most critical qualification for admissibility. Certifications, publications, or years of service are supporting factors but not independently sufficient under the Daubert or Frye standards.

Exam trap

EC-Council often tests the misconception that a certification or years of experience alone qualifies someone as an expert witness, but the legal standard under FRE 702 requires the witness to demonstrate that their knowledge, skill, experience, training, or education will actually assist the trier of fact.

How to eliminate wrong answers

Option A is wrong because a certification alone does not guarantee that the court will accept the testimony; the court must assess whether the witness's actual knowledge and experience will assist the trier of fact, and certifications are not a substitute for demonstrated competence. Option B is wrong because published articles in peer-reviewed journals are a factor under the Daubert standard but are not the most important qualification; the witness must still show that their expertise directly aids the court in understanding the evidence. Option D is wrong because 10 years of employment as a forensic analyst does not automatically qualify someone as an expert; the court evaluates the substance of their experience and whether it logically applies to the specific digital evidence in question.

230
Multi-Selecthard

A forensic investigator is examining a compromised Docker container on a Linux host. The investigator needs to collect volatile evidence from the running container before it is stopped. Which two actions should the investigator perform to capture the container's memory and running processes? (Choose two.)

Select 2 answers
A.Run 'docker logs <container_id>' to capture the container's stdout and stderr output
B.Use 'docker diff <container_id>' to list changes to the container's filesystem
C.Use 'docker checkpoint' to create a checkpoint of the running container, including its memory state
D.Run 'docker exec -it <container_id> ps aux' to list running processes inside the container
E.Use 'docker cp' to copy the container's /proc directory to the host for analysis
AnswersC, D

Docker checkpoint (using CRIU) captures the entire state of a running container, including memory, CPU registers, and open files, and saves it to disk. This allows the investigator to preserve volatile memory for later analysis without stopping the container. It is a valid method for capturing memory evidence from a running container.

Why this answer

To capture volatile evidence from a running Docker container, the investigator should list running processes and capture memory state. Running 'ps aux' inside the container provides a snapshot of active processes, while 'docker checkpoint' preserves the container's memory and state. Other options like copying /proc, reading logs, or checking filesystem diffs do not capture memory or process information reliably.

Exam trap

The trap here is assuming that copying /proc or reading logs captures memory, when these methods only provide partial or non-volatile data.

231
MCQeasy

Based on the log exhibit, what type of attack is occurring?

A.Man-in-the-middle attack
B.SQL injection attack
C.Denial of Service attack
D.Brute-force attack on SSH
AnswerD

This is a classic SSH brute-force attack: the log shows repeated "Failed password for root" messages from the same source IP, indicating automated guesses against a privileged account. Attackers run dictionary or credential-stuffing tools to try many passwords in rapid succession, and the steady stream of failures from a single origin is the definitive signature. The target is the SSH service, not the application layer, and the goal is unauthorized access, not interception or resource exhaustion.

Why this answer

The log shows multiple failed SSH login attempts from the same IP address with different usernames and passwords, which is characteristic of a brute-force attack targeting SSH. The repeated 'Failed password' entries for various user accounts (e.g., root, admin, user) indicate an automated attempt to guess credentials, not a single successful compromise or a different attack type.

Exam trap

EC-Council often tests the distinction between a brute-force attack and a DoS attack by including logs with repeated authentication failures, leading candidates to mistakenly choose DoS due to the high volume of events, but the key indicator is the specific 'Failed password' message targeting SSH, not a flood of traffic.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack would involve intercepting or modifying traffic between two parties, not repeated failed login attempts; there is no evidence of ARP spoofing, session hijacking, or traffic redirection in the log. Option B is wrong because SQL injection attacks target web application databases via malicious SQL queries in input fields, not SSH authentication logs; the log shows no SQL syntax or database error messages. Option C is wrong because a Denial of Service attack aims to overwhelm a service with traffic to cause disruption, not to repeatedly attempt authentication; the log shows sequential login failures without a flood of packets or resource exhaustion indicators.

232
MCQhard

During a malware investigation, an analyst identifies a suspicious file that appears to be a Windows executable. Using PEiD, the analyst detects the file is packed with UPX. After unpacking, the analyst runs the file in a sandbox and observes it modifies the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService. What behavioural indicator is primarily demonstrated?

A.Persistence mechanism
B.Command and control communication
C.Anti-forensic technique (timestomping)
D.Privilege escalation attempt
AnswerA

Adding a value to the Run or RunOnce registry key is a classic persistence mechanism because those keys are automatically processed at user logon. The shell (explorer.exe) reads entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, executing the specified command without requiring any additional user interaction. This ensures the malware re-launches after a reboot, making it a strong indicator of an autostart persistence technique.

Why this answer

The modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService is a classic persistence mechanism. By adding an entry to the Run key, the malware ensures that it executes automatically every time the user logs into the system, maintaining its presence across reboots.

Exam trap

EC-Council often tests the distinction between persistence and privilege escalation, where candidates mistakenly think modifying HKCU\Run requires administrative rights, but it only requires user-level access and is a persistence technique, not an escalation attempt.

How to eliminate wrong answers

Option B is wrong because command and control communication involves network traffic to an external server (e.g., HTTP, DNS, or IRC), not a local registry modification. Option C is wrong because anti-forensic techniques like timestomping alter file timestamps (e.g., using SetFileTime or touch), not registry keys. Option D is wrong because privilege escalation attempts typically target security tokens or exploit vulnerabilities to gain higher access (e.g., SeDebugPrivilege or UAC bypass), not setting a user-level Run key.

233
MCQmedium

During a forensic analysis of a compromised Linux server, you notice that the file /var/log/auth.log has been cleared. However, you find that the attacker's commands are still partially recoverable. Which artifact most likely contains the attacker's command history?

A./var/log/syslog
B.~/.bash_history
C./proc/1/cmdline
D./etc/shadow
AnswerB

~/.bash_history is the correct artifact because it is the per-user history file that bash appends with every command entered interactively. When a shell exits cleanly, the session's commands are written here, making it a direct record of user activity. Investigators commonly use it to reconstruct an attacker's command sequence, though it can be disabled or truncated.

Why this answer

The ~/.bash_history file stores the command history for individual user accounts, including commands executed by an attacker who gained shell access. Even if /var/log/auth.log is cleared, this file retains the attacker's command history unless explicitly deleted or truncated. This makes it a key artifact for recovering attacker activity.

Exam trap

The CHFI exam often tests the misconception that /var/log/syslog or /var/log/auth.log captures all user activity, but the trap here is that command history is user-specific and stored in the home directory's .bash_history file, not in system logs.

How to eliminate wrong answers

Option A is wrong because /var/log/syslog logs system messages and kernel events, not user command history; it typically does not capture individual shell commands. Option C is wrong because /proc/1/cmdline shows the command line arguments of the init process (PID 1), not the attacker's interactive shell commands. Option D is wrong because /etc/shadow stores hashed user passwords and password aging information, not command history.

234
MCQeasy

In Linux, which file contains hashed user passwords?

A./etc/gshadow
B./etc/group
C./etc/passwd
D./etc/shadow
AnswerD

/etc/shadow is the authoritative shadow password database that contains each user's hashed password and related aging metadata. It is typically readable only by root and the shadow group (mode 640 root:shadow) precisely because it holds credential verifiers. Fields include login name, password hash (often with $id$salt$hash format), last change, minimum/maximum age, warning, inactivity, and expiration. Thus the answer to the question is /etc/shadow.

Why this answer

The /etc/shadow file stores hashed user passwords along with password aging information, and is readable only by root to enhance security. In contrast, /etc/passwd contains user account information but stores only a placeholder (usually 'x' or '*') for the password hash, not the hash itself. This separation is a standard Linux security mechanism to prevent unauthorized access to password hashes.

Exam trap

EC-Council often tests the misconception that /etc/passwd still contains password hashes, leading candidates to choose option C, but modern Linux systems have moved hashes to /etc/shadow for security.

How to eliminate wrong answers

Option A is wrong because /etc/gshadow stores hashed group passwords and group administrator information, not user passwords. Option B is wrong because /etc/group defines group memberships and optionally group passwords (often stored as 'x' with hashes in /etc/gshadow), not user password hashes. Option C is wrong because /etc/passwd historically stored password hashes, but modern Linux systems use shadow passwords, and /etc/passwd now contains only a placeholder (e.g., 'x') indicating the hash is in /etc/shadow.

235
MCQmedium

A security analyst reviewing Apache access logs finds entries like: 192.168.1.10 - - [12/Jan/2023:15:23:11 +0000] "GET /search?q=1' OR '1'='1 HTTP/1.1" 200 5324. What attack is indicated?

A.Cross-site scripting (XSS)
B.SQL injection
C.Path traversal
D.Command injection
AnswerB

SQL injection occurs when attacker-controlled input is concatenated directly into a SQL statement without parameterization, changing the query's logic. The literal payload '1' OR '1'='1' is a textbook tautology: if placed in a WHERE clause (e.g., WHERE user='admin' AND password='1' OR '1'='1'), it evaluates TRUE for every row, allowing authentication bypass or data exfiltration. Web application firewalls often flag this exact pattern, and the correct remediation is prepared statements/parameterized queries, strict input validation, and least-privilege database accounts.

Why this answer

The log entry shows a SQL injection attempt via the 'q' parameter with a tautology. The 200 response indicates the request was processed, suggesting possible success.

236
MCQhard

A network forensic analyst examines a pcap file in Wireshark and sees an HTTP POST request to '/shell.jsp' with a parameter 'cmd' containing 'dir'. The response contains a directory listing. Which intrusion artifact is indicated?

A.SQL injection
B.Directory traversal
C.Webshell
D.Cross-site scripting (XSS)
AnswerC

A webshell is a server-side script (e.g., PHP or ASP) that accepts HTTP parameters such as 'cmd' and passes them to system functions like shell_exec(), allowing remote attackers to run arbitrary operating system commands. The pcap's 'cmd' parameter accompanied by a directory listing is the classic fingerprint of a webshell: the attacker issues ls/dir and the response contains the filesystem enumeration. This combination of HTTP request structure with observable command output directly matches webshell behavior.

Why this answer

The HTTP POST request to '/shell.jsp' with a 'cmd' parameter containing 'dir' and a response showing a directory listing is a classic indicator of a webshell. A webshell is a malicious script (e.g., JSP, ASP, PHP) uploaded to a web server that allows an attacker to execute arbitrary system commands via HTTP requests, effectively providing remote command execution. The presence of a command parameter and the server's response executing that command directly confirms the artifact is a webshell.

Exam trap

The trap here is that candidates confuse the directory listing output with directory traversal (Option B), but directory traversal reads files via path manipulation, not by executing a command like 'dir' through a server-side script parameter.

How to eliminate wrong answers

Option A is wrong because SQL injection involves manipulating SQL queries through input fields (e.g., ' OR 1=1--), not executing system commands like 'dir' via an HTTP parameter. Option B is wrong because directory traversal exploits path manipulation (e.g., '../../etc/passwd') to read arbitrary files, not to execute commands or receive a directory listing as a command output. Option D is wrong because cross-site scripting (XSS) injects client-side scripts (e.g., JavaScript) into web pages viewed by other users, not server-side command execution via a POST parameter.

237
MCQhard

A forensic analyst is examining a Windows system and finds that the UserAssist key in the NTUSER.DAT hive contains entries with Rot13-encoded names. What is the primary purpose of the UserAssist key?

A.Record USB device connection history
B.Store user password history
C.Log program execution counts and last run times
D.Track recently opened documents via Jump Lists
AnswerC

UserAssist is a per-user registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count that records GUI applications launched through Windows Explorer. Each value contains the ROT13-obfuscated path of an executable, with an embedded binary payload representing the number of times it was executed and the last execution timestamp encoded as a FILETIME. Forensic analysts decrypt the ROT13 and parse the binary data to prove a specific program was run, how often, and when, which is exactly what this correct answer describes.

Why this answer

The UserAssist key in the NTUSER.DAT hive is designed to track program execution counts and the last time each program was run by the user. The Rot13 encoding of the subkey names is a lightweight obfuscation to hide the logged application paths, but the core purpose remains forensic artifact for user activity timeline reconstruction.

Exam trap

The trap here is that candidates confuse the Rot13 encoding as a security feature for hiding passwords or sensitive data, when in fact it is merely a weak obfuscation of program paths and has nothing to do with password storage or USB tracking.

How to eliminate wrong answers

Option A is wrong because USB device connection history is recorded in the SYSTEM hive (USBSTOR key) and the setupapi.dev.log, not in the UserAssist key. Option B is wrong because user password history is stored in the SAM hive (as LM/NT hashes) or in Active Directory, not in UserAssist. Option D is wrong because recently opened documents via Jump Lists are stored as *.automaticDestinations-ms files in the user's AppData\Roaming\Microsoft\Windows\Recent directory, not in the UserAssist registry key.

238
MCQmedium

An Android forensic analyst connects a suspect device to their workstation and issues the command "adb backup -apk -shared -all -f backup.ab". Which type of acquisition is being performed?

A.Manual acquisition through device UI
B.Physical acquisition via JTAG
C.Logical acquisition via ADB backup
D.File system acquisition via dd
AnswerC

`adb backup` is a logical acquisition method because it leverages Android's Backup Service to request that each app's internal data, settings, and databases be serialized into a single .ab archive, excluding hidden regions and unallocated clusters. This high-level extraction is governed by the app's `backupAgent` and the device's backup policy, meaning some apps may opt out entirely or omit sensitive files. Unlike a physical or file system image, it yields no deleted remnants or raw partitions—so while it is a valid ADB-based forensic export, it does not produce a bit-for-bit copy of the storage medium.

Why this answer

The command `adb backup -apk -shared -all -f backup.ab` creates a full Android backup via the Android Debug Bridge (ADB) protocol. This is a logical acquisition because it requests user data and installed APKs through the high-level backup service, not a bit-for-bit copy of the storage. The resulting `.ab` file is an Android Backup archive, which contains files and directories that the device’s backup manager chooses to export, making it a logical extraction.

Exam trap

The CHFI exam often tests the distinction between logical and physical acquisition by presenting a command that looks like it might be low-level (e.g., containing 'backup' or 'all') but is actually a logical method, leading candidates to mistakenly choose physical or file system acquisition.

How to eliminate wrong answers

Option A is wrong because manual acquisition through the device UI involves navigating menus and copying data manually, not using ADB commands. Option B is wrong because physical acquisition via JTAG requires hardware-level access to the device’s JTAG interface to dump raw flash memory, not a software command over USB. Option D is wrong because file system acquisition via `dd` creates a bit-for-bit image of a partition or block device, whereas `adb backup` only extracts logical files and does not capture deleted data or unallocated space.

239
MCQeasy

A forensic investigator examines a hard drive and needs to recover deleted files. Which tool is specifically designed for file carving by scanning raw data for file headers and footers without relying on the file system?

