Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 451–525

745 questions total · 10pages · All types, answers revealed

Page 6

Page 7 of 10

Page 8
451
Multi-Selecteasy

Which TWO of the following are indicators of a webshell attack found in web server logs? (Select TWO)

Select 2 answers
A.Abnormal HTTP methods like OPTIONS or TRACE
B.High volume of traffic from a single IP
C.Requests to a .asp or .php file with parameters like cmd or exec
D.Frequent 404 errors for non-existent pages
E.POST requests to a script file in an upload directory
AnswersC, E

Webshells are often coded in dynamic script languages and expose command execution through parameters such as cmd, exec, or command. A request to a .asp or .php file that includes these parameter names strongly suggests an attacker is attempting to pass shell commands to the server. Such parameter names are unnatural for legitimate application workflows, making this a highly specific webshell indicator.

Why this answer

Option C is correct because webshells are typically small scripts (e.g., .asp, .php, .jsp) that accept command parameters such as cmd, exec, or shell, so log entries showing requests to such files with those parameter names are a strong indicator of command execution through a webshell. Option E is correct because attackers commonly upload a webshell into a writable upload directory and then interact with it via POST requests, so repeated POSTs to a script in an upload folder in the web logs is a classic webshell traffic pattern. Option A is not specific to webshells, since OPTIONS and TRACE are legitimate HTTP methods and their presence alone does not indicate a webshell.

Option B is too generic, as high traffic from one IP can result from many benign causes such as crawlers, load balancers, or DoS activity. Option D is also non-specific, because frequent 404 errors usually indicate broken links, scanning, or enumeration rather than webshell command execution.

Exam trap

EC-Council often tests the distinction between generic web anomalies (like high traffic or 404 errors) and webshell-specific indicators (like command parameters in script requests), so candidates mistakenly select broad traffic patterns instead of the precise log entries that reveal command execution.

452
MCQmedium

A forensic examiner uses a hardware write blocker when imaging a suspect's hard drive. What is the primary function of a hardware write blocker?

A.To encrypt the data on the suspect drive
B.To prevent any data from being written to the suspect drive
C.To connect the suspect drive via USB
D.To increase the speed of data acquisition
AnswerB

A hardware write blocker is designed to guarantee the integrity of digital evidence by intercepting write commands from the forensic host to the suspect drive. It allows read-only access at the physical interface, ensuring that no bytes are altered on the source media during acquisition or analysis. This preservation of the original evidence is essential for maintaining a chain of custody and for admissibility in court.

Why this answer

A hardware write blocker is a device placed between the suspect drive and the forensic workstation that intercepts and blocks any write commands from the host system. Its primary function is to ensure that no data—such as file system metadata, temporary files, or operating system writes—can be written to the suspect drive, thereby preserving the original evidence in a forensically sound manner. This is critical for maintaining the integrity of the evidence and ensuring it is admissible in court.

Exam trap

EC-Council often tests the distinction between the function of a write blocker (preventing writes) and its physical interface (e.g., USB), leading candidates to mistakenly choose the interface option as the primary function.

How to eliminate wrong answers

Option A is wrong because encrypting the data on the suspect drive would alter the evidence and is not the function of a write blocker; encryption is a separate process typically applied to the forensic image, not the original drive. Option C is wrong because while many hardware write blockers do connect via USB or other interfaces, that is a means of connection, not the primary function; the core purpose is write protection, not the interface type. Option D is wrong because hardware write blockers do not increase acquisition speed; in fact, they may introduce a slight latency, and speed is determined by the drive interface and imaging software, not the blocker itself.

453
Multi-Selecthard

In ext3/ext4 file systems, which THREE of the following are key structures used for file metadata and recovery?

Select 3 answers
A.Journal
B.Superblock
C.Master File Table ($MFT)
D.File Allocation Table (FAT)
E.Inode table
AnswersA, B, E

The journal is a dedicated circular area (or a separate journal device) that records pending metadata changes before they are committed to the main filesystem, providing crash consistency and fast recovery. In ext3 this is implemented by the Journaling Block Device (JBD), and ext4 uses JBD2, which supports checksums and more flexible journaling modes. This journal is a defining feature of ext3/ext4 that distinguishes them from earlier ext2, making it a correct ext3/ext4 component.

Why this answer

The Journal (A) is correct because ext3/ext4 are journaling file systems that record pending metadata (and optionally data) transactions to a circular log, enabling fast crash recovery and consistency by replaying or discarding incomplete operations. The Superblock (B) is correct because it stores critical file system metadata such as block size, total inode and block counts, mount state, and pointers to block group descriptors, and ext3/ext4 keep backup superblocks for recovery if the primary is corrupted. The Inode table (E) is correct because each file or directory is represented by an inode holding metadata (permissions, timestamps, ownership, size, and block pointers), and the inode table is the on-disk array of these inodes.

The Master File Table (C) is not correct because $MFT is the core metadata structure of NTFS, not ext3/ext4. The File Allocation Table (D) is not correct because FAT is the allocation structure of the FAT12/FAT16/FAT32 file systems, not ext3/ext4.

Exam trap

CHFI often tests the distinction between filesystem-specific structures (e.g., ext3/ext4 vs. NTFS vs. FAT), so candidates mistakenly associate $MFT or FAT with Linux filesystems due to general file system knowledge.

454
MCQeasy

Which file system artifact in NTFS records file system events such as file creation, deletion, and modification, and is often used to track attacker activities?

A.Event Logs
B.Prefetch files
C.USN Journal
D.Registry
AnswerC

The USN Journal (Update Sequence Number Journal) is a native NTFS feature that persistently records every change to files and directories on the volume, including creation, deletion, renaming, attribute changes, and data writes, each tagged with a monotonically increasing USN. It functions as a change journal that applications can query for backup, search indexing, and forensic reconstruction, and it exists even when Windows auditing is off. Because it resides in NTFS metadata ($Extend\$UsnJrnl) and tracks all filesystem modifications regardless of the user-mode API used, it is the definitive artifact for file system event activity.

Why this answer

The USN (Update Sequence Number) Journal is a native NTFS feature that logs all changes to files and directories on a volume, including creation, deletion, and modification events. Forensic analysts use it to reconstruct timelines of attacker activity because it records the reason for the change (e.g., USN_REASON_FILE_CREATE, USN_REASON_FILE_DELETE) along with timestamps and file references, even if the file is later deleted or renamed.

Exam trap

The CHFI exam often tests the distinction between file-system-level journals (USN Journal) and higher-level logs (Event Logs), so candidates mistakenly choose Event Logs because they associate 'events' with Windows Event Viewer, not realizing the USN Journal is the specific NTFS artifact for file operations.

How to eliminate wrong answers

Option A is wrong because Event Logs (e.g., Security, System, Application logs) record system-wide events like logins and service starts, but they do not specifically log per-file NTFS operations such as creation, deletion, or modification at the file system level. Option B is wrong because Prefetch files (.pf) are used by Windows to speed up application startup by caching the first few seconds of execution; they track program execution order and frequency, not file system events like creation or deletion. Option D is wrong because the Registry stores configuration settings, user preferences, and system state, but it does not maintain a sequential record of file system changes; it is not a journal of file operations.

455
MCQmedium

A company receives a legal hold notice regarding a lawsuit. What immediate action should the company take to comply?

A.Delete all emails older than 30 days to free up storage
B.Immediately format the hard drives of all employees involved
C.Preserve all potentially relevant electronic documents and data
D.Ignore the notice because it is not a court order
AnswerC

The correct action is to implement a litigation hold preserving all potentially relevant electronic documents and data, including emails, attachments, metadata, and backup copies. The organization must notify custodians of their duty and suspend any automated deletion, archiving, or alteration processes. This protects the integrity and provenance of the ESI so it can be produced in discovery without allegations of spoliation.

Why this answer

A legal hold notice triggers a duty to preserve all potentially relevant electronically stored information (ESI). Under the Federal Rules of Civil Procedure (FRCP) Rule 37(e), failure to preserve can lead to spoliation sanctions. The immediate action is to issue a litigation hold notice and suspend routine data deletion policies, ensuring that all relevant emails, documents, and logs are preserved in their current state.

Exam trap

EC-Council often tests the misconception that a legal hold notice is optional or that routine deletion policies can continue, but the trap is that preservation duties begin immediately upon anticipation of litigation, regardless of whether a formal court order has been served.

How to eliminate wrong answers

Option A is wrong because deleting emails older than 30 days violates the preservation obligation and constitutes spoliation, which can result in adverse inference instructions or monetary sanctions. Option B is wrong because formatting hard drives destroys all data, including potentially relevant evidence, and is a textbook example of intentional spoliation. Option D is wrong because a legal hold notice, even if not a formal court order, carries legal weight under FRCP and common law; ignoring it can lead to severe penalties for failure to preserve evidence.

456
MCQmedium

A forensic analyst finds a file with the .plist extension on a Mac system. What type of artifact is this?

A.Log file
B.Executable binary
C.Email database
D.Property list file
AnswerD

A .plist (property list) file is Apple's structured serialization format for key-value pairs, arrays, and typed data, encoded as either XML or binary (with the 'bplist00' header). It is used pervasively for configuration—such as Info.plist for app metadata, preferences in ~/Library/Preferences, and app-specific data containers. The extension directly identifies this format, and forensic examiners routinely parse plists to extract settings, timestamps, and user activity, which is why this option is correct.

Why this answer

The .plist extension stands for 'property list', a structured data file used by macOS and iOS applications to store serialized objects like configuration settings, user preferences, and application state. These files are XML or binary-encoded and are a key artifact in forensic analysis for recovering user activity, application usage, and system configuration. Option D is correct because .plist files are explicitly defined as property list files in Apple's developer documentation.

Exam trap

The CHFI exam often tests the misconception that .plist files are log files because they store application data, but they are specifically property list files used for configuration and preferences, not event logs.

How to eliminate wrong answers

Option A is wrong because .plist files are not log files; macOS logs are typically stored in .log, .asl, or .tracev3 formats under /var/log or via the unified logging system. Option B is wrong because executable binaries on macOS use Mach-O format with extensions like .app, .dylib, or no extension, and .plist files are data files, not executable code. Option C is wrong because email databases on macOS are stored in .mbox, .emlx, or SQLite formats (e.g., in ~/Library/Mail/), not as .plist files.

457
MCQmedium

In MySQL forensics, which log file is most commonly used to detect unauthorized data exfiltration or changes to database records?

A.Binary log
B.Slow query log
C.General query log
D.Error log
AnswerA

The binary log records all data-modifying statements and row-level changes in chronological order, making it the primary source for reconstructing unauthorised record alterations or exfiltration activity. Unlike the error log or general query log, it captures committed transactions with before-and-after values, directly satisfying the requirement to detect changes to database records.

Why this answer

The binary log is the correct choice because it records all changes to database data and structure (e.g., INSERT, UPDATE, DELETE, CREATE, ALTER) in a binary format that can be replayed for point-in-time recovery. In MySQL forensics, this log is the primary source for detecting unauthorized data exfiltration or modifications, as it captures the exact SQL statements or row changes that altered the database, along with timestamps and server IDs. Unlike other logs, the binary log is specifically designed to track every write operation, making it indispensable for reconstructing malicious activity.

Exam trap

A common misconception is that the general query log (Option C) is the best for detecting data changes because it logs all queries, but the trap is that it logs both reads and writes without the granular, replayable change tracking of the binary log, and it is frequently turned off in production, making the binary log the actual forensic goldmine.

How to eliminate wrong answers

Option B is wrong because the slow query log only records queries that exceed a defined execution time threshold (e.g., long_query_time), focusing on performance issues rather than capturing all data-changing operations; it would miss fast, unauthorized modifications. Option C is wrong because the general query log records all client connections and queries (both reads and writes) in plain text, but it is often disabled in production due to performance overhead and does not provide the structured, binary-level detail needed for precise forensic reconstruction of data changes. Option D is wrong because the error log only records server startup/shutdown events, crashes, and critical errors (e.g., InnoDB corruption), not the actual data manipulation statements required to detect exfiltration or record changes.

458
MCQmedium

A security analyst notices that a log file on a Linux server shows repeated failed SSH login attempts from an external IP address, but no successful login from that IP. However, the /var/log/auth.log file has been recently truncated. Which type of evidence is the truncated log file?

A.Hearsay evidence
B.Best evidence
C.Circumstantial evidence
D.Direct evidence
AnswerC

Circumstantial evidence requires a logical inference to connect the evidence to a fact in issue, such as inferring intent from behavior. The truncated log is not the basis for an inference; its tampered state is the very fact at issue and is observable directly. Because no intermediate deduction is needed to see that the file has been altered, it is not merely circumstantial.

Why this answer

The truncated log file is circumstantial evidence. While the truncation itself is a directly observable fact, the conclusion that someone intentionally altered or destroyed the log to conceal failed SSH attempts requires inference. Other explanations (e.g., log rotation, system error) are possible.

Direct evidence proves a fact without inference, such as an eyewitness testimony or a video recording of the tampering. Therefore, the truncated log file is circumstantial evidence.

Exam trap

The trap is to confuse the physical existence of an artifact with direct evidence. Direct evidence must prove the ultimate fact without relying on inference. A truncated file's condition only suggests tampering through reasoning, making it circumstantial.

How to eliminate wrong answers

Option A is wrong because hearsay evidence is an out-of-court statement offered to prove the truth of the matter asserted, and a truncated log file is not a statement but a physical artifact; forensic examiners treat logs as real evidence, not hearsay. Option B is wrong because best evidence refers to the original document or recording when its content is at issue, but here the issue is the state of the log file (truncated), not the content of the log entries; the truncated file itself is the best evidence of tampering, but the term 'best evidence' is a legal rule about proving the content of a writing, not a classification of evidence type. Option C is wrong because circumstantial evidence requires an inference to connect the evidence to a fact (e.g., the truncation implies someone deleted logs), but the truncated log file is direct evidence of the act of truncation itself—no inference is needed to see that the file was truncated.

459
Multi-Selecthard

Which THREE of the following are valid memory forensic artifacts that can be extracted using the Volatility framework?

Select 3 answers
A.pstree
B.pslist
C.ls -l
D.netscan
E.dir /r
AnswersA, B, D

The `pstree` plugin in Volatility reconstructs the full process ancestry by walking the _EPROCESS structures in the memory dump, displaying parent-child relationships. It is a critical artifact because it exposes unusual process hierarchies, such as a benign-looking child spawned by a malicious parent, which may indicate code injection or a rootkit. Unlike a flat process list, pstree shows the lineage, assisting investigators in tracing process execution paths.

Why this answer

The Volatility framework provides plugins that parse a memory image and reconstruct kernel-level data structures, so pstree (A) is valid because it walks the active process list and renders the parent-child process hierarchy from the EPROCESS structures. pslist (B) is also valid because it enumerates active processes by traversing the doubly linked list of EPROCESS objects in the kernel, a core memory-forensic artifact. netscan (D) is valid because it recovers network connection and socket artifacts (TCP/UDP endpoints, listening ports, owning PIDs) from memory pool structures. By contrast, ls -l (C) is a Linux shell command for listing filesystem directory entries, and dir /r (E) is a Windows CMD command for listing files with alternate data streams; neither is a Volatility plugin nor a memory artifact extraction technique.

