Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 376–450

745 questions total · 10pages · All types, answers revealed

Page 5

Page 6 of 10

Page 7
376
Multi-Selecthard

During a forensic analysis of an SSD, the analyst encounters challenges due to TRIM and wear-leveling. Which TWO statements accurately describe the impact of these features on data recovery?

Select 2 answers
A.TRIM immediately and permanently erases deleted file data at the block level
B.Wear-leveling can scatter fragments of a file across different NAND chips, complicating physical imaging
C.Both TRIM and wear-leveling are transparent to the operating system and have no impact on forensic analysis
D.Wear-leveling ensures that deleted files are overwritten with zeros to prevent forensic recovery
E.TRIM is only effective on HDDs, not SSDs
AnswersA, B

TRIM commands cause the SSD to erase blocks, preventing recovery.

Why this answer

A is correct because TRIM commands (ATA Data Set Management command) instruct the SSD controller to immediately erase invalidated logical block addresses (LBAs) at the block level, making the original data unrecoverable via standard forensic tools. This is not a simple deletion of file system metadata but a physical erasure of the underlying NAND flash cells, which prevents recovery of the file content even with advanced carving techniques.

Exam trap

EC-Council's CHFI exam often tests the misconception that TRIM is a file system operation or that wear-leveling actively sanitizes deleted data, when in reality TRIM is a hardware-level command and wear-leveling is a longevity mechanism that incidentally complicates forensic reconstruction.

377
MCQeasy

In Android forensics, which of the following acquisition methods provides the most complete and forensically sound image of the device's internal storage?

A.Manual extraction through the user interface
B.Logical extraction via ADB
C.File system extraction
D.Physical extraction using a JTAG or chip-off technique
AnswerD

Physical extraction using a JTAG or chip-off technique is the most comprehensive acquisition method because it reads the raw flash memory chips directly, bypassing the Android operating system and its file system driver. JTAG (Joint Test Action Group) connects to the device's test access port to command the CPU to dump the flash contents, while chip-off involves physically desoldering the NAND/eMMC chip and reading it with a dedicated programmer; both yield a complete bit-for-bit image of the entire flash memory, including deleted files, unallocated space, hidden partitions, and data remnants that software-based methods cannot access. This approach is particularly valuable when the device is damaged, locked, or otherwise unresponsive, though it is invasive, may require breaking the device, and demands deep knowledge of the specific chip datasheet and interface protocols.

Why this answer

Physical extraction using a JTAG or chip-off technique provides the most complete and forensically sound image because it accesses the raw NAND flash memory at the hardware level, bypassing the operating system and any software-based restrictions. This method captures deleted data, unallocated space, and the entire file system structure, including areas not accessible via logical or file system extractions, ensuring a bit-for-bit copy of the internal storage.

Exam trap

EC-Council often tests the misconception that logical extraction via ADB is sufficient for a complete forensic image, but candidates must recognize that only physical methods (JTAG/chip-off) capture the entire raw storage, including deleted and hidden data.

How to eliminate wrong answers

Option A is wrong because manual extraction through the user interface only captures data visible to the user through the device's screen and does not access underlying file systems, deleted data, or unallocated space, making it highly incomplete and not forensically sound. Option B is wrong because logical extraction via ADB (Android Debug Bridge) uses the Android operating system's APIs to retrieve only active files and directories, missing deleted data, slack space, and low-level system partitions. Option C is wrong because file system extraction, while more thorough than logical extraction, still relies on the device's kernel to parse the file system and cannot recover data from unallocated blocks or areas outside the mounted file system, unlike physical extraction.

378
MCQmedium

A security analyst reviews Windows Security Event Logs and finds multiple Event ID 4625 entries from a single source IP address targeting various usernames. Which type of attack is MOST likely occurring?

A.Password spraying attack
B.Brute-force attack on a single account
C.Pass-the-hash attack
D.Kerberoasting attack
AnswerA

Password spraying is a low-and-slow attack in which an adversary chooses a handful of common passwords and tries them individually across many user accounts from a single source IP. In Windows Security logs this manifests as multiple Event ID 4625 failed-logon events with different account names but the same source workstation/IP and a common failure code such as 0xC000006D, often within a short window. Because each account is hit only once or twice, the total event volume stays low, evading threshold-based brute-force detection while still matching the observed pattern of many usernames from the same source.

Why this answer

Event ID 4625 indicates a failed logon attempt. When multiple usernames are targeted from a single source IP, it suggests the attacker is trying a small set of common passwords against many accounts to avoid account lockout thresholds. This is the hallmark of a password spraying attack, which differs from a brute-force attack that focuses on many passwords for one account.

Exam trap

EC-Council often tests the distinction between 'many passwords, one user' (brute-force) and 'few passwords, many users' (password spraying), and the trap here is that candidates see multiple failed logons and immediately think brute-force, overlooking the pattern of multiple usernames from a single IP.

How to eliminate wrong answers

Option B is wrong because a brute-force attack on a single account would show repeated 4625 events for the same username, not multiple different usernames. Option C is wrong because a pass-the-hash attack uses NTLM hash values to authenticate without needing the plaintext password, and it typically results in successful logon events (Event ID 4624), not a series of failed logons. Option D is wrong because Kerberoasting targets service accounts by requesting Kerberos service tickets (TGS-REQ) and does not generate Event ID 4625; it instead produces Event ID 4769 with specific attributes.

379
MCQmedium

An investigator is analyzing a compromised MySQL database server. To determine the exact time and content of a suspect data exfiltration query, which MySQL log should be examined first, assuming it is enabled?

A.General query log
B.Error log
C.Binary log
D.Slow query log
AnswerA

The general query log is the correct choice because it captures every SQL statement received from clients, including SELECT queries, regardless of whether they modify data or exceed performance thresholds. In a MySQL compromise, attackers often use SELECT statements to exfiltrate sensitive data, and this log provides a complete chronological record of those reads. Unlike the binary or slow query logs, it does not filter by data-change events or execution time, making it the only reliable artifact for detecting and reconstructing data theft via query activity.

Why this answer

The general query log records every SQL statement received by the MySQL server, including SELECT queries used for data exfiltration. Since the investigator needs the exact time and content of the suspect query, this log provides a complete, chronological record of all client-sent statements, making it the primary source for identifying the exfiltration event.

Exam trap

A common misconception is that the binary log captures all queries, but it only captures data-changing statements (DML/DDL), not SELECTs, which are the primary vector for data exfiltration.

How to eliminate wrong answers

Option B (Error log) is wrong because it only records server startup/shutdown events, crashes, and critical errors, not the content of executed queries. Option C (Binary log) is wrong because it records changes to data (INSERT, UPDATE, DELETE) for replication and point-in-time recovery, but does not log SELECT queries, which are the typical exfiltration statements. Option D (Slow query log) is wrong because it only captures queries that exceed a defined execution time threshold (e.g., long-running SELECTs), and the exfiltration query may not be slow, so it could be missed entirely.

380
Multi-Selecteasy

Which TWO of the following are typical sources of evidence for network forensics? (Select TWO.)

Select 2 answers
A.Windows registry hives
B.bash_history
C.Firewall logs
D.Prefetch files
E.Packet capture (pcap) files
AnswersC, E

Firewall logs are a cornerstone of network forensics because they contain timestamped records of each connection attempt, including source and destination IP addresses, ports, protocol, and the action taken (allow, deny, or drop). These logs enable investigators to reconstruct attack paths, spot port scans, and identify successful or blocked outbound communications. They provide metadata about network transactions, even though they do not capture payloads.

Why this answer

Firewall logs (C) are a canonical network-forensics source because they record connection metadata such as source/destination IP addresses, ports, protocol, timestamps, and allow/deny actions, which lets an investigator reconstruct traffic flows and identify blocked or permitted communications. Packet capture (pcap) files (E) are also a core network-forensics source because they contain the actual captured frames/packets (e.g., from tcpdump/Wireshark), enabling deep protocol-level analysis of payloads, sessions, and anomalies. The other options are host-based artifacts rather than network evidence: Windows registry hives (A) store OS and application configuration, bash_history (B) records shell commands executed by a user, and Prefetch files (D) are Windows execution artifacts showing program run times and loaded modules.

Exam trap

The trap here is that candidates confuse host-based artifacts (registry, bash_history, Prefetch) with network-based evidence, failing to distinguish between evidence collected from a single endpoint versus evidence collected from network infrastructure or traffic captures.

381
Multi-Selectmedium

Which TWO of the following are appropriate techniques for identifying a webshell on a compromised web server?

Select 2 answers
A.Verifying SSL certificate validity
B.Searching for files with recent creation or modification timestamps in the web root
C.Running a full antivirus scan on the server
D.Analyzing web server logs for anomalous POST requests to script files that return 200 OK with large response sizes
E.Checking for open ports on the server
AnswersB, D

Searching for files with recent creation or modification timestamps in the web root is a practical initial triage because webshells are usually uploaded shortly before they are used, and the upload leaves a fresh file on disk. In particular, script files such as .php, .jsp, or .aspx that appear in web-accessible directories with timestamps matching the time of a suspected breach are strong candidates for further manual review. While attackers can alter timestamps to hide their tracks, this technique is still appropriate and often the first step in a forensic hunt for malicious web content.

Why this answer

Webshells are often detected by recent file timestamps and anomalous POST requests in logs.

382
Multi-Selectmedium

During a forensic investigation of a Windows 10 system, you need to analyze the file system to recover deleted files. Which TWO file system artifacts would be most useful for this purpose?

Select 2 answers
A.$LogFile
B.$Boot file
C.$MFT (Master File Table)
D.$Volume
E.$Bitmap
AnswersA, C

The $LogFile records transactional metadata changes, letting you reconstruct directory entries and cluster allocations before deletion, which supports recovering deleted files on NTFS. It satisfies the Windows 10 NTFS constraint directly, unlike FAT-based artifacts. Paired with $MFT, it exposes the pre-deletion state needed for forensic reconstruction.

Why this answer

The $MFT (Master File Table) is correct because it is the core NTFS metadata structure that contains a record for every file and directory, including entries for deleted files whose records may still hold the filename, timestamps, size, and data run locations needed for recovery. The $LogFile is correct because it is NTFS's transaction journal, which records metadata changes such as file creation, deletion, and renaming, allowing investigators to reconstruct prior states and corroborate evidence of deleted files. The $Boot file is not the best choice because it primarily stores volume boot code and basic geometry/BPB parameters, not per-file records.

The $Volume file holds volume label and version information, which is not useful for recovering deleted files. The $Bitmap tracks cluster allocation (which clusters are in use versus free) and can help locate unallocated space, but by itself it does not preserve deleted file metadata or names the way the $MFT and $LogFile do.

Exam trap

EC-Council often tests the misconception that $Bitmap is the primary artifact for file recovery, but it only shows which clusters are free, not the file names or metadata needed to reconstruct deleted files.

383
MCQmedium

An incident responder finds a suspicious LNK file in a user's Startup folder on a Windows system. The LNK file's target is "C:\Windows\System32\rundll32.exe" with a command-line argument "javascript:" followed by encoded text. What is the most likely purpose of this shortcut?

A.A shortcut to a network resource that failed
B.Legitimate update mechanism for Microsoft Office
C.A user-created automation script for daily tasks
D.A malicious persistence mechanism to execute payload via script
AnswerD

This is a classic Living-off-the-Land (LOLBin) technique: rundll32.exe, a signed Windows binary, can be abused to execute JavaScript via its exported functions, allowing malware to run under a legitimate process name. The .lnk file acts as a persistence mechanism, typically placed in the Startup folder or run key, and launches the JavaScript payload at logon to download and execute additional malware. This matches MITRE ATT&CK T1218.011, using a trusted binary to evade detection and achieve persistence.

Why this answer

The LNK file targets rundll32.exe with a JavaScript command-line argument, which is a known technique for executing arbitrary script code without writing a traditional executable to disk. This is commonly used by malware to establish persistence by placing the shortcut in the Startup folder, ensuring the script runs each time the user logs in.

Exam trap

The trap here is that candidates may assume rundll32.exe is only for DLL execution and overlook its ability to run script protocols, leading them to dismiss the malicious intent and choose a benign option like a legitimate update or automation script.

How to eliminate wrong answers

Option A is wrong because a shortcut to a failed network resource would not use rundll32.exe with a JavaScript argument; it would point to a UNC path or network drive. Option B is wrong because legitimate Microsoft Office updates do not use LNK files in the Startup folder with JavaScript payloads; they use Windows Update or Office Click-to-Run services. Option C is wrong because a user-created automation script would typically be a .bat, .ps1, or .vbs file, not a LNK file invoking rundll32.exe with encoded JavaScript, which is a hallmark of malicious obfuscation.

384
MCQeasy

A security analyst reviews Windows Security Event Log and observes Event ID 4625 repeatedly for a single user account from a remote IP address within a short timeframe. What is the MOST likely cause?

A.The user successfully logged on from a remote workstation
B.A brute-force password attack is occurring against that account
C.The user's account was created
D.A service was installed on the system
AnswerB

Event ID 4625 records failed logon attempts, and repeated occurrences against one account from a single remote IP within a short window indicate an attacker systematically guessing credentials. This satisfies the stem's brute-force pattern, distinguishing it from isolated mistyped passwords or lockout events (4740), which Microsoft Entra ID or local policy would log separately.

Why this answer

Event ID 4625 indicates a failed logon attempt. When this event is logged repeatedly for the same user account from a single remote IP address within a short timeframe, it is a classic indicator of an automated brute-force password attack, where an attacker tries many passwords against that account in rapid succession.

Exam trap

The trap here is that candidates may confuse Event ID 4625 with a successful logon (4624) or think it indicates account creation, but the CHFI exam tests the precise mapping of Event IDs to security events to catch those who rely on vague memory rather than exact knowledge.

How to eliminate wrong answers

Option A is wrong because Event ID 4625 specifically denotes a failed logon, not a successful one (which would be Event ID 4624). Option C is wrong because account creation is logged as Event ID 4720, not 4625. Option D is wrong because service installation generates Event ID 4697 (or 7045 in the System log), not 4625.

385
MCQeasy

Which file system artifact in NTFS is used to hide data by appending a stream to an existing file without affecting its primary data stream?

A.USN Journal
B.$Recycle.bin
C.Alternate Data Streams (ADS)
D.Master File Table ($MFT)
AnswerC

Alternate Data Streams (ADS) is an NTFS feature that allows a single file to contain multiple data streams, so additional data can be attached to a file without altering its primary content or visibly increasing its size. An attacker can hide data by writing to a stream such as 'legit.exe:hidden.exe', and this data is not shown in standard directory listings or Explorer's size calculations. This makes ADS the classic NTFS data-hiding technique, and forensic examiners must explicitly enumerate streams to detect such hidden payloads.