A.Foremost
B.Volatility
C.Autopsy
D.FTK Imager
AnswerA

Foremost is a classic file-carving utility that scans raw byte streams (such as a dd or E01 image) for known file signatures—e.g., JPEG headers 0xFFD8FF, PNG, ZIP—and extracts the intervening data as a reconstructed file. Because it operates directly on unallocated space and does not depend on filesystem metadata (MFT, inodes, directory entries), it can recover deleted files no longer listed in any index. It is driven by a configuration file defining the signatures and can use internal structural hints, such as embedded length fields, to improve recovery accuracy.

Why this answer

Foremost is a file carving tool that scans raw disk data for known file headers and footers (e.g., JPEG, PDF, ZIP) to recover files independently of the file system metadata. This makes it ideal when the file system is damaged or deleted, as it relies solely on content signatures rather than directory structures.

Exam trap

The CHFI exam often tests the distinction between file carving tools (Foremost) and forensic suites (Autopsy, FTK Imager) or memory analysis tools (Volatility), trapping candidates who confuse a tool's primary function with its ancillary features.

How to eliminate wrong answers

Option B (Volatility) is wrong because it is a memory forensics framework for analyzing RAM dumps, not a file carving tool for hard drives. Option C (Autopsy) is wrong because it is a digital forensics platform that relies on file system analysis and does not perform raw file carving by default; it uses tools like Foremost as plugins. Option D (FTK Imager) is wrong because it is primarily a disk imaging and preview tool that preserves file system metadata, not a dedicated file carver that scans raw data for headers and footers.

240
MCQeasy

Which tool is specifically designed for timeline analysis of forensic artifacts across multiple systems and can process output from various forensic tools?

A.Autopsy
B.Wireshark
C.Sleuth Kit
D.log2timeline
AnswerD

log2timeline, now part of the Plaso project, is specifically engineered to acquire and analyze timestamps from a wide array of artifact sources—file system metadata, Windows Registry, event logs, browser history, and third-party application logs—into a unified SQLite timeline database. Its dedicated tools such as pinfo and psort filter, sort, and output event timelines, making it the canonical purpose-built solution for timestamp correlation in digital forensics. Unlike generic analysis platforms or packet analyzers, its entire architecture is centered on timeline generation and analysis.

Why this answer

log2timeline (now part of the Plaso framework) is specifically designed for super timeline creation, aggregating and correlating timestamps from multiple forensic artifacts across different systems. It can ingest output from tools like The Sleuth Kit, Autopsy, and others to produce a unified, high-resolution timeline for analysis.

Exam trap

EC-Council often tests the distinction between a general forensic suite (like Autopsy or Sleuth Kit) and a specialized timeline analysis tool (log2timeline), leading candidates to choose a familiar tool that can perform some timeline functions but lacks the cross-tool aggregation capability.

How to eliminate wrong answers

Option A is wrong because Autopsy is a digital forensics platform that provides a GUI for analyzing disk images and file systems, but it is not specifically designed for cross-system timeline aggregation from multiple tools. Option B is wrong because Wireshark is a network protocol analyzer for capturing and inspecting live or recorded network traffic, not for timeline analysis of forensic artifacts. Option C is wrong because The Sleuth Kit is a collection of command-line tools for low-level file system and volume analysis, but it lacks the built-in capability to merge timestamps from diverse sources into a single super timeline.

241
MCQmedium

In a UK-based investigation, which legal framework governs the search and seizure of digital evidence?

A.Electronic Communications Privacy Act
B.PACE (Police and Criminal Evidence Act)
C.Fourth Amendment
D.GDPR
AnswerB

The Police and Criminal Evidence Act 1984 (PACE) is the primary legal framework for police powers in England and Wales, covering stop and search, arrest, detention, and the seizure of evidence. Its Codes of Practice, particularly Code B, set out detailed procedures for searching premises and seizing property, including digital devices, to ensure lawfulness and admissibility. In a UK-based investigation, PACE is the correct framework for authorising and conducting searches and seizures, and it also provides exclusionary powers under section 78.

Why this answer

The Police and Criminal Evidence Act 1984 (PACE) provides the legal framework for police powers, including search and seizure of digital evidence in the UK.

242
MCQmedium

During a malware analysis, an analyst runs a suspicious executable in a Cuckoo Sandbox and observes that the process creates a mutex named 'Global\XPSS-1.0.0' and writes a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What do these actions MOST likely indicate?

A.The malware is performing privilege escalation by exploiting a known vulnerability.
B.The malware is communicating with a command-and-control server to receive further instructions.
C.The malware is attempting to hide its presence by using a system mutex name and a legitimate registry location.
D.The malware is establishing persistence and ensuring only one instance of itself runs.
AnswerD

The Run registry key is a standard persistence mechanism that causes the malware to execute automatically every time the user logs on, ensuring it survives reboots. The named mutex provides a global lock that prevents multiple instances of the malware from running concurrently, which is crucial for avoiding detection through duplicate processes and for maintaining stable infection. Together, these artifacts conclusively indicate the malware's goal of persistent residency and single-instance control.

Why this answer

The mutex 'Global\XPSS-1.0.0' is used to prevent multiple instances of the malware from running simultaneously, which is a common anti-analysis and stability technique. Writing a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard method for achieving persistence, ensuring the malware executes automatically at user logon. Together, these actions directly indicate persistence and single-instance control, not privilege escalation, C2 communication, or hiding.

Exam trap

EC-Council often tests the distinction between persistence mechanisms and hiding techniques, trapping candidates who confuse a standard persistence location (Run key) with a stealth or concealment method, when hiding typically involves alternate data streams, registry run keys under Policies, or rootkit-level hooks.

How to eliminate wrong answers

Option A is wrong because creating a mutex and writing a Run key are not techniques for privilege escalation; privilege escalation typically involves exploiting vulnerabilities (e.g., via token manipulation or kernel exploits) to gain higher access rights, not mutex or registry operations. Option B is wrong because mutex creation and Run key persistence are local system actions; communication with a command-and-control server would involve network connections (e.g., HTTP, DNS, or IRC traffic) and is not directly indicated by these artifacts. Option C is wrong because the mutex name 'Global\XPSS-1.0.0' is not a standard system mutex (system mutexes often use 'Global\' prefix with well-known names like 'Global\MSCTF.CtfMonitor') and the Run key is a well-known persistence location, not a hiding technique; hiding would involve rootkits, fileless techniques, or stealthy registry locations like HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run.

243
MCQmedium

A web server log shows the following request: 'GET /../../../../etc/passwd HTTP/1.1' with a 200 response code. The web server is running Apache on Linux. What attack has likely succeeded?

A.Remote File Inclusion (RFI)
B.SQL injection
C.Cross-Site Request Forgery (CSRF)
D.Local File Inclusion (LFI) or Path Traversal
AnswerD

Local File Inclusion (LFI) or Path Traversal is correct because the URI uses the ../ sequence to escape the web root and access an arbitrary local file, /etc/passwd. The pattern /etc/passwd after multiple directory traversal segments indicates the web application is likely vulnerable to including or exposing local files via its handling of the requested path. This is a classic LFI/path traversal scenario where an attacker can read sensitive system files by manipulating the path input, and the file path resolution occurs on the server's local filesystem.

Why this answer

The request 'GET /../../../../etc/passwd HTTP/1.1' with a 200 response indicates the server successfully returned the contents of the /etc/passwd file. This is a classic path traversal attack (also known as Local File Inclusion) where the attacker uses '../' sequences to escape the web root directory and access arbitrary files on the Linux filesystem. Apache's default configuration does not block such sequences if directory traversal protections are missing, allowing the attacker to read sensitive system files.

Exam trap

A common mistake in the CHFI exam is confusing Local File Inclusion (LFI) with Remote File Inclusion (RFI). The key differentiator is that LFI uses relative path traversal (../) to access local files, while RFI includes a remote URL. This request accesses /etc/passwd via path traversal, indicating LFI.

How to eliminate wrong answers

Option A is wrong because Remote File Inclusion (RFI) involves including a remote file (e.g., from an external URL) into the server's execution context, not traversing local directories to read a local file. Option B is wrong because SQL injection targets database queries via input fields (e.g., ' OR 1=1 --), not file path manipulation in HTTP requests. Option C is wrong because Cross-Site Request Forgery (CSRF) tricks an authenticated user's browser into making unintended requests on their behalf, and does not involve direct file path traversal in a GET request.

244
MCQhard

A company's legal department issues a legal hold notice for electronically stored information (ESI) related to a pending lawsuit. The IT department is tasked with preserving data. Which of the following actions is MOST likely to violate the legal hold requirements?

A.Notifying all employees to preserve documents related to the lawsuit.
B.Suspending routine deletion of emails older than 30 days.
C.Continuing to run a script that deletes temporary files older than 24 hours.
D.Taking a forensic image of the relevant servers.
AnswerC

Continuing to run the 24-hour temp-file deletion script violates the legal hold because the script operates as an ongoing, automated erosion of potentially relevant ESI. Temporary files are not categorically immaterial; they may contain fragments, cached versions, or undelivered drafts of emails and documents that fall within the scope of the lawsuit. By allowing a routine housekeeping process to persist unchecked, the company risks spoliation and sanctions, regardless of the files' temporary designation.

Why this answer

Continuing to run a script that deletes temporary files older than 24 hours directly destroys ESI that may be relevant to the lawsuit, violating the legal hold requirement to preserve all potentially relevant data. Legal hold mandates the suspension of any automated or manual processes that could alter or delete ESI, including temporary files that might contain fragments of relevant documents or metadata. Unlike suspending routine email deletion (Option B), which is a preservation action, the script actively purges data and thus breaches the hold.

Exam trap

EC-Council often tests the misconception that only 'obvious' data like emails or documents need preservation, but the trap here is that temporary files and caches are also ESI and must be preserved under a legal hold, making their automated deletion a violation.

How to eliminate wrong answers

Option A is wrong because notifying employees to preserve documents is a standard and necessary step to implement a legal hold, ensuring awareness and compliance. Option B is wrong because suspending routine deletion of emails older than 30 days is a proper preservation action that stops the destruction of potentially relevant ESI. Option D is wrong because taking a forensic image of relevant servers is a best-practice preservation technique that captures a point-in-time snapshot of data without altering it, fully compliant with legal hold requirements.

245
MCQeasy

An investigator needs to capture network traffic from a live network segment without altering the traffic flow. Which technique should they use?

A.Enable NetFlow on the router and capture flows
B.Configure a SPAN port on the switch
C.Deploy an ARP spoofing tool to redirect traffic
D.Set the NIC to promiscuous mode on the forensic workstation
AnswerB

Configuring a SPAN (Switched Port Analyzer) port on the switch copies ingress and egress frames from specified source ports or VLANs to a designated monitor port, where a forensic workstation can record full packets without altering the original traffic path. This non-intrusive mirroring preserves switch performance and avoids introducing latency or dropping frames, making it the standard method for lawful network capture at Layer 2.

Why this answer

A SPAN (Switched Port Analyzer) port, also known as a mirror port, copies all traffic from a specified source port or VLAN to a destination port where the forensic workstation is connected. This allows the investigator to capture traffic without injecting any frames or altering the forwarding behavior of the switch, thus preserving the integrity of the live network segment.

Exam trap

EC-Council often tests the misconception that promiscuous mode alone is sufficient for capturing all traffic on a switched network, but candidates forget that switches isolate traffic per port unless a SPAN port is configured.

How to eliminate wrong answers

Option A is wrong because NetFlow is a flow-based accounting and monitoring technology that exports aggregated flow records (e.g., source/destination IP, ports, protocol) rather than capturing full packet payloads; it cannot provide the raw packet-level data needed for deep forensic analysis. Option C is wrong because ARP spoofing actively sends forged ARP replies to redirect traffic through the attacker's machine, which alters the traffic flow and can cause network disruptions or detection, violating the requirement to not alter the traffic flow. Option D is wrong because setting a NIC to promiscuous mode only allows the workstation to receive all frames on the collision domain of its connected switch port, but on a modern switched network, the switch will not forward traffic destined for other ports to the forensic workstation, so promiscuous mode alone cannot capture traffic from other hosts without additional techniques like ARP spoofing or a SPAN port.

246
MCQmedium

A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?

A.Immediately power on the server to check for running processes.
B.Copy all files from the server to an external USB drive.
C.Run antivirus scan to ensure no malware is present before imaging.
D.Secure the scene, photograph the setup, document connections, remove hard drives, and create forensic images using a write-blocker.
AnswerD

This is the correct forensic process: first secure the scene to prevent interference, then photograph and document the physical setup and all connections to preserve the context. Identify and collect volatile data if applicable, then remove the hard drives using proper anti-static procedures. Using a write-blocker when creating a forensic image prevents any write operations to the original drive, and hashing the image ensures the preservation of a verifiable, bit-for-bit copy for analysis and chain-of-custody.

Why this answer

It follows the established forensic investigation process: secure the scene to prevent contamination, document the state of the server (photographs and connection diagrams), then physically remove the hard drives and create forensic images using a write-blocker to preserve the original data without alteration. This ensures evidence integrity and admissibility in legal proceedings.

Exam trap

EC-Council often tests the misconception that immediate data collection (like powering on or scanning) is acceptable, when in fact the first priority is to preserve the scene and prevent any modification to the evidence.

How to eliminate wrong answers

Option A is wrong because powering on a server that has been shut down can alter volatile data (e.g., memory contents, temporary files, system logs) and may trigger anti-forensic mechanisms, destroying evidence. Option B is wrong because copying files directly to an external USB drive modifies file metadata (e.g., last access timestamps) and does not capture deleted data or unallocated space, violating forensic best practices. Option C is wrong because running an antivirus scan on a live or powered-off system can modify files (e.g., quarantine, deletion, or repair) and alter the evidence, compromising its integrity.

247
Multi-Selectmedium

An investigator is analyzing a Windows system and wants to find evidence of USB device usage. Which TWO registry keys should be examined? (Select TWO.)

Select 2 answers
A.HKLM\SAM\SAM
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
C.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
E.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
AnswersC, D

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive system-wide registry hive for USB mass storage devices. Each subkey corresponds to a unique device instance, following the pattern Disk&Ven_[vendor]&Prod_[product]&Rev_[revision], with a serial-number subkey that can identify the exact device. It also contains the ParentIdPrefix value, which can be correlated with other artifacts such as Setupapi.dev.log and MountPoints2 to establish connection timelines. This key is a primary source for listing all USB storage devices ever plugged into the system.

Why this answer

Option C, HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, is correct because this key is where Windows records every USB mass-storage device that has ever been connected, storing device instance IDs, vendor/product identifiers, and serial numbers that directly evidence USB storage usage. Option D, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2, is correct because it tracks per-user mount points and drive-letter assignments for mounted volumes, including USB drives, showing which user mounted which removable device. Option A, HKLM\SAM\SAM, is incorrect because the SAM hive stores local account and group security data, not USB device artifacts.