Exam trap

The CHFI exam often tests the distinction between file system commands (like `ls -l` or `dir /r`) and memory forensic tools (like Volatility plugins), trapping candidates who confuse operating system commands with forensic extraction methods.

460
MCQmedium

An investigator is examining a FAT32 filesystem and needs to recover a deleted file. In FAT32, the directory entry for a deleted file has the first byte of the filename set to 0xE5. What does this indicate?

A.The file is a system file
B.The file is hidden
C.The file is encrypted
D.The file has been deleted
AnswerD

In FAT32, when a file or directory is deleted, the first byte of its 8.3 directory entry is replaced with 0xE5, which serves as a deletion/free marker. This is why 0xE5 in the first byte of a directory entry is a reliable indicator that the file has been deleted (or the directory entry is free). The remainder of the entry—including the starting cluster number, file size, and timestamps—often remains unchanged until the entry is reused, which is what makes data recovery possible.

Why this answer

In FAT32, when a file is deleted, the directory entry's first byte (the filename's first character) is overwritten with the value 0xE5. This is a deliberate marker used by the file system to indicate that the entry is available for reuse, meaning the file has been logically deleted. The data clusters remain intact until overwritten, which is why recovery tools look for entries with this byte to restore deleted files.

Exam trap

The trap here is that candidates confuse the 0xE5 deletion marker with other attribute flags (like hidden or system) or assume it indicates encryption, because they memorize attribute bits but overlook the specific byte value used for deletion in FAT directory entries.

How to eliminate wrong answers

Option A is wrong because system files in FAT32 are marked by the 'System' attribute bit in the directory entry's attribute byte, not by the first byte of the filename being 0xE5. Option B is wrong because hidden files are indicated by the 'Hidden' attribute bit (0x02) in the attribute field, not by the filename's first byte. Option C is wrong because FAT32 does not support native file encryption; encryption is handled at the application or OS level (e.g., EFS on NTFS), and there is no filename byte marker for encryption in FAT32.

461
MCQmedium

An investigator needs to recover a deleted partition from a disk that originally used an MBR partition table. Which tool can scan the disk for lost partitions and rebuild the partition table?

A.TestDisk
B.FTK Imager
C.Autopsy
D.PhotoRec
AnswerA

TestDisk is a specialized partition recovery utility that scans raw disk media for the signatures of missing or deleted partition entries, then rebuilds the Master Boot Record (MBR) or GUID Partition Table (GPT) so the original logical volumes become accessible again. Unlike file carvers, it restores the partition-level addressing that the operating system needs before any filesystem or file-level analysis can proceed. This makes it the correct tool when the goal is recovering a deleted partition rather than individual files.

Why this answer

TestDisk is specifically designed for data recovery and can scan a disk for lost partitions by analyzing the underlying MBR (Master Boot Record) structure. It can rebuild the partition table by searching for partition boot sectors and file system signatures, allowing recovery of deleted or corrupted partitions. This makes it the correct tool for the scenario described.

Exam trap

The trap here is that candidates often confuse PhotoRec (file recovery) with TestDisk (partition recovery), assuming both tools perform the same function, when in fact PhotoRec only recovers files and cannot rebuild partition tables.

How to eliminate wrong answers

Option B (FTK Imager) is wrong because it is a forensic imaging tool used to create bit-for-bit copies of drives and view file system contents, not to scan for lost partitions or rebuild partition tables. Option C (Autopsy) is wrong because it is a digital forensics platform that analyzes disk images and file systems, but it does not have native functionality to recover deleted partitions or rebuild MBR partition tables. Option D (PhotoRec) is wrong because it is a file carving tool that recovers individual files based on file signatures, not partitions; it operates at the file level, not the partition table level.

462
MCQeasy

A CHFI analyst is called to investigate a suspected insider threat. The suspect's laptop is turned on and logged in. The analyst needs to capture volatile data before shutting it down. Which of the following should the analyst capture first?

A.The contents of the RAM
B.The contents of the hard drive
C.The web browser cache
D.The system event logs
AnswerA

RAM contains volatile data such as running processes, network connections, and encryption keys, which are lost when the system is powered off. Capturing RAM first preserves this critical evidence. It is the most volatile and should be prioritized. Tools like FTK Imager or Volatility can be used for memory capture.

Why this answer

RAM is the most volatile data and is lost when the system is powered off. Capturing it first preserves running processes, network connections, and potentially encryption keys. Hard drive contents, event logs, and browser cache are non-volatile and can be acquired later.

Following the order of volatility is a key principle in forensic investigations.

Exam trap

The trap here is assuming that hard drive data is more important because it is larger, ignoring that RAM is irreplaceable once lost.

463
MCQeasy

A first responder is called to investigate a potential insider threat. The suspect's computer is turned off. What is the BEST procedure?

A.Compute a hash of the hard drive using a live CD.
B.Check the power cord and peripherals for tampering.
C.Seize the computer and transport it to a forensic lab for imaging.
D.Turn on the computer to see if it boots normally.
AnswerC

Seizing the computer and transporting it to a forensic lab preserves the original evidence for a proper bit-for-bit image using a write-blocker, ensuring data integrity and admissibility. A controlled lab environment allows for secure storage and careful analysis before any acquisition, maintaining a documented chain of custody from the scene onward. This is the recognized best practice for first responders.

Why this answer

When a suspect's computer is already turned off, the best procedure is to seize it and transport it to a forensic lab for imaging. This preserves the integrity of the evidence by preventing any accidental modification of the hard drive's contents, which could occur if the system is powered on or booted from a live CD. In forensic best practices, the first responder should never boot a suspect's computer, as doing so can alter critical system files, timestamps, and volatile data, compromising the chain of custody and admissibility of evidence.

Exam trap

EC-Council often tests the misconception that booting from a live CD is safe because it doesn't touch the hard drive, but in reality, even a live CD can modify the system's registry, page file, or metadata through normal operation, which is why seizing the computer for lab imaging is the only forensically sound option.

How to eliminate wrong answers

Option A is wrong because computing a hash of the hard drive using a live CD requires booting the suspect's computer, which alters the system state (e.g., writes to the page file, updates last access times) and violates the forensic principle of not modifying evidence. Option B is wrong because checking the power cord and peripherals for tampering is a physical inspection step that, while potentially useful, is not the best procedure; the priority is to secure the digital evidence by seizing the computer intact. Option D is wrong because turning on the computer to see if it boots normally will immediately alter the hard drive's contents (e.g., writing to the registry, updating logs, modifying file timestamps), destroying potential evidence and violating the forensic requirement to preserve the original state.

464
MCQmedium

Which of the following is the BEST description of Locard's exchange principle as applied to digital forensics?

A.Only original evidence is admissible in court
B.Digital evidence must be collected in a manner that preserves its integrity
C.Every contact leaves a trace; the perpetrator will leave digital traces on the crime scene
D.Evidence must be documented with a chain of custody
AnswerC

Locard's exchange principle states that every contact leaves a trace, and in the digital realm this manifests as persistent or volatile artifacts: log entries, deleted file fragments, browser history, network connections, or metadata on the victim's system. When a perpetrator accesses, copies, or exfiltrates data, they necessarily leave digital traces on the target's storage media, memory, or network infrastructure, just as physical contact transfers fibers. Digital forensics operationalizes this principle by identifying and recovering those traces to reconstruct the crime and link the suspect to the scene, making this the correct description.

Why this answer

Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means that when a perpetrator interacts with a system—whether by accessing files, running commands, or connecting to a network—they inevitably leave digital artifacts such as log entries, registry keys, metadata, or network connection records. Option C correctly captures this core concept of trace transfer in the digital domain.

Exam trap

EC-Council often tests whether candidates confuse Locard's exchange principle with general forensic procedures like chain of custody or evidence integrity, so the trap is picking a correct-sounding but non-specific option (B or D) instead of the precise definition of trace transfer.

How to eliminate wrong answers

Option A is wrong because it misstates admissibility rules; evidence does not have to be original to be admissible—duplicates or copies are often acceptable under rules like Federal Rule of Evidence 1003, provided they are accurate and authentic. Option B is wrong because it describes the general requirement for evidence integrity and proper collection procedures, which is a forensic best practice but not a description of Locard's exchange principle. Option D is wrong because chain of custody is a documentation process to track evidence handling, not a statement about the transfer of traces between a perpetrator and a crime scene.

465
Multi-Selecthard

A forensic analyst is recovering deleted files from an ext3 file system. Which TWO methods can be used to recover deleted inodes?

Select 2 answers
A.Using file carving tools like Foremost
B.Using dd to create a raw image
C.Analyzing the ext3 journal for deleted inode entries
D.Using debugfs to display the superblock
E.Scanning the inode table for orphan inodes
AnswersC, E

The ext3 journal (a circular log, typically stored in .journal or an on-disk journal device) records metadata transaction blocks describing changes to inodes, directory entries, and block bitmaps. When a file is unlinked, the corresponding inode modification—including the decremented link count and updated deletion flags—is written to the journal before being committed. If the journal still contains the relevant transaction, an analyst can extract the inode number, its block pointers, and the associated file data, even though the directory entry is gone. This is a valid inode-recovery method, though the journal's limited circular size means old entries may have been overwritten.

Why this answer

Option C is correct because the ext3 journal (introduced with journaling) retains metadata transactions, including records of inode allocations and deletions, so analyzing the journal with tools like ext3grep or jls can reveal deleted inode entries and their associated block pointers. Option E is correct because deleted inodes often remain in the inode table with their link count set to zero and are not immediately overwritten; scanning the inode table (e.g., with debugfs's lsdel or by walking inode structures) can identify these orphan inodes and recover their data. Option A is incorrect because file carving tools like Foremost operate on raw data streams and file signatures, not on inode structures, so they do not recover deleted inodes.

Option B is incorrect because dd merely creates a bit-for-bit raw image of the disk and performs no inode recovery itself. Option D is incorrect because using debugfs to display the superblock only shows file system metadata such as block counts and mount status, not deleted inode entries.

Exam trap

The CHFI exam often tests the distinction between data recovery (carving) and metadata recovery (inode/journal analysis), so the trap here is that candidates confuse file carving (Option A) with inode recovery, not realizing that inodes are metadata structures that require journal or inode table scanning, not content-based carving.

466
Multi-Selectmedium

Which TWO artifacts are commonly used to identify USB device insertion history on a Windows system? (Select TWO.)

Select 2 answers
A.NTUSER.DAT
B.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
C.prefetch files
D.setupapi.dev.log
E.Event ID 7045
AnswersB, D

The registry key HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is one of the most reliable artifacts for identifying USB storage devices. Under this key, each subkey corresponds to a specific device class and serial number, such as 'Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00' followed by the unique instance ID. It persists on the system even after the device is unplugged, enabling examiners to prove that a particular USB flash drive or external hard drive was connected at some point. This makes it a cornerstone of USB device forensic analysis.

Why this answer

The USBSTOR registry key and setupapi.dev.log contain information about USB devices connected to the system, including device IDs and timestamps.

467
Multi-Selecteasy

Which TWO of the following hashing algorithms are commonly used to verify the integrity of forensic images? (Choose two.)

Select 2 answers
A.SHA-3
B.SHA-1
C.RSA
D.AES
E.MD5
AnswersB, E

SHA-1 generates a 160-bit digest and is widely accepted for validating forensic image integrity, often recorded alongside MD5. It satisfies the stem's requirement by providing a second, independent hash to demonstrate that acquired evidence remains unchanged.

Why this answer

SHA-1 and MD5 are the two hashing algorithms most commonly used in forensic practice to verify the integrity of forensic images. They produce a fixed-size hash value (160-bit for SHA-1, 128-bit for MD5) that acts as a digital fingerprint; if the hash of the original image matches the hash of a copy, the data is considered unchanged. Despite known collision weaknesses, they remain the de facto standards in tools like FTK Imager, EnCase, and dd due to their speed and widespread tool support.

Exam trap

EC-Council often tests the distinction between hashing algorithms (integrity) and encryption algorithms (confidentiality), so the trap here is that candidates confuse RSA and AES as hashing algorithms because they are cryptographic primitives, but they serve entirely different purposes.

468
MCQmedium

During a forensic investigation, a lawyer objects to the admissibility of a log file on the grounds that it is hearsay. Which of the following is the BEST argument to overcome this objection?

A.The log file qualifies as a business record exception to the hearsay rule.
B.The log file is circumstantial evidence, not hearsay.
C.The log file is direct evidence of the intrusion.
D.The log file is the best evidence because it is an original record.
AnswerA

Under FRE 803(6), a log file is admissible as a business record if it was created at or near the time of the event by a person with knowledge, kept in the regular course of business, and it was the regular practice to make such a record. The custodian or qualified witness must lay a foundation, but once established, the log is an exception to the hearsay rule, not excluded as hearsay. This exception reflects the reliability of records routinely relied upon in business operations.

Why this answer

The log file is admissible under the business records exception to the hearsay rule (Federal Rule of Evidence 803(6)). This exception applies because logs are created automatically or by a person with knowledge, near the time of the event, in the regular course of business, and it is the regular practice to make such records. In digital forensics, system logs (e.g., Windows Event Logs, syslog) are routinely admitted under this exception, as they are generated by the system without the declarant's bias or memory issues.

Exam trap

EC-Council often tests the misconception that 'best evidence' or 'original record' automatically overcomes hearsay, but the trap here is that hearsay and best evidence are separate evidentiary rules, and only a specific exception like business records can defeat a hearsay objection.

How to eliminate wrong answers

Option B is wrong because circumstantial evidence is still subject to hearsay rules; the log file is an out-of-court statement offered to prove the truth of the matter asserted (e.g., that an intrusion occurred), which is hearsay, not circumstantial. Option C is wrong because direct evidence is evidence that directly proves a fact without inference, but a log file still requires interpretation and is a recorded statement, making it hearsay unless an exception applies. Option D is wrong because the best evidence rule (original document rule) applies to proving the content of a writing, recording, or photograph, but it does not overcome a hearsay objection; the log file could still be excluded as hearsay even if it is the original.

469
Multi-Selectmedium

A forensic examiner is preparing to testify as an expert witness. Which THREE of the following qualities are essential for the examiner's testimony to be admissible under the Daubert standard? (Select THREE)

Select 3 answers
A.The methods used have been tested and are subject to peer review
B.The techniques used are generally accepted within the forensic community
C.The examiner holds a degree in computer science
D.The examiner has testified in at least ten previous cases
E.The potential error rate of the methodology is known
AnswersA, B, E

Under the Daubert standard, the core inquiry is whether a methodology can be empirically tested and has survived scrutiny through publication and peer review. For forensic techniques such as disk imaging or hash function validation, this means the underlying procedure can be replicated and falsified, ensuring its reliability. The examiner's personal qualifications or prior case experience cannot compensate for a lack of scientific validity in the method itself.

Why this answer

Under Daubert v. Merrell Dow Pharmaceuticals, the trial judge acts as gatekeeper and assesses scientific testimony using several factors, three of which are reflected here. Option A is correct because Daubert explicitly considers whether the theory or technique can be (and has been) tested and whether it has been subjected to peer review and publication.