Why this answer

Alternate Data Streams (ADS) are a feature of the NTFS file system that allows a file to have multiple data streams associated with it. Data written to an alternate stream does not appear in the primary stream, so the file's size and content as seen by standard tools remain unchanged, making it a common method for hiding data.

Exam trap

CHFI often tests the misconception that the $MFT itself is used to hide data, but the $MFT is a metadata structure, not a storage mechanism for appending hidden streams to files.

How to eliminate wrong answers

Option A is wrong because the USN Journal (Update Sequence Number Journal) is a change journal that records modifications to files and volumes, not a mechanism for hiding data within a file. Option B is wrong because $Recycle.bin is a system folder used to store deleted files before permanent removal, not a file system artifact for appending hidden streams. Option D is wrong because the Master File Table ($MFT) is the central directory of all files and folders on an NTFS volume, containing metadata and file records, but it does not provide a way to append hidden data streams to an existing file.

386
MCQmedium

A malware analyst uses Cuckoo Sandbox to analyze a sample. The report shows that the sample sends HTTP POST requests to 'http://malicious.example.com/gate.php' with encrypted data. Which type of indicator of compromise (IoC) is this?

A.Host-based IoC
B.Memory-based IoC
C.Hash-based IoC
D.Network-based IoC
AnswerD

The URL and domain are classic network-based IoCs because they represent communication channels between the infected host and the attacker's command-and-control (C2) infrastructure. In Cuckoo's analysis, these are extracted from captured DNS queries, HTTP requests, or IRC/HTTPS sessions, making them directly associated with network traffic rather than host state or file content.

Why this answer

The HTTP POST request to a remote URL with encrypted data is a classic network-based indicator because it involves communication over a network protocol (HTTP) to an external server. Cuckoo Sandbox captures this as a network artifact, making it a network-based IoC (Option D). Host-based IoCs focus on file system or registry changes, memory-based on in-RAM artifacts, and hash-based on file fingerprints.

Exam trap

EC-Council often tests the distinction between host-based and network-based IoCs by presenting a network artifact (like an HTTP request) and expecting candidates to recognize it as network-based, not host-based, even though the malware runs on the host.

How to eliminate wrong answers

Option A is wrong because host-based IoCs refer to artifacts on the local system (e.g., files created, registry keys modified, processes spawned), not outbound network traffic. Option B is wrong because memory-based IoCs involve artifacts found in RAM (e.g., injected code, API hooks, process memory dumps), not network packets. Option C is wrong because hash-based IoCs are cryptographic hashes (e.g., MD5, SHA-1, SHA-256) of files, used to identify known malware samples, not behavioral network patterns.

387
MCQeasy

Which of the following BEST describes Locard's exchange principle as applied to digital forensics?

A.Digital evidence must be collected using a write blocker.
B.The chain of custody must be documented for evidence to be admissible.
C.Volatile data must be collected before powering off a system.
D.Every contact leaves a trace; an attacker will leave digital evidence on the compromised system.
AnswerD

Locard's exchange principle, originally formulated for physical crime scenes, states that every contact, however slight, leaves a trace, and in digital forensics this means an attacker's activities will invariably generate residual data on the compromised system, such as log entries, altered timestamps, prefetch files, or memory remnants. This transferred principle underlies the entire discipline of digital evidence identification because it gives examiners a theoretical basis for expecting to find attacker artifacts even when the intruder attempts to clean up. It is the only option that directly names the exchange principle rather than a forensic procedure, legal rule, or collection ordering strategy.

Why this answer

Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means that when an attacker interacts with a compromised system, they inevitably leave behind digital artifacts such as log entries, modified files, registry changes, or network connection records. Option D correctly captures this core concept as applied to digital forensics.

Exam trap

The trap here is that candidates confuse procedural best practices (write blockers, chain of custody, order of volatility) with the fundamental theoretical principle of trace evidence exchange, leading them to pick a practical step instead of the conceptual definition.

How to eliminate wrong answers

Option A is wrong because using a write blocker is a best practice for preserving the integrity of digital evidence during acquisition, but it is not a description of Locard's exchange principle. Option B is wrong because documenting the chain of custody is a legal and procedural requirement for evidence admissibility, not a statement of the exchange principle. Option C is wrong because collecting volatile data before powering off is a priority in incident response (order of volatility), but it does not describe the trace-leaving nature of Locard's principle.

388
MCQeasy

During a network forensic investigation, the analyst recovers a PCAP file. What type of information can be directly extracted from this file?

A.Files transferred via HTTP
B.Operating system version of the source host
C.Registry data of the destination host
D.Disk partition table of the sending computer
AnswerA

HTTP file transfers are visible in the packet payload because HTTP is an unencrypted application-layer protocol. During a network forensic investigation, an analyst can reconstruct the entire file by reassembling TCP segments and extracting the HTTP message body (e.g., using Wireshark's 'Follow TCP Stream' or NetworkMiner). As long as the capture contains complete traffic, the transferred file's content is directly recoverable from the PCAP data, making this the correct answer.

Why this answer

A PCAP file captures raw network packets. HTTP is an application-layer protocol that transmits data (e.g., files, web pages) in cleartext over TCP. By reassembling TCP streams from the captured packets, an analyst can directly extract files transferred via HTTP, as the payload contains the actual file content.

Exam trap

EC-Council often tests the distinction between what is directly extractable from packet payloads (e.g., HTTP files) versus what requires inference or additional forensic artifacts (e.g., OS fingerprinting or disk data), leading candidates to overestimate the information available in a PCAP.

How to eliminate wrong answers

Option B is wrong because the operating system version of the source host is not directly stored in packet headers; it can only be inferred through techniques like TCP/IP fingerprinting (e.g., analyzing TTL values, window sizes), not directly extracted. Option C is wrong because registry data resides on the local disk of the destination host and is never transmitted over the network in standard protocols; a PCAP contains only network traffic, not local filesystem artifacts. Option D is wrong because the disk partition table is a low-level disk structure that is not sent over the network during normal communication; it would require a full disk image, not a packet capture.

389
MCQmedium

Which network forensic technique involves analyzing the flow of network traffic to identify patterns and anomalies, often using tools like SiLK or nfdump?

A.Port scanning
B.NetFlow analysis
C.Signature-based detection
D.Deep packet inspection
AnswerB

NetFlow analysis is a network forensic technique that parses flow records—aggregated summaries of communication sessions containing source/destination IP addresses, ports, protocol, timestamps, and byte counts—exported by routers or switches. These records allow investigators to reconstruct traffic patterns and detect anomalies (e.g., exfiltration, beaconing) without inspecting packet payloads. Its strength lies in scalability and historical visibility, making it the correct technique for analyzing flow.

Why this answer

NetFlow analysis is the correct technique because it focuses on collecting and analyzing IP traffic flow metadata (e.g., source/destination IPs, ports, protocols, packet counts) to detect patterns and anomalies. Tools like SiLK and nfdump are specifically designed to process NetFlow data, making this the precise match for the question's description.

Exam trap

Candidates often confuse 'analyzing traffic flow' with 'deep packet inspection' because both involve network traffic, but only NetFlow focuses on flow metadata without payload examination.

How to eliminate wrong answers

Option A is wrong because port scanning is an active reconnaissance technique that probes open ports on a target system, not a passive analysis of network traffic flows. Option C is wrong because signature-based detection relies on predefined patterns (e.g., Snort rules) to identify known threats, not on flow-level metadata analysis for anomalies. Option D is wrong because deep packet inspection (DPI) examines the full payload of packets, including application-layer data, whereas flow analysis only looks at packet headers and aggregated flow records.

390
MCQmedium

An analyst suspects that an attacker used a web shell to execute commands on a Windows web server. Which Windows event ID should the analyst look for to detect service installation that may have been used for persistence?

A.7045
B.4624
C.4648
D.4720
AnswerA

Event ID 7045 indicates that a new service was installed on the Windows system. When an attacker exploits a web shell, they often escalate privileges or establish persistence by installing a malicious service that executes a payload at system startup. Therefore, a 7045 event appearing alongside web shell traffic is a strong indicator of post-exploitation activity, making it the most relevant option.

Why this answer

Event ID 7045 is logged by the Windows Service Control Manager when a new service is installed on the system. An attacker who gains a web shell often installs a malicious service to maintain persistence, and this event captures the service name, binary path, and service type, making it the primary forensic artifact to detect such activity.

Exam trap

The trap here is that candidates confuse event IDs for logon events (4624, 4648) or user creation (4720) with service installation, because they associate persistence broadly with any authentication or account change rather than the specific service creation event.

How to eliminate wrong answers

Option B (4624) is wrong because it logs successful logon events, not service installation; it would show interactive or network logons but not the creation of a service. Option C (4648) is wrong because it records explicit credential use (e.g., RunAs) and is unrelated to service creation. Option D (4720) is wrong because it logs user account creation, not service installation; while an attacker might create a user, the question specifically asks about service installation for persistence.

391
MCQhard

During a forensic investigation of a compromised web server, you find a file named 'cmd.aspx' in the uploads directory. The file contains: <%@ Page Language="C#" %><% Response.Write(System.Diagnostics.Process.Start("cmd.exe","/c "+Request.QueryString["cmd"])).StandardOutput.ReadToEnd(); %>. What is the most likely purpose of this file?

A.It is a database connection string
B.It is a legitimate ASP.NET application page for server management
C.It is a webshell used for remote command execution
D.It is a cross-site scripting payload
AnswerC

This is a classic ASP.NET webshell: it reads a command from the HTTP query string (often "cmd"), starts cmd.exe through Process.Start, and returns the command output in the HTTP response. This gives a remote attacker an unauthenticated command shell on the web server, making it a direct indicator of compromise. During a forensic investigation, such code should be preserved as malicious evidence and traced back to the upload or exploitation vector.

Why this answer

This is a webshell that executes arbitrary operating system commands via the 'cmd' query parameter. It allows remote command execution on the server.

392
MCQhard

In an email header, an analyst notices the following: 'Received: from mail.attacker.com (192.168.2.100) by mail.victim.com (Postfix) with ESMTP id ABC123 for <user@victim.com>; ...'. The 'From' address appears as 'ceo@victim.com'. Which type of attack is most likely?

A.Man-in-the-middle
B.Email spoofing
C.Malware attachment
D.Phishing
AnswerB

Email spoofing is the forgery of email header fields, typically the From/Reply-To address, to make a message appear to originate from a trusted source while it actually came from an unrelated or attacker-controlled server. Here, the originating Received server and HELO/EHLO identity do not align with the claimed From domain, which is exactly the signature of a spoofed message. SMTP lacks built-in sender authentication, so unlike a MITM that alters traffic in transit, this anomaly is the result of direct manipulation of the message headers during composition.

Why this answer

The email claims to be from 'ceo@victim.com' but was received from 'mail.attacker.com', indicating the sender forged the From address. This is email spoofing.

393
MCQeasy

An email forensic analyst receives a suspicious email and examines the full headers. Which header field is the MOST reliable for determining the true originating IP address of the sender, assuming no spoofing of the header?

A.Return-Path
B.Received
C.Message-ID
D.From
AnswerB

Each mail server that processes the email prepends its own Received header, creating a chronological chain from the origin to the destination. The bottommost Received header, added first, typically reveals the originating IP address of the sender's mail server or client, which is why it is the primary evidence for tracing. While the last Received header is added by the receiving server, the chain can be partially forged if the sending server is malicious, so analysts corroborate the first Received header with server logs.

Why this answer

The 'Received' header is the most reliable for determining the true originating IP address because each mail server that handles the email adds a new 'Received' field at the top of the header. The bottommost 'Received' header (the first one added) typically contains the IP address of the sender's MTA or the client's IP, assuming no spoofing. This field is sequentially added by each hop and is the primary source for tracing the email's path back to its origin.

Exam trap

EC-Council often tests that candidates confuse the 'From' or 'Return-Path' headers with the actual origin IP, but the trap is that these fields are easily spoofed and contain no IP information, whereas the 'Received' headers provide the true network path.

How to eliminate wrong answers

Option A is wrong because the 'Return-Path' header (also called 'envelope from') is used for bounce handling and contains the address specified in the SMTP MAIL FROM command, not the sender's IP address. Option C is wrong because the 'Message-ID' header is a unique identifier generated by the sending MUA or MTA for tracking and deduplication, and it contains no IP address information. Option D is wrong because the 'From' header is a user-visible field that can be arbitrarily set by the sender's email client and is easily forged; it does not provide any network-layer origin information.

394
MCQhard

A Windows system's registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' contains a subkey with a serial number. What does this artifact indicate?

A.A USB network adapter was attached
B.A USB storage device was attached
C.A USB printer was attached
D.A USB keyboard was attached
AnswerB

The USBSTOR subkey in HKLM\SYSTEM\CurrentControlSet\Enum is populated when Windows enumerates a USB mass-storage device, such as a flash drive, external HDD, or card reader. It creates a subkey named like Disk&Ven_<vid>&Prod_<pid>&Rev_<rev>, and the key's LastWrite time can be used as forensic timeline evidence of the device's most recent connection to the system. This is why this key points directly to a USB storage device.

Why this answer

The registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' specifically enumerates USB mass storage devices (e.g., flash drives, external hard drives). The presence of a subkey with a serial number indicates that a USB storage device was attached and recognized by the Windows operating system, as the serial number uniquely identifies the device. This key is a primary artifact in USB forensics for tracking storage device connections.

Exam trap

EC-Council often tests the misconception that all USB devices (e.g., keyboards, printers) are logged under the same 'USBSTOR' key, but in reality, only mass storage devices appear there, while other USB classes have separate enumeration paths.

How to eliminate wrong answers

Option A is wrong because USB network adapters are enumerated under 'HKLM\SYSTEM\CurrentControlSet\Enum\USB' with a class GUID of '{4d36e972-e325-11ce-bfc1-08002be10318}' (Net class), not under 'USBSTOR'. Option C is wrong because USB printers are enumerated under 'HKLM\SYSTEM\CurrentControlSet\Enum\USBPRINT' or with class GUID '{28d78fad-5a12-11d1-ae5b-0000f803a8c2}', not under 'USBSTOR'. Option D is wrong because USB keyboards are enumerated under 'HKLM\SYSTEM\CurrentControlSet\Enum\USB' with HID class GUID '{745a17a0-74d3-11d0-b6fe-00a0c90f57da}', not under 'USBSTOR'.

395
MCQmedium

During a forensic investigation, you need to acquire the RAM of a running Linux system. Which tool is specifically designed for memory acquisition on Linux?

A.Memdump
B.Volatility
C.WinPmem
D.LiME
AnswerD

LiME is a loadable kernel module built specifically for Linux memory acquisition, capturing RAM to a file or over the network with minimal footprint. Generic imaging tools copy disk, not volatile memory, so they cannot satisfy this requirement.

