Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 526–600

745 questions total · 10pages · All types, answers revealed

Page 7

Page 8 of 10

Page 9
526
MCQmedium

A security analyst observes multiple Event ID 4625 logon failures for a single user account within a short time frame, followed by Event ID 4624 logon success. Which attack technique is MOST likely indicated?

A.Kerberos golden ticket attack
B.SQL injection attack on the authentication database
C.Brute-force or password spraying attack
D.Pass-the-hash attack
AnswerC

The correct finding: a burst of 4625 events followed by a 4624 event is the canonical signature of brute-force or password-spraying. Brute-force creates many failed attempts per target account with different passwords, while spraying uses one password across many accounts; both generate numerous 4625 audit records. When one guess finally matches, a 4624 success appears, confirming the attack succeeded.

Why this answer

Event ID 4625 indicates failed logon attempts, and Event ID 4624 indicates a successful logon. A rapid sequence of failures followed by a success for the same user account is the classic signature of a brute-force or password spraying attack, where an attacker tries multiple passwords until one works. This pattern is specific to authentication attempts against the local SAM or domain controller via NTLM or Kerberos, not to post-authentication attacks.

Exam trap

EC-CHFI often tests the distinction between pre-authentication attacks (brute-force, password spraying) and post-authentication attacks (pass-the-hash, golden ticket), where candidates mistakenly associate any successful logon after failures with a hash-based attack instead of recognizing the sequential failure-success pattern as brute-force.

How to eliminate wrong answers

Option A is wrong because a Kerberos golden ticket attack forges a Ticket Granting Ticket (TGT) using the KRBTGT hash, which does not generate multiple Event ID 4625 failures; instead, it produces a single successful logon (4624) with unusual attributes like a non-existent user or anomalous ticket options. Option B is wrong because SQL injection targets the database query layer, not Windows Security Log events 4625/4624; it would generate SQL server errors or application-level logs, not sequential logon failures. Option D is wrong because a pass-the-hash attack uses stolen NTLM hashes to authenticate without knowing the plaintext password, typically resulting in a single successful logon (4624) without preceding 4625 failures, as the hash is valid.

527
MCQhard

During dynamic analysis of a suspicious executable in Cuckoo Sandbox, the report shows that the process created a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run named 'WindowsUpdate' and dropped a file 'svchost.exe' in %AppData%. Which conclusion is MOST consistent with these indicators?

A.The executable is cleaning up after itself by deleting temporary files
B.The executable is a dropper that installs a rootkit
C.The executable is a legitimate Windows update component
D.The executable is attempting to establish persistence via a Run key and masquerading as a system process
AnswerD

Writing to HKCU\...\CurrentVersion\Run causes the payload to execute automatically at each user logon, satisfying the persistence requirement. Dropping svchost.exe into %AppData% exploits name masquerading, since the genuine svchost.exe resides in %SystemRoot%\System32, so analysts trusting the filename alone may overlook the rogue copy.

Why this answer

The creation of a Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism that causes the executable to launch automatically at user logon. Dropping a file named 'svchost.exe' in %AppData% is a common masquerading technique, as the legitimate svchost.exe (Service Host) resides in C:\Windows\System32, not in the user's AppData folder. Together, these actions indicate the executable is establishing persistence and disguising itself as a trusted system process.

Exam trap

EC-Council often tests the distinction between persistence mechanisms and other malware behaviors, and the trap here is that candidates may confuse a dropper with a rootkit or assume any file named 'svchost.exe' is legitimate, ignoring the abnormal file path.

How to eliminate wrong answers

Option A is wrong because creating a Run key and dropping a file are actions that establish persistence, not cleanup; deleting temporary files would involve removing artifacts, not adding them. Option B is wrong because while the executable is a dropper (it drops a file), there is no evidence of a rootkit—rootkits typically hide processes or files via kernel-level hooks, not by simply adding a Run key and a masqueraded executable. Option C is wrong because legitimate Windows Update components do not write themselves to HKCU\Run or drop svchost.exe in %AppData%; Windows Update uses trusted system paths like C:\Windows\System32 and is managed by Windows Update service, not user-level Run keys.