Option B, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is incorrect because it lists programs configured to auto-start at logon, which is persistence-related rather than USB-usage evidence. Option E, HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList, is incorrect because it maps user SIDs to profile paths, not USB device connections.

Exam trap

EC-Council often tests the distinction between system-wide device enumeration (USBSTOR) and user-specific mount point history (MountPoints2), leading candidates to mistakenly select startup or profile keys that have no connection to USB artifacts.

248
MCQmedium

An analyst suspects that sensitive data was hidden in the NTFS Alternate Data Streams (ADS) of a file on a suspect's drive. Which tool is specifically designed to enumerate and extract data from ADS on a live Windows system?

A.Foremost
B.PhotoRec
C.dd
D.Streams.exe (Sysinternals)
AnswerD

Streams.exe, part of the Sysinternals suite, is the correct tool because it is specifically built to enumerate NTFS Alternate Data Streams, which are hidden metadata streams associated with files (e.g., 'file.txt:hidden.txt'). It scans the NTFS filesystem and displays the full path of each stream, including the stream name and file size, allowing an analyst to identify suspicious data hidden in ADS. This tool directly addresses the scenario of sensitive data concealed in an NTFS ADS, unlike generic carving or imaging utilities.

Why this answer

Streams.exe from Sysinternals is specifically designed to enumerate and extract data from NTFS Alternate Data Streams (ADS) on a live Windows system. It scans files and directories for hidden streams, displaying their names and sizes, and can optionally delete or extract them. This makes it the correct tool for the analyst's task.

Exam trap

EC-Council CHFI often tests the distinction between file carving tools (Foremost, PhotoRec) and tools that parse file system metadata (Streams.exe), leading candidates to mistakenly choose a carving tool for ADS enumeration.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool that recovers files based on headers and footers, not designed to enumerate or extract NTFS Alternate Data Streams. Option B is wrong because PhotoRec is also a file carving utility focused on recovering lost files from raw disk images, not ADS enumeration. Option C is wrong because dd is a low-level disk imaging tool that creates bit-for-bit copies of storage media; it does not parse NTFS metadata or expose ADS.

249
Multi-Selecthard

Which THREE of the following are challenges specific to SSD forensics compared to HDD forensics?

Select 3 answers
A.Garbage collection that automatically erases stale blocks
B.TRIM command causing data erasure
C.Wear leveling algorithms that relocate data
D.Platter rotation causing magnetic remanence
E.Controller-based compression reducing data size
AnswersA, B, C

Garbage collection is a background process in SSD controllers that consolidates valid data into fewer blocks and then erases entire blocks containing stale pages. Because it runs autonomously without any operating system command, it can physically erase data from deleted files before an investigator can image the drive, destroying remnants that might otherwise be recovered through file carving or chip-off analysis.

Why this answer

Option A is correct because SSD garbage collection proactively erases blocks containing stale or invalid pages in the background, so data that would remain recoverable on an HDD platter can be destroyed without any user action. Option B is correct because the TRIM command tells the SSD controller which LBAs are no longer in use, allowing those flash pages to be erased and making deleted data unrecoverable far faster and more thoroughly than on an HDD. Option C is correct because wear leveling relocates data across NAND blocks to spread erase cycles, so logical-to-physical mapping changes constantly and forensic tools cannot rely on fixed physical locations the way they can with HDD platters.

Option D is not correct because platter rotation and magnetic remanence are characteristics of HDDs, not SSD-specific challenges. Option E is not correct because controller-based compression is not a defining SSD forensic challenge in the way garbage collection, TRIM, and wear leveling are, and it is not marked as a correct answer here.

Exam trap

EC-CHFI often tests the distinction between HDD-specific features (like platter rotation and magnetic remanence) and SSD-specific challenges, so candidates mistakenly select HDD-related options because they sound technical, but they do not apply to solid-state drives.

250
MCQeasy

Which email header field is specifically used to verify that an email was not tampered with during transit and is signed by the sender's domain?

A.X-Originating-IP
B.Message-ID
C.Received
D.DKIM-Signature
AnswerD

DKIM-Signature contains a digital signature computed over selected canonicalized header fields and the message body using a private key held by the sending domain. The verifier retrieves the sender's public key from DNS (e.g., dkim._domainkey.example.com) to decrypt the hash and compare it to the hashed current content, thereby detecting any modification since signing. Because the signature is cryptographically bound to the message content and the signing domain, it specifically provides the required verification of both origin and integrity.

Why this answer

The DKIM-Signature header field is the correct answer because it provides a cryptographic signature that allows the receiver to verify that the email was not altered in transit and that it originated from the claimed domain. DKIM (DomainKeys Identified Mail) uses public-key cryptography, where the sender's domain publishes a public key in DNS, and the sending server signs the email with the corresponding private key. This ensures both integrity and domain-level authentication, directly matching the question's requirement.

Exam trap

A common misconception is that the Received header can verify integrity because it shows the mail path, but it lacks cryptographic signing and can be manipulated by any intermediate server. EC-Council expects you to know that only DKIM provides cryptographic integrity verification tied to the sender's domain.

How to eliminate wrong answers

Option A is wrong because X-Originating-IP is a non-standard header that records the IP address of the original sender's client, but it provides no cryptographic integrity verification or domain-level signing. Option B is wrong because Message-ID is a unique identifier for the email message, used for tracking and threading, but it has no security properties to verify tampering or sender domain authenticity. Option C is wrong because the Received header is added by each mail transfer agent (MTA) along the delivery path to trace the route, but it does not include a cryptographic signature and can be easily forged or modified by intermediate servers.

251
MCQhard

A forensic analyst is examining a hard drive that was imaged using a software write blocker. Which of the following is a potential disadvantage of using a software write blocker compared to a hardware write blocker?

A.It cannot be used with USB drives
B.It may be susceptible to operating system or driver vulnerabilities
C.It does not support hashing algorithms for integrity
D.It is more expensive than hardware write blockers
AnswerB

Software write blockers enforce read-only access by relying on the operating system kernel, storage drivers, and the blocker's own filter driver. If any of those trusted components has a vulnerability—for example, a privilege escalation bug or a flaw in the way the filter processes IOCTL requests—an attacker on the system could submit write commands directly to the storage device, bypassing the blocker. Because the blocker runs at the same privilege level as the code it is trying to protect against, it inherits the OS's security weaknesses. This inherent trust dependency is why hardware write blockers are often preferred for forensic soundness in hostile or unknown environments.

Why this answer

A software write blocker operates at the operating system level, intercepting write commands before they reach the storage device. Because it relies on the OS and its drivers, any vulnerability in the OS kernel, storage driver stack, or the blocker's own filter driver could be exploited, potentially allowing unintended writes to the evidence. In contrast, a hardware write blocker physically prevents write signals from reaching the drive at the bus level, offering a more robust isolation that is independent of the host OS's security state.

Exam trap

EC-Council often tests the misconception that software write blockers are functionally equivalent to hardware blockers, but the trap here is that candidates overlook the OS-layer dependency and vulnerability surface of software blockers, assuming they are just as reliable as physical write-blocking hardware.

How to eliminate wrong answers

Option A is wrong because software write blockers can be used with USB drives; they intercept write commands at the OS level regardless of the interface (SATA, USB, etc.), though some may require specific driver support. Option C is wrong because software write blockers do not inherently prevent hashing; hashing algorithms like SHA-256 are applied to the acquired image by forensic tools (e.g., FTK Imager, dd with sha256sum) independently of the write blocker. Option D is wrong because software write blockers are generally less expensive than hardware write blockers, often being free or low-cost tools (e.g., built-in OS features or open-source utilities), while hardware blockers involve dedicated electronic components.

252
MCQhard

In the context of e-discovery, what does the 'best evidence rule' require regarding digital documents?

A.That the original electronic file or a reliable duplicate be produced.
B.That all evidence be authenticated by a witness.
C.That only paper copies of digital documents are admissible.
D.That metadata is preserved in all copies.
AnswerA

Under Fed. R. Evid. 1002, proving a document's content requires the original; for ESI, FRE 1001(d) defines an original as any printout or other readable output that accurately reflects the information. A reliable duplicate—such as a forensic image with a matching SHA-256 hash or a native file produced with verified integrity—is admissible whenever there is no genuine question about the original's authenticity or unfairness from using the copy. In practice, producing the native file or load-file images with hash-verified integrity satisfies the rule.

Why this answer

The best evidence rule, codified in Federal Rule of Evidence 1002, requires the original writing, recording, or photograph to prove its content unless otherwise provided. In e-discovery, an original electronic file or a reliable duplicate (e.g., a bit-for-bit forensic image verified by a hash such as MD5 or SHA-1) satisfies this rule because the duplicate is functionally equivalent to the original for evidentiary purposes.

Exam trap

EC-Council often tests the misconception that the best evidence rule requires the 'original' in a physical sense, leading candidates to reject reliable duplicates, when in fact digital duplicates verified by hash are legally equivalent to the original under FRE 1003.

How to eliminate wrong answers

Option B is wrong because the best evidence rule does not mandate authentication by a witness; authentication is a separate requirement under FRE 901, which can be satisfied through testimony or circumstantial evidence like hash values. Option C is wrong because the rule does not require paper copies; in fact, paper copies of digital documents are often considered duplicates and may be admissible if they accurately reflect the original, but the rule prefers the original or a reliable duplicate, not exclusively paper. Option D is wrong because while metadata preservation is a best practice in forensics, the best evidence rule itself does not explicitly require metadata preservation in all copies; it focuses on the content of the document, not its metadata.

253
Multi-Selecteasy

A forensic analyst is performing static analysis of a Windows PE file. Which TWO of the following tools are specifically designed for static analysis of malware?

Select 2 answers
A.Wireshark
B.Cuckoo Sandbox
C.IDA Pro
D.Ghidra
E.Process Monitor
AnswersC, D

IDA Pro is an interactive disassembler that converts raw machine code into assembly mnemonics and constructs control-flow and cross-reference graphs, allowing an analyst to understand the binary's logic without running it. It parses the PE/ELF/Mach-O file formats, resolves imports and exports, and identifies function boundaries and string references directly from the file's static content. This aligns exactly with static analysis of a Windows binary because no code is executed; the tool operates solely on the on-disk representation.

Why this answer

IDA Pro (C) is a disassembler and debugger specifically built for reverse engineering binary executables, allowing an analyst to statically examine a PE file's code, imports, and structure without executing it. Ghidra (D) is the NSA's open-source software reverse engineering suite that likewise performs static disassembly and decompilation of PE files, making it a core static malware analysis tool. Both operate on the file on disk, matching the scenario's requirement for static analysis.

Wireshark (A) is a network protocol analyzer that inspects captured traffic, not PE binaries. Cuckoo Sandbox (B) is a dynamic analysis platform that executes malware in an isolated VM and observes behavior, so it is not static. Process Monitor (E) is a live runtime monitoring tool for file, registry, and process activity, also dynamic rather than static.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse network or process monitoring tools (Wireshark, Process Monitor) with static analysis, or mistake sandboxing (Cuckoo) for static analysis when it is inherently dynamic.

254
MCQeasy

Which Windows artifact is primarily used to determine the execution history of applications, including the path and run count?

A.LNK files
B.Jump lists
C.Prefetch files
D.Event logs
AnswerC

Prefetch files are generated by the Windows Prefetcher on each application launch to accelerate future startups by preloading referenced pages and DLLs. Each .pf file in C:\Windows\Prefetch contains the full executable path, a run count (stored at a specific offset in the header), the last execution timestamp, and a list of files accessed at startup. This makes Prefetch files the primary native artifact for determining the execution history, run count, and last run time of a specific application. They are especially powerful because they exist by default on desktop Windows installations, but forensic examiners should account for cases where Prefetch is disabled (e.g., on SSDs with certain configurations or via Group Policy).

Why this answer

Prefetch files (.pf) are created by Windows to speed up application startup by caching data about the files loaded during the first few seconds of execution. Each prefetch file records the application's path, the number of times it has been run (run count), and the last execution timestamp, making it the primary artifact for determining execution history.

Exam trap

EC-CHFI often tests the distinction between artifacts that track execution history (Prefetch) versus those that track file access or user activity (LNK files, Jump Lists), so candidates mistakenly choose LNK files because they associate shortcuts with program launches.

How to eliminate wrong answers

Option A is wrong because LNK files (shortcuts) store metadata about the target file's location and creation/modification times, but they do not track run count or execution history. Option B is wrong because Jump Lists store recently accessed files and tasks for an application pinned to the taskbar, but they do not record the number of times the application itself was executed. Option D is wrong because Event logs record system, security, and application events (e.g., process creation via Event ID 4688), but they are not the primary artifact for execution history and do not inherently track run count or prefetch-specific data.

255
MCQmedium

A security analyst is investigating a compromised Windows system and wants to see which processes were running at the time of memory capture. Which Volatility command should they use?

A.volatility -f mem.dump pslist
B.volatility -f mem.dump hashdump
C.volatility -f mem.dump malfind
D.volatility -f mem.dump netscan
AnswerA

The `pslist` plugin walks the doubly linked list of EPROCESS structures in the memory image, enumerating every running process at the time of capture. This directly satisfies the task of listing processes active on the compromised Windows system, making it the correct command. Note that because it relies on the linked list, processes that have deliberately unlinked themselves to evade detection will not appear, but for standard process enumeration it is the foundational Volatility command.

Why this answer

The `pslist` plugin in Volatility enumerates processes from the Windows kernel's EPROCESS structure list, showing all active processes at the time of memory capture. This is the correct command to identify running processes from a memory dump, as it directly parses the doubly-linked list of process objects maintained by the kernel.

Exam trap

CHFI often tests the distinction between `pslist` (which uses the kernel's process list) and `psscan` (which uses pool tag scanning), leading candidates to confuse `pslist` with other plugins like `malfind` or `netscan` that serve different forensic purposes.

How to eliminate wrong answers

Option B is wrong because `hashdump` extracts password hashes from the SAM registry hive, not running processes. Option C is wrong because `malfind` detects injected code or hidden processes by scanning for executable memory regions with suspicious permissions, but it does not list all running processes. Option D is wrong because `netscan` enumerates network connections and sockets, not processes.

256
MCQhard

An analyst runs 'dcfldd if=/dev/sdb of=/evidence/disk.dd hash=sha256 hashlog=/evidence/hash.log' on a Linux system. What is the primary advantage of using dcfldd over plain dd for forensic imaging?

A.It can acquire memory dumps from live systems
B.It supports compression of the output image
C.It automatically creates a write-blocked connection
D.It can compute hashes on-the-fly and log them
AnswerD

dcfldd computes hash values (MD5, SHA-1, SHA-256, etc.) as it reads data, allowing verification without a separate pass. It can log these hashes to a separate file (e.g., using the 'hashlog' or 'hashlog-md5' parameters) and display verified status for each segment. This is a key forensic feature because it ensures the acquired image is a true copy and provides an audit trail of the imaging process.