Why this answer

LiME (Linux Memory Extractor) is the correct tool because it is specifically designed to capture volatile memory (RAM) from Linux systems, loading as a loadable kernel module (LKM) to dump memory contents to a file or over the network. Unlike generic tools, LiME handles kernel address space layout randomization (KASLR) and can acquire memory without altering the system state, making it the standard for Linux forensic memory acquisition.

Exam trap

The CHFI exam often tests the distinction between acquisition and analysis tools, so the trap here is that candidates confuse Volatility (an analysis tool) with a memory acquisition tool, or assume WinPmem works on Linux because of the 'pmem' name, when it is Windows-only.

How to eliminate wrong answers

Option A is wrong because Memdump is a generic term for memory dumping utilities and not a specific tool for Linux memory acquisition; it often refers to Windows-based tools or simple dd commands, lacking the kernel module approach needed for reliable Linux RAM capture. Option B is wrong because Volatility is a memory analysis framework used to examine memory dumps, not a tool for acquiring memory; it processes existing dumps but does not perform the acquisition itself. Option C is wrong because WinPmem is a memory acquisition tool designed exclusively for Windows systems, using the winpmem driver to access physical memory, and is not compatible with Linux.

396
MCQeasy

During a mobile forensics investigation, an examiner needs to acquire data from an iPhone running iOS 14. Which of the following acquisition methods provides the MOST complete data extraction?

A.File system acquisition via jailbreak
B.Manual acquisition by browsing the device
C.Physical acquisition via JTAG or chip-off
D.Logical acquisition via iTunes backup
AnswerC

Physical acquisition via JTAG or chip-off is the gold standard for mobile forensic imaging because it accesses the raw NAND/eMMC storage controller directly, independent of the device's operating system. JTAG exploits the Joint Test Action Group debug port to force the CPU to dump memory, while chip-off removes the memory chip and reads it with a programmer; both produce a complete bit-for-bit forensic image, including deleted data, unallocated clusters, and partially overwritten file remnants that would be unavailable through any logical method. This approach preserves the entire chip's contents and allows advanced data recovery, though it requires skill, may destroy the device during chip removal, and must be performed with proper anti-static and bitstream-level hashing procedures.

Why this answer

Physical acquisition via JTAG or chip-off provides the most complete data extraction because it captures a bit-for-bit copy of the raw NAND flash memory, including deleted files, unallocated space, and system partitions that are otherwise inaccessible. On iOS 14, Apple's security features (e.g., full-disk encryption, SEP) limit logical and file system methods, but physical techniques bypass the operating system to retrieve the entire storage image, albeit with decryption challenges.

Exam trap

EC-Council often tests the misconception that jailbreak-based file system acquisition is the most complete method, but physical acquisition (JTAG/chip-off) is technically superior because it captures the entire raw storage, including areas the OS hides or encrypts.

How to eliminate wrong answers

Option A is wrong because jailbreaking iOS 14 is often not possible or reliable due to Apple's hardened security (e.g., KTRR, PAC), and even if achieved, file system acquisition still cannot access the raw physical memory or unallocated space, leaving gaps in data recovery. Option B is wrong because manual acquisition only captures visible data through the user interface, missing hidden files, metadata, and deleted content, making it the least complete method. Option D is wrong because logical acquisition via iTunes backup only retrieves files that iOS chooses to include in the backup (e.g., app data, settings), excluding system files, deleted data, and unallocated space, and it relies on the backup encryption state.

397
MCQmedium

Which of the following is a key requirement for digital evidence to be considered admissible in court?

A.The evidence must be authentic and its integrity must be verifiable
B.The evidence must have been collected by a law enforcement officer
C.The evidence must be stored on a write-blocked device
D.The evidence must be encrypted to ensure confidentiality
AnswerA

To be admissible, digital evidence must be authenticated — the proponent must show it is what it claims to be — and its integrity must be verifiable through a demonstrable chain of custody and cryptographic hash values. Courts require these to ensure the evidence has not been altered or corrupted from the time of acquisition to presentation, as a failure to prove authenticity or integrity undermines its reliability and relevance.

Why this answer

Digital evidence must be authentic and its integrity verifiable to meet the legal standard of admissibility, as established by rules such as the Federal Rules of Evidence (FRE 901) and the Daubert standard. Authentication requires proving that the evidence is what it claims to be, typically through a hash value (e.g., MD5, SHA-1, or SHA-256) computed before and after analysis to ensure no tampering occurred. Without verifiable integrity, the evidence could be challenged as altered, making it inadmissible regardless of how it was collected.

Exam trap

EC-Council often tests the misconception that procedural steps like write-blocking or law enforcement involvement are legal requirements, when in fact the core admissibility criterion is the ability to prove authenticity and integrity through verifiable means like hash values and chain of custody documentation.

How to eliminate wrong answers

Option B is wrong because digital evidence can be collected by any qualified forensic examiner, not exclusively a law enforcement officer; private-sector investigators or certified forensic analysts often handle evidence in civil cases. Option C is wrong because while write-blocking is a best practice to preserve evidence integrity, it is not a legal requirement for admissibility; evidence stored on a non-write-blocked device may still be admissible if integrity is otherwise proven (e.g., via hash verification). Option D is wrong because encryption is not a requirement for admissibility; in fact, encrypted evidence may be inadmissible if the decryption key is unavailable or if encryption obscures the evidence's authenticity, and confidentiality is separate from the legal standards of authenticity and integrity.

398
MCQeasy

In Android forensics, which command is used to extract a full physical image of a device's flash memory over USB using the Android Debug Bridge (ADB)?

A.adb pull /data data.img
B.adb shell dd if=/dev/block/mmcblk0 of=/sdcard/physical.img
C.adb backup -f backup.ab
D.adb install physical.img
AnswerB

adb shell dd if=/dev/block/mmcblk0 of=/sdcard/physical.img invokes the dd utility on the device to read the raw block device /dev/block/mmcblk0, which typically represents the entire internal storage or eMMC chip. This creates a bit-for-bit physical image that includes all data, including deleted files and unallocated sectors, making it ideal for forensic analysis; in practice, you would often redirect output via adb exec-out to a host rather than write to /sdcard to avoid altering evidence.

Why this answer

The `adb shell dd if=/dev/block/mmcblk0 of=/sdcard/physical.img` command uses the `dd` utility to perform a bit-for-bit copy of the raw block device representing the internal flash memory (mmcblk0) to a file on the device's SD card, which can then be pulled via ADB. This method captures a full physical image, including deleted data and unallocated space, which is essential for deep forensic analysis.

Exam trap

The CHFI exam often tests the distinction between logical acquisition (adb pull) and physical acquisition (adb shell dd), so the trap here is that candidates confuse the simple file copy command (adb pull) with the raw block-level imaging command (adb shell dd), assuming any command with 'pull' or 'backup' can produce a forensic image.

How to eliminate wrong answers

Option A is wrong because `adb pull /data data.img` only copies the logical contents of the /data partition, not a raw block-level image, and thus misses deleted files, unallocated space, and metadata from other partitions. Option C is wrong because `adb backup -f backup.ab` creates a logical backup of app data and system settings, not a physical image of flash memory; it does not capture the raw block device or unallocated space. Option D is wrong because `adb install physical.img` is used to install an APK file, not to extract an image; attempting to install a raw image file would fail or corrupt the device.

399
Multi-Selecthard

Which THREE of the following are characteristics of the GPT (GUID Partition Table) compared to MBR?

Select 3 answers
A.Partition information is stored in the boot code area
B.Uses a 32-bit Logical Block Address (LBA)
C.Partitions are identified by a Globally Unique Identifier (GUID)
D.Supports up to 128 primary partitions
E.Stores a backup partition table at the end of the disk
AnswersC, D, E

This is correct. Every GPT partition is assigned a Globally Unique Identifier (GUID) that serves as the partition's unique identity, in addition to a separate GUID for the partition type. These GUIDs are randomly generated and statistically unique, enabling robust identification that does not rely on disk order or numbering. The GPT header itself also has a GUID for the disk, making the entire layout disklabel-oriented rather than sector-offset-oriented.

Why this answer

Option C is correct because GPT identifies each partition and partition type with a Globally Unique Identifier (GUID), which avoids the MBR's reliance on simple numeric type bytes and enables robust, unique identification. Option D is correct because GPT by default provides space for 128 primary partitions in its partition entry array, unlike MBR's four-primary-partition limit. Option E is correct because GPT writes a primary partition table near the beginning of the disk and a backup copy at the end of the disk, allowing recovery if the primary table is damaged.

Option A is incorrect because GPT stores partition information in the GPT header and partition entry array, not in the boot code area; that description better fits MBR, where the partition table resides in the master boot record. Option B is incorrect because GPT uses 64-bit Logical Block Addressing (LBA), whereas MBR uses 32-bit LBA fields.

Exam trap

The CHFI exam often tests the misconception that GPT stores partition data in the boot code area (like MBR's partition table), but in reality, the boot code area in GPT is only a protective MBR with a single partition entry for backward compatibility.

400
MCQeasy

Locard's exchange principle is fundamental to forensic science. How does this principle apply to computer forensics?

A.Every action on a digital device leaves some trace of evidence.
B.Digital evidence is always volatile and must be preserved immediately.
C.Evidence must be collected within 24 hours.
D.Only physical evidence, such as fingerprints, can be left at a crime scene.
AnswerA

In digital forensics, Locard's exchange principle translates to the fact that any user or system action modifies the state of the device: opening a file updates access timestamps, running a program creates process artifacts, and network activity generates logs. These traces can reside in filesystem metadata, application history, event logs, unallocated space, or even slack space. Anti-forensic tools themselves leave traces—such as installation footprints, modified timestamps, or leftover logs—so a determined actor cannot act without leaving some recoverable evidence.

Why this answer

Locard's principle states that every contact leaves a trace; in digital forensics, this translates to digital traces left behind when a system is accessed.

401
MCQmedium

A forensic investigator is examining a Linux system and suspects that files were deleted to cover tracks. The investigator runs 'debugfs -R "lsdel" /dev/sda1' on an ext4 file system. The output shows several deleted inodes but does not include file names. What is the MOST likely reason for the missing file names?

A.The file names were encrypted by the attacker, so they do not appear in plain text.
B.The file system was mounted read-only, preventing debugfs from reading directory entries.
C.The debugfs lsdel command only works on ext3 file systems and not on ext4.
D.The ext4 file system does not store file names in the inode; they are stored in directory entries, which are removed upon deletion.
AnswerD

In ext4 (and other Unix-like file systems), file names are not stored in the inode. Instead, directory entries map names to inode numbers. When a file is deleted, the directory entry is removed, but the inode may retain metadata until it is reused. Thus, debugfs lsdel can list deleted inodes but cannot recover original file names from the inode alone. This is why file names are missing from the output.

Why this answer

In ext4, file names are stored in directory entries that map names to inode numbers. When a file is deleted, the directory entry is removed, but the inode may remain allocated or partially intact until reused. The debugfs lsdel command lists deleted inodes, but it cannot retrieve original file names because that information is not stored in the inode.

Therefore, the missing names are expected behavior.

Exam trap

The trap here is assuming that deleted inodes retain file names, when in fact names are stored separately in directory entries and are removed upon deletion.

402
MCQmedium

A cloud forensic investigator is examining AWS CloudTrail logs for signs of unauthorized access to an S3 bucket. Which of the following CloudTrail event names would indicate a successful attempt to list the objects in the bucket?

A.GetObject
B.PutObject
C.DeleteObject
D.ListObjects
AnswerD

ListObjects is the S3 API call that returns a list of object keys, sizes, and metadata for a bucket, optionally filtered by a prefix or delimiter, and in CloudTrail it is recorded as eventName 'ListObjects' (or 'ListObjectsV2' for the paginated version). This operation enables an actor to enumerate bucket contents without knowing specific keys in advance, which is exactly what a forensic investigator would look for to establish reconnaissance or unauthorized enumeration. As the correct answer, ListObjects indicates that someone accessed the bucket's inventory, unlike Get, Put, and Delete operations that target a single known object.

Why this answer

The ListObjects operation lists the objects in an S3 bucket; the CloudTrail event name is 'ListObjects'.

403
MCQhard

During a forensic investigation of a Windows 10 system, you find that a suspect used the 'cipher /w:C:' command. What is the primary forensic implication of this action?

A.It encrypts all files on the C: drive
B.It wipes free space, hindering recovery of deleted files
C.It enables file system journaling
D.It removes alternate data streams from files
AnswerB

When you delete a file, its data blocks are merely marked as available, leaving the underlying bytes on the physical disk. The cipher /w command systematically overwrites these free-space regions with a sequence of patterns (e.g., 0x00, 0xFF, and random data) to ensure that remnants of deleted files are no longer recoverable through forensic tools. This process directly impedes recovery by destroying the residual data that would otherwise remain on the drive, which is why this is the correct description of the command's purpose.

Why this answer

The 'cipher /w:C:' command overwrites all free space on the C: drive with three passes of random data (0x00, 0xFF, and a random byte). This action permanently destroys the remnants of previously deleted files, making them unrecoverable by forensic tools. The primary forensic implication is that it severely hinders the recovery of deleted files, which is a common anti-forensic technique.

Exam trap

The trap here is that candidates confuse the 'cipher' command's encryption functionality (using /e) with its free-space wiping capability (using /w), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because 'cipher /w' does not encrypt files; it only wipes free space, whereas encryption is performed by 'cipher /e' without the '/w' switch. Option C is wrong because the cipher command does not enable file system journaling; NTFS journaling is a built-in feature controlled by the 'fsutil' command, not by cipher. Option D is wrong because cipher /w does not specifically target alternate data streams (ADS); it wipes all free space indiscriminately, and ADS removal is typically done with tools like 'streams.exe' or by copying files to a non-NTFS volume.

404
MCQeasy

An analyst is investigating a compromised Linux system. Which file system structure holds metadata about every file and directory, including permissions, ownership, timestamps, and pointers to data blocks?

A.Journal
B.Block bitmap
C.Superblock
D.Inode
AnswerD

The inode is a per-file data structure containing all metadata for a file or directory, including mode/permissions, owner and group, size, access/modification/change timestamps, link count, and pointers to data blocks (direct, indirect, or extents). In ext4, the inode number, together with a generation counter, uniquely identifies a file, and directory entries map names to inode numbers. When a file is deleted, the inode may be cleared but often remains recoverable until the inode is reused, making it the central artifact for reconstructing file metadata and content.

Why this answer

The inode is the fundamental data structure in Unix/Linux file systems (e.g., ext2/3/4) that stores metadata for each file and directory, including permissions, ownership, timestamps (access, modify, change), and pointers to data blocks. Unlike the superblock or block bitmap, the inode does not store the file name (which is in directory entries) but contains all other essential metadata required for file system operations.