528
MCQeasy

Which tool is specifically designed to extract and analyze email metadata, including headers, from various email client formats such as PST and OST files?

A.Wireshark
B.EmailTracker
C.Aid4Mail
D.FTK Imager
AnswerC

Aid4Mail is a dedicated forensic email extraction and conversion tool engineered to parse Outlook PST/OST, MBOX, EML, MSG, and numerous other formats while preserving header fields, routing data, attachments, and internal metadata. It creates court-defensible exports with hash integrity and can process large mail stores with selective filtering, making it the appropriate tool for metadata and content analysis. This specialized parsing capability is exactly what distinguishes it from general-purpose forensic utilities.

Why this answer

Aid4Mail is a commercial forensic tool that can extract emails and metadata from PST, OST, MBOX, and other formats. EmailTracker is primarily for tracking email delivery, not forensic analysis of client files.

529
MCQmedium

An analyst reviews an Apache access log entry: '192.168.1.10 - - [10/Oct/2023:13:55:36 +0000] "GET /index.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. Which attack does this log entry most likely indicate?

A.SQL injection (SQLi) attack
B.Cross-site scripting (XSS) attack
C.Path traversal attack
D.Remote file inclusion (RFI) attack
AnswerA

The log entry contains classic SQL injection signatures: quote characters, SQL logical operators such as OR and AND, and observable query fragments like UNION SELECT. These tokens indicate an attempt to terminate a string literal and append a new SQL predicate to manipulate the database's response. A successful injection of this nature could allow an attacker to bypass authentication, extract data, or modify records, making this the correct classification.

Why this answer

The URL-encoded payload contains SQL injection syntax (%27 is a single quote), attempting to inject an OR condition. This is indicative of a SQL injection attempt.

530
MCQmedium

In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?

A.Amazon S3 access logs
B.AWS CloudWatch Logs
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records every AWS API call with the calling identity, source IP and timestamp, so the CreateUser and AttachUserPolicy events reveal both the IAM user and the unfamiliar address. This directly satisfies the stem's need to identify the specific API calls and their originator.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the identity of the caller (IAM user or role), the source IP address, and the specific API actions (e.g., CreateUser, AttachUserPolicy). In this scenario, CloudTrail logs will directly show which IAM user made the unusual API calls from the unfamiliar IP address, enabling the analyst to trace the unauthorized activity.

Exam trap

EC-CHFI often tests the distinction between CloudTrail (API activity logging) and CloudWatch Logs (monitoring and log aggregation), leading candidates to mistakenly choose CloudWatch Logs because they think 'logs' implies all logging, but CloudTrail is the specific service for API call auditing.

How to eliminate wrong answers

Option A is wrong because Amazon S3 access logs record requests made to S3 buckets (e.g., GET, PUT, DELETE objects), not IAM management API calls like creating users or assigning policies. Option B is wrong because AWS CloudWatch Logs is a service for monitoring, storing, and accessing log files from various sources (e.g., application logs, system logs), but it does not natively capture AWS API calls; it can only ingest CloudTrail logs if configured, but it is not the primary source for API call records. Option D is wrong because AWS Config is a service for evaluating and auditing resource configurations and compliance over time, not for recording real-time API calls or identifying the specific user who made them.

531
MCQmedium

In an investigation of a Windows system, the analyst uses Volatility's 'netscan' plugin and identifies a suspicious outbound connection to an IP address on port 4444. Which of the following is the most likely associated malicious activity?