Why this answer

D is correct because dcfldd is a specialized forensic version of dd that can compute cryptographic hashes (e.g., SHA-256) on-the-fly while writing the image, and log those hashes to a separate file (hashlog). This ensures data integrity verification without requiring a separate post-imaging hashing pass, which is a critical requirement in forensic imaging to prove the acquired image is an exact bit-for-bit copy of the source.

Exam trap

The trap here is that candidates may confuse dcfldd's on-the-fly hashing with other features like compression or memory acquisition, or assume that dd itself can perform hashing, when in fact plain dd has no built-in hash computation capability.

How to eliminate wrong answers

Option A is wrong because dcfldd is designed for disk imaging, not memory acquisition; tools like LiME or fmem are used for live memory dumps. Option B is wrong because dcfldd does not natively support compression; compression must be done via piping to gzip or using other tools like ewfacquire. Option C is wrong because dcfldd does not create a write-blocked connection; write-blocking is a hardware or software layer (e.g., using a hardware write-blocker or the Linux kernel's read-only mount) that must be established before running the imaging command.

257
Multi-Selecthard

A security analyst is investigating a potential webshell on an IIS server. Which THREE artifacts are commonly associated with webshell presence?

Select 3 answers
A.Increase in NetFlow traffic to a known good update server
B.Presence of encoded scripts in the web application directory
C.Event ID 4624 logon events from the service account
D.Unusual HTTP POST requests to .asp or .aspx files in IIS logs
E.Process creation events for cmd.exe or powershell.exe spawned by w3wp.exe
AnswersB, D, E

Because webshells must be accessible by the web server, they are nearly always planted in a web-accessible directory, such as wwwroot or a subfolder. Attackers routinely hide the malicious intent by encoding the payload—for instance with base64, hex, or gzinflate—so the file appears as an opaque script without readable function names. Legitimate web application code is rarely obfuscated in this manner, so the combination of placement in a web directory and encoded content is a strong, direct indicator of a webshell.

Why this answer

Option B is correct because webshells are typically dropped as script files (e.g., .asp, .aspx, .php) in web-accessible directories, and attackers frequently obfuscate or encode them (Base64, gzip, eval/execute blocks) to evade signature detection. Option D is correct because webshell interaction occurs over HTTP, so IIS logs commonly show anomalous POST requests to .asp/.aspx endpoints, often with unusual user agents, parameters, or response sizes indicating command execution. Option E is correct because IIS worker process w3wp.exe spawning cmd.exe or powershell.exe is a classic parent-child anomaly indicating remote command execution through a webshell.

Option A is not specific to webshells, since NetFlow to a legitimate update server is normal patching traffic and lacks host-level context. Option C is not indicative either, as Event ID 4624 logons by a service account are routine and do not by themselves evidence webshell activity.

Exam trap

Candidates often mistake Event ID 4624 logon events for webshell activity, but these are routine authentication events. The correct artifacts are unusual HTTP POST requests, encoded scripts, and child processes of w3wp.exe.

258
MCQeasy

An investigator needs to parse and analyze a Microsoft Outlook personal folders file (.pst). Which tool is specifically designed for this purpose?

A.Aid4Mail
B.FTK Imager
C.Wireshark
D.Sleuth Kit
AnswerA

Aid4Mail is purpose-built for email forensics, with a native parser that navigates Outlook's proprietary PST B-Tree structure and heap-node architecture to extract individual items such as messages, contacts, and calendar entries. It handles both ANSI and Unicode PST formats, preserves metadata and deleted-item remnants, and can export evidence to MSG, EML, or PDF while maintaining hash integrity for court presentation. This makes it the correct choice over generic disk or network tools for analyzing an Outlook mailbox.

Why this answer

Aid4Mail is a forensic email analysis tool that can parse Outlook PST files, among other formats, and extract metadata, attachments, and headers.

259
MCQmedium

An analyst detects a large amount of data being exfiltrated from a network over DNS queries. Which type of network analysis would BEST detect this activity?

A.Proxy log analysis
B.Firewall log analysis
C.Packet capture analysis
D.IDS/IPS log analysis
AnswerC

Packet capture analysis is the definitive method because it records the raw DNS datagrams, preserving every byte of the query name and answer section. An analyst using Wireshark, tcpdump, or NetworkMiner can inspect individual DNS QNAME labels for high entropy, long subdomains, or unusual RR types, then decode the embedded data. This also provides the original evidence needed for forensic reconstruction rather than relying on summary logs.

Why this answer

Packet capture analysis (C) is the best method because DNS exfiltration involves encoding stolen data into DNS query or response fields (e.g., subdomains, TXT records). Only full packet capture allows inspection of the raw DNS payloads, including the actual query names and response data, which is necessary to detect the anomalous patterns of data being tunneled over DNS. Proxy, firewall, and IDS/IPS logs typically only record metadata (source/destination, timestamps, allowed/denied actions) and do not provide the granularity to see the encoded data within DNS packets.

Exam trap

EC-Council often tests the misconception that IDS/IPS logs (D) are sufficient for detecting all types of network attacks, but in the case of DNS tunneling, the logs only show alerts for known signatures, not the raw payload data required to confirm exfiltration.

How to eliminate wrong answers

Option A is wrong because proxy logs record HTTP/HTTPS requests and responses, not raw DNS traffic; DNS exfiltration occurs at the network layer (UDP 53) and is not captured by a web proxy. Option B is wrong because firewall logs show allowed/denied connections and basic packet headers (IP, port, protocol) but do not decode or log the payload content of DNS queries, so the exfiltrated data hidden in DNS fields is invisible. Option D is wrong because IDS/IPS logs contain alerts based on signatures or anomalies, but many DNS exfiltration tools use legitimate-looking queries that evade signature-based detection; moreover, IDS logs only record triggered alerts, not the full packet data needed for analysis.

260
Multi-Selectmedium

Which THREE of the following are characteristics of the Master File Table ($MFT) in NTFS? (Choose three.)

Select 3 answers
A.It contains a record for every file and directory on the volume
B.Small files can be stored resident within the $MFT record
C.Each record is typically 1024 bytes in size
D.It is located at a fixed position at the beginning of the volume
E.It is only used for directory metadata
AnswersA, B, C

The $MFT is the NTFS master file table, a structured sequence of file record segments acting as the volume's inventory. Every file and directory, including system files and the $MFT itself, occupies at least one record. Each record stores the file's attributes (name, timestamps, data stream pointers, security descriptors) via attribute headers, and the record's number is the low 48 bits of a file's reference, making the table the definitive catalog of all volume items.

Why this answer

Option A is correct because the $MFT in NTFS maintains at least one file record for every file and directory stored on the volume, serving as the central index of all objects. Option B is correct because NTFS supports resident data, meaning small files (and small attributes) can be stored directly inside the $MFT file record rather than in separate clusters, which improves access efficiency. Option C is correct because each $MFT file record is normally 1024 bytes in size, a standard NTFS structure size that holds the record header and its attributes.

Option D is incorrect because the $MFT is not guaranteed to sit at a fixed position at the start of the volume; its location is recorded in the boot sector, and it can be moved or fragmented. Option E is incorrect because the $MFT is not limited to directory metadata; it indexes all files and directories and stores their attributes and, when resident, their data.

Exam trap

The CHFI exam often tests the misconception that the $MFT is at a fixed physical location on the disk, but in reality its location is dynamic and stored in the boot sector, and candidates may also mistakenly think the $MFT only holds directory metadata rather than records for every file and directory.

261
MCQmedium

An email forensic investigator examines a suspicious email and notices the following header: Received: from mail.evil.com (192.168.1.100) by mail.company.com. The DKIM-Signature header fails verification. What does this indicate?

A.The receiving server rejected the email
B.The email is legitimate and was forwarded through a relay
C.The email was sent from a compromised mail server
D.The email may be spoofed or its content altered
AnswerD

A DKIM failure means the message's signature does not verify against the public key published in the claimed sending domain's DNS records. This can occur when an attacker spoofs the domain and sends unsigned or incorrectly signed mail, or when the message body or selected headers were changed after the original signature was applied. Either way, the email is unreliable and may have been tampered with, directly supporting the conclusion that it is potentially spoofed or altered.

Why this answer

A failing DKIM-Signature indicates the email may have been tampered with during transit or was not signed by the claimed domain. This is a strong indicator of email spoofing or alteration.

262
MCQmedium

After collecting digital evidence from a suspect's computer, the forensic examiner creates a forensic image using FTK Imager. The examiner then computes the MD5 hash of the original drive and the image file. Which of the following BEST describes the purpose of this hashing?

A.To verify that the image is an exact bit-for-bit copy of the original.
B.To encrypt the data for secure storage.
C.To index the files for faster searching.
D.To reduce the storage size of the image.
AnswerA

A cryptographic hash algorithm such as SHA-256 produces a fixed-size digest that uniquely identifies the data contents of a file or device. By computing the hash of the original evidence and comparing it with the hash of the acquired image, an investigator can verify the image is an exact bit-for-bit clone. If even a single bit in the image differs, the hash digest will change, providing strong mathematical evidence that no data was altered, added, or lost during acquisition.

Why this answer

Hashing with MD5 (or SHA-1/SHA-256) produces a unique fixed-size digest of the data. By comparing the hash of the original drive to the hash of the forensic image, the examiner can confirm that the image is an exact bit-for-bit copy, ensuring the integrity of the evidence and that no data has been altered during acquisition.

Exam trap

EC-Council often tests the misconception that hashing is used for encryption or compression, leading candidates to confuse integrity verification with confidentiality or storage optimization.

How to eliminate wrong answers

Option B is wrong because hashing is a one-way function that does not encrypt data; encryption (e.g., AES) is used for secure storage, not hashing. Option C is wrong because hashing does not index files; indexing for faster searching is done by tools like Windows Search or forensic suites using file metadata and content parsing. Option D is wrong because hashing does not reduce storage size; forensic images are often compressed using algorithms like EWF (Expert Witness Format) or AFF, but hashing itself adds a small fixed-size digest without affecting the image size.

263
MCQmedium

A forensic examiner needs to acquire an image of a suspect's laptop hard drive. The laptop is running, and the examiner wants to capture volatile data first. According to best practices, which order of steps should the examiner follow?

A.Unplug the laptop, remove the drive, and boot the drive in a forensic workstation.
B.Immediately remove the hard drive, then capture RAM from the drive.
C.Create a full disk image over the network while the laptop is running.
D.Capture volatile data, then shut down normally, remove the drive, and image with a write blocker.
AnswerD

Collecting RAM first preserves evidence of running processes, encryption keys, and open network connections before they vanish at power-down. A normal shutdown lets the OS flush journaled filesystems and VSS snapshots, avoiding the inconsistency caused by hard cuts. Removing the drive afterward and attaching it to a forensic write blocker ensures that all writes are blocked, then tooling such as FTK Imager or dc3dd creates a bit-identical image verified with SHA-256; this is the accepted order of operations in NIST/CHFI guidance.

Why this answer

Forensic best practices mandate capturing volatile data (e.g., RAM, network connections, running processes) first, as this data is lost on power loss. After capturing volatile data, the examiner should perform a graceful shutdown to preserve file system integrity, then remove the drive and acquire a forensic image using a write blocker to prevent any modification to the original evidence.

Exam trap

The trap here is that candidates may think immediate power-off (Option A) preserves the disk state, but they forget that volatile data is lost and an unclean shutdown can corrupt the filesystem, making the image less reliable.

How to eliminate wrong answers

Option A is wrong because unplugging the laptop immediately destroys volatile data (RAM contents, encryption keys, network state) and may cause file system corruption from an unclean shutdown. Option B is wrong because removing the hard drive while the system is running is physically dangerous and technically impossible without first powering off; moreover, capturing RAM from the drive is nonsensical—RAM is volatile memory, not stored on the hard drive. Option C is wrong because creating a full disk image over the network while the laptop is running modifies the system state (network traffic, open files, timestamps) and violates the principle of maintaining evidence integrity; network imaging should only be used when a write-blocked local acquisition is impossible, and even then volatile data must be captured first.

264
MCQmedium

A Linux investigator wants to see all commands run by a user from the bash shell. Which file should be examined?

A./etc/passwd
B./var/log/auth.log
C.~/.bash_history
D./var/log/syslog
AnswerC

~/.bash_history is the per-user history file for the Bash shell, normally loaded in an interactive session and appended to when the shell exits or when history -a is invoked. It directly contains the command lines typed by that user, making it the correct primary source for this investigation. Note that its presence can be disabled or limited by HISTFILE, HISTSIZE, and HISTFILESIZE, and commands may be missing if history was truncated or multiple shells were used.

Why this answer

The ~/.bash_history file stores the command history for each user's bash shell session. When a user runs commands in bash, they are appended to this file (typically in the user's home directory) unless history logging is disabled. Examining this file allows an investigator to see the exact commands executed by that specific user from the bash shell.

Exam trap

EC-Council often tests the distinction between authentication logs (auth.log) and user command history (.bash_history), so candidates may mistakenly choose /var/log/auth.log because it logs user activity, but it only records authentication events, not shell commands.

How to eliminate wrong answers

Option A is wrong because /etc/passwd contains user account information (usernames, UIDs, home directories, shells) but does not log command execution history. Option B is wrong because /var/log/auth.log records authentication-related events such as login attempts, sudo usage, and SSH connections, not the commands run after login. Option D is wrong because /var/log/syslog captures general system messages (kernel, daemon, and application logs) but does not store per-user bash command history.

265
Multi-Selectmedium

A forensic examiner is analyzing an iOS device backup and wants to extract the user's iCloud-related artefacts. Which TWO of the following are typical sources of iCloud artefacts in an iTunes backup?

Select 2 answers
A.AddressBook.db
B.com.apple.accounts.plist
C.Call_history.db
D.Keychain database (keychain-backup.plist)
E.SMS.db
AnswersB, D

This preference plist (located at Library/Preferences/com.apple.accounts.plist in the backup's root domain) is the authoritative store for Accounts framework data, including iCloud (ACAccount). It records the user's Apple ID, account UUIDs, enabled iCloud services (e.g., Mail, Contacts, Calendars), and account status. A forensic examiner should parse this binary plist to identify iCloud account configuration and associated metadata, which directly answers the question.

Why this answer

Option B, com.apple.accounts.plist, is correct because this property list stores the device's configured account information, including iCloud account identifiers and settings, making it a primary source of iCloud-related artefacts in an iTunes backup. Option D, the Keychain database (keychain-backup.plist), is correct because iCloud credentials and tokens are protected within the keychain, and the backup's keychain-backup.plist preserves these secrets for forensic examination. Option A, AddressBook.db, is incorrect because it holds local contact data rather than iCloud account artefacts.

Option C, Call_history.db, is incorrect because it contains call log records, not iCloud configuration or credential data. Option E, SMS.db, is incorrect because it stores text message data, which is unrelated to iCloud account artefacts.