Exam trap

EC-Council often tests the misconception that the superblock holds per-file metadata, but the superblock only stores file system-wide configuration, not individual file attributes.

How to eliminate wrong answers

Option A is wrong because the journal is a circular log area used for crash recovery (e.g., in ext3/4) that records pending metadata or data changes, not a structure holding permanent metadata about every file. Option B is wrong because the block bitmap is a simple bit array that tracks which data blocks are free or allocated, not file-specific metadata like permissions or timestamps. Option C is wrong because the superblock stores global file system parameters (e.g., block size, total inode count, mount state) and does not contain per-file metadata.

405
MCQmedium

An IIS log entry shows: `2024-07-15 14:22:10 10.0.0.5 GET /../../windows/system32/cmd.exe 404 - Mozilla/5.0`. What attack technique does this log entry indicate?

A.Remote code execution (RCE)
B.Directory traversal
C.Cross-site request forgery (CSRF)
D.SQL injection
AnswerB

The presence of ../ (dot-dot-slash) sequences is a classic indicator of directory traversal, where an attacker manipulates file paths to escape the web root and access arbitrary files. In this IIS log entry, the request appears to target a system executable such as cmd.exe outside the website's home directory. Even though the response is 404, the attack pattern—traversing upward with ../ and requesting a sensitive Windows binary—clearly identifies a path traversal attempt rather than another vulnerability class.

Why this answer

The presence of '../' sequences in the URI path indicates a path traversal attack attempting to access files outside the web root.

406
MCQmedium

A security analyst finds the following entry in the Apache access log: 10.0.0.5 - - [20/Jan/2023:08:12:44 +0000] "GET /../../../../etc/passwd HTTP/1.1" 404 345 "-" "curl/7.68.0". Which attack was attempted?

A.Remote File Inclusion
B.Path Traversal
C.Command Injection
D.Cross-Site Request Forgery (CSRF)
AnswerB

The request in the Apache log uses multiple '../' sequences to traverse upward from the web root directory, aiming to access sensitive files such as ../../../../etc/passwd. This is a textbook directory traversal (path traversal) attack, categorized as CWE-22, where the application fails to validate or sanitize file path inputs. The repeated '..' segments allow the attacker to escape the intended document root and read files elsewhere on the filesystem, like password hashes or configuration secrets. Because the log shows a direct path traversal payload rather than code execution or URL inclusion, Path Traversal is the correct answer.

Why this answer

The URI contains '../../../../etc/passwd', which is a path traversal attempt to read the /etc/passwd file. The 404 status indicates the file was not found, but the intent is clear.

407
MCQhard

An investigator is analyzing a RAID 5 array consisting of three disks. One disk fails and is replaced. After rebuilding, the file system appears corrupted. What is the MOST likely cause?

A.Two disks failed simultaneously
B.The replacement disk is smaller than the original
C.The file system is not supported by the RAID controller
D.The array was configured with an incorrect stripe size
AnswerB

RAID 5 requires all member disks to have identical usable capacity, and the controller maps data across disks based on that fixed geometry. If the replacement disk is physically or logically smaller than the original, the controller cannot reconstruct the missing disk's full block range, causing rebuild I/O errors that may corrupt the logical drive or abort the rebuild entirely. This is a classic cause of apparent data corruption after a disk replacement, because the array's own metadata and data layout become inconsistent with the replacement disk's reduced sector count.

Why this answer

In a RAID 5 array, all disks must have the same capacity for the array to function correctly. If a replacement disk is smaller than the original, the RAID controller will either refuse to rebuild or will rebuild using only the smaller disk's capacity, truncating data and causing file system corruption. This is a common cause of post-rebuild corruption because the parity and data stripes are misaligned or missing.

Exam trap

A common misconception is that any disk of the same interface type (e.g., SATA) can replace a failed disk in a RAID array, ignoring the critical requirement for identical or larger capacity.

How to eliminate wrong answers

Option A is wrong because if two disks failed simultaneously in a RAID 5 array, the array would be completely lost and unrecoverable, not merely corrupted after a rebuild. Option C is wrong because RAID controllers operate at the block level, not the file system level; file system support is irrelevant to the RAID controller's ability to rebuild. Option D is wrong because the stripe size is set during initial array creation and does not change during a rebuild; an incorrect stripe size would cause performance issues or incompatibility from the start, not corruption specifically after a disk replacement.

408
MCQhard

A network analyst captures a packet with Wireshark showing a TCP SYN packet from IP 10.0.0.5 to 192.168.1.10 port 443, followed immediately by a SYN‑ACK from 192.168.1.10 to 10.0.0.5, then an RST from 10.0.0.5. What does this sequence MOST likely indicate?

A.A man‑in‑the‑middle attack
B.A denial‑of‑service (SYN flood) attack
C.A normal HTTPS session initiation
D.A TCP SYN scan (stealth scan)
AnswerD

A TCP SYN scan, also known as a stealth scan or half-open scan, works by sending an SYN packet to a port and observing the response: if SYN-ACK is received, the port is open, and the scanner immediately sends an RST to tear down the connection. This avoids completing the three-way handshake, so the target service never sees a full connection and may not write it to application logs. The captured sequence — SYN, SYN-ACK, RST — exactly matches this behavior. This is why it is correctly identified as a TCP SYN scan, as the RST after SYN-ACK is the signature of an active port-scanning tool like Nmap.

Why this answer

A SYN followed by SYN‑ACK and then RST is typical of a port scan where the scanner sends a SYN, receives a SYN‑ACK (port open), and then immediately resets the connection to avoid completing the handshake.

409
MCQhard

During a forensic examination of a Windows system infected with ransomware, the analyst finds that the file timestamps (creation, modification, access) for several critical system files have been altered to match legitimate Windows files. Which anti-forensic technique is MOST likely being used?

A.Data hiding via ADS
B.Steganography
C.Log wiping
D.Timestomping
AnswerD

Timestomping is an anti-forensic technique that deliberately alters a file's timestamps—such as creation, modification, and access times—typically on NTFS by modifying $STANDARD_INFORMATION or $FILE_NAME attributes. Attackers use it to make malicious files appear old, legitimate, or to match expected system activity, thereby evading investigative timelines. Detection often relies on inconsistencies between MFT attributes, USN journal entries, or comparing timestamps against volume shadow copies and prefetch data.

Why this answer

Timestomping is the deliberate alteration of file timestamps (creation, modification, access) to mislead forensic investigators. In this scenario, the ransomware modified critical system file timestamps to match legitimate Windows files, which is the hallmark of timestomping. This technique is commonly used to evade timeline analysis and hide the true sequence of malicious activity.

Exam trap

EC-Council often tests the distinction between timestomping (altering file timestamps) and log wiping (removing event logs), so the trap here is that candidates may confuse 'log wiping' with any timestamp-related manipulation, but log wiping specifically targets event logs, not file metadata.

How to eliminate wrong answers

Option A is wrong because data hiding via Alternate Data Streams (ADS) conceals data within NTFS file streams without altering timestamps, not by modifying them to match legitimate files. Option B is wrong because steganography hides data within other files (e.g., images or audio) and does not involve changing file timestamps. Option C is wrong because log wiping targets system or application logs to remove evidence, not file metadata timestamps on the filesystem.

410
MCQmedium

A forensic investigator needs to collect evidence from a Google Cloud Platform (GCP) environment. Which of the following GCP services provides audit logs for administrative activities and data access?

A.Cloud Storage logs
B.Cloud Monitoring
C.Cloud IAM
D.Cloud Audit Logs
AnswerD

Cloud Audit Logs are the correct source because they provide a comprehensive, immutable log of administrative and authentication activities across Google Cloud, including the identity of the caller, the action performed, the resource affected, and the timestamp. Admin Activity logs are enabled by default, and when data access is enabled, they capture read/write operations as well, making them the definitive auditable trail for forensic reconstruction of who did what, where, and when.

Why this answer

Cloud Audit Logs is the correct answer because it is the dedicated GCP service that captures and stores audit trails for administrative activities (Admin Activity audit logs) and data access (Data Access audit logs) within Google Cloud Platform. These logs record who did what, where, and when, which is essential for forensic investigations in cloud environments.

Exam trap

EC-CHFI candidates often confuse Cloud Audit Logs with Cloud Monitoring, mistakenly associating 'monitoring' with logging, but Cloud Monitoring is for metrics and alerts, not audit trails.

How to eliminate wrong answers

Option A is wrong because Cloud Storage logs refer to access logs and storage logs specific to Cloud Storage buckets, not the comprehensive audit logs for all GCP services. Option B is wrong because Cloud Monitoring (formerly Stackdriver Monitoring) is a metrics and alerting service, not a logging service for audit trails. Option C is wrong because Cloud IAM is an identity and access management service that controls permissions but does not generate or store audit logs.

411
MCQmedium

In an ext4 file system, after a file is deleted, the inode's di_mode field is set to 0 and the block pointers are cleared. However, the file content may still be recoverable until what happens?

A.The data blocks are overwritten by new files
B.The file system is unmounted
C.The superblock is updated
D.The journal is committed
AnswerA

When a file is deleted in ext4, the inode is unlinked and its block pointers are cleared from the directory structure, but the physical blocks themselves are only marked as free in the block bitmap. They remain intact until a subsequent file allocation reuses those same blocks and overwrites them with new data. Once this happens, the original file content is irrecoverably lost unless remnants survive in unallocated slack space. Thus, overwriting by new files is the definitive event that destroys deleted file data.

Why this answer

When a file is deleted in ext4, the inode's di_mode is set to 0 and block pointers are cleared, but the actual data blocks on disk remain unchanged. The file content remains recoverable until those specific data blocks are overwritten by new file data, because only then is the original content physically destroyed. This is why data recovery tools can often restore deleted files if the blocks have not been reused.

Exam trap

The trap here is that candidates often confuse metadata operations (like journal commits or superblock updates) with actual data destruction, assuming that file system housekeeping erases content, when in reality only block overwrites remove the raw data.

How to eliminate wrong answers

Option B is wrong because unmounting the file system does not overwrite data blocks; it only flushes cached metadata and ensures a clean state, leaving the deleted file's data intact. Option C is wrong because updating the superblock (e.g., via tune2fs or after a fsck) modifies global file system metadata like block counts and mount state, not the individual data blocks of a deleted file. Option D is wrong because committing the journal finalizes metadata transactions (e.g., inode deletion) but does not touch the data blocks themselves; journal commits are about consistency, not data erasure.

412
MCQeasy

A forensic analyst is examining a FAT32 file system and finds that the file allocation table indicates a cluster chain ending with 0x0FFFFFFF. What does this value signify?

A.End-of-file marker
B.Free cluster
C.Reserved cluster
D.Bad cluster
AnswerA

In a FAT32 file system, each cluster is represented by a 32-bit entry in the File Allocation Table, and the value 0x0FFFFFFF (along with 0x0FFFFFF8–0x0FFFFFFF) marks the last cluster of a file's cluster chain. This end-of-cluster-chain marker tells the operating system that no further clusters follow, so the file's data ends at that cluster. It is not a byte offset or a physical sector location, but a logical FAT entry indicating chain termination.

Why this answer

In FAT32 file systems, the File Allocation Table (FAT) uses 32-bit entries to track cluster allocation. The value 0x0FFFFFFF is the defined end-of-file (EOF) marker, indicating that the current cluster is the last in a file's cluster chain. This is a standard FAT32 convention, distinct from other special values like free or bad clusters.

Exam trap

The trap here is confusing the FAT32 EOF marker (0x0FFFFFFF) with the bad cluster marker (0x0FFFFFF7) or the reserved cluster range (0x0FFFFFF0–0x0FFFFFF6), as EC-Council often tests the exact hex values to catch candidates who memorize concepts without the precise numbers.

How to eliminate wrong answers

Option B is wrong because a free cluster is represented by the value 0x00000000 in FAT32, not 0x0FFFFFFF. Option C is wrong because reserved clusters are indicated by values in the range 0x0FFFFFF0 through 0x0FFFFFF6, not 0x0FFFFFFF. Option D is wrong because a bad cluster is marked with the value 0x0FFFFFF7 in FAT32, which is a specific sentinel for physical media defects.

413
Multi-Selectmedium

A forensics lab is preparing a new acquisition workstation for imaging suspect drives. The lab manager wants to ensure the workstation itself does not introduce evidence contamination or alter suspect media during imaging. Which two practices should be implemented? (Choose two.)

Select 2 answers
A.Install the suspect drive's original operating system on the workstation to match the environment
B.Use a hardware write-blocker between the workstation and the suspect drive
C.Disable the workstation's antivirus to improve imaging speed
D.Verify the acquired image hash against the source drive hash after imaging
E.Connect the suspect drive as the primary boot device to speed up access
AnswersB, D

A hardware write-blocker prevents the workstation from writing to the suspect drive, preserving the original media during imaging. This is a core lab practice to avoid evidence contamination and to ensure the source hash matches the image. Without it, the workstation could modify file system metadata and invalidate the acquisition.

Why this answer

The two practices that directly prevent contamination and alteration are using a hardware write-blocker and verifying the image hash against the source. The write-blocker stops writes to the suspect drive, and the hash comparison proves the image is an exact copy. The other options either modify the suspect drive, introduce unrelated data, or do not address evidence integrity.

Exam trap

The trap here is thinking that faster or more convenient configurations, such as booting from the suspect drive, are acceptable when they actually alter the evidence.

414
MCQhard

During an incident response, a first responder needs to collect volatile data from a compromised Windows 10 system. The system has PowerShell v5.1 available. Which PowerShell cmdlet should be used to capture a list of currently running processes with their associated command lines?

A.Get-Process | Where-Object {$_.CommandLine -ne $null}
B.Get-CimInstance Win32_Process | Select-Object Name, ProcessId, CommandLine
C.Get-WmiObject -Class Win32_Process | Export-Csv processes.csv
D.Get-Process | Format-List *
AnswerB

Get-CimInstance Win32_Process retrieves process information including the CommandLine property, which shows the full command used to start each process. Selecting Name, ProcessId, and CommandLine provides a clear, concise list. This is essential for identifying malicious processes with suspicious arguments. It is a reliable method on Windows 10 with PowerShell v5.1.

Why this answer

The Win32_Process CIM class includes the CommandLine property, which reveals the full command line for each process. Using Get-CimInstance with Select-Object for Name, ProcessId, and CommandLine provides a precise and efficient capture. Other options either lack command-line data or use deprecated cmdlets.

This approach is reliable and non-intrusive for volatile data collection.

Exam trap

The trap here is assuming that Get-Process returns command-line arguments, when in fact it does not; command lines require querying the Win32_Process class via CIM or WMI.