A.Reverse shell connection from a backdoor
B.DNS tunneling exfiltration
C.HTTP data exfiltration
D.Remote desktop session
AnswerA

Port 4444 is widely recognized as the default listener port for Metasploit's Meterpreter payload and many remote access Trojans (RATs). In a reverse shell scenario, the compromised Windows host actively establishes an outbound TCP connection to the attacker's command-and-control server on port 4444, effectively bypassing inbound firewall restrictions. When an analyst observes an established connection from a suspicious process to a remote IP on port 4444, it is a strong forensic indicator of a backdoor providing interactive command-line access to the attacker. This matches the observed network activity and explains the analyst's conclusion.

Why this answer

Port 4444 is the default port for the Metasploit Meterpreter reverse TCP payload. A Volatility netscan result showing an outbound connection to this port strongly indicates a reverse shell, where the compromised system initiates a connection back to an attacker's listener to bypass firewalls. This is a classic backdoor behavior, not a standard service.

Exam trap

The CHFI exam often tests the association of default ports with specific attack types, and the trap here is that candidates may confuse port 4444 with common services like HTTP or RDP, or assume any outbound connection is data exfiltration, rather than recognizing it as a reverse shell indicator.

How to eliminate wrong answers

Option B is wrong because DNS tunneling exfiltration typically uses UDP port 53, not TCP port 4444, and relies on encoding data in DNS queries/responses. Option C is wrong because HTTP data exfiltration uses TCP port 80 or 443, not port 4444, and would appear as standard web traffic. Option D is wrong because Remote Desktop Protocol (RDP) uses TCP port 3389, not port 4444, and is a legitimate administrative tool, not a malicious backdoor.

532
MCQeasy

You are a forensic analyst investigating a Windows workstation that shows signs of malware infection. The user reports that the system is slow, network activity is high, and several files have been encrypted with a .encrypted extension. A ransom note named README.txt has been left on the desktop demanding payment. You have acquired a memory dump using FTK Imager and a disk image using dd. You need to identify the malware family and gather indicators of compromise (IOCs). Which of the following is the MOST appropriate first step?

A.Extract the ransom note and search for known ransomware identifiers such as Bitcoin wallet addresses or contact email.
B.Run the malware sample in a sandbox environment to observe its behavior.
C.Perform static analysis of the encrypted files to determine the encryption algorithm used.
D.Immediately disconnect the system from the network and power it off to preserve evidence.
AnswerA

Ransom notes typically contain unique attribution artifacts—Bitcoin/cryptocurrency wallet addresses, victim IDs, Tor payment portal URLs, or contact emails—that can be cross-referenced against threat intelligence feeds (e.g., Abuse.ch, NoMoreRansom, or vendor reports) to pinpoint the exact ransomware family and, often, the specific variant and version. Extracting and parsing these identifiers is non-destructive, requires no special tooling, and gives the analyst a focused search target before investing time in malware dynamic analysis. This IOC-led approach is the fastest way to transition from an unknown incident to a known threat profile, enabling immediate acquisition of family-specific decryption tools, YARA rules, and network indicators.

Why this answer

The ransom note (README.txt) is a primary source of ransomware identifiers such as Bitcoin wallet addresses, contact emails, or Tor payment site URLs. Extracting these IOCs from the note allows you to quickly cross-reference known ransomware families (e.g., Ryuk, Maze, LockBit) via threat intelligence feeds, which is the most efficient first step in malware forensics before deeper analysis.

Exam trap

EC-Council often tests the principle of 'triage before deep analysis'—candidates mistakenly choose sandboxing (B) or static analysis (C) first, but the exam expects you to start with the most accessible, high-value IOC source (the ransom note) to quickly identify the malware family.

How to eliminate wrong answers

Option B is wrong because running the malware sample in a sandbox is premature; you must first identify the malware family and IOCs from the ransom note to safely handle the sample and avoid accidental encryption or network propagation. Option C is wrong because static analysis of encrypted files to determine the encryption algorithm is resource-intensive and often inconclusive without the encryption key; the ransom note provides faster, actionable intelligence. Option D is wrong because immediately disconnecting and powering off the system may destroy volatile evidence (e.g., network connections, running processes) and is not the first step—preservation should follow initial IOC collection.