Option B is correct because general acceptance in the relevant scientific or forensic community, though originally the Frye test, remains a Daubert factor the court may weigh. Option E is correct because Daubert requires consideration of the known or potential error rate of the methodology, along with the existence and maintenance of standards controlling its operation. Option C is not required, since Daubert focuses on the reliability of the methodology rather than a specific academic degree, and Option D is not required because prior testimony experience is not one of the Daubert reliability factors.

Exam trap

EC-Council CHFI often tests the misconception that personal qualifications (e.g., degrees or experience) are Daubert factors, when in fact the standard focuses strictly on the scientific reliability of the methodology itself.

470
MCQmedium

An investigator finds evidence of data hidden using Alternate Data Streams (ADS) on an NTFS volume. Which command would display all ADS associated with files in a directory?

A.dir /s
B.dir /x
C.dir /r
D.dir /a
AnswerC

The /r switch, introduced in Windows Vista, explicitly instructs dir to enumerate all alternate data streams associated with each file. For every file that has an ADS, the output includes an additional line in the format 'filename:streamname:$DATA', which is the standard NTFS stream representation. This switch directly queries the NTFS stream list, so it can disclose data that was hidden by writing bytes to a named stream. Given the investigation involves hidden data via alternate streams, /r is the correct command-line option.

Why this answer

The `dir /r` command in Windows displays alternate data streams (ADS) associated with files on an NTFS volume. ADS are a feature of NTFS that allow additional data to be stored with a file, hidden from standard directory listings. The `/r` switch specifically lists all streams, including the main stream and any alternate streams, making it the correct choice for forensic identification of hidden data.

Exam trap

The trap here is that candidates may confuse `dir /r` with other switches like `/s` (recursive listing) or `/a` (attribute display), assuming ADS are shown by default or through attribute-based commands, when in fact only `/r` explicitly reveals alternate streams.

How to eliminate wrong answers

Option A is wrong because `dir /s` lists files in the specified directory and all subdirectories recursively, but does not display alternate data streams. Option B is wrong because `dir /x` displays the short (8.3) file names for files with long names, not ADS. Option D is wrong because `dir /a` displays files with specified attributes (e.g., hidden, system), but does not reveal ADS.

471
MCQhard

During a network forensic investigation, the analyst examines firewall logs and notices a large number of outbound connections from an internal server to various IP addresses on port 443 at regular intervals. The connections are all initiated by a process called 'svchost.exe' running from a non-standard location (C:\Windows\Temp). What is the MOST likely explanation?

A.The server is running a scheduled backup to an external cloud service
B.The server is performing legitimate Windows Update checks
C.The server is infected with malware that is beaconing to a command-and-control server
D.The server is being used as a proxy for internal users
AnswerC

The correct indicator set is process-name spoofing combined with network beaconing: the malware uses the legitimate name svchost.exe but executes from the Temp folder, which no built-in Windows service does because the Service Control Manager loads service binaries using the full ImagePath—normally C:\Windows\System32\svchost.exe. The attacker then creates periodic outbound connections at fixed or jittered intervals to a small set of external IPs, typically carrying small, encrypted payloads, to receive commands or exfiltrate data—a classic C2 beacon signature. Defenders observe a single host producing repeatable timing patterns with low data volume per connection, which is nearly pathognomonic for malware.

Why this answer

Svchost.exe running from C:\Windows\Temp is a classic sign of malware masquerading as a legitimate Windows process. The regular outbound connections on port 443 (HTTPS) at fixed intervals indicate beaconing behavior, where the infected host periodically contacts a command-and-control (C2) server to receive instructions or exfiltrate data. Legitimate svchost.exe resides in C:\Windows\System32, and any deviation from this path is a strong indicator of compromise.

Exam trap

EC-Council CHFI exam often tests the misconception that svchost.exe is always legitimate, but the key trap here is that the process path (C:\Windows\Temp) is abnormal, and candidates may overlook this detail and incorrectly assume the activity is a normal Windows Update or backup operation.

How to eliminate wrong answers

Option A is wrong because scheduled backups to cloud services typically use dedicated backup software or Windows Server Backup, not svchost.exe from a non-standard path, and would not exhibit regular beaconing intervals. Option B is wrong because legitimate Windows Update checks use svchost.exe from C:\Windows\System32, not C:\Windows\Temp, and updates are initiated by the Windows Update service (wuauserv) via HTTP/HTTPS on port 80/443 but not at rigidly regular intervals. Option D is wrong because using a server as a proxy for internal users would involve a proxy service (e.g., Squid, Microsoft TMG) or a configured proxy role, not svchost.exe from a temp directory, and would show connections from multiple internal clients, not just outbound from the server.

472
MCQeasy

Which Android file system location is MOST likely to contain user-installed app data, preferences, and cached information?

A./vendor/
B./data/data/
C./system/
D./mnt/sdcard/
AnswerB

The /data/data directory (accessible as /data/user/0 on modern Android) is the standard, sandboxed root for each installed application's private data, including SQLite databases, SharedPreferences, cache files, and native libraries. Access is protected by Linux UID permissions—each app runs with a unique UID—so only the app itself and the root user can read these files. For forensic examiners, this is the primary source for recovering user app data such as chat logs, browser history, and app-generated artifacts.

Why this answer

The /data/data/ directory on Android devices stores application-specific data for user-installed apps, including preferences (shared preferences XML files), databases, and cached information. This location is part of the internal storage partition and is sandboxed per app, ensuring that each app can only access its own data directory. It is the primary repository for runtime app data, making it the most relevant for forensic analysis of user-installed app artifacts.

Exam trap

EC-Council often tests the misconception that user-installed app data is stored on the SD card (/mnt/sdcard/) because users commonly see app files there, but in Android's security model, private app data is strictly kept in /data/data/ and not on external storage.

How to eliminate wrong answers

Option A is wrong because /vendor/ contains proprietary firmware and system-level binaries provided by the device manufacturer, not user-installed app data. Option C is wrong because /system/ holds the Android operating system files (e.g., framework, core apps) and is read-only in normal operation; user-installed app data is never stored here. Option D is wrong because /mnt/sdcard/ (or /sdcard) is the external or emulated storage mount point for user-accessible files like photos and downloads, but it does not contain app-specific private data, preferences, or cached information that is sandboxed per app.

473
MCQmedium

A forensic analyst finds multiple Prefetch files in C:\Windows\Prefetch with recent timestamps. What is the primary value of Prefetch files in an investigation?

A.They store the user's web browsing history
B.They list all network connections made by the system
C.They record the first and last execution times of applications
D.They contain the actual content of user documents
AnswerC

Prefetch is designed as a performance mechanism, but forensically it acts as an application execution artifact: each .pf file contains a 'last run time' header field and a run count, while the file's creation timestamp indicates when the executable was first executed. This combination lets an analyst reconstruct first and last run times (and frequency) for programs like browsers, document viewers, and executables of interest, even if the system timezone offset must be accounted for during parsing. Because Prefetch files are created automatically for commonly run executables and are plain binary files, tools such as PECmd or Prefetch Parser can extract these timestamp values reliably.

Why this answer

Prefetch files in Windows store metadata about application launches, including the first and last execution times. This allows forensic analysts to determine when a specific program was run, which is crucial for timeline analysis and identifying unauthorized or malicious software execution.

Exam trap

EC-Council often tests the misconception that Prefetch files contain user data or network logs, but they only store execution metadata; candidates confuse Prefetch with other artifacts like browser cache or event logs.

How to eliminate wrong answers

Option A is wrong because web browsing history is stored in browser-specific locations (e.g., Chrome's History file, IE's index.dat) and not in Prefetch files. Option B is wrong because network connections are logged via Netstat or Windows Firewall logs, not Prefetch; Prefetch only tracks application execution. Option D is wrong because Prefetch files contain metadata (e.g., timestamps, file paths, run count) and never the actual content of user documents.

474
MCQhard

A malware analyst is examining a suspicious Windows executable. Running 'strings' reveals references to 'C:\Windows\System32\drivers\etc\hosts' and IP addresses 185.130.5.21 and 192.168.1.1. Dynamic analysis in a sandbox shows the binary modifies the hosts file and creates a mutex named 'Global\Mtx_Update'. Which behavioral indicator is MOST clearly associated with persistence?

A.Modifying the hosts file with an entry for 192.168.1.1
B.Connecting to IP 185.130.5.21 on port 443
C.Writing temporary files to %TEMP%
D.Creating the mutex 'Global\Mtx_Update'
AnswerA

The hosts file at %SystemRoot%\System32\drivers\etc\hosts is consulted by the Windows DNS resolver on every name-resolution attempt, so an entry mapping a domain to 192.168.1.1 changes system-wide resolution behavior even after a reboot. This is a persistent system-level configuration change that can silently redirect a target hostname to an attacker-controlled IP, enabling traffic interception, credential harvesting, or bypass of DNS-based defenses. Unlike transient runtime actions, this modification remains active until the file is edited or the entry is removed.

Why this answer

Modifying the hosts file to redirect a legitimate domain to 192.168.1.1 is a classic persistence mechanism: the malware ensures that every time the system resolves that domain, it points to the attacker-controlled IP, effectively hijacking network traffic persistently across reboots without needing to run at startup. This behavior directly maintains unauthorized control over name resolution, which is a hallmark of persistence.

Exam trap

EC-Council often tests the distinction between persistence (surviving reboot) and other behavioral indicators like mutex creation or network connections, so the trap here is confusing a mutex (used for single-instance control) with a persistence mechanism.

How to eliminate wrong answers

Option B is wrong because connecting to an external IP (185.130.5.21) on port 443 is a network communication indicator (C2 beaconing), not a persistence mechanism—it does not ensure the malware survives a reboot. Option C is wrong because writing temporary files to %TEMP% is a common execution artifact (e.g., dropping payloads or logs) but does not by itself guarantee the malware will re-execute after a system restart. Option D is wrong because creating a mutex (Global\Mtx_Update) is a synchronization primitive used to prevent multiple instances of the malware from running simultaneously; it does not provide any mechanism for automatic re-execution upon boot.

475
Multi-Selectmedium

A forensic investigator is analyzing a Windows system suspected of malware infection. Which THREE of the following are common persistence mechanisms that malware may use?

Select 3 answers
A.Scheduled Tasks via schtasks
B.Creating a Windows service
C.Adding an entry to the hosts file
D.Modifying the boot.ini file
E.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AnswersA, B, E

The Task Scheduler service can create tasks that run executables at specified times or system events, and schtasks.exe is a command-line interface for this. Malware can create hidden or named tasks that trigger on logon, idle, or unusual events, making them a robust persistence vector. Investigators should enumerate scheduled tasks via schtasks /query or the Task Scheduler API and compare against a known baseline.

Why this answer

Scheduled Tasks via schtasks (A) are a common persistence mechanism because malware can register a task with the Task Scheduler service to execute its payload at logon, on a schedule, or on system events, surviving reboots. Creating a Windows service (B) is also a classic persistence technique, since services configured with auto-start (e.g., via sc.exe create or the Service Control Manager) launch automatically at boot under a privileged account. The Run key at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (E) is a well-known autostart location that Windows reads at user logon to launch listed programs, making it a favorite for malware persistence.

Adding an entry to the hosts file (C) is not a persistence mechanism; it only redirects DNS resolution and does not cause code to execute. Modifying boot.ini (D) is not applicable to modern Windows systems, which use the Boot Configuration Data (BCD) store, and boot.ini was used only on legacy BIOS-based Windows XP/2003 systems.

Exam trap

The CHFI exam tests the distinction between persistence mechanisms that cause automatic code execution on startup/logon and other system modifications (like hosts or boot.ini) that alter behavior but do not re-launch the malware. Windows services are explicitly a key persistence mechanism, but candidates sometimes overlook them because they blend in with normal system processes.

476
MCQmedium

During a forensic investigation, an analyst recovers a hard drive that uses GPT partitioning. The analyst needs to locate the backup GPT header to verify partition table integrity. Where is the backup GPT header typically stored on the disk?

A.The first sector of the last partition
B.The last sector of the disk
C.Sector 0 (the MBR sector)
D.Sector 1 (immediately after the protective MBR)
AnswerB

The backup GPT header is deliberately written to the last logical sector of the disk (LBA N−1) to provide redundancy if the primary header at LBA 1 is corrupted or lost. It contains a copy of the disk GUID, partition entries' CRC, and the pointer to the backup partition-entry array, allowing full GPT reconstruction. Forensic examiners should read the final sector of the device image, not the last sector of any partition, to locate this structure. This design ensures the partitioning scheme can be recovered even when the primary header is unrecoverable.

Why this answer

The backup GPT header is stored in the last sector of the disk (LBA -1) to provide redundancy. If the primary GPT header in LBA 1 is corrupted, the backup can be used to reconstruct the partition table. This design ensures the GPT structure can be recovered even if the beginning of the disk is damaged.

Exam trap

The trap here is confusing the backup GPT header's location with the primary GPT header (Sector 1) or assuming it resides within a partition, when in fact it is always at the very last sector of the disk.

How to eliminate wrong answers

Option A is wrong because the backup GPT header is not stored in the first sector of the last partition; it occupies the last sector of the entire disk, independent of partition boundaries. Option C is wrong because Sector 0 (LBA 0) contains the protective MBR, not the GPT header or its backup. Option D is wrong because Sector 1 (LBA 1) holds the primary GPT header, not the backup.

477
MCQmedium

During a database forensic investigation, an analyst recovers a MySQL binary log file (binlog.000012) from a compromised server. Which command should the analyst use to extract the actual SQL statements from this binary log in a human-readable format?

A.mysqldump --binlog binlog.000012
B.mysqlimport --binlog binlog.000012
C.mysqlcheck --binlog binlog.000012
D.mysqlbinlog binlog.000012
AnswerD

mysqlbinlog is the official MySQL utility for reading binary log files and converting their events into human-readable SQL statements or, with appropriate options, into replayable SQL for database restoration. It supports statement-based, row-based, and mixed binlog formats, and it allows selective forensic analysis using time ranges, position ranges, and offset filters. In a database forensic investigation, running mysqlbinlog binlog.000012 reveals the exact transactional operations, timestamps, server IDs, and event sequence recorded in that log, enabling reconstruction of unauthorized changes or data exfiltration attempts.

Why this answer

The `mysqlbinlog` utility is specifically designed to parse MySQL binary log files and output the contained SQL statements in a human-readable format. Binary logs record all data-changing operations (e.g., INSERT, UPDATE, DELETE) in a proprietary binary format, so only `mysqlbinlog` can decode them back into readable SQL for forensic analysis.

Exam trap

EC-Council often tests the distinction between MySQL administrative utilities (mysqldump, mysqlcheck, mysqlimport) and the forensic-specific tool mysqlbinlog, exploiting the common misconception that any MySQL command with 'binlog' in its name can read binary logs.

How to eliminate wrong answers

Option A is wrong because `mysqldump` is a backup tool that exports database schemas and data as SQL text, not a binary log reader; it has no `--binlog` option. Option B is wrong because `mysqlimport` is used to load data from text files into tables using LOAD DATA INFILE, and it does not interact with binary logs. Option C is wrong because `mysqlcheck` is a maintenance utility for checking, repairing, and optimizing tables; it cannot decode binary log files.