415
Multi-Selectmedium

Which TWO of the following tools are primarily used for timeline analysis in digital forensics? (Select TWO.)

Select 2 answers
A.Nmap
B.The Sleuth Kit (mactime)
C.Autopsy
D.Plaso
E.Wireshark
AnswersB, D

The Sleuth Kit's mactime tool parses the body file format produced by fls and other TSK tools to generate chronological timelines from disk images. It specifically correlates MACB times (modification, access, change, birth) for filesystem objects, enabling investigators to reconstruct file activity across a timeline. As a focused command-line utility within a broader forensic toolkit, mactime is a primary and canonical tool for timeline analysis, which is why this option is correct.

Why this answer

The Sleuth Kit's mactime tool (option B) is correct because it builds a bodyfile of MAC times (modified, accessed, changed, and created timestamps) from file system metadata and renders it into a chronological timeline, which is the core of timeline analysis in digital forensics. Plaso (option D) is also correct because it is a Python-based engine that parses many artifact types and, via its log2timeline/psort components, produces a super-timeline correlating events across sources, making it a primary timeline analysis tool. Autopsy (option C) is a full forensic platform that can display timelines, but it is not primarily a timeline analysis tool in the sense of the dedicated mactime and Plaso utilities.

Nmap (option A) is a network discovery and port-scanning tool, and Wireshark (option E) is a packet capture and protocol analyzer; neither is designed for building forensic event timelines.

Exam trap

EC-Council often tests the distinction between tools that are 'used in forensics' versus those 'primarily for timeline analysis,' so candidates may mistakenly select Autopsy because it is a popular forensics suite, but it is not a dedicated timeline analysis tool like mactime or Plaso.

416
Multi-Selecthard

Which THREE of the following are commonly used for persistence on a Windows system? (Choose THREE.)

Select 3 answers
A.LNK files
B.Registry Run keys
C.Service installations
D.Prefetch files
E.Scheduled tasks
AnswersB, C, E

Run keys under HKCU and HKLM execute specified programs at user logon or system start, giving malware automatic re-execution across reboots. This satisfies the persistence requirement by surviving restarts without further user action, unlike one-off execution or volatile artefacts.

Why this answer

Registry Run keys (B) are a classic Windows persistence mechanism because entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run are automatically executed at user logon or system startup. Service installations (C) provide persistence by registering a service with the Service Control Manager (e.g., via sc.exe create or New-Service), allowing malicious code to run at boot under a privileged context. Scheduled tasks (E) persist by creating a task through schtasks.exe or the Task Scheduler COM API that triggers execution at logon, startup, or on a schedule.

LNK files (A) are shortcut files that can execute payloads when clicked but are not an automatic persistence mechanism by themselves, and Prefetch files (D) are forensic artifacts generated by the Windows prefetcher to speed up application launches, not a persistence technique.

Exam trap

EC-CHFI often tests the distinction between execution artifacts (like Prefetch files) and actual persistence mechanisms, leading candidates to mistakenly select Prefetch because it records execution, but it does not cause automatic re-execution.

417
MCQmedium

A forensic investigator finds a suspicious file named `cmd.aspx` in the web root of a compromised IIS server. The file contains code that accepts command input via HTTP GET parameters and executes it on the server. What is the MOST likely classification of this file?

A.Trojan horse
B.Cross-site scripting (XSS) exploit
C.SQL injection payload
D.Web shell
AnswerD

A web shell is a malicious script placed on a web server that accepts commands via HTTP parameters—often using names like 'cmd'—to execute system processes, upload/download files, or create reverse shells. It provides persistent remote command execution and is the precise classification for a file that appears to be a command execution handler on an infected web server. This matches the forensic finding exactly.

Why this answer

A file that accepts commands via HTTP and executes them on the server is a web shell. ASPX is a common extension for .NET web shells.

418
MCQmedium

During an investigation, a forensic analyst must preserve a hard drive that is part of a RAID array. Which of the following is the MOST appropriate method to preserve the evidence?

A.Power off the system and remove only the drive with the operating system
B.Disconnect all drives and image a logical volume after the RAID controller
C.Image each physical drive individually using a write blocker
D.Rebuild the array in a different system and then image
AnswerC

Imaging each physical drive individually with a write blocker is the correct forensic method because it guarantees that no write operations reach the source disks, allowing a true bit-for-bit copy of every member, including unallocated space, deleted metadata, and RAID configuration data. With complete images of all drives, the array can be reconstructed offline in a controlled environment using tools like mdadm or specialist RAID recovery software, preserving the original order and stripe parameters. This maintains chain of custody and enables repeatable analysis without modifying evidence.

Why this answer

Imaging each physical drive individually with a write blocker preserves the exact bit-for-bit state of every disk in the RAID array, including metadata, parity, and superblock information. This approach ensures that the logical volume can be reconstructed later in a controlled environment without altering the original evidence, which is critical for maintaining chain of custody and forensic integrity.

Exam trap

EC-Council often tests the misconception that imaging a logical volume or rebuilding the array is acceptable, but the trap here is that any operation that allows the RAID controller or OS to write to the drives (even during a read) can alter evidence, making individual physical imaging with a write blocker the only forensically sound method.

How to eliminate wrong answers

Option A is wrong because removing only the operating system drive from a RAID array destroys the array's configuration and may cause the controller to mark the remaining drives as degraded or foreign, potentially overwriting critical metadata. Option B is wrong because imaging a logical volume after the RAID controller introduces the risk of the controller altering data during read operations (e.g., on-the-fly parity recalculation or bad block remapping), and it does not capture the physical state of each drive, which may be needed for parity analysis or recovery of deleted data. Option D is wrong because rebuilding the array in a different system can trigger automatic synchronization or reconstruction processes that modify data on the drives, thereby contaminating the evidence and violating forensic best practices.

419
MCQhard

A forensic examiner is analyzing an Android device that has been factory reset. Which of the following artefacts is MOST likely to still be recoverable from the device's flash memory after a factory reset, assuming no overwrite has occurred?

A.The GUID Partition Table (GPT)
B.The device's encryption keys
C.The Android OS system files
D.User data such as photos and contacts
AnswerD

A factory reset in Android formats the userdata partition by deleting its ext4 or f2fs metadata and marking blocks as free, but it does not necessarily overwrite the underlying sectors on the flash storage. Forensic examiners can therefore carve files from unallocated space using techniques like file signature carving, and if the device's encryption was disabled or the cryptographic keys can be derived/reset, data like photos and contacts may be reconstructed. This is precisely why the examiner should focus on residual user data in unallocated space after a reset.

Why this answer

After a factory reset on an Android device, the operating system typically performs a 'fastboot format' or 'wipe data/factory reset' which only unmounts the userdata partition and marks its blocks as free in the ext4 or F2FS filesystem metadata. The actual user data (photos, contacts, etc.) remains physically stored in the NAND flash memory until those blocks are overwritten by new data. Because no overwrite has occurred in this scenario, the raw data is still recoverable using forensic tools that bypass the filesystem and read the flash memory directly.

Exam trap

EC-Council often tests the misconception that a factory reset securely erases all data, when in fact it only removes filesystem pointers, leaving the underlying data recoverable until overwritten.

How to eliminate wrong answers

Option A is wrong because the GUID Partition Table (GPT) is stored in the boot partition area (LBA 1–34) and is not erased or affected by a factory reset; it remains intact and is not a user-data artifact. Option B is wrong because encryption keys are stored in the device's dedicated hardware-backed keystore (e.g., Trusted Execution Environment or StrongBox) and are securely wiped or invalidated during a factory reset, making them unrecoverable. Option C is wrong because Android OS system files reside in the system partition, which is read-only and not modified by a factory reset; they are not user data and are not the target of recovery in this context.

420
MCQmedium

A security analyst is reviewing Apache access logs and finds repeated requests to /index.php?id=1' OR '1'='1. Which type of attack is MOST likely being attempted?

A.Remote file inclusion
B.Path traversal
C.SQL injection
D.Cross-site scripting (XSS)
AnswerC

This payload is a textbook SQL injection tautology: placing 1' OR '1'='1 inside a WHERE clause, such as WHERE user='admin' AND pass='1' OR '1'='1', makes the entire predicate evaluate to true, allowing authentication bypass or full table extraction. In an Apache access log, the malicious string can appear as part of the request URI or, less commonly, in the request body when access logging includes POST data. The single quote breaks out of the SQL string literal, and the OR condition forces a true result for every row, which is the definitive indicator of SQL injection testing or exploitation. Any defense should focus on parameterized queries, not input filtering alone, because the payload is syntactically valid SQL.

Why this answer

The pattern 1' OR '1'='1 is a classic SQL injection payload attempting to bypass authentication or extract data. The single quote and OR condition are characteristic of SQLi.

421
Multi-Selecthard

Which TWO of the following are valid methods to collect logs from Docker containers for forensic analysis? (Select TWO)

Select 2 answers
A.Using docker logs command to retrieve container logs
B.Using docker inspect to get log configuration
C.Copying log files from the container using docker cp
D.Using docker exec to run syslog inside the container
E.Using docker image to view the image layers
AnswersA, C

The `docker logs` command is the canonical method for retrieving the console output of a container, as it reads the stdout and stderr streams that were captured by the container runtime. By default, these streams are stored in a JSON-file log on the host under `/var/lib/docker/containers/<container-id>/<container-id>-json.log`, and `docker logs` presents them in a human-readable format. It also supports flags like `--since`, `--tail`, and `--follow` to filter or stream the logs, making it a direct and efficient way to collect a container's standard output without needing to access its filesystem.

Why this answer

Option A is correct because the `docker logs` command retrieves the stdout/stderr output captured by the container's configured logging driver (e.g., json-file, journald), which is the primary source of application logs for forensic review. Option C is correct because `docker cp` allows an investigator to copy log files written inside the container's filesystem (e.g., /var/log/app.log) to the host for offline analysis, which is essential when logs are not sent to stdout/stderr. Option B is not a collection method; `docker inspect` only reveals the logging driver and configuration (such as LogPath), not the log contents themselves.

Option D is not a valid collection method because running syslog inside the container starts a new logging service rather than extracting existing container logs. Option E is incorrect because `docker image` inspects image layers and metadata, which contain no runtime container logs.

Exam trap

EC-Council often tests the distinction between commands that retrieve logs (`docker logs`, `docker cp`) versus commands that inspect configuration or modify the container, leading candidates to mistakenly select `docker inspect` or `docker exec` as log collection methods.

422
MCQhard

During a forensic investigation, a first responder notices that a computer is running and suspects that volatile data may be present. According to best practices, what should the responder do to preserve the most volatile data first?

A.Perform a graceful shutdown to avoid data corruption
B.Remove the hard drive immediately while the system is running
C.Capture the contents of RAM using a forensic tool, then shut down
D.Immediately unplug the power cord to freeze the system state
AnswerC

This is the correct action because RAM is the most volatile data store and must be captured first per the forensics order of volatility (RFC 3227). A trusted memory acquisition tool — such as FTK Imager, WinPmem, or LiME — creates a bit-for-bit copy of physical memory, which is hashed (e.g., SHA-256) to preserve integrity. After the memory image is securely stored on external media, an administrator-issued shutdown writes only unavoidable OS logs and closes services in a controlled manner, preserving the disk while the critical volatile evidence is already secured.

Why this answer

Volatile data, such as the contents of RAM, is lost when power is removed. The first responder must capture this data using a forensic tool (e.g., FTK Imager, WinPmem, or LiME) before performing a shutdown. This follows the Order of Volatility (RFC 3227), which prioritizes capturing registers, cache, and RAM before any persistent storage.

Exam trap

The trap here is that candidates often confuse 'preserving data integrity' with 'avoiding corruption' and choose a graceful shutdown (Option A), not realizing that the shutdown process itself destroys the most volatile evidence.

How to eliminate wrong answers

Option A is wrong because a graceful shutdown allows the operating system to overwrite or clear volatile data (e.g., memory pages, temporary files, and encryption keys) during the shutdown process, destroying potential evidence. Option B is wrong because removing the hard drive while the system is running can cause electrical damage to the drive and controller, and it does not preserve RAM; the volatile data in memory is lost immediately when power is interrupted. Option D is wrong because immediately unplugging the power cord causes an abrupt loss of power, which destroys all volatile data in RAM and cache, and may also cause filesystem corruption on the hard drive due to incomplete write operations.

423
MCQhard

During a forensic examination of a macOS system, you find a file at /private/var/log/system.log and also notice a directory /private/var/db/diagnostics/. What is the significance of these locations?

A.They are both plain-text log files used for system monitoring
B.The diagnostics directory contains binary log data from the unified logging system
C.The diagnostics directory contains compressed archives of system.log
D.These locations are remnants of third-party security software
AnswerB

The diagnostics directory is the on-disk repository for unified logging, introduced in macOS Sierra, where entries are stored in compressed binary tracev3 files. These files capture detailed event-level data with nanosecond timestamps, message metadata, and privacy-scoped redaction, making them a rich source for forensic timelines. Investigators typically query this store with the 'log' command, not with text editors.

Why this answer

/private/var/db/diagnostics/ stores binary log data from Apple's unified logging system (os_log), which is the primary logging mechanism in macOS since Yosemite. Unlike the plain-text /private/var/log/system.log, these binary logs capture high-fidelity, structured diagnostic data that can be queried using the `log` command (e.g., `log show --archive`). This directory is critical for forensic analysis of system events, crashes, and performance issues.

Exam trap

EC-Council often tests the misconception that all macOS logs are plain-text files, leading candidates to overlook the binary unified logging system stored in /private/var/db/diagnostics/.

How to eliminate wrong answers

Option A is wrong because /private/var/db/diagnostics/ does not contain plain-text log files; it stores binary log archives from the unified logging system, while /private/var/log/system.log is a plain-text file. Option C is wrong because the diagnostics directory does not contain compressed archives of system.log; it holds binary .tracev3 and .logarchive files that are independent of the legacy system.log. Option D is wrong because these are native macOS system directories, not remnants of third-party security software; they are part of Apple's core logging infrastructure.

424
MCQhard

A forensic analyst is investigating a MySQL database server breach. Which log is MOST useful for identifying a series of queries that exfiltrated data, assuming the attacker used a compromised application account?

A.General query log
B.Binary log
C.Slow query log
D.Error log
AnswerA

The general query log is the only MySQL log that records the complete text of every SQL statement as received from clients, including plain SELECT queries used for data exfiltration. When enabled (general_log=ON), each client connection and statement is written to a file or table, giving an investigator a direct timeline of query activity, timestamps, and the exact data being read. It is the definitive source for detecting and reconstructing unauthorized data retrieval.

Why this answer

MySQL general query log logs all queries, but can be resource-intensive. Binary logs record changes. Error logs contain errors.