533
MCQhard

During memory analysis, an examiner uses the Volatility 'malfind' plugin and discovers a process with executable code in an executable heap. Which technique is most likely being used by malware to avoid detection?

A.Process hollowing
B.DLL injection
C.Heap spraying
D.Reflective DLL loading
AnswerC

Heap spraying is an exploitation technique that fills the process heap with many blocks of crafted data, often a repeated pattern of benign opcodes followed by shellcode, to make execution land at a predictable address. These allocations are typically marked PAGE_EXECUTE_READWRITE, which is exactly what Volatility's malfind plugin targets when it searches for executable writable heap regions. Malfind further validates the region by disassembling the contents, and the repetitive coding pattern found in a heap spray is a strong indicator of this technique, making it the correct answer.

Why this answer

The 'malfind' plugin in Volatility detects memory pages with executable code in non-standard locations, such as executable heaps. Heap spraying is a technique where malware allocates multiple heap blocks and fills them with malicious shellcode, then exploits a vulnerability to redirect execution to that heap. This results in executable code present in heap memory, which malfind flags.

Exam trap

CHFI often tests the distinction between where code is stored (heap vs. DLL vs. process image) and candidates confuse heap spraying with DLL injection because both involve injecting code, but heap spraying specifically places code in the heap, not in a loaded module.

How to eliminate wrong answers

Option A is wrong because process hollowing involves replacing the legitimate code of a process with malicious code in its memory space, which typically appears in the .text section, not specifically in an executable heap. Option B is wrong because DLL injection loads a malicious DLL into a process's address space, placing code in the DLL's memory regions, not necessarily in the heap. Option D is wrong because reflective DLL loading loads a DLL from memory without using the standard LoadLibrary API, but the code resides in the DLL's mapped memory, not in the heap.

534
MCQmedium

During malware analysis, an investigator finds that a suspicious process is injecting code into a legitimate system process (e.g., explorer.exe). Which technique is being used?

A.API hooking
B.Process hollowing
C.Code injection
D.DLL injection
AnswerC

Code injection is the correct classification because the finding that code was inserted into a running process directly matches this term. It encompasses any technique that places executable code into the virtual address space of another process and then causes it to run, often by creating a remote thread or using an asynchronous procedure call. The stem's description is a general definition of code injection, not limited to a specific delivery vector.

Why this answer

Code injection is the correct answer because the scenario describes a process injecting arbitrary code into a legitimate system process like explorer.exe. This is the generic term for techniques where malicious code is written into the address space of another process and executed, often via Windows API calls such as WriteProcessMemory and CreateRemoteThread. The question explicitly states 'injecting code,' which directly maps to the broad category of code injection, not a specific subtype.

Exam trap

The CHFI exam often tests the distinction between generic code injection and its specific subtypes (like DLL injection or process hollowing), trapping candidates who choose a narrower term when the question uses the broad phrase 'injecting code' without specifying the delivery mechanism.

How to eliminate wrong answers

Option A is wrong because API hooking intercepts and modifies function calls within a process (e.g., using SetWindowsHookEx or Detours), but it does not involve injecting new code into a separate process's memory space; it redirects existing calls. Option B is wrong because process hollowing replaces the legitimate code of a process (e.g., suspending explorer.exe, unmapping its original code, and writing malicious code into the same process) rather than injecting code into an already-running legitimate process; it creates a hollowed process from the start. Option D is wrong because DLL injection is a specific subtype of code injection that loads a DLL into a target process (using LoadLibrary or reflective loading), but the question does not specify that a DLL is involved—it only mentions 'injecting code,' which could be shellcode or other executable code, making the broader term 'code injection' more accurate.