478
Multi-Selecthard

A forensic examiner is analyzing a Linux system suspected of being used as a C2 server. Which THREE artifacts should the examiner prioritize to find evidence of command execution and persistence? (Select three.)

Select 3 answers
A.~/.bash_history
B./var/log/syslog
C./etc/passwd
D./var/log/auth.log
E./etc/crontab
AnswersA, D, E

~/.bash_history records commands typed in interactive Bash sessions, revealing executed tooling, downloaded payloads and reconnaissance. This satisfies the stem's command execution and persistence constraint, since it directly evidences what the operator ran on the suspected C2 host.

Why this answer

Option A, ~/.bash_history, is correct because it records the interactive commands executed by a user's Bash shell, which can reveal attacker commands used to establish or operate C2 functionality. Option D, /var/log/auth.log, is correct because on Debian-based Linux systems it captures authentication events such as SSH logins, sudo usage, and failed login attempts, which help trace unauthorized access and privilege escalation tied to persistence. Option E, /etc/crontab, is correct because it is a system-wide cron table where scheduled jobs can be added by attackers to maintain persistence and periodically re-execute malicious commands.

Option B, /var/log/syslog, is not among the marked answers because although it contains general system messages, it is less directly focused on command execution and persistence than the selected artifacts. Option C, /etc/passwd, is not among the marked answers because it primarily lists local user accounts and does not by itself provide evidence of command execution or persistence mechanisms.

Exam trap

EC-ChFI often tests the distinction between logs that record authentication events (auth.log) versus logs that record command execution (bash_history), and candidates may mistakenly choose syslog thinking it captures all system activity, but it does not reliably capture per-user shell commands.

479
MCQeasy

An analyst is examining a Windows 10 system and discovers a file in the $Recycle.bin folder with a name like '$RABCDEF.txt'. The analyst wants to recover the original file path and deletion date. Which forensic artifact should the analyst examine?

A.The corresponding $I file (e.g., $IABCDEF.txt) in $Recycle.bin
B.The Windows Event Logs
C.The USN journal
D.The $MFT entry for the $R file
AnswerA

The $I file in the $Recycle.bin folder is an index entry created when a file is deleted via Explorer; it stores the original file name, full path before deletion, and the deletion timestamp. Because the $R file is renamed to a random name, the $I file is the authoritative source for reconstructing the original location and time. Forensic tools parse $I files to recover this metadata directly.

Why this answer

The $I file (e.g., $IABCDEF.txt) in the $Recycle.bin folder is the index file that stores metadata about the deleted file, including the original file path, original size, and the date and time when the file was deleted. The $R file contains only the actual data content of the deleted file, not its metadata. Therefore, examining the corresponding $I file is the correct method to recover the original file path and deletion date.

Exam trap

EC-Council CHFI often tests the misconception that the $R file itself contains metadata like the original path or deletion date, when in fact the $R file is only the data content, and all metadata is stored exclusively in the corresponding $I file.

How to eliminate wrong answers

Option B is wrong because Windows Event Logs may record some deletion events (e.g., via Sysmon or auditing), but they do not reliably store the original file path and deletion date for every file moved to the Recycle Bin, and they are not the primary forensic artifact for this purpose. Option C is wrong because the USN journal records changes to files (e.g., rename, delete) but does not store the original file path or the exact deletion timestamp in a structured way that directly maps to the $R file; it is a change journal, not a metadata store for recycled files. Option D is wrong because the $MFT entry for the $R file only contains metadata about the $R file itself (e.g., its name, timestamps, data runs) but does not contain the original file path or the deletion date; the original path is stored only in the $I file's header.

480
MCQmedium

An investigator must acquire a 2 TB USB 3.0 external hard drive as evidence in a fraud case. The drive contains a single NTFS volume with 500 GB of allocated data. The investigator needs to create a forensic image that captures all allocated and unallocated space, and the acquisition must be completed as quickly as possible while maintaining evidential integrity. Which acquisition method should the investigator use?

A.Perform a sparse acquisition that only copies allocated clusters
B.Create a logical image of the NTFS volume using EnCase Logical Evidence File (LEF)
C.Use the dd command with a software write blocker to create a raw image
D.Create a physical image using a hardware write blocker and FTK Imager in E01 format
AnswerD

A physical image captures every sector, including allocated and unallocated space, preserving all potential evidence. Using a hardware write blocker prevents any writes to the source drive, maintaining integrity. FTK Imager with E01 compression reduces file size and is a standard forensic format, making this the correct choice for speed and completeness.

Why this answer

A physical image captures every sector, including unallocated space, which is essential for recovering deleted evidence in a fraud case. A hardware write blocker ensures the source drive is not altered, preserving evidential integrity. E01 compression reduces storage and transfer time compared to raw formats, addressing the speed requirement.

Logical or sparse acquisitions would omit critical areas, making them unsuitable.

Exam trap

The trap here is assuming that a logical image or sparse acquisition is sufficient because it captures the visible files, but it misses unallocated space where deleted evidence often resides.

481
MCQmedium

During a forensic investigation, the examiner uses a write blocker to connect the suspect drive to the forensic workstation. What is the PRIMARY purpose of using a write blocker?

A.To speed up the data acquisition process
B.To encrypt the data on the evidence drive
C.To prevent the operating system from writing data to the evidence drive
D.To allow the evidence drive to be used as a boot device
AnswerC

When an evidence drive is attached to a forensic workstation, the operating system may automatically write metadata, update access timestamps, mount a volume, or modify system log entries. A write blocker intercepts write commands at the drive interface (such as ATA, SATA, or USB) and returns a fabricated success status without ever issuing the write to the physical disk. This ensures that the original drive remains bit-for-bit unchanged, which is essential for later hash verification of the forensic image. By preventing OS writes, the blocker preserves the evidentiary integrity of the source medium.

Why this answer

The primary purpose of a write blocker is to intercept and block any write commands from the operating system to the evidence drive, ensuring that the original data remains unaltered (bit-for-bit identical) during acquisition. This maintains the forensic integrity of the evidence, which is critical for admissibility in legal proceedings. Without a write blocker, the OS could automatically write metadata, logs, or temporary files to the drive, contaminating the evidence.

Exam trap

The CHFI exam often tests the misconception that write blockers are used to prevent the examiner from accidentally writing to the drive, but the real trap is that candidates confuse the purpose with data protection (encryption) or performance enhancement, rather than understanding it is strictly about preserving the original state by blocking OS-level writes.

How to eliminate wrong answers

Option A is wrong because write blockers do not speed up acquisition; in fact, they may slightly slow it due to command filtering overhead, and speed depends on the interface (e.g., SATA, USB) and imaging tool. Option B is wrong because write blockers do not encrypt data; encryption is a separate process (e.g., using BitLocker or VeraCrypt) and would actually hinder forensic analysis by obscuring the original data. Option D is wrong because write blockers are designed to prevent any writes, including boot-time writes; booting from the evidence drive would require write access for the OS to modify system files and logs, which defeats the purpose of preservation.

482
MCQhard

In a UK-based investigation, the police seize a computer without a warrant. The suspect's lawyer argues that the evidence is inadmissible because it violates which law?

A.Police and Criminal Evidence Act (PACE)
B.Fourth Amendment to the US Constitution
C.General Data Protection Regulation (GDPR)
D.Computer Misuse Act
AnswerA

The Police and Criminal Evidence Act 1984 (PACE) is the primary statutory framework governing police powers to search premises and seize property in England and Wales. Where a computer is lawfully seized, PACE and its Codes of Practice impose conditions on how the device is handled, including making an inventory, and subsequent forensic examination must respect the scope of the original warrant or power. This makes PACE the correct legal basis for the seizure, not any constitutional, data-protection, or computer-offence statute.

Why this answer

The Police and Criminal Evidence Act (PACE) 1984 governs the powers of police in England and Wales to search, seize, and retain evidence. Without a warrant, the seizure of a computer likely violates PACE's requirements for lawful entry and seizure, making the evidence inadmissible under UK law.

Exam trap

EC-Council often tests the distinction between US constitutional law (Fourth Amendment) and UK statutory law (PACE), causing candidates to mistakenly apply US legal principles to a UK scenario.

How to eliminate wrong answers

Option B is wrong because the Fourth Amendment to the US Constitution applies only to searches and seizures by US government entities, not to UK police investigations. Option C is wrong because the General Data Protection Regulation (GDPR) governs the processing of personal data, not the legality of evidence seizure without a warrant. Option D is wrong because the Computer Misuse Act criminalizes unauthorized access to computer systems, but does not regulate police seizure procedures or admissibility of evidence.

483
MCQeasy

In Windows forensics, which artifact is a database of metadata about files and applications accessed by the user, used to populate the 'Recent Items' and 'Quick Access' lists?

A.Jumplists
B.Prefetch files
C.LNK files
D.ShellBags
AnswerA

Jumplists are stored as .automaticDestinations-ms and .customDestinations-ms files in the user's Recent folder, implemented as COM Structured Storage (OLE compound file) databases. Each destination contains a stream whose embedded LNK blobs hold metadata about opened files, directories, and tasks, along with timestamps, file paths, and application IDs. Thus they are the best answer for a database of file/application metadata.

Why this answer

Jumplists are the correct answer because they are a Windows artifact that stores metadata about recently accessed files and applications, directly populating the 'Recent Items' and 'Quick Access' lists in the taskbar and File Explorer. Each jumplist is a database file (e.g., .automaticDestinations-ms or .customDestinations-ms) containing entries with timestamps, file paths, and application IDs, making them a key source for forensic reconstruction of user activity.

Exam trap

EC-Council often tests the misconception that LNK files (Option C) are the primary artifact for 'Recent Items', but jumplists are the actual database that aggregates and manages these entries, while LNK files are just individual shortcuts that may be referenced within the jumplist.

How to eliminate wrong answers

Option B is wrong because Prefetch files (.pf) are used to speed up application startup by caching file access patterns, not to populate 'Recent Items' or 'Quick Access' lists; they track execution history but not user-accessed file metadata. Option C is wrong because LNK files (.lnk) are shortcuts that point to a specific file or application, but they are not a database of metadata; they are individual artifacts that can appear in jumplists but do not themselves aggregate the 'Recent Items' list. Option D is wrong because ShellBags store folder view settings (e.g., window size, position, and view mode) for Explorer windows, not a database of recently accessed files or applications for 'Recent Items' or 'Quick Access'.

484
MCQmedium

An iOS forensic examiner recovers a Keychain dump from an iPhone. Which of the following types of data is typically NOT stored in the iOS Keychain?

A.Wi-Fi passwords
B.Safari saved passwords
C.SMS message content
D.VPN credentials
AnswerC

SMS message content is physically stored in the SQLite database located at /private/var/mobile/Library/SMS/sms.db, with message bodies in the 'message' table and multimedia payloads in an adjacent attachments directory. The iOS Keychain is reserved for small encrypted secrets—passwords, tokens, certificates, and private keys—and does not store conversational text. Even after recovering and decrypting a keychain dump, an examiner must turn to sms.db to obtain SMS or iMessage body text, so SMS content is the only listed item that is truly absent from a keychain dump and is therefore the correct answer.

Why this answer

The iOS Keychain is designed to store small, sensitive credentials such as passwords, keys, and certificates. SMS message content is stored in the SMS/MMS database (sms.db) under the protected /private/var/mobile/Library/SMS/ directory, not in the Keychain. Keychain items are encrypted per-app or per-service, whereas SMS messages are managed by the Messages app and stored in a SQLite database with its own encryption layer.

Exam trap

EC-Council often tests the misconception that all sensitive user data (including messages) is stored in the Keychain, but the Keychain is strictly for credentials and secrets, not for bulk message content.

How to eliminate wrong answers

Option A is wrong because Wi-Fi passwords are stored in the iOS Keychain as network credentials, accessible via the System Keychain. Option B is wrong because Safari saved passwords are stored in the Keychain under the iCloud Keychain or local Keychain for autofill. Option D is wrong because VPN credentials (e.g., L2TP, IPSec shared secrets, or certificate-based authentication) are stored in the Keychain as part of the VPN configuration payload.

485
MCQmedium

A forensic analyst is examining a Microsoft Outlook PST file as part of an email investigation. Which tool is specifically designed to parse and analyze PST files and extract email metadata?

A.Wireshark
B.EmailTracker
C.Sleuth Kit
D.Aid4Mail
AnswerD

Aid4Mail is a forensic-grade email extraction tool specifically designed to parse Microsoft Outlook PST files by interpreting their internal B-tree structure, MAPI property tags, and folder hierarchy. It preserves crucial artifacts such as message timestamps, folder structures, and attachment metadata, and can export to EML, MSG, MBOX, or PDF while maintaining hash-based data integrity for evidence handling. It also supports password-protected PSTs and recovers partially damaged or deleted items, which are common challenges in real investigations. For a forensic analyst examining a PST, Aid4Mail is the appropriate comprehensive solution.

Why this answer

Aid4Mail is a forensic email analysis tool that supports PST, OST, MBOX, and other formats. It is commonly used for email investigations.

486
MCQhard

After a factory reset on an Android device, a forensic examiner attempts to recover user data. Which of the following statements is most accurate regarding the recoverability of data?

A.Some user data may be recoverable from the /data partition if it has not been overwritten
B.Data in /data/data/ is securely wiped using TRIM commands, making recovery impossible
C.All user data is permanently destroyed and cannot be recovered
D.Only Google account tokens are recoverable after a factory reset
AnswerA

Factory reset on Android typically reformats the /data partition by re-creating its filesystem metadata, which removes logical pointers to user files but does not automatically zero or erase every data block on the flash storage. As a result, files that occupied previously allocated blocks can remain physically intact until overwritten by subsequent writes, and forensic tools can carve these residuals. If device encryption is in use and the key is properly discarded, recovery becomes harder, but this is a separate mechanism and does not make the raw remnants inherently impossible to recover.

Why this answer

A factory reset on Android typically performs a fast format of the /data partition, which only erases the file system metadata (e.g., ext4 journal and inode tables) but does not overwrite the actual data blocks. Therefore, user data may remain on the flash storage and be recoverable using forensic tools until those blocks are overwritten by new writes. This is why option A is correct: some user data may be recoverable from the /data partition if it has not been overwritten.

Exam trap

The CHFI exam often tests the misconception that a factory reset performs a full secure wipe, when in reality it only removes file system pointers and does not overwrite the underlying data, making recovery possible until overwritten.

How to eliminate wrong answers

Option B is wrong because TRIM commands are issued by the file system to the eMMC/NAND controller to mark blocks as unused, but they do not securely wipe data; they only allow the controller to garbage-collect blocks, and data remnants can often be recovered before physical erasure. Option C is wrong because a factory reset does not perform a secure erase or overwrite of all user data; it only removes file system pointers, leaving the underlying data intact until overwritten. Option D is wrong because not only Google account tokens but also other user data (e.g., app data, cached files, photos) may be recoverable from the /data partition after a factory reset.

487
MCQmedium

Which tool is specifically designed to extract metadata from email messages, including tracking the route and identifying the originating IP address?