Slow query log logs slow queries. The general query log is best for seeing all queries from a compromised account.

425
MCQhard

A SOC analyst is analyzing a packet capture from a network where an internal host communicated with a known malicious IP. The analyst uses Wireshark and applies a display filter to isolate all HTTP traffic. Which filter expression should he use?

A.http.request
B.ip.proto == 6
C.tcp.port == 80
D.http
AnswerD

The 'http' filter is correct because it selects every packet in which Wireshark's HTTP dissector successfully identifies HTTP protocol data, encompassing requests, responses, status lines, headers, and bodies. Unlike port-based filters, it is application-layer aware and verifies the presence of HTTP semantics, not just a well-known port number. This makes it the precise, protocol-specific filter an SOC analyst should use to capture the complete picture of HTTP traffic on the wire.

Why this answer

The correct filter is 'http' because in Wireshark, simply typing 'http' as a display filter captures all HTTP traffic, including both requests and responses. This is the most straightforward way to isolate all HTTP packets without limiting to a specific direction or port.

Exam trap

The trap here is that candidates often confuse display filters with capture filters or assume that HTTP traffic only uses port 80, leading them to choose 'tcp.port == 80' instead of the simpler and more comprehensive 'http' filter.

How to eliminate wrong answers

Option A is wrong because 'http.request' only filters for HTTP request packets, not responses, so it would miss half the HTTP traffic. Option B is wrong because 'ip.proto == 6' filters for TCP protocol traffic in general, not specifically HTTP, and would include all TCP-based protocols (e.g., SSH, FTP). Option C is wrong because 'tcp.port == 80' filters traffic on TCP port 80, but HTTP can also run on other ports (e.g., 8080, 8000), and it would miss HTTP traffic on non-standard ports.

426
MCQmedium

An email forensic analyst receives a suspicious email and wants to verify the originating IP address. The analyst extracts the email headers and sees multiple 'Received' fields. Which 'Received' header should the analyst consider as the most trustworthy source of the sender's IP?

A.The first 'Received' header at the top
B.The last 'Received' header at the bottom
C.The 'X-Originating-IP' header
D.The 'Return-Path' header
AnswerB

The bottommost Received header is chronologically the first hop recorded, inserted by the sender's first SMTP server or mail user agent at the time of submission. It is the deepest part of the routing chain and provides the closest traceable IP/HELO information to the true origin, making it the best evidence for identifying the actual source. Analysts rely on this header because subsequent servers append above it without altering its content in normal operation.

Why this answer

The last 'Received' header at the bottom is the most trustworthy because email headers are added in reverse chronological order: each mail server prepends its own 'Received' field to the top of the header block. Therefore, the bottommost 'Received' header represents the first hop from the sender's MTA (Mail Transfer Agent) or the originating client, making it the closest to the true source IP.

Exam trap

A common trap in CHFI is to assume headers are chronological from top to bottom, leading candidates to select the first 'Received' header as the origin. In reality, the bottommost header is the earliest hop.

How to eliminate wrong answers

Option A is wrong because the first 'Received' header at the top is the most recent addition, added by the recipient's mail server, not the sender's; it reflects the last hop, not the origin. Option C is wrong because 'X-Originating-IP' is a non-standard, optional header that may be set by the sender's webmail interface (e.g., Outlook Web Access) but is often absent, easily spoofed, or not present in SMTP-transmitted emails; it is not a reliable forensic source. Option D is wrong because the 'Return-Path' header (or envelope sender) contains the bounce address (MAIL FROM) and is set by the sender's MTA, but it does not carry the originating IP address; it is used for delivery failure notifications, not for IP traceability.

427
MCQhard

A forensic investigator is analyzing a malware sample that appears to be packed. Using PEiD, the analyst detects an entropy value of 7.8 and the entry point section is named 'UPX0'. Which of the following tools should the analyst use NEXT to unpack the malware for static analysis?

A.UPX -d
B.Ghidra
C.Process Monitor
D.IDA Pro
AnswerA

UPX -d is the correct command-line invocation because the -d flag tells the UPX utility to decompress (unpack) an executable that was previously packed with UPX. This restores the original program code and data so a malware analyst can statically inspect the actual malicious logic rather than the small decompression stub. It is the most direct, automated method available in the standard toolset for this exact purpose.

Why this answer

The presence of 'UPX0' as the entry point section name and an entropy value of 7.8 (very high, indicating compression or encryption) strongly suggests the malware is packed with UPX (Ultimate Packer for eXecutables). The correct next step is to use UPX with the -d (decompress) switch to unpack the binary, restoring the original executable for static analysis. This is a standard, reversible unpacking method that does not require dynamic analysis or disassembly of the packed stub.

Exam trap

EC-Council often tests the distinction between tools for unpacking versus tools for analysis, expecting candidates to recognize that UPX -d is the direct unpacking utility, while Ghidra and IDA Pro are analysis tools that require an already-unpacked binary for effective static analysis.

How to eliminate wrong answers

Option B (Ghidra) is wrong because Ghidra is a reverse-engineering framework for disassembly and decompilation, not a dedicated unpacking tool; attempting to analyze a packed binary in Ghidra without first unpacking it would yield obfuscated or compressed code, making static analysis ineffective. Option C (Process Monitor) is wrong because Process Monitor is a dynamic analysis tool for capturing real-time system activity (registry, file system, process/thread activity), not for unpacking or static analysis of a binary. Option D (IDA Pro) is wrong because IDA Pro is an interactive disassembler and debugger; while it can be used to analyze packed binaries with plugins, the immediate next step after detecting UPX packing is to use the UPX tool itself to decompress the file, as IDA Pro is not a dedicated unpacker and would still require unpacking first for effective static analysis.

428
MCQhard

An incident responder is analyzing a compromised web server and finds a file named 'cmd.aspx' in the uploads directory. The file contains ASP.NET code that accepts commands via the 'cmd' parameter and executes them on the server. Which of the following best describes this artifact?

A.A legitimate administrative tool for server management
B.A webshell allowing remote command execution
C.A backdoor installed via a SQL injection vulnerability
D.A malware dropper for deploying ransomware
AnswerB

The file is a webshell because it accepts attacker-supplied input through HTTP parameters and passes it directly to a function such as system(), exec(), shell_exec(), or eval(). This provides unauthenticated remote command execution on the web server, allowing an attacker to run arbitrary commands, read sensitive files, or pivot to the internal network. The presence of obfuscated code, a small file size, and a recently modified timestamp in a writable web directory strongly corroborates this conclusion.

Why this answer

The file 'cmd.aspx' is an ASP.NET webshell that accepts commands via the 'cmd' parameter and executes them server-side. This is a classic indicator of a webshell, which provides remote command execution (RCE) capabilities to an attacker, not a legitimate administrative tool.

Exam trap

The CHFI exam often tests the distinction between the artifact itself (webshell) and the method of compromise (e.g., SQL injection), so candidates may incorrectly choose option C because they focus on how the file got there rather than what the file is.

How to eliminate wrong answers

Option A is wrong because legitimate administrative tools for ASP.NET server management (e.g., Remote Desktop, PowerShell Remoting, or IIS Manager) do not use a single file named 'cmd.aspx' in an uploads directory; such tools require authentication and are not typically placed in user-writable folders. Option C is wrong because while SQL injection could be used to upload a webshell, the artifact itself is the webshell, not the injection vector; the question asks what the file 'cmd.aspx' best describes, not how it was installed. Option D is wrong because a malware dropper is a program that installs other malware (e.g., ransomware), but 'cmd.aspx' is a webshell that provides interactive command execution, not a dropper that deploys additional payloads.

429
MCQhard

During a forensic investigation, an analyst uses the following command: dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync. What is the effect of the conv=noerror,sync option?

A.It verifies the integrity of the image using a hash algorithm
B.It ignores read errors and pads bad blocks with zeros in the output image
C.It creates a compressed image to save disk space
D.It enables logging of all I/O errors to a separate file
AnswerB

The `noerror` flag instructs `dd` to continue copying when it encounters read errors, while the `sync` flag pads each failed read block with zeros so that the output image retains the same block size and overall length as the source. This prevents the process from aborting and produces a complete, though partially zero-filled, image for analysis. Without these flags, `dd` would terminate on the first read error and leave an incomplete image.

Why this answer

The `conv=noerror,sync` option in `dd` instructs the tool to continue processing even when a read error is encountered (`noerror`) and to pad the output block with zeros (`sync`) to maintain the correct block size and offset alignment. This ensures that the forensic image remains a bit-for-bit copy of the source device in terms of size and structure, with corrupted sectors replaced by zeros rather than causing the imaging process to abort or produce a truncated image.

Exam trap

The CHFI exam often tests the misconception that `conv=noerror,sync` performs error correction or data recovery, when in fact it simply ignores errors and pads with zeros, which can lead to data loss if the analyst assumes the image is pristine.

How to eliminate wrong answers

Option A is wrong because `conv=noerror,sync` does not perform any hash verification; integrity verification is done separately using tools like `md5sum`, `sha1sum`, or `dd` with `conv=noerror` combined with a separate hash calculation. Option C is wrong because `dd` does not compress data; compression requires piping through `gzip` or using `conv=lz4` (if supported) or a separate compression tool. Option D is wrong because `dd` does not have a built-in logging feature for I/O errors; error logging must be implemented by redirecting stderr or using wrapper scripts.

430
MCQeasy

In the context of the US Fourth Amendment, what is typically required for law enforcement to seize a computer for forensic examination?

A.A subpoena duces tecum
B.No legal authorization is needed if the computer is in plain view
C.Consent of the owner, a warrant, or exigent circumstances
D.Only a warrant issued by a judge
AnswerC

A computer may be lawfully seized under the Fourth Amendment based on (1) a warrant issued by a judge upon probable cause and particularly describing the things to be seized; (2) voluntary and intelligent consent given by the owner or a person with apparent authority, which can be limited in scope; or (3) exigent circumstances, such as imminent destruction of evidence or a threat to safety, that justify immediate action before obtaining a warrant. These are well-established exceptions routinely applied in digital forensics, allowing officers to secure a device while awaiting a warrant or to accept a user's consent to search and seize it. Therefore, this option correctly enumerates the primary situations in which computer seizure is lawful.

Why this answer

The Fourth Amendment requires law enforcement to obtain a warrant based on probable cause, obtain the owner's consent, or demonstrate exigent circumstances before seizing a computer for forensic examination. This protects against unreasonable searches and seizures, and a computer's storage capacity means it can contain vast amounts of personal data, so the same constitutional protections apply as to a physical home or vehicle.

Exam trap

EC-Council often tests the misconception that a warrant is always required, ignoring that consent and exigent circumstances are equally valid legal bases for seizure without a warrant.

How to eliminate wrong answers

Option A is wrong because a subpoena duces tecum compels the production of documents or records, but it does not authorize law enforcement to physically seize a computer for forensic examination; it is a discovery tool, not a search warrant. Option B is wrong because the plain view doctrine only applies if the officer is lawfully present and the incriminating nature of the computer is immediately apparent, but it does not automatically permit seizing the device for a full forensic examination without a warrant or other exception. Option D is wrong because while a warrant is a common method, it is not the only method; consent and exigent circumstances are also valid exceptions under the Fourth Amendment.

431
MCQmedium

Which Windows artifact is specifically designed to track the most recently used (MRU) files for specific applications and can be found in the NTUSER.DAT registry hive?

A.Prefetch files
B.Jump Lists
C.MRU lists in the registry
D.LNK files
AnswerC

Most Recently Used (MRU) lists in the registry are exactly the artifact designed for tracking recently opened files. For example, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU stores PIDLs of files selected through common dialog boxes, while application-specific keys like HKCU\Software\Microsoft\Notepad and HKCU\Software\Microsoft\WordPad record the last file paths opened by those applications. These registry values are maintained by the operating system and applications specifically to store this historical MRU data, making them the canonical answer.

Why this answer

The NTUSER.DAT registry hive contains per-user MRU (Most Recently Used) lists that track files recently accessed by specific applications, such as the 'RecentDocs' key for Office applications or 'ComDlg32' for common dialog boxes. These registry keys are explicitly designed to store MRU data, making them the direct artifact for this purpose.

Exam trap

EC-Council often tests the distinction between registry-based MRU lists (stored in NTUSER.DAT) and file-system artifacts like Jump Lists or LNK files, so candidates mistakenly choose Jump Lists because they also track recent files, but they are not stored in the registry hive.

How to eliminate wrong answers

Option A is wrong because Prefetch files are located in the C:\Windows\Prefetch folder and track application launch sequences and file paths for system-wide performance optimization, not per-user MRU lists in the registry. Option B is wrong because Jump Lists are stored as .customDestinations-ms files in the user's AppData\Roaming\Microsoft\Windows\Recent directory and provide a graphical list of recent files for taskbar applications, but they are not stored in the NTUSER.DAT hive. Option D is wrong because LNK files (shortcuts) are stored in the user's Recent folder and other locations, tracking file access via shell link data, but they are not registry-based MRU lists within NTUSER.DAT.

432
MCQeasy

A first responder arrives at a crime scene where a computer is powered on and displaying a desktop. According to best practices, which of the following actions should the responder take FIRST?

A.Press Ctrl+Alt+Del to check for active user sessions.
B.Connect a write blocker and begin imaging the hard drive.
C.Unplug the power cord immediately to preserve volatile data.
D.Photograph the scene and the computer screen.
AnswerD

Photographing the scene and the computer screen is the first and most critical step because it creates a permanent, objective record of the system's exact state before any interaction occurs. The display may contain incriminating messages, open files, or system logs that are purely volatile and would be lost if the computer is touched, rebooted, or powered down. This documentation, including cable connections and visible media, solidifies the chain of custody and provides the contextual integrity that later forensic analysis depends on, which is why it takes precedence over any hardware or software intervention.

Why this answer

The first priority at a live crime scene is to document the state of the system before any interaction. Photographing the screen captures volatile data (e.g., open windows, running processes, time) that would be lost upon any keystroke or power change. This aligns with the order of volatility (RFC 3227) and ensures a legally defensible chain of custody from the outset.

Exam trap

The CHFI exam often tests the misconception that preserving volatile data means immediately pulling the plug, when in fact the correct first step is to document the live state without altering it.

How to eliminate wrong answers

Option A is wrong because pressing Ctrl+Alt+Del alters the system state (e.g., may trigger a secure attention sequence, lock the screen, or launch Task Manager), potentially destroying volatile evidence and violating the principle of non-interference. Option B is wrong because connecting a write blocker and imaging the hard drive requires physical access and software interaction that can modify the system’s memory and state; imaging should only occur after documenting and preserving volatile data. Option C is wrong because unplugging the power cord immediately destroys all volatile data (RAM, network connections, process lists) and can cause file system corruption, which is contrary to the goal of preserving evidence.