535
MCQmedium

You are a forensic analyst investigating a suspected malware infection on a Windows 10 workstation. The user reports that the system has been slow and that unexpected pop-ups appear. You have acquired a memory dump and a disk image. During analysis, you find a suspicious process named 'svch0st.exe' running with PID 4567. The process has loaded several DLLs, including 'wininet.dll' and 'ws2_32.dll'. You also find that the process has an active TCP connection to an external IP address 203.0.113.5 on port 4444. In the disk image, you find an executable file at C:\Users\Public\svch0st.exe with a creation date that matches the start of symptoms. The file's hash is not in any known malware database. You decide to perform dynamic analysis by running the file in a sandbox. However, the sandbox environment has no network connectivity. The executable runs but does not exhibit any malicious behavior. What should you do next to determine if the file is malicious?

A.Conduct a thorough static analysis using a disassembler and debugger to understand the code
B.Delete the suspicious file and run a full antivirus scan on the system
C.Re-run the sample in a sandbox with simulated network connectivity or a controlled network to observe C2 communication
D.Perform a forensic imaging of the system again and compare with the original image
AnswerC

Re-running the sample in a sandbox with simulated network connectivity or a controlled network is the correct approach because many malware families remain dormant until they establish C2 communication, at which point they download additional payloads, exfiltrate data, or execute commands. A network-enabled sandbox provides a safe, but realistic environment where the analyst can observe DNS queries, HTTP/S connections, beaconing intervals, and the exact data exchanged with the C2 server. This dynamic analysis yields actionable indicators of compromise (IoCs) and reveals the malware's full functionality without risking real network infection.

Why this answer

The sandbox lacked network connectivity, which prevented the malware from reaching its command-and-control (C2) server. Many malware samples, especially those using HTTP or raw TCP for C2, will remain dormant or exhibit no malicious behavior when they cannot connect to the external IP. By providing simulated or controlled network connectivity, you can trigger the malicious payload and observe the actual C2 communication, confirming the file's intent.

Exam trap

The CHFI exam often tests the misconception that static analysis is always sufficient to determine maliciousness, but the trap here is that malware can be conditionally dormant and only activate when network connectivity is present, making dynamic analysis with network simulation essential.

How to eliminate wrong answers

Option A is wrong because static analysis alone cannot reliably determine if the file is malicious when it has no known hash and the sample is designed to only activate upon network connectivity; static analysis may miss obfuscated or conditionally executed code. Option B is wrong because deleting the file and running an antivirus scan is a reactive, non-analytical step that destroys evidence and does not answer whether the file is malicious; the file's hash is unknown, so antivirus may not detect it. Option D is wrong because performing another forensic imaging and comparing it to the original image would only show changes on disk, not reveal the runtime behavior or network-dependent activation of the malware; it is a redundant step that does not address the core question of whether the file is malicious.

536
MCQhard

A security analyst suspects an attacker has hidden data in the Host Protected Area (HPA) of a suspect's hard drive. Which of the following tools is BEST suited to detect and access the HPA?

A.Foremost
B.EnCase
C.WinPmem
D.PhotoRec
AnswerB

EnCase is a comprehensive forensic platform with the ability to acquire and analyze HPA and DCO regions. It uses low-level ATA commands, such as IDENTIFY DEVICE and DEVICE CONFIGURATION IDENTIFY, to detect the presence of hidden capacity and then creates a bit-for-bit image of those areas. This ensures that any data concealed by a suspect in the HPA or DCO is captured and can be examined, making EnCase the correct tool for this scenario.

Why this answer

EnCase is the best tool for detecting and accessing the Host Protected Area (HPA) because it has built-in support for reading ATA commands that identify and access the HPA, such as IDENTIFY DEVICE and SET MAX ADDRESS. It can bypass the operating system's abstraction layer to directly query the drive's native command set, allowing forensic acquisition of the HPA region that is normally hidden from standard disk utilities.