A.EmailTracker
B.Wireshark
C.MailXaminer
D.Outlook
AnswerA

EmailTracker is purpose-built for email forensic metadata extraction: it parses RFC 5322 headers to capture originating IP addresses, Received-chain hops, Message-ID, SPF/DKIM/DMARC authentication results, and timestamps. It then visualizes the routing path to help investigators identify the actual sender and trace email provenance, a capability no generic network or mailbox tool provides.

Why this answer

EmailTracker is a tool that analyzes email headers to trace the path and identify the source IP, often used in email forensics.

488
MCQhard

A security analyst observes a suspicious process creating multiple mutexes with names like 'XxX_12345' and 'XxX_67890' and making outbound connections to an IP address 185.130.5.1 on port 443. Which behavioral indicator is MOST consistent with malware communication?

A.The process is performing data exfiltration via DNS tunneling
B.The process is attempting to spread to other machines via SMB
C.The mutexes indicate an attempt to prevent multiple instances, and outbound connections suggest C2 activity
D.The process is a legitimate application using mutexes for inter-process communication
AnswerC

Malware commonly creates specific named mutexes to ensure only one instance runs, preventing duplicate infections and making analysis harder; the presence of these mutexes is a behavioral indicator. Multiple outbound TLS connections to a fixed external IP on 443 are a classic command-and-control pattern, especially when the IP is a known suspicious address like 185.130.5.1, so combined these observations point to C2 activity.

Why this answer

The creation of mutexes with a consistent naming pattern (e.g., 'XxX_12345') is a classic anti-replication mechanism used by malware to ensure only one instance runs on a system, preventing conflicts and detection. The outbound connections to a specific IP on port 443 (HTTPS) are highly indicative of command-and-control (C2) communication, as malware often uses encrypted channels to blend in with legitimate traffic. Option C correctly identifies both the mutex's purpose (preventing multiple instances) and the network behavior (C2 activity), making it the most consistent with malware communication.

Exam trap

The CHFI exam often tests the misconception that any outbound connection on port 443 is automatically legitimate HTTPS traffic, but the trap here is that malware frequently uses this port for C2, and the mutex pattern is a key differentiator from benign software.

How to eliminate wrong answers

Option A is wrong because DNS tunneling involves encoding data in DNS queries/responses, typically on UDP port 53, not outbound HTTPS connections on port 443; the mutex names also have no relation to DNS. Option B is wrong because SMB propagation uses port 445 (or 139) for file and printer sharing, not port 443, and mutexes are not a standard mechanism for spreading via SMB. Option D is wrong because while legitimate applications do use mutexes for inter-process communication, the combination of suspicious mutex names (e.g., 'XxX_') and outbound connections to an external IP on a common C2 port (443) is not typical of benign software; legitimate apps rarely hardcode such patterns for external communication.

489
MCQeasy

In Windows registry forensics, which registry hive contains the SAM database storing local user account hashes?

A.HKLM\Security
B.HKLM\System
C.NTUSER.DAT
D.HKLM\Sam
AnswerD

HKLM\SAM is the loaded registry view of the Security Accounts Manager database, and it contains the local user account hashes under HKLM\SAM\SAM\Domains\Account\Users. Each user key is named by the account's relative identifier (RID), and the V value contains the LM/NTLM hash verifiers used by Windows to authenticate local accounts. This is how the operating system exposes the credential store in the registry, making SAM the correct forensic target.

Why this answer

The SAM (Security Account Manager) database, which stores local user account password hashes (LM and NTLM hashes), is mounted in the Windows registry under the HKLM\SAM hive. This hive is directly accessible only by the SYSTEM account for security reasons, and it contains the hashes in the SAM\SAM\Domains\Account\Users subkey. Option D is correct because HKLM\Sam is the exact registry path where the SAM database resides.

Exam trap

In CHFI, a common mistake is confusing HKLM\Security (stores cached domain credentials) with HKLM\SAM (stores local account hashes). Also, NTUSER.DAT only contains user-specific settings, not system-wide account data.

How to eliminate wrong answers

Option A is wrong because HKLM\Security stores security policy settings, audit policies, and cached domain logon credentials, not the SAM database with local user hashes. Option B is wrong because HKLM\System contains system-wide configuration, device drivers, and control sets (e.g., CurrentControlSet), but not user account hashes. Option C is wrong because NTUSER.DAT is a per-user registry hive loaded under HKEY_CURRENT_USER, containing user-specific settings and preferences, not the system-wide SAM database.

490
MCQmedium

A security analyst detects that a known malware sample writes to the registry key 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service. This behavior is characteristic of which type of persistence mechanism?

A.Scheduled task
B.AppInit_DLLs
C.Startup folder entry
D.Windows service
AnswerD

The registry key HKLM\SYSTEM\CurrentControlSet\Services\<malware> is the canonical storage location for a Windows service definition, including the ImagePath to the executable, the Start value (e.g., 2 for AUTO_START), and the service Type. The Service Control Manager (SCM) enumerates these keys at system boot and launches the service according to its Start value, typically with SYSTEM privileges. This gives malware a reliable, auto-starting, system-level persistence mechanism that survives reboots and runs even before any user logs in. Therefore, the evidence strongly indicates the malware was installed as a Windows service.

Why this answer

The malware writes to 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service, which is the exact mechanism for registering a Windows service. This persistence method ensures the malware runs automatically when the system boots, as the Service Control Manager (SCM) loads services based on this registry key. Option D is correct because this behavior directly corresponds to the Windows service persistence technique.

Exam trap

The CHFI exam often tests the distinction between registry-based persistence mechanisms; the trap here is that candidates confuse the 'Services' registry key with other common persistence locations like 'Run' keys or 'AppInit_DLLs', but the specific 'ImagePath' value under a service subkey uniquely identifies Windows service persistence.

How to eliminate wrong answers

Option A is wrong because scheduled tasks are configured via the Task Scheduler and stored in 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule' or XML files in '\Windows\System32\Tasks', not under the Services registry key. Option B is wrong because AppInit_DLLs persistence uses the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs' registry value to load DLLs into every user-mode process, not by creating a service entry. Option C is wrong because the Startup folder entry involves placing a shortcut or executable in 'C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup' or the All Users startup folder, not modifying the Services registry hive.

491
MCQmedium

During a forensic investigation, an analyst uses a tool to create a bit-for-bit copy of a hard drive while ensuring the original is not modified. Which of the following is a hardware write blocker that can be used for this purpose?

A.FTK Imager
B.Tableau
C.dd
D.EnCase
AnswerB

Tableau is a manufacturer of dedicated hardware write blockers, not just imaging software. A Tableau device sits between the suspect drive and the forensic workstation, intercepting ATA/SCSI commands at the hardware level and physically gating any write command from reaching the storage medium. This hardware-level enforcement is exactly what forensic investigators need to guarantee that the original evidence remains unaltered, making Tableau the correct answer.

Why this answer

A hardware write blocker physically prevents any write commands from reaching the original drive at the SATA/IDE bus level, ensuring the drive remains unaltered during acquisition. Tableau is a well-known manufacturer of forensic hardware write blockers that operate transparently to the imaging software, making it the correct choice for a hardware-based solution.

Exam trap

The CHFI exam often tests the distinction between software tools (FTK Imager, dd, EnCase) and dedicated hardware write blockers (Tableau), trapping candidates who assume any forensic imaging tool inherently provides write protection.

How to eliminate wrong answers

Option A is wrong because FTK Imager is a software tool, not a hardware device; it relies on the operating system or a separate hardware blocker to prevent writes. Option C is wrong because dd is a Unix/Linux command-line utility for bit-for-bit copying, but it is software and does not inherently block writes to the source drive without additional safeguards like a hardware blocker or a read-only mount. Option D is wrong because EnCase is a forensic software suite that can acquire images, but it is not a hardware write blocker; it depends on external hardware or software write protection to ensure the source is not modified.

492
MCQmedium

Which of the following is an example of Locard's Exchange Principle as applied to digital forensics?

A.A suspect's computer contains log files showing they accessed a server
B.A hard drive is encrypted and cannot be read
C.A firewall blocks all incoming traffic from a specific IP address
D.A write blocker prevents data from being written to a drive
AnswerA

Locard's exchange principle holds that any contact leaves traces; a network connection from a suspect's computer to a server is such a contact. The log files on the suspect's system are digital remnants of that interaction, demonstrating that the access transferred data and left artifacts on both endpoints. These artifacts are analogous to physical trace evidence, making this a valid example of the principle.

Why this answer

Locard's Exchange Principle states that every contact leaves a trace. In digital forensics, this translates to the idea that when a system interacts with another, digital artifacts (such as log entries, registry keys, or network connection records) are created. Option A is correct because the log files on the suspect's computer are a direct trace of the contact between the suspect's system and the server, demonstrating the principle in a digital context.

Exam trap

EC-Council often tests the misconception that any security tool or data protection mechanism (like encryption or firewalls) is an example of Locard's Exchange Principle, when in fact the principle specifically requires evidence of a transfer or contact trace, not a barrier or lack of access.

How to eliminate wrong answers

Option B is wrong because encryption is a protective measure that prevents data access, not an example of trace evidence exchange; it does not demonstrate the creation of digital artifacts from contact. Option C is wrong because a firewall rule that blocks traffic is a security control that prevents contact, not a trace of contact that has already occurred; it does not illustrate the exchange of digital evidence. Option D is wrong because a write blocker is a hardware or software tool used to preserve evidence integrity during acquisition, not an example of a trace left by an interaction; it prevents modification, not exchange.

493
MCQeasy

Which of the following is the primary purpose of performing static analysis on a suspicious binary?

A.Capturing network traffic generated by the binary
B.Observing the binary's runtime behaviour in a sandbox
C.Analysing the binary's code and structure without executing it
D.Modifying the binary to bypass anti-analysis techniques
AnswerC

Static analysis is the process of examining a binary without executing it, focusing on its structural and code-level characteristics. This includes parsing file headers (PE/ELF), analysing import and export tables, extracting readable strings, detecting packers, and disassembling or decompiling code into control flow graphs. The goal is to understand the program's functionality, capabilities, and potential vulnerabilities purely from its inert representation, making it safe for initial triage of unknown or malicious files.

Why this answer

Static analysis examines a binary's code and structure without executing it, allowing analysts to identify malicious indicators such as embedded strings, import tables, and cryptographic constants. This approach avoids triggering anti-analysis mechanisms that activate upon execution, making it a foundational step in malware forensics.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse observing runtime behavior (dynamic) with examining code without execution (static).

How to eliminate wrong answers

Option A is wrong because capturing network traffic is a dynamic analysis technique that requires executing the binary to observe its communication, not static analysis. Option B is wrong because observing runtime behavior in a sandbox is dynamic analysis, which executes the binary and risks triggering anti-VM or anti-sandbox code. Option D is wrong because modifying the binary to bypass anti-analysis is an active evasion technique, not a purpose of static analysis; static analysis is non-invasive and does not alter the binary.

494
MCQmedium

During an e-discovery process, a legal hold is issued. What is the PRIMARY purpose of a legal hold?

A.To authorize forensic examiners to image all company devices
B.To prevent the destruction or alteration of potentially relevant evidence
C.To encrypt all data to prevent unauthorized access during litigation
D.To notify the opposing party of the intent to use electronic evidence
AnswerB

The core purpose of a legal hold is to ensure that potentially relevant electronically stored information (ESI) is preserved in place, preventing its destruction, alteration, or loss during the e-discovery process. It suspends normal document-retention and recycling schedules so that evidence remains intact and authentic for later collection and review. Failure to implement a proper hold can lead to spoliation and severe sanctions, including adverse inference instructions or case-dispositive penalties.

Why this answer

The primary purpose of a legal hold is to preserve all forms of potentially relevant evidence by suspending normal data retention and deletion policies. This ensures that data, including emails, documents, and logs, is not altered or destroyed during the e-discovery process, which is critical for maintaining the integrity of evidence for litigation.

Exam trap

EC-Council often tests the distinction between preservation (legal hold) and collection (imaging), so candidates mistakenly choose authorization for imaging because they conflate the forensic process with the legal obligation to preserve.

How to eliminate wrong answers

Option A is wrong because a legal hold does not authorize forensic imaging; that requires a separate court order or explicit consent, and imaging is a technical step that follows preservation. Option C is wrong because encryption is a security measure to protect data from unauthorized access, not a preservation mechanism, and it can actually hinder e-discovery if keys are not managed properly. Option D is wrong because notifying the opposing party about the intent to use electronic evidence is part of the discovery phase, not the preservation phase, and is governed by rules like FRCP 26, not a legal hold.

495
MCQhard

During a forensic investigation of a compromised web server, an analyst finds the following entry in the IIS access log: 192.168.1.5, -, 04/May/2024:14:23:11, GET /scripts/..%5c../windows/system32/cmd.exe, 200. What is the probable attack vector?

A.Brute force attack
B.Cross-site scripting
C.Path traversal
D.SQL injection
AnswerC

The ..%5c.. sequence is URL encoding where %5c represents a backslash, so the payload decodes to ..\.., the classic directory-traversal prefix used to escape the web root. When processed by a vulnerable IIS server, this allowed an attacker to request files like C:\windows\system32\cmd.exe with the unencoded traversal string intact. The request is a single crafted path with encoded separators, which is precisely the signature of a path traversal attack rather than any of the other categories listed.

Why this answer

The log shows a path traversal attempt using URL-encoded backslashes (%5c) to navigate to cmd.exe. The 200 status indicates the request succeeded. This is a classic path traversal attack.

496
MCQeasy

In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?

A.Audit log
B.Error log
C.Transaction log
D.Slow query log
AnswerC

The transaction log (also known as the redo log or write-ahead log) is the authoritative database component that sequentially records every data modification operation before it is committed to the main data files. In crash recovery, this log ensures ACID durability by enabling rollback of uncommitted transactions and replay of committed ones. Because it captures the before-and-after images (or logical changes) of all successful and incomplete transactions, it is the correct answer for a log that records every transaction.

Why this answer

Transaction logs (also called redo logs) record all changes to the database, enabling point-in-time recovery and auditing of data modifications.

497
MCQeasy

Which network forensic tool is BEST suited for analyzing NetFlow data to identify top talkers and detect anomalies?

A.SiLK
B.tcpdump
C.Nmap
D.Wireshark
AnswerA

SiLK (System for Internet-Level Knowledge) is a suite of flow analysis tools designed to collect, store, and query NetFlow/IPFIX flow records. It ingests exported flow data from routers and switches, then uses tools like rwfilter and rwstats to perform high-speed, field-based filtering and statistical aggregation without touching raw packet payloads. This makes it the correct choice for analyzing NetFlow data.

Why this answer

SiLK (System for Internet-Level Knowledge) is specifically designed for large-scale NetFlow data analysis, providing tools to aggregate flow records, identify top talkers (e.g., using rwtop or rwstats), and detect anomalies through statistical baselines. Unlike packet-level tools, SiLK works directly with flow summaries, making it efficient for high-volume network traffic analysis in forensic investigations.

Exam trap

EC-Council often tests the distinction between packet-level forensics (tcpdump/Wireshark) and flow-level forensics (SiLK), trapping candidates who assume Wireshark can analyze NetFlow data because it can capture packets, when in fact NetFlow is a separate export protocol requiring dedicated tools.