433
Multi-Selecthard

A first responder arrives at a crime scene where a computer is running. Which THREE actions should the first responder take to preserve volatile evidence?

Select 3 answers
A.Collect contents of RAM using a tool like FTK Imager or dd
B.Unplug the power cord immediately
C.Record active network connections using netstat
D.Run a full antivirus scan on the system
E.Photograph the screen to capture current state
AnswersA, C, E

Collecting RAM with FTK Imager or dd is correct because memory holds volatile, ephemeral data—encryption keys, plaintext credentials, running processes, injected code, and evidence of malware that never touches disk. FTK Imager can create a forensic memory dump while dd, if used with a memory-specific driver, also works; both must be executed carefully to avoid altering the state they are capturing. This action preserves the single most fragile category of evidence before it disappears the moment the system loses power or reboots.

Why this answer

Option A is correct because RAM contents are highly volatile and lost on power-off, so capturing memory with a tool like FTK Imager or dd preserves running processes, encryption keys, and other in-memory artifacts. Option C is correct because netstat records active network connections and listening ports, which are volatile and can reveal remote sessions or exfiltration activity before they disappear. Option E is correct because photographing the screen captures the current visual state of the running system, including open windows and displayed data, without altering the machine.

Option B is not appropriate because unplugging the power cord immediately destroys volatile evidence such as RAM and active connections. Option D is not appropriate because running an antivirus scan modifies the system, overwrites volatile data, and can destroy evidence rather than preserve it.

Exam trap

EC-Council often tests the misconception that immediately cutting power is the safest action, but the trap is that this destroys the most volatile evidence (RAM) and can corrupt the filesystem, whereas a proper forensic response prioritizes capturing memory first.

434
MCQmedium

During a malware investigation, you find that a process named `svchost.exe` is making outbound connections to an IP address known to be malicious. What tool would be BEST to capture the network traffic for further analysis?

A.PEiD
B.Process Explorer
C.Regshot
D.Wireshark
AnswerD

Wireshark is the correct tool because it is a network protocol analyzer that captures live packets and decodes hundreds of protocols, allowing you to inspect individual frames, follow TCP streams, and filter traffic by IP, port, or protocol. In a malware investigation, it reveals command-and-control activity, malicious payloads, and data exfiltration patterns associated with the suspicious process's network communications.

Why this answer

Wireshark is the best tool for capturing and analyzing network traffic because it can intercept packets at the network interface level, allowing you to inspect the full payload and headers of outbound connections from `svchost.exe` to the malicious IP. This enables deep analysis of protocols, data exfiltration attempts, and command-and-control communication patterns, which is essential in malware forensics.

Exam trap

EC-Council often tests the distinction between process analysis tools (like Process Explorer) and network analysis tools (like Wireshark), leading candidates to mistakenly choose Process Explorer because it can show network connections in its lower pane, but it cannot capture or inspect packet contents.

How to eliminate wrong answers

Option A is wrong because PEiD is a tool for detecting packers, cryptors, and compilers in executable files, not for capturing network traffic. Option B is wrong because Process Explorer is a process management and analysis tool that shows process details, handles, and DLLs, but it does not capture or analyze network packets. Option C is wrong because Regshot is a registry comparison tool used to detect changes made to the Windows registry, not for network traffic capture.

435
MCQhard

During an internal investigation, an employee is suspected of leaking sensitive data. The security team finds that the employee's computer has been turned off. Which of the following evidence types would be LOST due to the system being powered off?

A.System logs stored in the Event Viewer
B.Files stored on the hard drive
C.Registry hives
D.Contents of RAM and network connections
AnswerD

The contents of RAM and active network connections are the most volatile evidence on a live system. RAM loses all data the instant power is cut, wiping out running processes, open network sockets, and any decrypted data or encryption keys; likewise, the current TCP/UDP connection table, ARP cache, and routing state exist only while the operating system is operational. Consequently, these must be captured using live forensic toolkits before shutdown, as any delay or power loss destroys them irrecoverably.

Why this answer

When a system is powered off, the contents of volatile memory (RAM) are immediately lost because RAM requires constant electrical power to retain data. Similarly, active network connections are terminated and their state is lost, as they are maintained in kernel memory structures that are not persisted to disk. Therefore, any evidence residing only in RAM (e.g., encryption keys, running processes, unencrypted data) or transient network session details (e.g., active TCP/UDP connections, IP addresses) is permanently lost upon shutdown.

Exam trap

The CHFI exam often tests the distinction between volatile and non-volatile evidence, and the trap here is that candidates mistakenly think system logs or registry hives are volatile because they are 'system' data, when in fact they are stored on the hard drive and persist after power-off.

How to eliminate wrong answers

Option A is wrong because system logs stored in the Event Viewer are written to the hard drive (e.g., %SystemRoot%\System32\winevt\Logs\) and persist across reboots; they are not lost when the system is powered off. Option B is wrong because files stored on the hard drive are non-volatile and remain intact after shutdown; they can be imaged and analyzed forensically even after power loss. Option C is wrong because registry hives (e.g., SAM, SYSTEM, SOFTWARE) are stored as files on the hard drive (e.g., C:\Windows\System32\config\) and survive power-off; they are not dependent on RAM for persistence.

436
MCQeasy

Which mobile forensics tool is specifically designed for physical extraction of iOS devices, including bypassing passcodes and extracting full file system images?

A.Oxygen Forensic Detective
B.Magnet AXIOM
C.Cellebrite UFED
D.GrayKey
AnswerD

GrayKey, developed by Grayshift, is a dedicated iOS forensic tool engineered specifically for physical extraction and passcode bypass. It exploits hardware and software vulnerabilities to gain full file-system access from locked iPhones/iPads, bypassing the Secure Enclave's retry limits. Law enforcement agencies use GrayKey for targeted deep extraction of iOS devices, making it the only option in this list uniquely designed for this purpose.

Why this answer

GrayKey is a specialized forensic tool developed by GrayShift that performs physical extraction on iOS devices, including bypassing passcodes and obtaining full file system images. It exploits hardware and software vulnerabilities in iOS to extract data, making it the correct choice for this specific task.

Exam trap

The trap here is that candidates often confuse Cellebrite UFED's broad device support with the specific ability to perform physical extraction and passcode bypass on iOS, but Cellebrite's iOS capabilities are more limited compared to GrayKey's specialized focus.

How to eliminate wrong answers

Option A is wrong because Oxygen Forensic Detective is a comprehensive forensic platform that supports logical and file system extractions for iOS, but it does not specialize in physical extraction or passcode bypass for iOS devices. Option B is wrong because Magnet AXIOM is a digital forensic tool that focuses on artifact analysis and logical extractions, not physical extraction or passcode bypass for iOS. Option C is wrong because Cellebrite UFED supports physical extraction for many devices, but for iOS, it primarily relies on logical extraction or using the device's backup, and does not consistently bypass passcodes for full physical extraction like GrayKey does.

437
MCQhard

During a forensic examination of a solid-state drive (SSD), the analyst notices that the TRIM command was enabled. What challenge does this pose for data recovery?

A.It erases data blocks immediately after deletion, preventing recovery
B.It causes fragmentation, making file recovery more complex
C.It causes the drive to encrypt data automatically
D.It physically destroys the NAND cells, making the drive unusable
AnswerA

When the OS deletes a file on an SSD with TRIM enabled, it sends an ATA DATA SET MANAGEMENT command that instructs the controller to physically erase the involved NAND blocks right away, rather than simply marking the space as reusable in the file system. This immediate erasure means that the actual data cells are zeroed or invalidated, eliminating the possibility of recovery with conventional file carving or deep recovery tools, which rely on residual data. From a forensic perspective, TRIM effectively defeats many standard deleted-file recovery workflows on modern SSDs.

Why this answer

The TRIM command (ATA Data Set Management command) instructs the SSD controller to immediately erase the physical NAND blocks corresponding to deleted logical block addresses (LBAs). This proactive garbage collection operation resets the cells to an erased state, making it impossible for forensic tools to recover the original data from those blocks, as the data is physically overwritten with null values or marked as invalid.

Exam trap

The trap here is that candidates may confuse TRIM with wear leveling or assume it only affects performance, missing the critical forensic implication that TRIM permanently destroys deleted data at the physical NAND level, making recovery impossible even with advanced techniques like chip-off or JTAG.

How to eliminate wrong answers

Option B is wrong because TRIM does not cause fragmentation; in fact, TRIM helps maintain performance by allowing the SSD controller to optimize block allocation, reducing write amplification and fragmentation. Option C is wrong because TRIM is a command for block erasure, not encryption; SSDs may support hardware encryption (e.g., OPAL or eDrive), but TRIM itself does not encrypt data. Option D is wrong because TRIM does not physically destroy NAND cells; it simply marks blocks as invalid for garbage collection, and normal wear from program/erase cycles is what eventually degrades cells, not the TRIM command itself.

438
MCQeasy

A first responder is called to a scene where a Windows laptop is suspected of being used in a crime. The laptop is turned on and logged in. The responder needs to preserve the most volatile evidence first. Which of the following should be captured first?

A.The contents of RAM
B.The event logs
C.The Windows Registry
D.The pagefile.sys file
AnswerA

RAM contains the most volatile data, including running processes, network connections, and encryption keys. It is lost when the system is powered off. Capturing RAM first aligns with the order of volatility and ensures critical evidence is preserved. This is a fundamental first-responder principle for live systems.

Why this answer

The order of volatility dictates that RAM is the most volatile and should be captured first. Registry, pagefile, and event logs are stored on disk and persist after shutdown, making them less volatile. Capturing RAM first ensures that running processes, network connections, and potentially encryption keys are preserved before any other action.

Exam trap

The trap here is assuming that disk-based artifacts like the registry or event logs are more volatile than RAM, when actually RAM is lost immediately upon power-off.

439
MCQeasy

Which of the following is the primary purpose of using a hardware write blocker during disk acquisition?

A.To decrypt the drive during acquisition
B.To prevent any writes to the original evidence drive
C.To compress the acquired image
D.To increase the speed of the acquisition
AnswerB

The primary purpose of a write blocker is to guarantee the integrity of the original evidence by creating a read-only interface between the drive and the forensic workstation. It intercepts and blocks all write commands issued by the operating system, including those that might occur from normal mounting, file system metadata updates, or malware, ensuring the source drive remains bit-for-bit unchanged. This preservation is essential for maintaining a legally defensible chain of custody and allowing a subsequent hash verification to prove evidence authenticity.

Why this answer

A hardware write blocker is a device placed between the suspect drive and the forensic workstation that intercepts and blocks any write commands from the host operating system, ensuring that the original evidence drive remains unaltered. This is critical for maintaining the integrity of digital evidence, as any modification to the source drive could render it inadmissible in court. The primary purpose is therefore to prevent any writes to the original evidence drive, preserving its exact state for forensic analysis.

Exam trap

EC-Council often tests the misconception that a write blocker performs active functions like decryption or compression, when in reality it is a passive hardware filter that only enforces read-only access at the bus level.

How to eliminate wrong answers

Option A is wrong because a hardware write blocker does not perform decryption; decryption requires separate tools or keys and is not a function of write-blocking hardware. Option C is wrong because compression of the acquired image is handled by imaging software (e.g., FTK Imager, dd with gzip) after the write blocker has ensured read-only access, not by the write blocker itself. Option D is wrong because a write blocker does not increase acquisition speed; in fact, it may introduce a slight latency due to the hardware bridge, and speed is determined by the interface (e.g., SATA, USB) and the imaging tool, not the blocker.

440
Multi-Selecteasy

Which TWO of the following are anti-forensic techniques used by malware to evade detection?

Select 2 answers
A.Packing
B.Logging errors
C.Timestomping
D.Encryption of communication
E.Creating mutexes
AnswersA, C

Packing is a legitimate software distribution technique that malicious actors repurpose for anti-forensic effect. A packer compresses and often encrypts the original executable payload, embedding it within a decompressor stub, so the on-disk byte sequence no longer matches known malware signatures. At runtime, the stub unpacks the payload in memory, defeating static signature-based scans and complicating file-level triage by forensic investigators.

Why this answer

Packing (A) is an anti-forensic technique because it compresses or encrypts the malware's executable with a runtime unpacker stub, hiding strings, imports, and code from static analysis tools such as disassemblers and signature scanners. Timestomping (C) is anti-forensic because malware deliberately modifies file system timestamps (e.g., $STANDARD_INFORMATION vs. $FILE_NAME attributes in NTFS) to make malicious files appear older or to blend with legitimate files, frustrating timeline analysis. Logging errors (B) is not anti-forensic; it is a normal software development or debugging practice that actually leaves evidence behind.

Encryption of communication (D) is a defense-evasion/confidentiality technique for command-and-control traffic, not an anti-forensic technique targeting investigator artifacts. Creating mutexes (E) is a host-based evasion technique to prevent multiple malware instances from running, not a method to defeat forensic analysis.

Exam trap

The CHFI exam often tests the distinction between anti-forensic techniques (which actively hide or destroy forensic evidence) and general security mechanisms (like encryption of communication) that do not directly target forensic artifacts.

441
MCQeasy

A junior examiner is preparing a forensics lab workstation that will be used to image suspect drives. The lab policy states the workstation must never write to a connected suspect drive. Which practice ensures this requirement is met?

A.Connect the suspect drive through a hardware write-blocker before imaging
B.Enable BitLocker on the suspect drive before connecting it
C.Mount the suspect drive with the read-only attribute set in Windows Disk Management
D.Image the drive over the network using a mapped drive letter
AnswerA

A hardware write-blocker physically intercepts write commands on the interface, so the suspect drive cannot be modified during imaging. This is the standard lab practice for preserving evidence integrity and is expected by CHFI when acquiring suspect media. Using it before imaging ensures the original drive remains unaltered and the hash of the source matches the image.

Why this answer

Imaging suspect media without altering it requires a hardware write-blocker placed between the workstation and the drive. Software attributes, encryption, and network mapping do not guarantee the drive stays unmodified. The write-blocker enforces read-only at the interface level, which is the accepted lab practice for preserving evidence integrity.

Exam trap

The trap here is assuming that a read-only attribute or a mapped network drive is equivalent to a hardware write-blocker, when only the hardware device reliably blocks writes.

442
MCQmedium

A malware analyst is using a tool to monitor registry and file system changes during the execution of a suspicious binary. Which tool is specifically designed to take snapshots of the registry and file system before and after execution to identify changes?

A.Regshot
B.Cuckoo Sandbox
C.Process Explorer
D.Process Monitor
AnswerA

Regshot is a lightweight open-source utility that captures a baseline snapshot of the Windows registry and, optionally, the file system, then produces a second snapshot after the malware is executed. It compares the two snapshots and generates a detailed diff report, making it ideal for quickly identifying persistence locations, new files, and altered keys. Because it is not a real-time logger, it does not overwhelm the analyst with noise; instead, it gives a clean before-and-after view of system changes.