Exam trap

The trap here is that candidates often confuse file carving tools (Foremost, PhotoRec) with forensic acquisition tools that can access hidden disk areas, assuming any recovery tool can see all data on a drive, when in fact HPA requires direct ATA command support.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool that recovers files based on headers and footers from raw disk images or unallocated space; it does not have any capability to issue ATA commands or detect the HPA. Option C is wrong because WinPmem is a memory acquisition tool for capturing RAM, not a storage forensics tool for accessing hidden disk areas like the HPA. Option D is wrong because PhotoRec is another file carving utility focused on recovering lost files from media, and it lacks the low-level ATA command support needed to identify or access the HPA.

537
MCQmedium

A forensic lab is establishing a chain of custody procedure. Which practice is considered best according to CHFI guidelines?

A.Require biometric authentication for all lab personnel
B.Store evidence in a secure room with limited access
C.Use encryption to protect evidence files
D.Document every transfer of evidence with signatures and timestamps
AnswerD

Proper chain-of-custody documentation requires an unbroken chronological record that identifies every individual who had control of the evidence, the exact date and time of each transfer, and the reason for the transfer. Each exchange must be signed by both the releasing and receiving custodians to verify that the evidence was in their possession and was not unaccounted for. This documentation is pivotal in court to demonstrate that the evidence is authentic and has not been substituted, altered, or tampered with. Without signatures and timestamps, a court may deem the evidence inadmissible on the grounds of a broken custody chain.

Why this answer

The chain of custody is fundamentally a legal and procedural requirement to demonstrate the integrity and admissibility of digital evidence. CHFI guidelines emphasize that every transfer of evidence must be meticulously documented with signatures, timestamps, and purpose to create an unbroken audit trail, which is the only practice that directly satisfies the legal standard for evidence handling.

Exam trap

EC-Council often tests the distinction between security controls (like encryption or access restrictions) and procedural documentation (like signatures and timestamps), leading candidates to confuse physical or technical safeguards with the legal requirement for an auditable chain of custody.

How to eliminate wrong answers

Option A is wrong because biometric authentication controls access to the lab but does not document the transfer or handling of evidence, which is the core requirement for chain of custody. Option B is wrong because storing evidence in a secure room with limited access is a physical security measure, not a documentation procedure; it does not create the required audit trail for each transfer. Option C is wrong because encryption protects evidence files from unauthorized access or tampering but does not provide a documented record of who handled the evidence and when, which is essential for chain of custody.

538
MCQeasy

A forensic analyst is examining a USB flash drive formatted with the FAT32 file system. The analyst needs to determine the total number of sectors in a cluster and the number of reserved sectors. Which of the following structures in the FAT32 file system contains this information?

A.The root directory entry, which contains metadata about the file system including cluster size and reserved sector count.
B.The boot sector (also known as the Volume Boot Record), which contains the BIOS Parameter Block with fields for sectors per cluster and reserved sector count.
C.The FAT (File Allocation Table) itself, which stores cluster chain information and also includes the total sector count in its header.
D.The FSInfo sector, which stores the total number of sectors and the number of free clusters, and also includes the cluster size.
AnswerB

The boot sector of a FAT32 volume contains the BIOS Parameter Block (BPB), which includes critical file system geometry such as bytes per sector, sectors per cluster, number of reserved sectors, number of FATs, and total sectors. Forensic analysts can parse the BPB to determine cluster size and reserved sectors, which are essential for navigating the file system and recovering data.

Why this answer

In FAT32, the boot sector contains the BIOS Parameter Block (BPB), which defines the file system's geometry, including sectors per cluster and reserved sector count. These values are essential for interpreting the FAT and locating data. The FAT itself holds cluster chain information, the root directory stores file entries, and the FSInfo sector provides free cluster hints.

Only the boot sector provides the authoritative file system parameters needed for forensic analysis.

Exam trap

The trap here is assuming that the FSInfo sector or the FAT contains file system geometry, when those details are actually stored in the boot sector's BIOS Parameter Block.

539
MCQmedium

A forensic investigator is analyzing a cloud environment hosted on Amazon Web Services (AWS). A compromised EC2 instance was used to exfiltrate data to an external IP address. The investigator needs to determine which AWS API calls were made to modify security groups to allow outbound traffic to that IP. Which AWS service should the investigator use to obtain this information?