How to eliminate wrong answers

Option B (tcpdump) is wrong because it captures raw packets at the interface level, not NetFlow data; it lacks the ability to aggregate flows or identify top talkers from flow records. Option C (Nmap) is wrong because it is a port scanning and network discovery tool, not designed to parse or analyze NetFlow data for anomaly detection. Option D (Wireshark) is wrong because it performs deep packet inspection on live captures or pcap files, but it does not natively consume NetFlow records (e.g., IPFIX or Cisco NetFlow v5/v9) and cannot efficiently summarize flow-level statistics like top talkers.

498
MCQhard

An analyst is investigating a possible data exfiltration via email. The analyst notices that the email headers contain a DKIM-Signature field that is invalid. Which of the following does a failed DKIM check indicate?

A.The email's content has been modified since it was signed
B.The email was sent through a proxy server
C.The email client does not support DKIM
D.The email was sent from a different domain than the one in the From field
AnswerA

DKIM signs specific header fields and the message body with a private key; verification uses the public key in DNS. A failed check means the signed content no longer matches the signature, indicating modification in transit or after signing.

Why this answer

A failed DKIM check indicates that the email's content has been modified since it was signed by the sending domain's private key. DKIM uses an asymmetric cryptographic signature (typically RSA or ECDSA) to ensure the integrity of specific header fields and the body hash. When the signature verification fails, it means the hash computed from the received message does not match the decrypted hash from the signature, proving tampering or corruption.

Exam trap

EC-CHFI often tests the distinction between DKIM verification failure (integrity check) and domain alignment (DMARC), so candidates mistakenly choose the domain mismatch option when the question specifically asks about a failed DKIM check.

How to eliminate wrong answers

Option B is wrong because a proxy server does not inherently cause a DKIM failure; DKIM verifies the signature against the original signing domain's public key, and a proxy that does not alter the signed headers or body will not break the signature. Option C is wrong because DKIM support is a server-side (MTA) function, not a client-side feature; the email client does not perform DKIM signing or verification. Option D is wrong because a failed DKIM check does not indicate a domain mismatch; the DKIM-Signature includes the 'd=' tag specifying the signing domain, and a mismatch between the 'From' domain and the 'd=' domain would be a separate policy issue (e.g., DMARC alignment), not a cryptographic verification failure.

499
Multi-Selecteasy

Which TWO of the following are primary purposes of using the GrayKey tool in iOS forensics?

Select 2 answers
A.Perform static analysis of iOS malware
B.Decrypt iOS application binaries for analysis
C.Extract the full file system from a locked iOS device
D.Bypass the iOS passcode to gain access to the device
E.Create an encrypted iTunes backup
AnswersC, D

Once GrayKey successfully bypasses or brute-forces a lock screen passcode, one of its primary forensic functions is creating a full file system extraction from the iOS device's internal storage. This extraction preserves the user data partition, application sandboxes, and system files in a forensically sound manner for later analysis. Unlike logical backups, this captures deleted files and unallocated data, making it a core reason investigators deploy GrayKey.

Why this answer

Option C is correct because GrayKey is a hardware-based forensic tool designed to perform full file system extractions from iOS devices, including locked ones, providing investigators with a complete image of the device's data rather than just a logical backup. Option D is correct because a core function of GrayKey is passcode bypass — it uses brute-force and exploit techniques to defeat the iOS lock screen passcode, which is the prerequisite that enables the full file system extraction in option C. Options A and B are incorrect because GrayKey is not a static malware analysis platform nor a binary decryption tool; those tasks are handled by disassemblers and reverse-engineering suites such as IDA Pro, Ghidra, or Hopper.

Option E is incorrect because GrayKey does not create encrypted iTunes backups — that is the function of iTunes/Finder or libimobiledevice, and GrayKey's purpose is direct device extraction, not backup generation.

Exam trap

EC-Council often tests the distinction between 'bypassing the passcode' (option D) and 'extracting the file system' (option C) as separate but complementary purposes, leading candidates to incorrectly select only one when both are primary functions of GrayKey.

500
MCQmedium

Which of the following BEST describes the purpose of a legal hold in e-discovery?

A.To suspend the deletion of data that may be relevant to upcoming litigation
B.To encrypt data for secure storage
C.To obtain a search warrant for digital evidence
D.To permanently delete irrelevant data
AnswerA

A legal hold, also known as a litigation hold, is a proactive directive issued to suspend any routine deletion or destruction of data that could be discoverable in pending or reasonably anticipated litigation. It overrides standard data retention policies and disables automatic purging mechanisms so that electronically stored information (ESI) remains intact for ediscovery and potential use as evidence. Implementing a legal hold is a cornerstone of the duty to preserve, and failure to do so can result in spoliation sanctions.

Why this answer

A legal hold (also known as a litigation hold) is a directive that suspends the normal deletion or destruction of data that may be relevant to pending or reasonably anticipated litigation. In e-discovery, this ensures that potentially relevant electronically stored information (ESI) is preserved and not altered or destroyed, thereby preventing spoliation of evidence. The purpose is to maintain the integrity and availability of data for discovery obligations under rules such as FRCP Rule 37(e).

Exam trap

The CHFI exam often tests the distinction between preservation (legal hold) and other e-discovery phases like collection or processing, leading candidates to confuse a legal hold with a search warrant or encryption, when in fact it is a proactive suspension of deletion policies.

How to eliminate wrong answers

Option B is wrong because encrypting data for secure storage is a security measure, not a preservation mechanism; encryption does not prevent deletion or alteration of data, and it can actually hinder e-discovery if keys are not managed properly. Option C is wrong because obtaining a search warrant is a legal process for law enforcement to seize evidence, not a civil e-discovery preservation directive; a legal hold is issued by a party or court, not a warrant. Option D is wrong because permanently deleting irrelevant data is the opposite of a legal hold; a legal hold preserves potentially relevant data, while deletion of irrelevant data may occur after the hold is lifted and data is deemed non-responsive.

501
Multi-Selectmedium

Which TWO of the following are common indicators of a path traversal attack found in web server logs? (Select 2)

Select 2 answers
A.Requests containing a large number of User-Agent strings
B.Requests containing '../' sequences
C.Requests containing '<script>' tags
D.Requests containing '%2e%2e%2f'
E.Requests containing 'OR 1=1'
AnswersB, D

The literal '../' sequence is the most direct directory traversal pattern, made of two dots and a slash used to move up one directory level in a hierarchical file system. An attacker appends multiple instances (e.g., ../../../../etc/passwd) to escape the web root and read arbitrary files. Its presence in URI path or parameter values is a primary signature for path traversal detection.

Why this answer

Option B is correct because '../' is the canonical directory traversal sequence used to climb out of the web root and reference files outside the intended directory, so its appearance in request paths is a classic path traversal indicator. Option D is correct because '%2e%2e%2f' is the URL-encoded form of '../' (where %2e is '.', and %2f is '/'), and attackers frequently encode traversal sequences to bypass naive filters, making it an equally common log indicator. Option A is not a path traversal indicator; multiple or unusual User-Agent strings relate to client identification, bot activity, or user-agent spoofing, not directory traversal.

Option C describes '<script>' tags, which indicate cross-site scripting (XSS) attempts rather than path traversal. Option E describes 'OR 1=1', a SQL injection tautology used to bypass authentication or manipulate queries, not a file-path traversal technique.

Exam trap

EC-Council often tests that candidates recognize both raw and URL-encoded forms of path traversal sequences, as many mistakenly think only the raw '../' is an indicator, overlooking the encoded variant '%2e%2e%2f'.

502
Multi-Selectmedium

A forensic analyst is examining a Windows system and wants to identify recently accessed files and programs. Which TWO artifacts should the analyst prioritize? (Select TWO.)

Select 2 answers
A.Jump Lists
B.Event ID 4624 logs
C.Prefetch files
D.System Restore points
E.SAM registry hive
AnswersA, C

Jump Lists are forensic artifacts stored in %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations and CustomDestinations. They maintain MRU (most recently used) lists of files and applications associated with particular AppUserModelIDs, capturing timestamps of when files were opened or saved. This makes them a direct source for determining recently accessed documents and corresponding applications on a per-user basis.

Why this answer

Jump Lists (A) are correct because they are per-application AutomaticDestinations/CustomDestinations files stored under the user's AppData\Roaming\Microsoft\Windows\Recent\ folder that record recently and frequently opened files and programs, directly matching the goal of identifying recently accessed items. Prefetch files (C) are correct because Windows creates .pf files in C:\Windows\Prefetch that track program execution, including run counts and last-run timestamps, which reveal recently executed programs. Event ID 4624 (B) is a Security log entry for successful logons, showing account authentication rather than file or program access.

System Restore points (D) are snapshots used for system rollback and do not directly enumerate recently accessed files or programs. The SAM registry hive (E) stores local user account and credential data, not recent file or program usage.

Exam trap

EC-CHFI often tests the distinction between artifacts that record user activity (Jump Lists, Prefetch) versus those that record system-level events (Event ID 4624) or authentication data (SAM), leading candidates to mistakenly select Event ID 4624 because they associate 'logon' with 'access'.

503
MCQmedium

During a forensic investigation, a junior analyst suggests using a software write blocker to image a suspect's hard drive. Which of the following is the PRIMARY concern with relying solely on a software write blocker in a high-stakes legal case?

A.Software write blockers may be circumvented if the operating system is compromised.
B.Software write blockers require additional licensing fees.
C.Software write blockers are not compatible with all operating systems.
D.Software write blockers are too slow for large drives.
AnswerA

A software write blocker operates as a kernel driver or userspace filter within the very operating system it is trying to protect. If that OS is compromised—for example, by a rootkit or malicious kernel module—the blocker's I/O filtering can be disabled, bypassed, or spoofed, allowing writes to reach the evidence media unnoticed. This is why hardware write blockers are preferred: they enforce read-only protection at the device/interface level, independent of the state of the host operating system.

Why this answer

Software write blockers are not as reliable as hardware ones because they rely on the operating system, which can be compromised; hardware write blockers provide physical write protection.

504
MCQmedium

Refer to the exhibit. During a malware investigation, a forensic analyst runs the commands shown. What is the most likely conclusion?

A.Svchost.exe processes are hosting legitimate Windows services; no malware is present.
B.The malware has injected code into svchost.exe using a reflective DLL injection tool.
C.The malware is using port 4444 for Windows Update communications.
D.Rundll32.exe with PID 1500 is likely a backdoor listening on port 4444.
AnswerD

rundll32.exe is a legitimate Windows binary used to load and execute functions exported from DLLs, but by default it does not create network listeners. When a rundll32 process is observed listening on TCP port 4444—a port heavily associated with Metasploit and backdoor payloads—it strongly suggests that the process has loaded a malicious DLL that opens a remote command shell. The combination of an unusual process acting as a network server on a non-standard port is classic evidence of a backdoor.

Why this answer

The netstat output shows a listening connection on port 4444 associated with PID 1500, which the tasklist command identifies as rundll32.exe. Port 4444 is a common backdoor port (often used by Metasploit or other RATs), and rundll32.exe is a legitimate Windows binary frequently abused by malware to host malicious code (e.g., via DLL sideloading or reflective injection). The combination of an unusual listening port and a process that is not a typical network service (like svchost.exe) strongly indicates a backdoor.

Exam trap

EC-Council often tests the ability to correlate netstat output (port and PID) with tasklist output (PID and process name) to identify suspicious process-port pairs, and the trap here is assuming that svchost.exe is always the culprit when a backdoor is present, when in fact rundll32.exe is a common masquerading host for injected code.

How to eliminate wrong answers

Option A is wrong because svchost.exe processes can host legitimate services, but the exhibit shows no evidence of svchost.exe listening on port 4444; the PID 1500 is rundll32.exe, not svchost.exe. Option B is wrong because while reflective DLL injection into svchost.exe is possible, the netstat output directly ties port 4444 to PID 1500 (rundll32.exe), not to any svchost.exe PID. Option C is wrong because Windows Update does not use port 4444; it uses HTTP (port 80) or HTTPS (port 443) over TCP, and the exhibit shows no svchost.exe process associated with that port.

505
MCQhard

A forensic examiner finds a file on an NTFS volume that appears to have data hidden in its alternate data stream. The file's size is reported as 10 KB, but the volume's cluster size is 4 KB. How many clusters of file slack could potentially contain hidden data in the primary stream?

A.12 KB
B.4 KB
C.2 KB
D.0 KB
AnswerC

The file size is 10 KB, and NTFS uses 4 KB clusters on this volume. The file consumes two full clusters (8 KB) and then 2 KB of a third cluster, leaving 2 KB of slack in that final cluster. This remaining space is not part of the file size but is still allocated to the file, and it may contain remnants of previously stored data that a forensic examiner should analyze.

Why this answer

The file's primary stream occupies 10 KB, which requires 3 clusters (3 × 4 KB = 12 KB). The slack space is the unused portion of the last cluster: 12 KB - 10 KB = 2 KB. This 2 KB of file slack in the primary stream could potentially contain hidden data, making option C correct.

Exam trap

EC-Council CHFI often tests the distinction between allocated space and slack space, and the trap here is that candidates mistakenly calculate the total allocated clusters (12 KB) as slack instead of subtracting the actual file size from the allocated space.

How to eliminate wrong answers

Option A is wrong because 12 KB is the total allocated space (3 clusters × 4 KB), not the slack. Option B is wrong because 4 KB would be the slack if the file size were exactly 8 KB (2 clusters), but here the file is 10 KB, leaving only 2 KB of slack. Option D is wrong because file slack always exists when the file size is not a multiple of the cluster size; 10 KB is not a multiple of 4 KB, so slack is present.

506
MCQhard

During a cloud forensics investigation, an analyst examines AWS CloudTrail logs and finds an event with "userIdentity":{"type":"AssumedRole","arn":"arn:aws:sts::123456789012:assumed-role/AdminRole/i-0abcd1234efgh5678"}. What does the 'i-0abcd1234efgh5678' portion most likely represent?

A.The AWS account ID of the role's trusted entity
B.The role's unique identifier assigned by IAM
C.The unique ID of the IAM user who assumed the role
D.The session name, which is typically the EC2 instance ID
AnswerD

The session name is the correct field because, when an EC2 instance obtains temporary credentials through an instance profile, CloudTrail records that session name as the EC2 instance ID. It appears after the colon in the principalId, for example AROAI... : i-1234567890abcdef0, and as the final segment of the assumed-role ARN. Correlating this suffix with EC2 instance IDs enables the analyst to identify the exact instance that made the API call. This is why the session name, and not the role ID or account ID, is the key forensic attribute in this scenario.

Why this answer

In CloudTrail, when an EC2 instance assumes a role, the session name is often the instance ID. The 'i-' prefix and alphanumeric string indicate an EC2 instance ID.

507
MCQmedium

During a forensic investigation of a Linux system, you need to determine which commands a user executed in their shell session. Which file would you examine to find this information?