Why this answer

Regshot is a lightweight open-source tool designed specifically to compare registry hives and file system snapshots taken before and after executing a binary. It generates a detailed report of added, modified, or deleted keys and files, making it ideal for malware analysis to quickly identify persistence mechanisms or configuration changes.

Exam trap

The CHFI exam often tests the distinction between snapshot-based comparison tools (Regshot) and real-time monitoring tools (Process Monitor), leading candidates to confuse Process Monitor's live logging capability with the before-and-after snapshot functionality required by the question.

How to eliminate wrong answers

Option B is wrong because Cuckoo Sandbox is an automated dynamic malware analysis environment that executes binaries in a virtual machine and logs system calls, network traffic, and memory dumps, but it does not specialize in taking before-and-after registry and file system snapshots like Regshot does. Option C is wrong because Process Explorer is a task manager and process analysis tool from Sysinternals that shows detailed process information, handles, and DLLs, but it does not capture registry or file system snapshots for comparison. Option D is wrong because Process Monitor (Procmon) is a real-time monitoring tool that logs registry, file system, process, and thread activity as it happens, but it does not provide a before-and-after snapshot comparison; it requires manual filtering and analysis of a continuous event stream.

443
Multi-Selectmedium

Which two of the following are characteristics of the ext4 file system? (Choose TWO.)

Select 2 answers
A.Uses a Master File Table ($MFT) to store file metadata
B.Uses a file allocation table (FAT) to track clusters
C.Uses a journal to maintain file system consistency
D.Stores directory entries in a B-tree structure
E.Supports extents for contiguous block allocation
AnswersC, E

ext4 is a journaling file system that logs pending metadata and sometimes data changes to a journal area on disk before committing them to their final location, enabling rapid recovery and consistency after a crash or power failure. It supports journaling modes such as ordered, writeback, and journal, each balancing performance against consistency guarantees. This journaling mechanism is a definitive characteristic of ext4.

Why this answer

Option C is correct because ext4 is a journaling file system: it writes metadata (and optionally data) changes to a journal before committing them to the main file system, so an interrupted operation can be replayed or rolled back to keep the file system consistent. Option E is correct because ext4 introduced extents, which describe a contiguous range of blocks with a single descriptor instead of one pointer per block, reducing fragmentation overhead and improving performance for large files. Option A is wrong because the Master File Table ($MFT) is an NTFS structure, not an ext4 one.

Option B is wrong because a file allocation table (FAT) belongs to FAT12/FAT16/FAT32, whereas ext4 uses inodes and block bitmaps. Option D is wrong because ext4 uses H-tree (hashed B-tree) indexing for directory entries, not a plain B-tree structure.

Exam trap

EC-CHFI often tests the distinction between file system-specific structures (like $MFT for NTFS vs. inodes for ext4) and the misconception that all modern file systems use B-trees for directories, when ext4 actually uses HTrees (a variant of hash trees).

444
MCQeasy

An analyst recovers a hard drive from a suspect's computer. The drive has a partition table that uses a 32-bit identifier and a maximum partition size of 2 TB. Which partition table type is present?

A.HFS+
B.GPT
C.APFS
D.MBR
AnswerD

MBR (Master Boot Record) is a legacy partition table that uses 32-bit entries in its partition table, limiting the maximum addressable partition size to 2 TB (or 2.2 TB with 512-byte sectors). It resides in the first 512 bytes of the disk and contains boot code plus four primary partition entries. This 2 TB ceiling is the exact characteristic indicated in the question, making MBR the correct answer.

Why this answer

The Master Boot Record (MBR) partition table uses a 32-bit identifier for partition entries and, with traditional 512-byte sectors, supports a maximum partition size of 2 TB. This matches the description exactly, making MBR the correct answer.

Exam trap

A common misconception in CHFI exams is that GPT is the only partition table supporting large drives, but the question's specific mention of a '32-bit identifier' and '2 TB maximum' directly points to MBR, not GPT.

How to eliminate wrong answers

Option A is wrong because HFS+ is a file system used by macOS, not a partition table type, and it does not use a 32-bit partition identifier or impose a 2 TB partition limit based on partition table structure. Option B is wrong because GPT uses a 64-bit partition identifier and supports partition sizes far exceeding 2 TB (up to 9.4 ZB), not a 32-bit identifier with a 2 TB cap. Option C is wrong because APFS is a file system (not a partition table) designed for Apple devices, and it relies on GPT or MBR for partitioning, not a 32-bit identifier of its own.

445
Multi-Selecthard

A security analyst is investigating a potential data breach in a GCP environment. The analyst reviews the GCP audit logs and finds the following events: (1) A service account was granted the 'roles/storage.objectAdmin' role on a storage bucket containing sensitive data, (2) The service account then listed objects in the bucket, (3) The service account downloaded several objects. Which THREE actions should the analyst take immediately?

Select 3 answers
A.Analyze the IAM policy change that granted the role to identify the source
B.Revoke the service account's excessive permissions
C.Contact law enforcement immediately
D.Preserve the audit logs by exporting them to a secure location
E.Delete the storage bucket to prevent further access
AnswersA, B, D

Analyzing the IAM policy change that granted the role is the definitive step for identifying the source because it reveals the exact principal, timestamp, and method used to elevate privileges. Check Cloud Admin Activity audit logs for 'google.iam.admin.v1.SetIAMPolicy' events, noting whether the grant came from a compromised user, an OAuth token, or an external session. This forensic root-cause analysis establishes the attack vector and scope, guiding appropriate containment and recovery efforts.

Why this answer

Option A is correct because the first event is an IAM policy change (granting roles/storage.objectAdmin), and the analyst must trace the Admin Activity audit log entry for SetIamPolicy to identify the principal, source IP, user agent, and timestamp that made the grant. Option B is correct because roles/storage.objectAdmin grants full control over objects (create, read, update, delete), which is excessive for a service account that only needs to read sensitive data; revoking or downgrading the binding (e.g., to roles/storage.objectViewer) immediately limits further exfiltration. Option D is correct because audit logs are the primary forensic evidence and can be altered or aged out under the default 30-day Data Access log retention, so exporting them to a secure, immutable location (e.g., a locked Cloud Storage bucket or BigQuery dataset) preserves the chain of custody.

Option C is not appropriate as an immediate technical step since law enforcement should be engaged only after internal incident response confirms a breach and per organizational/legal guidance. Option E is wrong because deleting the bucket destroys evidence and does not stop the already-granted service account from acting elsewhere; containment should be done via IAM revocation and key disabling instead.

Exam trap

EC-CHFI emphasizes the importance of preserving evidence and following forensic procedures; candidates might mistakenly choose to delete the bucket thinking it stops the breach, but that destroys evidence and violates forensic chain of custody.

446
Multi-Selectmedium

An analyst is examining a memory dump using Volatility and wants to identify network connections. Which TWO Volatility plugins can be used to list network connections?

Select 2 answers
A.netscan
B.dlllist
C.pstree
D.connscan
E.pslist
AnswersA, D

netscan is the correct Volatility plugin for this task because it enumerates active TCP and UDP endpoints by walking the kernel's network structures (e.g., TCP_ENDPOINT and UDP_ENDPOINT lists via the ADDR_OBJ). It is specifically designed to reveal established, listening, and even closed-but-recent connections in a memory dump, making it the direct equivalent of 'netstat -an' for memory forensics. For network connection analysis on modern Windows (Vista+), netscan is the go-to plugin as it uses the tcpip.sys endpoint objects rather than the older, less reliable pool tags.

Why this answer

The netscan plugin (option A) is correct because it scans memory for network artifacts such as TCP and UDP endpoints, including connections and listening sockets, and works across modern Windows versions by carving pool tags and structures. The connscan plugin (option D) is also correct because it scans physical memory for TCP connection objects (TCPT_OBJECT pool tags) and reports local and remote addresses and ports, making it suitable for older Windows memory images. The dlllist plugin (option B) only lists loaded DLLs per process, pstree (option C) shows parent-child process relationships, and pslist (option E) enumerates active processes; none of these directly list network connections.

Exam trap

The CHFI exam often tests the distinction between netscan and connscan, where candidates mistakenly think connscan is the only option for network connections, but netscan is required for newer Windows versions and both are valid depending on the OS version.

447
Multi-Selectmedium

Which THREE of the following are commonly used network forensic data sources?

Select 3 answers
A.NetFlow logs
B.Prefetch files
C.IDS/IPS alerts
D.Packet captures (PCAP)
E.Windows registry hives
AnswersA, C, D

NetFlow logs are network-level metadata records generated by Cisco and other network devices that summarize traffic flows between hosts. Each flow record contains the source and destination IP addresses, ports, protocol, timestamps, total bytes and packets, and sometimes TCP flags — but critically no payload content. This makes NetFlow valuable for high-level pattern analysis such as detecting command-and-control beacons, anomalous data-transfer volumes, or internal lateral movement, while remaining relatively lightweight to store. As a core source of network telemetry, NetFlow is a mainstream network forensics artifact.

Why this answer

NetFlow logs (A) are a core network forensic source because routers and switches export flow records containing metadata such as source/destination IP, ports, protocol, byte/packet counts, and timestamps, enabling traffic pattern and anomaly analysis without full payload capture. IDS/IPS alerts (C) are network forensic data because they record detections of malicious or policy-violating traffic (e.g., Snort/Suricata signatures, anomaly events) with associated IPs, ports, and timestamps that support incident reconstruction. Packet captures (D) are the richest network forensic source, preserving full packet payloads at layers 2–7 (typically stored as PCAP/PCAPNG via tools like Wireshark or tcpdump) for protocol-level and content analysis.

Prefetch files (B) and Windows registry hives (E) are host-based artifacts stored on the endpoint's filesystem, not network traffic data sources, so they do not belong in this list.

Exam trap

The CHFI exam often tests the distinction between host-based forensic artifacts (like Prefetch files and registry hives) and network-based forensic sources, so candidates mistakenly include local system artifacts when the question explicitly asks for network forensic data sources.

448
MCQeasy

In an email header, which field typically contains the IP address of the original sending client?

A.Return-Path
B.Message-ID
C.Received
D.DKIM-Signature
AnswerC

The Received header is inserted by every SMTP server that handles the message, and each line records the IP address of the transmitting host, the receiving server, protocol information, and a timestamp. The bottommost Received line is the first one added, showing the connection from the originating client or its final relay. Therefore, forensically it is the go-to field for discovering the sending IP address.

Why this answer

The 'Received' field in an email header is added by each mail transfer agent (MTA) that processes the message, and the first 'Received' header (at the bottom of the header block) typically contains the IP address of the original sending client (the SMTP client that initiated the connection). This field records the 'from' IP and the 'by' host, making it the definitive source for tracing the origin of the email.

Exam trap

EC-Council often tests the misconception that the 'Return-Path' field contains the sender's IP address, when in fact it only holds the email address for bounce handling, not any network-layer information.

How to eliminate wrong answers

Option A is wrong because the 'Return-Path' field contains the envelope sender (the bounce address), not the IP address of the sending client; it is used for non-delivery reports, not for tracing the original source IP. Option B is wrong because the 'Message-ID' field is a unique identifier string generated by the sending MUA or MTA, but it does not contain any IP address information; it is used for message tracking and threading. Option D is wrong because the 'DKIM-Signature' field contains a cryptographic signature and associated domain information (e.g., d=domain), but it does not include the sending client's IP address; it is used for email authentication, not origin IP tracing.

449
MCQmedium

A forensic analyst is examining a Windows 10 system for evidence of USB device usage. Which registry hive and key path should she check to find a list of USB devices that have been connected to the system?

A.HKLM\SAM\SAM\Domains\Account\Users
B.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
C.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.NTUSER.DAT\Software\Microsoft\Windows\ShellNoRoam\BagMRU
AnswerB

USBSTOR enumerates storage-class USB devices, recording vendor, product and serial number for each device ever attached. This key sits under the SYSTEM hive's CurrentControlSet, making it the definitive artefact for proving historical USB mass-storage connections on Windows 10.

Why this answer

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum stores the device instance IDs and class GUIDs for every USB mass storage device that has ever been connected to the system. This is the primary forensic artifact for enumerating historical USB device attachments on Windows 10.

Exam trap

The EC-Council CHFI exam often tests the misconception that USB device history is stored in the SAM hive or in user-specific NTUSER.DAT shell bags, when in fact the definitive list resides in the SYSTEM hive's USBSTOR enumeration key.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM\Domains\Account\Users contains local user account password hashes and security identifiers (SIDs), not USB device connection history. Option C is wrong because HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run stores startup programs and autorun entries, not USB device enumeration data. Option D is wrong because NTUSER.DAT\Software\Microsoft\Windows\ShellNoRoam\BagMRU tracks folder view settings and shell bag MRU (most recently used) data for Explorer, not USB device identifiers.

450
Multi-Selectmedium

A forensic examiner is analyzing an Android device for potential evidence of a specific app’s data. Which TWO locations within the device’s file system would MOST likely contain application-specific data?

Select 2 answers
A./data/data/<package_name>/
B./recovery/
C./ (root directory)
D./sdcard/Android/data/<package_name>/
E./system/app/
AnswersA, D

/data/data/<package_name>/ is the core of an Android app's private internal storage, residing on the /data partition. This sandboxed directory contains the app's databases (e.g., SQLite), shared preferences in XML files, cached web content, and other files the app reads/writes at runtime. Although protected by Linux UID permission barriers, forensic extraction via a full filesystem image or ADB backup (if backed up) can recover valuable user-generated data, cookies, and session tokens critical to an investigation. This is the primary location for evidentiary data produced by an application's own execution.

Why this answer

Option A, /data/data/<package_name>/, is correct because this is the primary internal storage location where an Android app's private data—such as SQLite databases, shared_preferences XML files, and cached files—is stored under its package name, accessible only with root or a forensic image. Option D, /sdcard/Android/data/<package_name>/, is correct because it is the app-specific external storage directory (on the emulated /sdcard partition) where apps commonly place user-generated files, downloads, and caches that are often recoverable without root. Option B, /recovery/, is not app-specific data; it holds the recovery partition image used for system recovery and OTA updates.

Option C, / (root directory), is the top-level filesystem hierarchy containing system directories, not a location for a particular app's data. Option E, /system/app/, contains pre-installed system APK files, not the runtime data generated by a specific application.

Exam trap

EC-Council often tests the misconception that `/system/app/` contains user app data, when in fact it only holds pre-installed APK files, not runtime or user-generated data.

Page 5

Page 6 of 10

Page 7

All pages