A.VPC Flow Logs
B.AWS Config
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail records API activity in an AWS account, including calls to modify security groups (e.g., AuthorizeSecurityGroupEgress). By analyzing CloudTrail logs, the investigator can identify who made the API call, when, and from which IP address, and the parameters including the allowed IP. This directly answers the question.

Why this answer

AWS CloudTrail is the service that logs all API activity in an AWS account, including security group modifications. It captures the identity of the caller, the time, the source IP, and the request parameters. CloudWatch Logs, AWS Config, and VPC Flow Logs do not provide this level of API call detail.

Therefore, CloudTrail is the correct source.

Exam trap

The trap here is assuming that VPC Flow Logs or AWS Config capture API call details, when they only show network traffic or resource configurations.

540
MCQmedium

An examiner is analyzing an NTFS volume and suspects that a suspect hid data using Alternate Data Streams (ADS). Which tool or method is MOST appropriate to list all ADS on the volume?

A.Execute 'dir /r' in a Windows command prompt on the mounted image
B.Run 'ls -la' from a Linux forensic environment
C.Use 'icacls' to view security descriptors and detect ADS
D.Mount the image in Autopsy and run the 'Find File' module
AnswerA

The 'dir /r' command is a built-in Windows utility that enumerates alternate data streams (ADS) on NTFS volumes. When run against a mounted forensic image or drive, it displays each file accompanied by any named streams in the format 'file.txt:streamname:$DATA'. This directly queries the NTFS $ATTRIBUTE_LIST and $DATA attributes through the Windows filesystem driver, making it the simplest standard technique to confirm the presence and names of hidden ADS.

Why this answer

The 'dir /r' command in Windows Command Prompt is specifically designed to display alternate data streams (ADS) on NTFS volumes. It lists all files and directories, including any hidden streams attached to them, making it the most direct and appropriate method for an examiner to enumerate all ADS on a mounted NTFS volume.

Exam trap

The CHFI exam often tests the misconception that Linux tools like 'ls -la' can universally detect NTFS-specific features, but candidates must remember that ADS are a Windows/NTFS construct requiring native Windows commands or specialized forensic tools.

How to eliminate wrong answers

Option B is wrong because 'ls -la' in a Linux forensic environment does not natively display NTFS alternate data streams; it requires additional tools like 'ntfs-3g' or 'streams' to detect ADS, and even then it's not the most straightforward method. Option C is wrong because 'icacls' is used to view and modify security descriptors (permissions) on files and folders, not to list alternate data streams; it has no capability to enumerate ADS. Option D is wrong because while Autopsy can detect ADS, the 'Find File' module is a general search tool that does not specifically list all ADS on a volume; the 'File Analysis' or 'ADS' module would be more appropriate, but the question asks for the most appropriate method, and 'dir /r' is simpler and more direct.

541
MCQeasy

Which of the following is the BEST definition of Locard's exchange principle in computer forensics?

A.Every contact leaves a trace; an attacker will leave digital traces on a system
B.Chain of custody must be maintained to prove evidence integrity
C.The best evidence rule requires original evidence over copies
D.Digital evidence must be collected in a forensically sound manner to be admissible in court
AnswerA

Locard's exchange principle holds that every contact between two objects results in a mutual transfer of material; in digital forensics this translates to the unavoidable persistence of digital residues such as filesystem metadata, registry keys, log entries, and volatile memory fragments whenever an attacker interacts with a system. Even if an intruder attempts to cover their tracks, actions like opening a file update its last-accessed timestamp, network connections leave connection logs, and command execution may persist in shell history or process artifacts, making the principle foundational for identifying and reconstructing attacker activity.

Why this answer

Locard's exchange principle states that when a person interacts with a scene, they leave something behind and take something with them. In digital forensics, this means that an attacker will leave traces of their activity on the system (e.g., logs, malware) and may also remove evidence.