Exam trap

EC-Council often tests the misconception that iCloud artefacts are found in user-facing databases like SMS.db or AddressBook.db, when in fact they reside in system configuration files like plists and the Keychain database.

266
Multi-Selectmedium

An analyst is reviewing firewall logs and sees repeated outbound connections from an internal host to a known malicious IP on port 443. Which TWO network forensic data sources would BEST help determine if data exfiltration occurred?

Select 2 answers
A.Network flow records showing packet sizes and counts
B.Full packet capture (PCAP) of the sessions
C.IDS alerts for signatures
D.Windows security event logs
E.Proxy logs with TLS interception and decrypted content
AnswersB, E

A full packet capture preserves the raw network frames, including the application-layer payload of every session. By reassembling the TCP streams, the analyst can reconstruct the exact data segments transmitted, such as uploaded files, commands, or stolen records. This makes PCAP the only log source that gives complete, packet-level proof of outbound data content, subject to encryption.

Why this answer

Option B (Full packet capture (PCAP) of the sessions) is correct because PCAP records the actual bytes of each TCP session on port 443, allowing an analyst to inspect payloads, TLS handshake metadata, certificate details, and transferred content to confirm whether sensitive data left the host. Option E (Proxy logs with TLS interception and decrypted content) is correct because a TLS-intercepting proxy terminates the outbound TLS connection, decrypts the HTTP/HTTPS traffic, and logs URLs, methods, request/response bodies, and uploaded data, which directly reveals exfiltration over 443. Option A is not among the marked correct answers: flow records only show metadata such as byte/packet counts and timing, which can suggest large transfers but cannot confirm exfiltration content.

Option C is not marked correct because IDS signature alerts indicate suspicious activity but do not by themselves prove that data was exfiltrated. Option D is not marked correct because Windows security event logs focus on host authentication, account, and policy events rather than the contents or destinations of outbound TLS sessions.

Exam trap

The trap here is that candidates often choose NetFlow records (A) thinking they can detect exfiltration by abnormal traffic patterns, but they overlook that without payload inspection, you cannot confirm data was actually stolen; only PCAP and decrypted proxy logs provide the necessary content-level evidence.

267
MCQeasy

Which Windows Registry hive contains user-specific configuration such as MRU lists and UserAssist artifacts?

A.NTUSER.DAT
B.HKLM\SAM
C.SYSTEM
D.HKLM\System
AnswerA

NTUSER.DAT is the per-user registry hive that Windows loads into HKEY_CURRENT_USER when a user logs on. It contains user-specific configuration such as desktop settings, environment variables, application preferences, and network drive mappings, stored in the user's profile directory. This makes it the only hive among the options that directly holds individual user settings.

Why this answer

The NTUSER.DAT file is the registry hive that stores per-user configuration settings, including MRU (Most Recently Used) lists and UserAssist artifacts. When a user logs into a Windows system, this hive is loaded into HKEY_CURRENT_USER (HKCU), making it the primary source for user-specific forensic artifacts such as executed program traces and file access history.

Exam trap

The EC-Council CHFI often tests the misconception that HKLM\System or SYSTEM contains user-specific data, but these hives are system-wide and do not store per-user artifacts like MRU lists or UserAssist entries.

How to eliminate wrong answers

Option B (HKLM\SAM) is wrong because it contains the Security Account Manager database with user account hashes and group memberships, not user-specific MRU lists or UserAssist artifacts. Option C (SYSTEM) is wrong because it is a system-level hive storing hardware configuration, device drivers, and system services, not per-user activity data. Option D (HKLM\System) is wrong because it is the same as the SYSTEM hive loaded under HKEY_LOCAL_MACHINE, which holds system-wide settings and boot configuration, not user-specific forensic artifacts like MRU or UserAssist.

268
MCQeasy

Locard's exchange principle in digital forensics states that:

A.The chain of custody must be documented for all evidence
B.Digital evidence is always stored in the cloud
C.Only the forensic examiner can handle evidence
D.Every contact leaves a trace, and digital evidence is no exception
AnswerD

This is a direct application of Locard's exchange principle to digital media: any interaction with a computer system—opening a file, sending an email, or connecting a peripheral—leaves persistent remnants such as file system timestamps, RAM fragments, or log entries. Even when a user attempts to delete data, copies may survive in slack space, unallocated sectors, or shadow copies, demonstrating that contact with digital evidence leaves traces. This principle underpins digital forensic methodologies for reconstructing user activity.

Why this answer

Locard's exchange principle, originally from forensic science, asserts that whenever two objects come into contact, a transfer of material occurs. In digital forensics, this translates to the fact that digital devices and systems inevitably leave traces of their interactions—such as log entries, metadata, file artifacts, or network packets—making it possible to reconstruct events. Option D correctly captures this core idea that every contact leaves a trace, and digital evidence is no exception.

Exam trap

EC-Council often tests whether candidates confuse procedural concepts (like chain of custody) with the foundational scientific principle of trace evidence transfer, leading them to pick Option A instead of D.

How to eliminate wrong answers

Option A is wrong because the chain of custody is a procedural requirement for maintaining evidence integrity, not a statement of Locard's exchange principle. Option B is wrong because digital evidence can reside on local storage (e.g., hard drives, SSDs, RAM) as well as in the cloud; the principle applies regardless of storage location. Option C is wrong because multiple authorized personnel (e.g., first responders, investigators, analysts) may handle evidence under proper protocols, not exclusively the forensic examiner.

269
MCQeasy

Which of the following principles states that when two objects come into contact, there is a transfer of material between them?

A.The best evidence rule
B.Locard's exchange principle
C.The chain of custody
D.The hearsay rule
AnswerB

Locard's exchange principle states that whenever two objects come into contact, there is a cross-transfer of trace material; in forensic computing, this translates to the persistence of artifacts such as filesystem metadata, unallocated slack space, and cache/log entries even after user attempts at deletion. This principle forms the foundation of digital trace recovery, guiding examiners to preserve volatile memory and hard drive remains because every interaction necessarily leaves some discoverable residue.

Why this answer

Locard's exchange principle is a foundational concept in forensic science stating that whenever two objects come into contact, there is a transfer of material between them. In digital forensics, this principle applies to the transfer of digital artifacts (e.g., file fragments, metadata, network traces) when systems interact, such as when a suspect's device connects to a server or when data is copied between storage media.

Exam trap

The CHFI exam often tests the distinction between legal rules (best evidence, hearsay, chain of custody) and forensic principles (Locard's exchange), so candidates mistakenly choose a legal term that sounds related to evidence handling rather than the actual transfer concept.

How to eliminate wrong answers

Option A is wrong because the best evidence rule is a legal standard requiring original evidence (e.g., original hard drive or bit-for-bit image) rather than copies, not a principle about material transfer upon contact. Option C is wrong because the chain of custody is a procedural documentation process that tracks evidence handling from collection to court presentation, not a principle of material exchange. Option D is wrong because the hearsay rule is an evidentiary rule that excludes out-of-court statements offered for the truth of the matter, not a forensic transfer principle.

270
MCQeasy

Which tool is specifically designed to acquire RAM from a Linux system for forensic analysis?

A.WinPmem
B.LiME
C.EnCase
D.FTK Imager
AnswerB

LiME (Linux Memory Extractor) is a loadable kernel module (LKM) designed specifically to acquire physical memory from Linux systems. By executing in kernel space, LiME can directly address physical memory pages and write them to a block device or transmit them over the network, overcoming the restrictions imposed on /dev/mem and /dev/kmem. It is the standard tool for forensically sound Linux RAM acquisition because it is kernel-version-specific and can be loaded on a live target without rebooting, making it the correct answer for this question.

Why this answer

LiME (Linux Memory Extractor) is a Loadable Kernel Module (LKM) specifically designed to capture volatile memory (RAM) from Linux systems. Unlike other tools that rely on user-space access, LiME operates at the kernel level, ensuring a more complete and forensically sound acquisition of the entire physical address space, including memory regions that user-space tools cannot reach.

Exam trap

The CHFI exam often tests the distinction between cross-platform tools and OS-specific tools, leading candidates to mistakenly choose a familiar Windows tool (like FTK Imager or WinPmem) for a Linux-specific task.

How to eliminate wrong answers

Option A (WinPmem) is wrong because it is a Windows-only memory acquisition tool, part of the Rekall project, and does not support Linux systems. Option C (EnCase) is wrong because it is a commercial forensic suite primarily used for disk imaging and analysis, not a dedicated tool for live RAM acquisition from Linux. Option D (FTK Imager) is wrong because it is a Windows-based forensic imaging tool that can acquire memory on Windows systems but lacks native support for Linux memory acquisition.

271
MCQeasy

In Windows forensics, which artifact is used to track recently executed programs on a per-user basis?

A.Jump lists
B.UserAssist
C.ShellBags
D.Prefetch files
AnswerB

UserAssist is a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist in NTUSER.DAT that logs each per-user program execution, recording a Run Counter and Last Execution Time. The subkeys are GUIDs representing specific application categories, and the values are ROT13 encoded in many Windows versions, which can be easily decoded by forensic tools. Because it is stored per-user in the user hive, it directly ties an executed binary to a specific user account, making it the primary artifact for investigating recently executed programs.

Why this answer

UserAssist is a Windows registry key (under NTUSER.DAT) that records the execution count and last execution time of GUI-based programs for each user. It is specifically designed to track recently executed programs on a per-user basis, making it the correct artifact for this forensic question.

Exam trap

The CHFI exam often tests the distinction between system-wide artifacts (Prefetch) and per-user artifacts (UserAssist), and the trap here is that candidates confuse Prefetch's global execution tracking with UserAssist's user-specific logging.

How to eliminate wrong answers

Option A is wrong because Jump Lists store recently accessed files and application-specific tasks, not a direct log of executed programs. Option C is wrong because ShellBags track folder view settings and window positions, not program execution history. Option D is wrong because Prefetch files track all program launches system-wide, not on a per-user basis, and are stored in C:\Windows\Prefetch.

272
MCQmedium

A security analyst responds to a suspected data breach. The analyst documents the scene, photographs the computer, and labels the cables. Which phase of the forensic investigation process is being performed?

A.Collection
B.First response
C.Examination
D.Reporting
AnswerB

First response is correct because it comprises the initial, time-critical actions: securing the scene, identifying the scope of compromise, preserving volatile evidence (memory, running processes, network sockets), and documenting the exact system state and time. These actions prevent further data loss and ensure that fleeting digital artifacts are not destroyed by powering down or by ongoing attacker activity. Framework guidance such as NIST SP 800-86 and ISO 27037 explicitly places scoping and preservation at the outset, before any formal collection or analysis. Thus, the first step in a suspected breach is the first response, not a later forensic phase.

Why this answer

The actions described—documenting the scene, photographing the computer, and labeling cables—are part of the First Response phase. This phase occurs immediately after an incident is detected and focuses on preserving the integrity of the scene and evidence before any collection or analysis begins. In the CHFI methodology, First Response includes securing the area, creating a detailed log of the initial state, and ensuring no unauthorized changes occur.

Exam trap

EC-Council often tests the distinction between First Response and Collection, where candidates mistakenly think that any hands-on action (like labeling cables) is part of Collection, but Collection specifically refers to the technical acquisition of data, not scene preservation.

How to eliminate wrong answers

Option A is wrong because Collection involves the actual acquisition of digital evidence (e.g., creating bit-for-bit forensic images using tools like dd or FTK Imager), not the initial scene documentation and labeling. Option C is wrong because Examination is the in-depth analysis of acquired data (e.g., file carving, registry analysis, timeline reconstruction), which occurs after evidence has been collected and preserved. Option D is wrong because Reporting is the final phase where findings are documented and presented, not the initial response activities.

273
MCQmedium

During a forensic investigation, an analyst creates a bit-for-bit copy of a suspect's hard drive using the 'dd' command with the following parameters: dd if=/dev/sda of=/evidence/image.dd bs=4k conv=noerror,sync. What is the purpose of 'conv=noerror,sync'?

A.To hash the output image
B.To ensure the command runs with superuser privileges
C.To ignore read errors and pad with zeros
D.To compress the output image
AnswerC

This is correct. conv=noerror instructs dd to continue after encountering read errors, while sync pads each short or errored read block with zeros to maintain the expected block size. Together they ensure the output image file remains complete and exactly sized, even when the source device has bad sectors—making them essential for forensic imaging of damaged media.

Why this answer

'conv=noerror,sync' tells dd to continue reading even when encountering read errors (noerror) and to pad the output with zeros (sync) to maintain the same total size as the original drive. This ensures a complete forensic image is created despite bad sectors, preserving the integrity of the acquisition for analysis.

Exam trap

The CHFI exam often tests the misconception that 'sync' refers to flushing disk caches (like the sync command) rather than its actual function of padding output with null bytes on read errors.

How to eliminate wrong answers

Option A is wrong because hashing is not performed by the conv parameter; hashing requires separate tools like sha256sum or md5sum, or using dd with piped output to a hash function. Option B is wrong because superuser privileges are obtained via sudo or running as root, not through conv parameters; conv controls data conversion, not permissions. Option D is wrong because compression is not a function of conv; compression requires piping dd output through gzip or using a separate tool like dc3dd with built-in compression.

274
Multi-Selecteasy

Which TWO of the following are valid email header fields that can be used to detect email spoofing? (Select 2)

Select 2 answers
A.Subject
B.Received-SPF
C.Content-Type
D.MIME-Version
E.DKIM-Signature
AnswersB, E

The Received-SPF header is specifically designed for authentication and is inserted by the receiving mail system after it evaluates the envelope sender against the publishing domain's SPF policy. The header records the check result (e.g., pass, fail, softfail), the HELO identity, and the client IP, providing traceable evidence of the SPF verdict. This makes Received-SPF a modern, standards-based email header that is valid for verifying and auditing sender authorization.

Why this answer

SPF and DKIM are email authentication mechanisms that help detect spoofing. SPF checks if the sending server is authorized, DKIM verifies the email integrity.

275
MCQeasy

Which of the following BEST defines the chain of custody in digital forensics?

A.The legal authority required to seize evidence
B.The order in which forensic tools are applied to evidence
C.The physical security measures used to store evidence
D.The chronological documentation of evidence handling, transfer, and analysis
AnswerD

Chain of custody records who handled evidence, when, and how it moved between parties. This chronological documentation proves integrity from seizure through analysis, satisfying the requirement to show uncontaminated, unbroken possession of digital evidence in court.

Why this answer

The chain of custody is a formal, chronological record that documents every instance of evidence handling, transfer, and analysis from the moment of seizure through its entire lifecycle. This documentation is critical to prove that evidence has not been tampered with, altered, or corrupted, thereby maintaining its admissibility in legal proceedings under rules such as Federal Rule of Evidence 901.

Exam trap

The CHFI exam often tests the distinction between the physical security of evidence (Option C) and the procedural documentation of its handling (Option D), leading candidates to confuse storage controls with the chain of custody itself.