A./var/log/auth.log
B./etc/passwd
C./var/log/syslog
D./home/username/.bash_history
AnswerD

.bash_history is the default per-user history file in the home directory of a user running the GNU Bash shell; it records commands interactively typed at the shell's prompt, appended in plain text, and can be read with the 'history' builtin. Each line is one command, and the order generally reflects the order of execution, though Bash does not by default store a timestamp unless HISTTIMEFORMAT is configured. For a forensic investigation this file is the most direct source of a user's command activity, but a sophisticated user can clear or edit the file, and commands running non-interactively or in subshells may not be captured.

Why this answer

The .bash_history file in a user's home directory stores the command history for that user's interactive Bash shell sessions. By default, Bash appends each command to this file when the session ends, making it the primary source for reconstructing a user's executed commands during forensic analysis.

Exam trap

The trap here is that candidates often confuse /var/log/auth.log (which logs authentication events) with command history, but auth.log does not capture the actual commands typed in a shell.

How to eliminate wrong answers

Option A is wrong because /var/log/auth.log records authentication-related events such as login attempts, sudo usage, and SSH connections, not the specific commands executed within a shell session. Option B is wrong because /etc/passwd stores user account information (usernames, UIDs, home directories) and has no relation to command history. Option C is wrong because /var/log/syslog captures general system messages from daemons and kernel, but does not log individual shell commands.

508
MCQmedium

An incident responder is analyzing AWS CloudTrail logs to determine if an unauthorized user accessed an S3 bucket. Which of the following CloudTrail event fields should be examined to identify the IAM user or role that made the API call?

A.sourceIPAddress
B.eventSource
C.requestParameters
D.userIdentity
AnswerD

`userIdentity` is the correct field because CloudTrail populates it with the identity of the principal that made the request. It includes the type (IAMUser, AssumedRole, Root, etc.), the ARN, the account ID, the access key ID, and—for temporary credentials—the session context. This is the definitive attribute for mapping an event to a specific IAM user or role and is essential for attribution during incident response.

Why this answer

The userIdentity field contains details about the identity that made the request, including ARN, user name, and type (IAM user, role, etc.).

509
Multi-Selectmedium

An analyst is investigating a potential data breach on an Android device. Which TWO artefacts are MOST useful for determining which third-party apps were installed and used? (Select TWO.)

Select 2 answers
A.Full system dump (dd image)
B.packages.xml file in /data/system/
C.Wi-Fi connection logs
D./data/data/ directory listing
E.SMS database (mmssms.db)
AnswersB, D

packages.xml, located in /data/system/, records every installed package with metadata including installer, version and permissions. This persistent system-level record survives app removal, letting the analyst enumerate third-party installations and identify which were present during the breach window.

Why this answer

The packages.xml file in /data/system/ records all installed packages, including third-party apps, their permissions, and installation metadata. The /data/data/ directory contains per-package subdirectories with application-specific data, confirming actual usage and stored data. Together, these two artefacts provide definitive evidence of which third-party apps were installed and used on the device.

Exam trap

The CHFI exam often tests the misconception that a full system dump (dd image) is the most useful artefact for app analysis, when in reality the structured packages.xml and /data/data/ directory provide more direct and actionable evidence.

510
MCQmedium

A forensic analyst creates a forensic image of a hard drive using the dd command: dd if=/dev/sda of=/evidence/image.dd bs=4096 conv=noerror,sync. What is the purpose of the 'conv=noerror,sync' option?

A.It verifies the hash of the image after creation
B.It synchronizes the output with the input to ensure data integrity
C.It continues on read errors and pads the output with zeros to maintain the same size
D.It enables direct memory access for faster imaging
AnswerC

The `noerror` flag instructs `dd` to continue processing after encountering a read error, rather than aborting. The `sync` flag complements this by padding the incomplete block with zeros so that the total output size matches the source drive's size. This approach ensures that the resulting forensic image maintains the original geometry and allows for later analysis of the damaged region.

Why this answer

The `conv=noerror,sync` option in the `dd` command instructs the tool to continue processing when a read error is encountered (`noerror`) and to pad the output block with zeros (`sync`) to maintain the same total size as the original drive. This ensures that the forensic image remains a bit-for-bit copy in terms of size, even if physical sectors are unreadable, preserving the integrity of the acquisition process for analysis.

Exam trap

EC-Council often tests the misconception that `sync` means 'synchronize data integrity' or 'flush buffers,' when in fact it specifically pads output with zeros on read errors to maintain block alignment.

How to eliminate wrong answers

Option A is wrong because hash verification is not performed by `conv=noerror,sync`; that would require a separate tool like `sha256sum` or `md5sum` after imaging. Option B is wrong because `sync` in this context pads with zeros on read errors, not synchronizes I/O operations; synchronization of data is handled by the kernel's buffer cache, not this option. Option D is wrong because direct memory access (DMA) is a hardware-level feature not controlled by `dd` options; `dd` uses standard system calls for reading and writing.

511
MCQmedium

A legal hold is issued by an organization's legal department. What is the primary purpose of a legal hold?

A.To notify employees that litigation is pending
B.To authorize law enforcement to seize computers
C.To preserve all relevant data that may be needed for a legal case
D.To encrypt all company data for security
AnswerC

A legal hold suspends routine deletion and alteration so that potentially relevant evidence remains intact and admissible. It satisfies the stem's preservation requirement by freezing data across custodians and systems before litigation, preventing spoliation rather than merely collecting or reviewing documents already gathered.

Why this answer

A legal hold is a directive issued by an organization's legal department to suspend the routine deletion or alteration of data that may be relevant to pending or reasonably anticipated litigation. Its primary purpose is to preserve all potentially relevant electronically stored information (ESI) and physical records in their current state, ensuring spoliation does not occur. This obligation arises under the Federal Rules of Civil Procedure (FRCP) Rule 37(e) and similar e-discovery regulations, which require organizations to take reasonable steps to preserve data once litigation is reasonably anticipated.

Exam trap

CHFI often tests the distinction between a legal hold (a civil preservation duty) and law enforcement seizure (a criminal investigative action), leading candidates to incorrectly select Option B because they conflate 'hold' with 'seize'.

How to eliminate wrong answers

Option A is wrong because a legal hold is not merely a notification to employees that litigation is pending; it is a directive to preserve data, and while notification may be part of the process, the primary purpose is preservation, not notification. Option B is wrong because a legal hold is an internal civil litigation preservation mechanism, not a law enforcement seizure authorization; law enforcement seizures are governed by warrants or subpoenas under statutes like the Electronic Communications Privacy Act (ECPA), not by a legal hold. Option D is wrong because encryption is a security measure for protecting data confidentiality, not a preservation technique; a legal hold requires data to be retained in its original form, and encryption could actually hinder forensic acquisition and analysis if keys are lost.

512
MCQhard

You are investigating a Windows 10 workstation that exhibits slow performance and frequent pop-ups. The user reports that the system started acting strangely after installing a 'PDF Converter' from an email attachment. You suspect malware. You have captured a memory dump using FTK Imager and a network capture during the infection. In the memory dump, you find a suspicious process 'conhost.exe' running from a non-standard location (C:\Users\Public\Temp). The process has an open handle to a file named 'config.ini' in the same directory. The network capture shows periodic HTTPS connections to 'malicious.com' on port 443 from the workstation's IP. Using Volatility, you extract the process's command line: 'conhost.exe -hidden -log C:\Users\Public\Temp\output.log'. Which of the following is the BEST immediate course of action to contain the threat and preserve evidence?

A.Delete the config.ini file and the conhost.exe executable immediately.
B.Restore the system to a previous restore point.
C.Terminate the suspicious conhost.exe process and run a full antivirus scan.
D.Isolate the workstation from the network, then create a forensic image of the hard disk for analysis.
AnswerD

Isolating the workstation from the network by disconnecting the cable or disabling the NIC immediately severs Command & Control (C2) channels and halts any lateral movement to other hosts, preserving the network flow data and the current state of live connections. Creating a forensic image of the hard disk using a write-blocker and bit-for-bit imaging tools maintains the integrity of evidence, allowing recovery of deleted files, unallocated space, and file system slack that may contain residual malware or attacker artifacts. This evidence-preserving approach aligns with forensic best practices, keeps proper chain of custody, and enables thorough static and dynamic analysis in a controlled lab environment—unlike the destructive or ineffective alternatives.

Why this answer

The primary goal in a malware incident is to contain the threat and preserve evidence for forensic analysis. Isolating the workstation from the network prevents further data exfiltration (e.g., the HTTPS connections to malicious.com) and stops the malware from communicating with its C2 server. Creating a forensic image of the hard disk preserves the full state of the system, including the malicious conhost.exe, config.ini, and output.log files, which are critical for reverse engineering and attribution.

Terminating the process or deleting files before imaging would destroy volatile evidence and potentially trigger anti-forensic mechanisms.

Exam trap

EC-Council often tests the principle that containment and evidence preservation take precedence over immediate remediation, so candidates mistakenly choose to terminate the process or delete files (Option A or C) thinking they are stopping the threat, but this destroys volatile evidence and may trigger anti-forensic behavior.

How to eliminate wrong answers

Option A is wrong because deleting the config.ini file and conhost.exe executable destroys evidence and may trigger anti-forensic routines (e.g., file wiping or self-deletion) that could corrupt the memory dump or hinder analysis. Option B is wrong because restoring to a previous restore point overwrites critical system files and registry keys, destroying evidence of the infection and potentially leaving remnants of the malware in shadow copies or unallocated space. Option C is wrong because terminating the process and running an antivirus scan may alter the system state (e.g., killing the process removes its memory artifacts) and the scan could quarantine or delete malicious files, compromising the forensic integrity of the evidence.

513
Multi-Selectmedium

Which TWO of the following are valid justifications for a first responder to power off a computer at a crime scene? (Select TWO)

Select 2 answers
A.To prevent the computer from overheating
B.To save time during the investigation
C.The computer is destroying evidence (e.g., running a data wiping program)
D.The computer is in a hazardous environment (e.g., flooding)
E.The computer is actively being used to commit a crime
AnswersC, D

Active evidence destruction is an accepted exception to the preserve-state rule: volatile data is lost, but ongoing wiping would eliminate the entire disk. Powering off halts the destructive process immediately, satisfying the justification of preventing further evidence loss.

Why this answer

Option C is correct because if a system is actively destroying evidence—such as running a data-wiping utility, secure-delete command, or encryption routine—the first responder must cut power immediately to preserve volatile and non-volatile data before it is irrecoverably lost. Option D is correct because a hazardous environment like flooding, fire, or electrical danger poses a risk to life and safety, and preserving human safety takes precedence over evidence collection, justifying powering off (or otherwise safely disconnecting) the machine. Option A is not a valid justification because modern computers have thermal protections and overheating is not a recognized forensic reason to power down, which would actually destroy volatile evidence.

Option B is not valid because saving time is never an acceptable justification for altering a crime scene, as proper forensic procedure prioritizes evidence integrity over speed. Option E is not valid because a computer actively being used to commit a crime should typically be left running to capture live evidence (e.g., RAM, network connections, running processes), not powered off.

Exam trap

EC-Council often tests the distinction between 'actively being used to commit a crime' (which requires live acquisition) and 'actively destroying evidence' (which justifies immediate power-off), causing candidates to mistakenly select Option E as a valid justification.

514
MCQhard

A forensics examiner finds a suspicious entry in the Windows Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to a PowerShell command. Which persistence mechanism does this represent, and what is the MOST likely impact?

A.Registry run key persistence; the command executes each time the user logs in.
B.Service persistence; the malware runs as a system service.
C.Scheduled task persistence; the command runs at a scheduled time.
D.Bootkit persistence; the malware loads before the OS.
AnswerA

HKCU\...\CurrentVersion\Run entries are per-user autostart locations. Windows reads them at logon and launches the referenced command, so the PowerShell payload executes each time that user signs in, giving the attacker persistent code execution without administrative rights.

Why this answer

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard Windows Run key that automatically executes programs when the user logs in. A PowerShell command placed here will run with the user's privileges at each interactive logon, establishing persistence without requiring elevated privileges or system-level access.

Exam trap

EC-Council often tests the distinction between user-level (HKCU) and machine-level (HKLM) Run keys, and candidates mistakenly associate any registry entry with service persistence or scheduled tasks due to overlapping persistence concepts.

How to eliminate wrong answers

Option B is wrong because service persistence requires entries under HKLM\System\CurrentControlSet\Services or HKCU\Services, not the Run key, and typically runs as SYSTEM or a dedicated service account, not at user logon. Option C is wrong because scheduled task persistence uses the Task Scheduler (schtasks.exe or taskschd.msc) and is stored in %SystemRoot%\Tasks or the Task Scheduler XML files, not in the Run registry key. Option D is wrong because bootkit persistence involves modifying the Master Boot Record (MBR), Volume Boot Record (VBR), or early OS boot components (e.g., bootmgr) to load before the OS kernel, which is entirely unrelated to user-level registry Run keys.

515
MCQmedium

During a malware analysis, a suspicious executable is detected. The analyst runs `strings` on the binary and finds references to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` and a URL `http://evil.com/beacon`. What does this indicate?

A.The malware is a file infector that modifies system binaries
B.The malware uses a mutex for synchronization
C.The malware establishes persistence and communicates with a remote server
D.The malware performs privilege escalation via a known vulnerability
AnswerC

The executable created a Run registry key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) to ensure it launches on every user logon, and it resolved and contacted an external URL, exfiltrating data or receiving commands. This combination of an autostart mechanism and a remote communication channel is the classic signature of a backdoor or RAT, making persistence and C2 the correct characterization of its behavior.

Why this answer

The presence of a registry key reference to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` indicates the malware is configured to launch automatically at system startup, establishing persistence. The embedded URL `http://evil.com/beacon` suggests the malware will make outbound HTTP requests to a remote command-and-control (C2) server for beaconing or data exfiltration. Together, these artifacts confirm persistence and remote communication, making option C correct.

Exam trap

EC-Council often tests the distinction between persistence mechanisms (like registry Run keys) and other malware behaviors (like file infection or privilege escalation), so candidates mistakenly associate any registry reference with file infection or confuse a URL with an exploit payload.

How to eliminate wrong answers

Option A is wrong because a file infector modifies system binaries (e.g., .exe or .dll files) to inject malicious code, but the `strings` output shows no evidence of file modification or infection routines—only a registry run key and a URL. Option B is wrong because a mutex is a synchronization object used to prevent multiple instances of malware from running, and no mutex name or reference is present in the provided strings; the artifacts shown are purely persistence and network indicators. Option D is wrong because privilege escalation exploits target vulnerabilities (e.g., CVE-XXXX) to gain higher access, but the strings reveal no exploit code, DLL injection paths, or UAC bypass techniques—only a registry autorun key and a beacon URL.

516
MCQeasy

In Linux forensics, which file contains information about user account passwords in hashed form?

A./etc/passwd
B./etc/shadow
C./etc/group
D./var/log/auth.log
AnswerB

The /etc/shadow file stores the actual hashed password for each local user, along with password-aging metadata such as the date of last change, minimum and maximum age, warning period, and account expiration. Access is restricted to root and the shadow group, so its 0640 (or 0000) permissions prevent ordinary users from harvesting hashes for offline brute-force attacks. In a forensic acquisition, this file is a primary source for credential recovery—tools like unshadow combine passwd and shadow to feed hash-cracking utilities like John the Ripper or hashcat.