How to eliminate wrong answers

Option A is wrong because legal authority to seize evidence (e.g., a search warrant or subpoena) is a prerequisite for lawful collection, not the ongoing tracking of evidence after seizure. Option B is wrong because the order of forensic tool application (e.g., using FTK Imager before Autopsy) is a procedural workflow choice, not a documentation requirement for evidentiary integrity. Option C is wrong because physical security measures (e.g., locked safes, access logs) are part of evidence storage controls, but they do not constitute the chronological documentation of handling and transfer that defines chain of custody.

276
MCQmedium

During a forensic investigation, an analyst discovers data hidden in the Host Protected Area (HPA) of a hard drive. Which tool is commonly used to view and access the HPA?

A.PhotoRec
B.fdisk
C.dd
D.hdparm
AnswerD

hdparm issues ATA commands that read the drive's maximum addressable sector count and can unlock or reveal the Host Protected Area, which the BIOS and OS normally hide. It is the standard Linux utility for inspecting and accessing HPA regions during forensic examination.

Why this answer

D (hdparm) is correct because the Host Protected Area (HPA) is a reserved area on an ATA/IDE hard drive that can be accessed and manipulated using ATA commands. The hdparm utility in Linux provides the -N flag to view and change the HPA size, allowing an analyst to detect and access hidden data stored in this region.

Exam trap

The EC-CHFI exam often tests the misconception that dd can directly access the HPA, but dd only reads the logical block addresses visible to the OS, which excludes the HPA until it is explicitly revealed with hdparm.

How to eliminate wrong answers

Option A is wrong because PhotoRec is a file carving tool designed to recover deleted files from raw disk images or partitions; it does not interact with ATA commands or the HPA. Option B is wrong because fdisk is a partition table editor that works with the Master Boot Record (MBR) or GPT, but it cannot see or access the HPA since the HPA exists outside the addressable space reported by the drive. Option C is wrong because dd is a low-level data duplication tool that copies data from a source to a destination; while it can read a disk, it cannot directly access the HPA unless the HPA has been temporarily removed (e.g., with hdparm) because the HPA is hidden from standard read commands.

277
MCQeasy

Which email header field is MOST reliable for identifying the true origin of an email, assuming no header tampering occurred at the initial MTA?

A.Received
B.Message-ID
C.From
D.DKIM-Signature
AnswerA

Received headers are prepended by every SMTP server that handles the message, so the bottom-most (earliest) Received line is added by the first device that accepts the message. This often reflects the original connecting IP address unless the sender controls a relay server that deliberately strips or alters headers. In forensic analysis, this chain is the most reliable source of the true origin.

Why this answer

The 'Received' header is the most reliable for identifying the true origin of an email because each MTA that processes the message adds a new 'Received' header at the top, recording the IP address and timestamp of the previous hop. Assuming no tampering occurred at the initial MTA, the bottommost 'Received' header (the first added) contains the originating IP address of the sender's MTA or client, providing a direct trace back to the source.

Exam trap

EC-CHFI often tests the misconception that the 'From' header is reliable for origin identification, but the trap is that 'From' is easily spoofed and is not validated by SMTP, whereas 'Received' headers are added by each MTA and provide a verifiable chain of custody.

How to eliminate wrong answers

Option B is wrong because the Message-ID header is a unique identifier generated by the sending MUA or MTA, but it does not contain any routing or origin IP information; it is used for threading and deduplication, not for tracing the sender's location. Option C is wrong because the 'From' header is a user-supplied field that can be easily spoofed or forged, as it is not validated by the SMTP protocol (RFC 5321) and only represents the claimed sender, not the actual origin. Option D is wrong because the DKIM-Signature header validates that the email was signed by a domain's private key and has not been altered in transit, but it does not directly reveal the originating IP address or MTA; it only confirms the signing domain's involvement, which may be a third-party service.

278
MCQhard

A forensic analyst finds a suspicious .plist file in /Library/LaunchDaemons/ on a macOS system. The file contains a key "ProgramArguments" with a path to a script in /tmp. Which persistence mechanism does this indicate?

A.Cron job
B.Launch daemon
C.Login item
D.Kernel extension
AnswerB

A LaunchDaemon is defined by a plist placed in either /Library/LaunchDaemons/ (system-wide) or /System/Library/LaunchDaemons/ (Apple-sanctioned system services). These plists contain keys such as ProgramArguments, RunAtLoad, and KeepAlive, and launchd loads them during boot to execute services with root privileges, independent of any user session. A suspicious plist in the Library is therefore most consistent with a LaunchDaemon, especially if it resides in the LaunchDaemons subdirectory and lacks a user-specific component.

Why this answer

The .plist file located in /Library/LaunchDaemons/ with a 'ProgramArguments' key pointing to a script in /tmp is the standard configuration for a launch daemon. Launch daemons are system-wide background processes managed by launchd, and they are defined by plist files in /Library/LaunchDaemons/ (for system-wide daemons) or /System/Library/LaunchDaemons/ (for Apple-provided daemons). The presence of 'ProgramArguments' specifies the executable or script to run, making this a classic launch daemon persistence mechanism.

Exam trap

EC-Council often tests the distinction between launch daemons (system-wide, in /Library/LaunchDaemons/) and launch agents (per-user, in ~/Library/LaunchAgents/), and candidates may confuse the two or incorrectly associate .plist files with cron jobs or login items.

How to eliminate wrong answers

Option A is wrong because cron jobs are configured via crontab files (e.g., /etc/crontab or user crontabs) and do not use .plist files in /Library/LaunchDaemons/; cron is a legacy scheduler, not a launchd-based mechanism. Option C is wrong because login items are managed through System Preferences > Users & Groups or via the com.apple.loginitems.plist file in the user's Library/Preferences, not through a system-level plist in /Library/LaunchDaemons/. Option D is wrong because kernel extensions (.kext) are loaded into the kernel space and are installed in /System/Library/Extensions/ or /Library/Extensions/, not configured via plist files in /Library/LaunchDaemons/.

279
Multi-Selectmedium

Which TWO of the following are methods used to hide data within the NTFS file system?

Select 2 answers
A.USN Journal
B.File slack space
C.Volume Shadow Copy
D.Alternate Data Streams (ADS)
E.Encrypting File System (EFS)
AnswersB, D

File slack space is the gap between the end of a file's logical data and the end of the last allocated cluster in NTFS. This residual space can be filled with arbitrary data without affecting the file's size or visible content, making it invisible in normal directory listings. Since the operating system typically does not overwrite slack space until the cluster is reused, it provides a persistent and covert storage area. This is a classic steganographic method that forensic analysts detect by performing raw sector-level analysis of allocated clusters.

Why this answer

File slack space (B) is correct because NTFS allocates disk space in clusters (typically 4 KB), so a file smaller than its last cluster leaves unused bytes between the logical end-of-file and the end of the allocated cluster; this residual space can be written with hidden data without altering the file's visible content. Alternate Data Streams (ADS) (D) are correct because NTFS supports multiple named data streams per file via the $DATA attribute, allowing extra data to be attached to a file (e.g., 'file.txt:hidden.txt') that standard directory listings and many tools do not display. The USN Journal (A) is a change-logging metadata feature that records file system modifications, not a concealment method.

Volume Shadow Copy (C) creates point-in-time snapshots for backup/recovery, and EFS (E) provides encryption for confidentiality, neither of which is a technique for hiding data inside NTFS structures.

Exam trap

The CHFI exam often tests the distinction between hiding data (e.g., slack space, ADS) and protecting data (e.g., EFS) or system artifacts (e.g., USN Journal, Volume Shadow Copy), so candidates may confuse backup or encryption mechanisms with actual data hiding techniques.

280
MCQmedium

A security analyst reviews firewall logs and sees repeated outbound connections from an internal server to an external IP on port 443. The server is not supposed to initiate outbound connections. Which action should the analyst take FIRST?

A.Block the external IP at the firewall
B.Ignore the traffic as it is encrypted
C.Disable the server's network connection
D.Investigate the server for signs of compromise
AnswerD

Investigating the server for signs of compromise is the appropriate first response to repeated connections, as it determines whether the external IP's activity has successfully exploited a vulnerability. This includes checking for unauthorized processes, anomalous registry entries, new user accounts, scheduled tasks, modified binaries, and indicators of compromise (IOCs) such as unusual outbound connections or file hashes. Establishing a baseline and correlating firewall logs with endpoint logs enables the analyst to identify the attack vector, scope, and appropriate remediation steps.

Why this answer

The server is exhibiting anomalous behavior by initiating outbound connections on port 443 (HTTPS) when it should not be doing so. This is a classic indicator of a potential compromise, such as a command-and-control (C2) callback or data exfiltration. The first priority is to investigate the server for signs of compromise to understand the scope and nature of the threat before taking any disruptive action.

Exam trap

The trap here is that candidates often choose to block the IP immediately (Option A) or disable the server (Option C) without first investigating, failing to recognize that the CHFI methodology prioritizes evidence preservation and root cause analysis over immediate containment.

How to eliminate wrong answers

Option A is wrong because blindly blocking the external IP at the firewall may disrupt legitimate traffic if the IP is shared or used by other services, and it does not address the root cause—the server may still be compromised and could use a different IP or port. Option B is wrong because encrypted traffic (TLS/SSL on port 443) can still be malicious; encryption does not imply safety, and the analyst must inspect the traffic using SSL interception or endpoint forensics. Option C is wrong because disabling the server's network connection is a reactive measure that could cause business disruption and destroy volatile evidence (e.g., active network connections, memory artifacts) needed for forensic analysis.

281
MCQhard

A forensic examiner needs to analyze the contents of a Windows prefetch file (.pf) to determine the last execution time of an application. Which tool would BEST accomplish this task?

A.prefetch.exe (built‑in Windows tool)
B.ShellBags Explorer
C.PECmd
D.JumpLister
AnswerC

PECmd (Prefetch Explorer Command-Line) is a free and widely accepted tool by Eric Zimmerman that parses Windows Prefetch (.pf) files. It extracts the executable's last run time, run count, and the list of referenced files and DLLs, exporting the results to CSV, HTML, or JSON for further triage. Because it stabilizes and standardizes prefetch decoding, it is the recommended option when an examiner needs to prove which binaries executed on a system.

Why this answer

PECmd (Prefetch Explorer Command-line) is a dedicated forensic tool from Eric Zimmerman's suite designed specifically to parse Windows prefetch files (.pf). It extracts detailed metadata including the last execution time, run count, and referenced files, making it the best choice for this task. Built-in Windows tools do not provide a 'prefetch.exe' utility, and other options like ShellBags Explorer or JumpLister target different artifacts (registry shell bags and jump lists, respectively).

Exam trap

The trap here is that candidates may assume a built-in Windows tool named 'prefetch.exe' exists or confuse prefetch analysis with other Windows forensic artifacts like shell bags or jump lists, leading them to pick a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because there is no built-in Windows tool named 'prefetch.exe'; Windows does not ship a command-line utility for parsing prefetch files, and the system's own prefetching mechanism is managed by the operating system without a user-facing executable for forensic analysis. Option B is wrong because ShellBags Explorer is designed to parse registry shell bag data (MRU lists for folder views), not prefetch files; it cannot extract execution timestamps from .pf files. Option D is wrong because JumpLister is used to parse Windows jump lists (stored in %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations), which track recently opened files via the taskbar, not application execution times stored in prefetch files.

282
MCQeasy

Which principle states that every contact leaves a trace?

A.Locard's exchange principle
B.Chain of custody
C.Best evidence rule
D.Hearsay rule
AnswerA

Locard's exchange principle, articulated by French forensic scientist Edmond Locard, holds that every contact between a person and an environment results in a mutual transfer of material. This foundational axiom means a perpetrator both leaves trace evidence at a scene and carries trace evidence away, enabling forensic examiners to link individuals to locations. It is the scientific basis for analyzing fibers, hair, glass, soil, biological fluids, and even digital residues.

Why this answer

Locard's exchange principle is the foundational forensic concept stating that whenever two objects come into contact, there is a transfer of material between them. In computer forensics, this means that digital activity—such as accessing a file, sending a packet, or connecting to a network—inevitably leaves traces in logs, memory, registry entries, or file metadata. This principle underpins the entire discipline of digital evidence recovery.

Exam trap

EC-Council often tests the distinction between a forensic principle (Locard's) and legal or procedural rules (chain of custody, best evidence, hearsay), so candidates mistakenly select a legal term that sounds related to evidence handling rather than the core scientific concept.

How to eliminate wrong answers

Option B (Chain of custody) is wrong because it is a procedural documentation process that tracks the handling of evidence from collection to court presentation, not a principle about trace evidence. Option C (Best evidence rule) is wrong because it is a legal rule requiring original evidence (e.g., original hard drive rather than a copy) to be presented in court, not a statement about contact leaving traces. Option D (Hearsay rule) is wrong because it is a legal rule excluding out-of-court statements offered for the truth of the matter, unrelated to physical or digital trace evidence.

283
Multi-Selecthard

Which THREE of the following are indicators of a webshell on a compromised web server? (Select THREE.)

Select 3 answers
A.Multiple failed login attempts in auth.log
B.Presence of system commands in web server error logs
C.Unusual files with .asp, .php, or .jsp extensions in web directories
D.Outbound connections from the web server to suspicious IP addresses
E.High CPU usage from the web server process
AnswersB, C, D

Webshells often invoke server-side commands through PHP functions like system(), exec(), or shell_exec() with attacker-supplied input. When these commands produce errors or partial output that is not sanitized, the web server's error log may capture snippets of OS commands such as id, whoami, ls -la, or cat /etc/passwd. A properly functioning application should never intentionally write raw system command output to error logs, so their presence is a strong sign of webshell activity.

Why this answer

Option B is correct because webshells typically execute operating-system commands (e.g., cmd.exe, /bin/sh, whoami, net user) that get recorded in web server error logs when the shell's input or output triggers errors, making such command strings a strong indicator of compromise. Option C is correct because attackers drop webshell files with executable web extensions such as .asp, .php, or .jsp into web-accessible directories (often with obfuscated or unusual names) so they can be invoked remotely over HTTP. Option D is correct because a webshell commonly initiates outbound connections from the web server to attacker-controlled command-and-control or exfiltration IP addresses, which is anomalous for a server that should mainly receive inbound HTTP requests.

Option A is not specific to webshells, since multiple failed logins in auth.log indicate brute-force or credential attacks against SSH or other services rather than a web-based backdoor. Option E is also not specific, because high CPU usage from the web server process can result from legitimate traffic spikes, misconfiguration, or other malware, and is not a distinctive webshell indicator.

Exam trap

EC-Council often tests the distinction between generic performance anomalies (like high CPU) and specific forensic artifacts (like command strings in logs), leading candidates to over-select Option E as a webshell indicator when it is actually a non-specific symptom.

284
MCQmedium

A forensic analyst is examining a Windows system for evidence of a program that runs automatically every time the system starts. Which registry key is commonly used to achieve persistence via the 'Run' key?

A.HKLM\SAM\SAM
B.HKLM\Software\Microsoft\Windows\CurrentVersion\Run
C.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
D.HKLM\SYSTEM\CurrentControlSet\Services
AnswerB

This key is the per-machine Run key and is one of the classic autostart locations processed when a user logs on. Each value under it is a command-line string whose data is the full path or command used to start a program, and the system executes all such entries automatically at logon. Because entries here apply to every interactive user and require no special privileges to write in some use cases, this is a common persistence mechanism and the correct registry location to inspect for automatic startup programs.

Why this answer

The 'Run' key at HKLM\Software\Microsoft\Windows\CurrentVersion\Run is the standard registry location used by legitimate software and malware alike to execute a program automatically at every system startup. This key stores values that point to executable paths, and Windows’ Winlogon process reads these values during boot to launch the specified programs. It is a primary persistence mechanism in Windows forensics.

Exam trap

CHFI often tests the distinction between the 'Run' key and the 'Services' key (option D), as candidates may confuse auto-start services with the simpler 'Run' registry persistence mechanism.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM contains the Security Account Manager (SAM) database with hashed user passwords, not startup program configurations. Option C is wrong because HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon stores settings for the Winlogon process (e.g., Userinit, Shell) and is not the standard 'Run' key for user-level or machine-level auto-start programs. Option D is wrong because HKLM\SYSTEM\CurrentControlSet\Services holds service definitions and their start types (e.g., auto-start services), but it is not the 'Run' key; services are a separate persistence mechanism managed by the Service Control Manager (SCM).

285
MCQhard

A security analyst runs a dynamic analysis of a suspected malware sample using Cuckoo Sandbox. The report shows that the sample created a mutex named 'Global\MyMaliciousMutex', added a registry run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and attempted to communicate with an IP address 185.10.68.12 on port 443. Which of the following is the BEST immediate indicator of compromise (IoC) to share with the threat intelligence team?

A.The registry run key location
B.The sample's MD5 hash
C.The IP address 185.10.68.12
D.The mutex name 'Global\MyMaliciousMutex'
AnswerC

The IP address 185.10.68.12 is the command-and-control endpoint that the malware dials out to, so it is the most immediately actionable indicator for containment. An analyst can block this IP at the firewall or proxy, add it to a threat intelligence feed, and alert on any matching egress traffic. This directly severs the malware's ability to receive commands or exfiltrate data, unlike host-based artifacts. In a live engagement, isolating this network indicator is a critical first step before deeper host remediation.

Why this answer

The IP address 185.10.68.12 on port 443 is the best immediate indicator of compromise (IoC) because it is a network-based artifact that can be directly blocked at the firewall or monitored for outbound connections. Network-based IoCs are often prioritized in threat intelligence sharing because they enable proactive perimeter defense and are actionable across multiple systems, unlike host-based artifacts (mutexes, registry keys) that require endpoint-level detection. Additionally, the IP address is independent of file hashes and can be used to detect or block communications even when the malware binary changes.

Exam trap

The CHFI exam often tests the concept that network-based IoCs (IP addresses, domains) are considered more immediate and actionable for threat intelligence sharing than host-based artifacts (mutexes, registry keys) because they enable perimeter defense and are less dependent on specific file hashes that change with each variant.

How to eliminate wrong answers

Option A is wrong because the registry run key location (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is a standard persistence mechanism used by many legitimate applications, making it a weak IoC without additional context; it is not unique to this malware and can be easily changed by the attacker. Option B is wrong because the sample's MD5 hash is a file-based hash that can be trivially modified by recompiling or packing the malware, and it is not immediately actionable for network defense or threat intelligence sharing compared to a network indicator. Option D is wrong because the mutex name 'Global\MyMaliciousMutex' is a host-based artifact that can be easily altered by the malware author in a new variant, and it is not directly observable from network traffic or useful for blocking at the perimeter.

286
MCQmedium

A forensic analyst is investigating a Windows system for evidence of USB device usage. Which registry key is MOST useful for determining the first time a USB device was connected and its serial number?

A.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
B.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellBags
D.HKLM\SYSTEM\CurrentControlSet\Enum\USB
AnswerA

This is the authoritative artifact for USB mass storage device forensics. Each time a USB drive or external storage device is attached, Windows enumerates it under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, creating a subkey whose name contains the device instance ID, vendor, product, revision, and often the unique serial number. The LastWrite time of these subkeys reflects when the device was installed/configured, enabling an examiner to reconstruct a timeline of device connections and identify the specific physical drive by its serial number.

Why this answer

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum stores a subkey for each USB mass storage device that has ever been connected to the system. Each subkey is named with the device's serial number, and its creation timestamp reflects the first time the device was enumerated (i.e., first connected). This makes it the definitive source for both the serial number and the initial connection time of a USB device.

Exam trap

EC-Council often tests whether candidates confuse the generic USB hub enumeration key (USB) with the mass storage device-specific key (USBSTOR), leading them to pick Option D instead of A.

How to eliminate wrong answers

Option B is wrong because MountPoints2 stores user-specific drive letter mappings and volume GUIDs, not serial numbers or first-connection timestamps for USB devices. Option C is wrong because ShellBags tracks folder view settings and window positions for Explorer, not USB device enumeration or serial numbers. Option D is wrong because the USB key under Enum contains generic USB hub and controller descriptors, not the USB mass storage device instances with serial numbers that USBSTOR provides.

287
MCQhard

An investigator creates a forensic image using dcfldd with the following command: dcfldd if=/dev/sdb of=image.dd hash=sha256 hashwindow=10M hashlog=hash.txt. What is the effect of the 'hashwindow=10M' parameter?

A.It divides the output into 10 MB chunks and hashes each chunk, logging the results
B.It sets the input buffer size to 10 MB for performance
C.It verifies the hash of the input device in 10 MB windows before copying
D.It causes the tool to hash the entire image only after completion
AnswerA

The hashwindow parameter in dcfldd instructs the tool to compute a cryptographic hash (e.g., MD5 or SHA-256) for every 10 MiB segment of the data stream as it copies, logging each segment's hash to a designated hash log. This piecewise hashing enables examiners to verify specific portions of an acquired image independently rather than relying solely on a single hash for the entire output, which is especially critical for very large forensic images. It is specified alongside hash= and hashlog= options to produce a record of per-window hashes during acquisition.

Why this answer

The `hashwindow=10M` parameter in dcfldd instructs the tool to compute a SHA-256 hash for every 10 MB segment (window) of the input data as it is being copied, and then log each segment's hash to the specified hashlog file. This allows the investigator to verify the integrity of individual chunks of the forensic image, which is useful for detecting corruption or tampering in specific regions of the image without rehashing the entire file.

Exam trap

The CHFI exam often tests the distinction between 'hashing during acquisition' and 'hashing after completion' — the trap here is that candidates may assume `hashwindow` is for performance tuning (buffer size) or for pre-copy verification, rather than understanding it as a segmentation feature for incremental hashing and logging.

How to eliminate wrong answers

Option B is wrong because `hashwindow` does not control the input buffer size; dcfldd uses separate parameters (e.g., `bs=`) for block size and buffer settings, and `hashwindow` is specifically for segment-based hashing. Option C is wrong because `hashwindow` does not cause the tool to verify the hash of the input device before copying; it computes hashes of the output chunks during the copy process, not as a pre-copy verification step. Option D is wrong because `hashwindow=10M` causes hashing to occur incrementally during the imaging process, not only after completion; the `hashlog` file is populated as each 10 MB window is processed.

288
Multi-Selectmedium

A forensic analyst is examining a Windows system for evidence of USB device usage. Which TWO registry locations are known to store USB device history?

Select 2 answers
A.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Prefetch
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E.HKLM\SAM\SAM\Domains\Account\Users
AnswersA, B

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the Windows Plug and Play device enumeration tree for USB mass storage devices, recording every device instance that has ever been connected to the system. Each subkey is named with the device's vendor, product, and unique serial number, and it persists even after the device is unplugged, making it a critical artifact for proving a specific USB drive was attached. Forensic examiners use this key to identify not only the make/model but also the serial number and, when correlated with SetupAPI logs, the first/last connection times.

Why this answer

Option A is correct because HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the primary registry key where Windows records USB mass storage devices that have been connected, storing device instance IDs, serial numbers, and vendor/product information used to prove USB storage usage. Option B is correct because HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 tracks per-user mounted volumes, including USB drives, by recording volume GUIDs and drive-letter mappings that correlate a device to a specific user account. Option C is incorrect because the Prefetch registry path does not exist as a USB history store; prefetch execution evidence resides in C:\Windows\Prefetch as .pf files, not in that registry location.

Option D is incorrect because HKCU\...\Run is an autostart persistence key for programs launched at logon, not a record of USB device connections. Option E is incorrect because HKLM\SAM\...\Users stores local account and credential-related data (such as RID-based user records and password hashes), not USB device history.

Exam trap

EC-Council often tests the distinction between system-wide (HKLM) and user-specific (HKCU) registry hives, and candidates mistakenly think only one location stores USB history, overlooking that both USBSTOR and MountPoints2 are valid and complementary sources.

289
MCQmedium

A forensic analyst needs to create a timeline of file system activity from a disk image. Which tool is specifically designed for this purpose and can parse various artifacts such as registry, prefetch, and log files?

A.Wireshark
B.Volatility
C.Plaso (log2timeline)
D.FTK Imager
AnswerC

Plaso, also known as log2timeline, is the correct tool because it is purpose-built for constructing super timelines from diverse forensic artifacts, including file system metadata, event logs, and application logs. It ingests disk images or directories, parses time-stamped evidence using modular parsers, and outputs a unified, correlated timeline in SQLite or bodyfile format. Unlike single-purpose tools, Plaso correlates timestamps from multiple sources, enabling robust reconstruction of file system activity such as creation, modification, and access events.

Why this answer

Plaso (log2timeline) is the correct tool because it is specifically designed to create super timelines of file system activity from disk images. It parses a wide range of artifacts including the Windows Registry, Prefetch files, event logs, and other log files, correlating timestamps to reconstruct a chronological sequence of system events.

Exam trap

EC-Council often tests the distinction between acquisition tools (FTK Imager), analysis tools for specific artifacts (Volatility for memory, Wireshark for network), and comprehensive timeline tools (Plaso), so the trap here is assuming a general-purpose tool like FTK Imager can perform artifact parsing and timeline creation when it is only for imaging and preview.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects live network traffic (e.g., TCP/IP packets), not a tool for parsing file system artifacts or building timelines from disk images. Option B is wrong because Volatility is a memory forensics framework used to analyze RAM dumps (volatile memory) for processes, network connections, and kernel objects, not for parsing file system artifacts like the registry or prefetch files from a disk image. Option D is wrong because FTK Imager is a disk imaging and preview tool used to acquire and view disk images, but it does not parse artifacts or generate timelines; it is a data acquisition tool, not an analysis tool for timeline creation.

290
MCQeasy

During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?

A.Immediately power off the computer to prevent data alteration
B.Begin collecting data by copying all files to an external drive
C.Disconnect the computer from the network and take a photograph of the screen
D.Ask the user to save their work and then shut down normally
AnswerC

Disconnecting the network cable isolates the machine from live remote control, stops exfiltration, and prevents a remote actor from remotely wiping or modifying the evidence. Taking a photograph of the screen before any interaction preserves the visible state of running applications, chat windows, encryption banners, and console output, which would be lost immediately upon shutdown or further user activity. This staged approach follows the order of volatility while simultaneously documenting the live scene.

Why this answer

Securing the scene and documenting everything is the first priority to preserve evidence and ensure chain of custody. Powering off or accessing the system without proper documentation can lead to evidence spoliation.

291
MCQeasy

In network forensics, which tool is commonly used to analyze and visualize NetFlow data to identify network traffic patterns?

A.Wireshark
B.Splunk
C.Nmap
D.SolarWinds NetFlow Traffic Analyzer
AnswerD

SolarWinds NetFlow Traffic Analyzer is a purpose-built network flow collector that receives NetFlow, IPFIX, sFlow, and J-Flow data directly from routers and switches, exporting the records into a SQL database for long-term forensic retention. It computes bandwidth utilization per interface, identifies top talkers and protocols (using Cisco NBAR), and performs baseline anomaly detection to flag suspicious traffic patterns. Because it ingests flow metadata instead of individual packets, it can scale to large enterprise environments and answer forensic questions about which endpoints communicated, for how long, and at what volume — exactly the capability the question requires.

Why this answer

SolarWinds NetFlow Traffic Analyzer (NTA) is specifically designed to collect, analyze, and visualize NetFlow data (and other flow protocols like sFlow, IPFIX, and J-Flow) to identify network traffic patterns, bandwidth usage, and top talkers. Unlike packet-level tools, NTA works on flow records exported by routers and switches, making it ideal for high-level traffic pattern analysis in network forensics.

Exam trap

In network forensics, it is important to distinguish between packet-level analysis (e.g., Wireshark) and flow-level analysis (e.g., NetFlow analyzers). Candidates often mistakenly choose Wireshark because it is a well-known forensic tool, but it cannot natively handle NetFlow data without conversion or plugins.

How to eliminate wrong answers

Option A is wrong because Wireshark is a packet analyzer that captures and inspects individual packets at the frame level, not flow-level data like NetFlow; it cannot natively parse or visualize NetFlow exports without additional plugins or conversion. Option B is wrong because Splunk is a general-purpose log and event management platform that can ingest NetFlow data via add-ons, but it is not a dedicated NetFlow analyzer and requires significant configuration to visualize traffic patterns; the question asks for a tool 'commonly used to analyze and visualize NetFlow data,' and Splunk is not the primary or most direct tool for that purpose. Option C is wrong because Nmap is a network scanning and discovery tool used for port scanning, OS detection, and service enumeration; it does not collect or analyze NetFlow data at all.

292
MCQeasy

Which of the following is a unique challenge in cloud forensics compared to traditional digital forensics?

A.Encryption of data at rest
B.Lack of network connectivity
C.Inability to acquire disk images
D.Multi-tenancy and data isolation
AnswerD

Multi-tenancy is a defining architectural property of cloud computing, where multiple customers share the same physical hardware and storage. This creates a unique forensic challenge: isolating a target tenant's evidence without exposing or processing co-tenant data, which may be subject to privacy and legal protections. Investigators must use careful acquisition methods, such as provider-supported volume snapshots, and may need court orders tailored to prevent data leakage. The co-mingling of data across tenants is a challenge with no direct analog in traditional single-owner digital forensics.

Why this answer

In cloud forensics, multi-tenancy and data isolation present a unique challenge because multiple customers share the same physical infrastructure, and forensic investigators must ensure that data acquisition from one tenant does not inadvertently expose or contaminate another tenant's data. This requires careful coordination with the cloud provider to isolate logical boundaries, often using techniques like snapshot-based acquisition or API-driven evidence collection, which are not typical in traditional single-owner digital forensics.