Why this answer

In Linux, the /etc/shadow file stores user account passwords in hashed form, along with password aging information. This file is readable only by root (or privileged processes) to prevent unauthorized access to password hashes, unlike /etc/passwd which is world-readable and historically stored hashes but now typically shows an 'x' placeholder. The hashes are generated using algorithms like SHA-512 (crypt $6$) or yescrypt, as specified in the shadow file format.

Exam trap

Candidates often mistakenly think that /etc/passwd still contains password hashes, as it did in older Unix systems, but modern Linux distributions separate hashes into /etc/shadow for security.

How to eliminate wrong answers

Option A is wrong because /etc/passwd stores user account information (username, UID, GID, home directory, shell) but not password hashes; modern systems place an 'x' in the password field to indicate the hash is in /etc/shadow. Option C is wrong because /etc/group stores group membership information and group passwords (if any), not individual user password hashes. Option D is wrong because /var/log/auth.log is a log file for authentication events (e.g., login attempts, sudo usage), not a file containing stored password hashes.

517
MCQeasy

According to Locard's exchange principle, which of the following is TRUE in a digital forensic context?

A.A suspect will always leave traces of their activity on a computer system.
B.Only physical evidence, not digital evidence, is subject to exchange.
C.Digital evidence is always volatile and cannot be preserved.
D.The absence of evidence proves the suspect is innocent.
AnswerA

Locard's exchange principle holds that contact between two entities results in mutual transfer of material. In digital forensics this means a suspect's activity inevitably leaves traces on the system, satisfying the principle's assertion of unavoidable evidence transfer during interaction.

Why this answer

In a digital forensic context, Locard's exchange principle holds that whenever a suspect interacts with a computer system, they will inevitably leave traces of that activity. This can include artifacts such as registry entries, log files, prefetch files, browser history, or metadata, even if the user attempts to delete or obfuscate their actions. The principle underpins the entire field of digital forensics, asserting that digital interaction always produces residual data.

Exam trap

The CHFI exam often tests the misconception that Locard's principle only applies to physical evidence, leading candidates to incorrectly select Option B, when in fact the principle is universally applied to all forms of evidence, including digital.

How to eliminate wrong answers

Option B is wrong because Locard's exchange principle applies to both physical and digital evidence; digital evidence is subject to exchange through data remnants, logs, and metadata, not just physical traces. Option C is wrong because digital evidence is not always volatile — many types, such as files on a hard drive or logs on a server, are persistent and can be preserved through proper forensic imaging and write-blocking techniques. Option D is wrong because the absence of evidence does not prove innocence; it may indicate that the suspect used anti-forensic techniques, that evidence was overwritten, or that the examiner lacked the tools or authority to recover it.

518
MCQmedium

An analyst is analyzing a disk image and finds a 512-byte sector at LBA 0 that contains a bootloader and a partition table. The partition table has four entries, each 16 bytes. What type of partition table is this?

A.Apple Partition Map
B.MBR
C.GPT
D.BSD disklabel
AnswerB

The Master Boot Record (MBR) is exactly a 512-byte sector at LBA 0: the first 446 bytes contain boot code, the following 64 bytes form the partition table (four 16-byte entries), and the last two bytes are the 0x55AA signature at offsets 510-511. This precise structure matches the analyst's finding, including the 64-byte table and signature. The partition entries store type, start LBA, and size, allowing the OS to locate logical partitions.

Why this answer

The Master Boot Record (MBR) partition table is defined by a 512-byte sector at LBA 0 that contains a bootloader (first 446 bytes) and four 16-byte partition entries (total 64 bytes), ending with a 2-byte signature (0x55AA). This matches the description exactly, making B the correct answer.

Exam trap

EC-Council CHFI often tests the distinction between MBR and GPT by emphasizing the number of partition entries (four vs. many) and the sector location (LBA 0 vs. LBA 1+), tricking candidates who confuse the protective MBR in GPT with an actual MBR partition table.

How to eliminate wrong answers

Option A (Apple Partition Map) is wrong because it uses a different layout starting at block 1 (not LBA 0) and does not have a fixed 512-byte sector with a bootloader and four 16-byte entries; it uses a descriptor block with 64-byte partition entries. Option C (GPT) is wrong because GPT uses a protective MBR at LBA 0, but the actual partition table is stored in GPT headers and entries at LBA 1 and beyond, with 128-byte entries, not four 16-byte entries. Option D (BSD disklabel) is wrong because it typically resides within a slice of an MBR partition, not at LBA 0, and its label structure is different, often using 16-byte entries but not in the MBR format with a bootloader.

519
Multi-Selecthard

A forensic examiner has acquired a disk image using FTK Imager and needs to ensure the image is an exact duplicate of the original drive. Which THREE of the following methods can be used to verify integrity? (Select THREE)

Select 3 answers
A.Compute the SHA-256 hash of the image and compare it to the original drive's hash
B.Compute the MD5 hash of the image and compare it to the original drive's MD5 hash
C.Verify the cyclical redundancy check (CRC-32) of the image file
D.Use the 'verify' function within FTK Imager which automatically computes and compares hashes
E.Check the file size of the image matches the original drive's capacity
AnswersA, B, D

Computing the SHA-256 hash of the acquired image and comparing it against the hash computed from the original drive is the gold standard for forensic integrity verification. SHA-256 is a NIST-approved cryptographic hash function that produces a unique 256-bit digest; because it is collision-resistant and preimage-resistant, even a single flipped bit in the image will cause a completely different digest. This comparison verifies that the acquisition process created a bit-for-bit identical copy, providing a defensible basis for subsequent analysis and court testimony.

Why this answer

SHA-256 is a cryptographic hash function that produces a unique 256-bit digest. By computing the SHA-256 hash of the acquired image and comparing it to the hash computed from the original drive, the examiner can verify bit-for-bit integrity with extremely high collision resistance, ensuring the image is an exact duplicate.

Exam trap

EC-Council often tests the distinction between error-detection codes (CRC-32) and cryptographic hash functions (SHA-256, MD5), leading candidates to mistakenly select CRC-32 as a valid integrity verification method for forensic images.

520
MCQmedium

During a Windows forensic analysis, you find a suspicious LNK file in a user's Recent folder. Which of the following is NOT typically retrievable from an LNK file?

A.Username of the user who created the LNK file
B.Target file creation timestamp
C.Volume serial number of the target drive
D.Target file path
AnswerA

The Shell Link binary format has no dedicated field for the creating user's username or SID. LNK files identify the machine via the MachineID string and the target volume via a serial number, but attribution to a specific account must be reconstructed through indirect evidence like the NTFS USN journal, Prefetch, or shellbags, not read directly from the .lnk file.

Why this answer

LNK files store metadata about the target file and the system environment, but they do not record the username of the user who created the LNK file. The creation timestamp of the LNK file itself is stored, but the username is not part of the LNK file structure. Instead, the username context is inferred from the user's profile folder path where the LNK resides, not from the file's internal data.

Exam trap

EC-Council CHFI often tests the misconception that LNK files store the creator's username because they associate the file with a user's Recent folder, but the username is derived from the folder path, not the file's internal data.

How to eliminate wrong answers

Option B is wrong because LNK files do store the target file's creation timestamp in the shell link header (as a FILETIME structure). Option C is wrong because the volume serial number of the target drive is stored in the volume ID structure within the LNK file. Option D is wrong because the target file path is stored in the link target identifier (ITPIDLIST) and the link info structure, making it fully retrievable.

521
MCQeasy

In email forensics, which artifact is stored in Outlook's Personal Folders (.pst) files and can be analyzed using tools like Aid4Mail or EmailTracker?

A.Only the email body text
B.Emails and attachments only
C.Email headers only
D.Emails, attachments, calendars, contacts, and other mailbox items
AnswerD

A .pst is a comprehensive personal folders backup that stores an entire mailbox tree: email items with attachments, calendar entries, contacts, tasks, notes, and journal records, all as structured MAPI objects. This breadth is what makes it invaluable in investigations, as deleted or orphaned items may remain in free-space blocks or the folder hierarchy. Therefore the correct characterization is a full mailbox archive, not a subset.

Why this answer

Outlook Personal Folders (.pst) files are not limited to storing just email content; they are a comprehensive container for multiple mailbox items. In addition to emails and attachments, .pst files store calendars, contacts, tasks, notes, journal entries, and other mailbox artifacts. Tools like Aid4Mail and EmailTracker can parse the entire .pst structure to extract and analyze all these item types, making option D correct.

Exam trap

The CHFI exam often tests the misconception that .pst files only store emails and attachments, when in fact they are a full mailbox container that includes calendars, contacts, tasks, and other items.

How to eliminate wrong answers

Option A is wrong because .pst files store far more than just the email body text; they include headers, attachments, and other mailbox items. Option B is wrong because .pst files contain not only emails and attachments but also calendars, contacts, tasks, and other items. Option C is wrong because .pst files store the complete email object (body, headers, attachments) and other mailbox items, not just headers.

522
MCQeasy

Under the US Fourth Amendment, when is a warrant generally NOT required for a computer search and seizure?

A.When the evidence is stored in the cloud
B.When the computer is owned by a corporation
C.When the investigation involves a civil case
D.When the suspect has given consent
AnswerD

Consent is a classic exception to the Fourth Amendment's warrant requirement, as recognized in Schneckloth v. Bustamonte, because a person who voluntarily, knowingly, and intelligently relinquishes his or her privacy interest in the premises or effects cannot later complain about the search. The consent must be freely given and may be limited in scope or withdrawn at any time, but when it is valid, it renders a warrant unnecessary.

Why this answer

Under the Fourth Amendment, a warrant is generally required for searches and seizures, but one well-established exception is voluntary consent. When a suspect freely and knowingly agrees to a search of their computer or digital device, law enforcement may proceed without a warrant, provided the consent is not coerced and the scope of the search is not exceeded. This principle applies regardless of whether the data is stored locally or remotely, as long as the consenting party has actual or apparent authority over the device or data.

Exam trap

EC-Council often tests the misconception that the Fourth Amendment does not apply to corporate-owned devices or cloud data, but the trap here is that consent is a specific, well-recognized exception that overrides the warrant requirement, whereas the other options describe scenarios where a warrant is still generally required unless another exception applies.

How to eliminate wrong answers

Option A is wrong because the Fourth Amendment generally requires a warrant for cloud-stored data, as the user retains a reasonable expectation of privacy in data held by a third-party provider under the Stored Communications Act (18 U.S.C. § 2703), unless an exception like consent or exigent circumstances applies. Option B is wrong because corporate ownership does not automatically waive Fourth Amendment protections; while business records may have reduced privacy expectations, a warrant is still required for a search unless an exception such as consent from an authorized corporate officer or the plain view doctrine is present. Option C is wrong because the Fourth Amendment applies to government searches in both criminal and civil cases; in civil investigations, a warrant or a valid exception (e.g., consent, subpoena) is still required, and the absence of criminal charges does not eliminate the need for a warrant.

523
MCQmedium

Which hashing algorithm is commonly used in forensic imaging to verify the integrity of evidence and is considered more secure than MD5?

A.SHA-256
B.SHA-1
C.CRC32
D.MD5
AnswerA

SHA-256, a member of the SHA-2 family, produces a 256-bit digest and is currently considered cryptographically secure for integrity verification. In forensic imaging, it is the de facto standard because it is collision-resistant and preimage-resistant, meaning it is computationally infeasible to find two different data sets with the same hash or to reconstruct original data from the digest. Tools such as EnCase, FTK, and dd with sha256sum use it to validate that a forensic image is a perfect bit-for-bit copy of the original medium.

Why this answer

SHA-256 is the correct answer because it is a widely adopted cryptographic hash function in forensic imaging tools (e.g., FTK Imager, EnCase) to verify evidence integrity. It produces a 256-bit (32-byte) hash value and is considered collision-resistant, making it significantly more secure than MD5, which has known collision vulnerabilities.

Exam trap

EC-Council often tests the misconception that SHA-1 is still acceptable for forensic integrity checks because it was once the standard, but the trap is that SHA-1 is now deprecated due to practical collision attacks, while SHA-256 is the current recommended minimum.

How to eliminate wrong answers

Option B is wrong because SHA-1 produces a 160-bit hash and has been deprecated by NIST since 2011 due to demonstrated collision attacks (e.g., SHAttered). Option C is wrong because CRC32 is a cyclic redundancy check designed for error detection in data transmission, not a cryptographic hash, and it is easily reversible and collision-prone. Option D is wrong because MD5 is a 128-bit hash that is cryptographically broken; collisions can be generated in seconds using tools like hashclash, making it unsuitable for forensic integrity verification.

524
Multi-Selecteasy

A forensic analyst reviews a Windows system for signs of malware persistence. Which TWO registry locations are commonly used to achieve persistence via auto-start programs?

Select 2 answers
A.HKLM\SAM\SAM\Domains\Account\Users
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
C.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKLM\SYSTEM\CurrentControlSet\Services
E.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AnswersC, E

This HKLM Run key is a critical persistence location: at every user logon, the Winlogon process reads it and launches each listed executable for all accounts, requiring administrative privileges to modify. Values are command lines (e.g., 'C:\malware.exe') that run early in the logon sequence, before the desktop is fully interactive. Because it has system-wide scope, it is a top target for malware persistence and a primary check during a forensic investigation for auto-start mechanisms.

Why this answer

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run are standard auto-start locations for all users and current user respectively. RunOnce keys execute once and are also used. But the most common are Run keys.

525
Multi-Selecteasy

A forensic analyst is examining a Docker container image for malware. Which TWO techniques can help analyze the image layers?

Select 2 answers
A.Use 'docker history' to view the build history of the image
B.Use 'docker images' to list all images
C.Use 'docker inspect' to view the image metadata
D.Use 'docker save' to export the image as a tar file and extract layers
E.Use 'docker export' on a running container
AnswersA, D

The docker history command lists each layer's creation instruction, size and originating command from the image manifest. This reveals suspicious build steps such as downloads or shell commands, satisfying the need to inspect layer provenance without running the container.

Why this answer

Option A is correct because 'docker history' displays the image's build history, showing each layer's creation command (from the Dockerfile instructions), sizes, and IDs, which lets a forensic analyst trace what was executed or added during the build and spot suspicious layers. Option D is correct because 'docker save' exports the full image (all layers plus metadata) as a tar archive, which can be extracted to inspect each layer's filesystem contents directly, including deleted or hidden files, without running the container. Option B is not suitable because 'docker images' only lists image names, tags, sizes, and IDs on the host; it provides no layer-level detail.

Option C is not the best fit because 'docker inspect' returns image metadata (config, environment, entrypoint, layer digests) but not the actual layer contents or build commands needed for deep layer analysis. Option E is incorrect because 'docker export' flattens a running container's filesystem into a single tar, losing the layer history and structure, and it targets containers rather than images.

Exam trap

EC-Council often tests the distinction between image-level commands (docker history, docker save) and container-level commands (docker export), trapping candidates who confuse exporting a container's filesystem with extracting image layers.

Page 6

Page 7 of 10

Page 8

All pages