Exam trap

The EC-Council CHFI exam often tests the misconception that encryption is the primary cloud forensic challenge, but the real unique issue is multi-tenancy and data isolation due to shared infrastructure and legal/privacy boundaries.

How to eliminate wrong answers

Option A is wrong because encryption of data at rest is a challenge in both cloud and traditional forensics; it is not unique to the cloud. Option B is wrong because lack of network connectivity is a general forensic challenge that can occur in any environment, not specific to cloud forensics. Option C is wrong because inability to acquire disk images is not a defining challenge; cloud forensics can acquire disk images via provider APIs or snapshots, though the process differs from physical acquisition.

293
MCQmedium

A forensic analyst needs to collect evidence from a running Windows system without altering the system state. Which tool should they use to acquire volatile memory?

A.Wireshark
B.dd
C.DumpIt
D.Tableau write blocker
AnswerC

DumpIt is a memory acquisition tool for Windows that creates a raw physical memory dump (typically a .raw or .bin file) from a running system. It uses undocumented Windows kernel structures and the \\.\PhysicalMemory interface to read RAM without requiring a full installation, making it ideal for incident response. DumpIt preserves volatile evidence such as running processes, open network connections, and loaded kernel modules, which is exactly what the analyst needs.

Why this answer

DumpIt is a lightweight memory acquisition tool designed specifically for capturing the contents of volatile memory (RAM) on a running Windows system. It minimizes interaction with the system to avoid altering the memory state, making it ideal for forensic collection of live evidence.

Exam trap

EC-Council often tests the distinction between volatile memory acquisition and disk imaging, leading candidates to confuse tools like dd (for disks) with memory-specific tools like DumpIt.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting network traffic, not for acquiring volatile memory from a running system. Option B is wrong because dd is a disk imaging tool typically used for creating bit-for-bit copies of storage devices, not for capturing RAM contents, and it does not handle Windows memory structures natively. Option D is wrong because a Tableau write blocker is a hardware device used to prevent writes to storage media during acquisition, but it does not acquire volatile memory; it is used for forensic imaging of hard drives or SSDs.

294
MCQeasy

An investigator needs to recover deleted files from a USB drive formatted with FAT32. Which of the following techniques would be most effective, assuming the files have not been overwritten?

A.Check the journal for recent changes
B.Examine the FAT for unallocated clusters and reconstruct files
C.Analyze the $MFT for orphaned entries
D.Use the 'foremost' tool to carve based on file signatures
AnswerB

Correct. FAT32's File Allocation Table stores cluster chains. Deleted files have their FAT entries zeroed but data clusters remain. Examining the FAT for unallocated clusters and reconstructing from the directory entry's starting cluster and size allows recovery if not overwritten.

Why this answer

FAT32 does not have a journal (eliminating A). The Master File Table ($MFT) is used by NTFS, not FAT32 (eliminating C). While file carving with tools like 'foremost' (D) can recover files based on signatures, it is less effective for deleted files on FAT32 because it may fail to recover fragmented files and does not leverage the file system's own structure.

The most effective technique is to examine the File Allocation Table (FAT) for unallocated clusters and reconstruct the files from the directory entry's starting cluster and size (B), assuming the clusters have not been overwritten. This uses the file system metadata to directly locate the file's data.

Exam trap

A common trap is to assume that file carving (D) is always the best method. However, when the file system is intact and the metadata is available, analyzing the FAT provides a more reliable and efficient recovery. Also, note that FAT32 lacks a journal (A) and does not use $MFT (C).

How to eliminate wrong answers

Option A is wrong because FAT32 does not have a journal; journaling is a feature of NTFS (via $LogFile) and ext3/4, not FAT32. Option C is wrong because the $MFT (Master File Table) is a component of NTFS, not FAT32; FAT32 uses directory entries and the FAT, not an MFT. Option D is wrong because while 'foremost' is a valid file carving tool that works on any file system by searching for file signatures (headers/footers), it is a generic data carving technique that does not leverage the file system's metadata (like the FAT) to reconstruct files; it is less reliable for fragmented files and does not use the FAT's cluster chain information, making it less effective than option B for FAT32 recovery.

295
MCQeasy

A forensic analyst needs to acquire RAM from a live Linux system for memory analysis. Which tool is specifically designed for this purpose and can capture memory without rebooting?

A.FTK Imager
B.Volatility
C.LiME
D.dd
AnswerC

LiME (Linux Memory Extractor) is a loadable kernel module (LKM) purpose-built for capturing volatile memory from live Linux systems. It uses kernel APIs to traverse physical memory ranges, handles memory holes properly, and can write to a raw or LiME-format image file on local storage or stream it over TCP to a forensic server. Because it runs in kernel mode, it provides a forensically sound and consistent snapshot, making it the de facto standard for Linux RAM acquisition.

Why this answer

LiME (Linux Memory Extractor) is specifically designed to capture volatile memory from live Linux systems without requiring a reboot. It loads a kernel module that safely dumps RAM contents to a file, preserving the memory image for forensic analysis. Unlike dd, LiME handles memory-mapped I/O and avoids corrupting the system state during acquisition.

Exam trap

EC-Council often tests the distinction between acquisition tools (like LiME) and analysis tools (like Volatility), trapping candidates who confuse the role of Volatility as a memory capture tool rather than a post-acquisition analysis framework.

How to eliminate wrong answers

Option A is wrong because FTK Imager is a Windows-based forensic imaging tool that does not natively support live Linux memory acquisition; it can acquire disk images but not RAM from a running Linux system. Option B is wrong because Volatility is a memory analysis framework used to examine memory dumps, not a tool for capturing memory; it requires an existing memory image as input. Option D is wrong because dd is a generic disk cloning tool that can read from /dev/mem or /dev/crash, but it is not designed for safe, live memory acquisition on modern Linux systems—it may cause system instability or incomplete captures due to kernel memory protections and lacks the ability to handle memory-mapped regions properly.

296
MCQmedium

A security analyst is reviewing firewall logs and notices repeated connection attempts from an internal IP to an external server on TCP port 4444. The internal host is a web server. What is the MOST likely explanation?

A.The web server is serving HTTPS traffic on port 4444
B.The web server is performing DNS queries
C.The web server is being scanned for open ports
D.The web server has a reverse shell connection to a command-and-control server
AnswerD

An outbound TCP connection from a compromised web server to a single external IP on a non-standard high port such as 4444 is a classic reverse-shell indicator. Because the server initiates the connection, it can evade typical inbound firewall restrictions, allowing an attacker to receive a shell session through a listener on the command-and-control host. The repeated nature of the connections suggests beaconing for instructions, a hallmark of C2 communication.

Why this answer

Repeated outbound connections from an internal web server to an external server on TCP port 4444 strongly indicate a reverse shell, which is a common technique used by malware to establish command-and-control (C2) communication. Unlike a standard client-server model, the internal host initiates the connection to bypass firewalls that block inbound traffic, and port 4444 is frequently associated with Metasploit's default reverse shell payload (e.g., meterpreter). This behavior is anomalous for a web server, which typically serves HTTP/HTTPS on ports 80/443 and does not initiate persistent outbound connections to arbitrary external IPs on non-standard ports.

Exam trap

The key trap here is that candidates see 'connection attempts' and assume it is an inbound scan (Option C), but the question specifies the internal IP is the source, meaning the web server is initiating the connection, which is the hallmark of a reverse shell or C2 beacon. In CHFI, understanding traffic direction and common C2 port usage is critical.

How to eliminate wrong answers

Option A is wrong because HTTPS traffic is served on TCP port 443 by default, not 4444; while a server could be configured to use a non-standard port, a web server serving HTTPS would not repeatedly initiate outbound connections to an external server—it would listen for inbound connections. Option B is wrong because DNS queries use UDP port 53 (or TCP port 53 for zone transfers), not TCP port 4444, and DNS traffic is typically ephemeral and not characterized by repeated connection attempts to a single external IP. Option C is wrong because a port scan would originate from an external source targeting the internal web server, not from the internal web server to an external server; the log shows outbound connections from the internal host, indicating it is the initiator, not the target of a scan.

297
Multi-Selectmedium

A malware analyst is performing static analysis on a suspicious PE file. Which TWO of the following are examples of anti-forensic techniques that the malware might use to hinder analysis? (Select TWO.)

Select 2 answers
A.Using TLS encryption for network communication
B.Packing or obfuscating the malicious code
C.Creating registry keys for persistence
D.Writing temporary files to the %TEMP% directory
E.Timestomping to modify file creation and modification timestamps
AnswersB, E

Packing or obfuscating the malicious code is a core anti-forensic technique because it compresses, encrypts, or otherwise transforms the executable's original machine code, rendering it opaque to static signature-based detection and manual reverse engineering. The malware's true payload is only revealed at runtime when it unpacks itself in memory, forcing analysts to use dynamic analysis or memory forensics. This deliberate obfuscation directly impedes the malware analyst's ability to inspect the code, making it the correct answer.

Why this answer

Option B is correct because packing or obfuscating the malicious code (e.g., with UPX, Themida, or custom crypter) hides the true code and strings from static analysis tools, forcing the analyst to unpack or emulate before meaningful inspection is possible. Option E is correct because timestomping deliberately alters a file's $STANDARD_INFORMATION and/or $FILE_NAME timestamps (creation, modification, access, MFT entry change) to mislead investigators about when the malware was placed or executed, which is a classic anti-forensic technique. Option A is not an anti-forensic technique against static analysis; TLS is simply an encrypted transport that hinders network traffic inspection, not examination of the PE file itself.

Option C is a persistence mechanism (e.g., Run keys, Services), not an anti-forensic measure. Option D is normal runtime behavior for many programs and does not specifically hinder static analysis of the PE file.

Exam trap

EC-Council often tests the distinction between anti-forensic techniques (which actively hinder analysis) and common malware behaviors (which are forensic artifacts themselves), so candidates mistakenly select persistence or file-writing options as anti-forensic when they are actually evidence-creating actions.

298
MCQeasy

During an iOS forensics investigation, an examiner wants to extract call history records from an iPhone backup. Which SQLite database file should be examined?

A.SMS.db
B.AddressBook.db
C.call_history.db
D.Calendar.sqlitedb
AnswerC

call_history.db is the correct source for call records on iOS devices. This SQLite database, commonly found under /private/var/mobile/Library/CallHistoryDB/, stores recent calls with fields such as the caller/called number, timestamp, duration, and call status (incoming, outgoing, missed). The database is periodically flushed or pruned, but deleted records may remain in free pages or the WAL file until overwritten. Its schema directly answers the examiner's question about call history.

Why this answer

In iOS forensics, call history records are stored in the SQLite database file named 'call_history.db' (or 'CallHistory.storedata' in newer iOS versions). This database contains tables such as 'call' and 'ZCALLRECORD' that log incoming, outgoing, and missed calls along with timestamps and durations. Examining this file directly from an iTunes backup or device extraction provides the examiner with the complete call log.

Exam trap

EC-Council often tests the specific naming of iOS forensic artifacts; the trap here is that candidates confuse 'SMS.db' (which stores messages) with call logs, or assume call history is stored in a more generic database like 'AddressBook.db'.

How to eliminate wrong answers

Option A is wrong because SMS.db stores SMS and iMessage conversations, not call history records. Option B is wrong because AddressBook.db (or Contacts.sqlitedb) stores contact names, phone numbers, and email addresses, but does not contain call logs. Option D is wrong because Calendar.sqlitedb stores calendar events and reminders, not telephony call records.

299
MCQhard

A forensic lab receives a sealed evidence bag containing a laptop seized during an investigation. The chain-of-custody form shows the bag was sealed at the scene by an officer. Before beginning analysis, the examiner must document the evidence. Which action best preserves the chain of custody at this point?

A.Ask the officer who sealed the bag to re-seal it in the lab before analysis
B.Immediately open the bag and begin imaging to save time
C.Store the bag in the evidence locker and delay documentation until analysis begins
D.Photograph the sealed bag and its seal number, then record the date, time, and examiner name before opening
AnswerD

Photographing the sealed bag and recording the seal number, date, time, and examiner name creates an auditable record of the bag's condition at receipt. This documentation links the seal applied at the scene to the examiner who opens it, preserving continuity. It is the expected first step before any analysis and supports later testimony about evidence integrity.

Why this answer

Chain of custody requires documenting the evidence's condition at every transfer. Photographing the sealed bag, recording the seal number, and logging the date, time, and examiner name before opening establishes an unbroken record from seizure to analysis. Skipping, delaying, or re-sealing without documentation creates gaps that weaken admissibility.

Exam trap

The trap here is treating chain of custody as a formality that can be completed later, when in fact the receipt documentation is the critical link that proves the evidence was not altered.

300
MCQhard

During a forensic examination of a solid-state drive (SSD), you notice that files deleted several months ago cannot be recovered using traditional file carving tools. Which SSD feature is MOST likely preventing recovery?

A.TRIM
B.Over-provisioning
C.Garbage Collection
D.Wear levelling
AnswerA

TRIM is an ATA command that explicitly informs the SSD controller of pages that are no longer in use, prompting the controller to erase those physical blocks either immediately or during idle time. Because the erasure is performed at the flash level, the actual data is removed or invalidated, preventing recovery via file carving. This makes TRIM the critical factor that distinguishes SSD forensic examinations from HDD ones, as deleted files become inaccessible to software-based recovery tools.

Why this answer

The TRIM command (ATA Data Set Management command) allows the operating system to inform the SSD which data blocks are no longer in use. When TRIM is enabled, the SSD's controller immediately erases those blocks internally, making the original file data unrecoverable by file carving tools because the physical NAND cells are zeroed or marked as invalid. For files deleted months ago, TRIM would have already been issued for those LBAs, so traditional carving that relies on residual data in unallocated space fails.

Exam trap

EC-Council often tests the distinction between TRIM (an OS-to-SSD command that explicitly tells the drive to erase unused blocks) and Garbage Collection (a firmware-level process that may or may not erase data without TRIM), leading candidates to incorrectly choose Garbage Collection because they confuse background maintenance with the specific command that prevents recovery.

How to eliminate wrong answers

Option B (Over-provisioning) is wrong because over-provisioning reserves extra NAND capacity for performance and wear levelling, but it does not actively erase user-deleted data; it only provides spare blocks for the controller. Option C (Garbage Collection) is wrong because garbage collection consolidates valid data and erases stale blocks in the background, but it is triggered by the SSD's firmware and typically occurs after TRIM has marked blocks as invalid; without TRIM, garbage collection may not immediately erase deleted files. Option D (Wear levelling) is wrong because wear levelling distributes write/erase cycles across all NAND blocks to prolong drive life, but it does not intentionally erase user data; it moves data around and may incidentally overwrite old blocks, but it is not the primary mechanism preventing recovery of long-deleted files.

Page 3

Page 4 of 10

Page 5

All pages