542
Multi-Selectmedium

Which TWO of the following are valid reasons for using a hardware write blocker over a software write blocker? (Select two.)

Select 2 answers
A.Hardware write blockers support faster transfer speeds than software blockers
B.Hardware write blockers can be bypassed by malware on the forensic workstation
C.Hardware write blockers operate at the physical layer and are OS-independent
D.Hardware write blockers provide a physical barrier that prevents any writes from reaching the suspect drive
E.Hardware write blockers are cheaper than software solutions
AnswersC, D

Operating at the physical layer, a hardware write blocker intercepts bus-level signaling and ATA/SCSI command flow before those commands reach the suspect drive, so no driver in the host OS is involved. This OS-independence ensures identical forensic behavior across Windows, Linux, and other operating systems and does not rely on the integrity of the workstation's software stack. It also means the write blocker remains effective regardless of the host's operating system or file system.

Why this answer

Option C is correct because hardware write blockers sit inline on the storage interface (e.g., SATA, SAS, USB, or IDE) and enforce write protection at the physical/electrical layer, so they function independently of the operating system and require no drivers or host OS support. Option D is correct because this inline hardware design provides a true physical barrier: write commands are intercepted and blocked before they reach the suspect drive, ensuring the evidence disk cannot be altered. Option A is not a valid reason, since hardware blockers generally do not offer faster transfer speeds than software blockers and speed is not their purpose.

Option B is incorrect because a hardware blocker cannot be bypassed by malware on the forensic workstation; that risk applies to software write blockers running on a compromised OS. Option E is incorrect because hardware write blockers are typically more expensive than software write blockers, not cheaper.

Exam trap

The CHFI exam often tests the misconception that hardware write blockers are faster than software blockers, when in reality the hardware bridge introduces overhead, and the key advantage is OS independence and physical write prevention, not speed.

543
MCQeasy

In Linux forensics, an investigator examines /var/log/auth.log and finds repeated entries of "Failed password for root from 10.0.0.5 port 22 ssh2". Which type of attack is most likely indicated?

A.DNS cache poisoning attack
B.SQL injection attack
C.ARP spoofing attack
D.Brute force attack on SSH
AnswerD

A brute-force attack against SSH is the classic finding in auth.log, where sshd writes every authentication attempt via messages like 'Failed password for <user> from <IP> port <port> ssh2'. A sustained pattern of many such failures in a short window—especially with changing usernames or source IPs—indicates automated password guessing. This aligns with the observed log entries, and PAM may also log 'authentication failure' before sshd closes the connection. Because auth.log directly records this sequence, the investigator can correlate failed attempts and possibly successful follow-up logins to assess compromise.

Why this answer

Repeated 'Failed password for root' entries in /var/log/auth.log indicate multiple authentication attempts against the SSH service. This pattern is characteristic of a brute force attack, where an attacker systematically tries many passwords to gain unauthorized access to the root account via SSH.

Exam trap

This exam often tests the distinction between network-layer attacks (ARP spoofing, DNS poisoning) and application-layer attacks (SSH brute force), and the trap here is confusing repeated failed login attempts with a network-level attack like ARP spoofing.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning attacks target DNS resolver caches with forged DNS responses, not SSH authentication logs. Option B is wrong because SQL injection attacks exploit web application input fields to manipulate database queries, not SSH login attempts. Option C is wrong because ARP spoofing attacks manipulate ARP tables on a local network to intercept traffic, not SSH authentication logs.

544
Multi-Selectmedium

Which TWO of the following are valid reasons for a first responder to power off a computer system at a crime scene? (Select TWO)

Select 2 answers
A.To save time during the investigation
B.To make it easier to transport the system
C.When the system is actively destroying evidence (e.g., a data wiping program is running)
D.To prevent the destruction of volatile data by allowing it to be captured before shutdown
E.When the system is a potential threat to first responders (e.g., a bomb or hazardous environment)
AnswersC, E

When a data-wiping program is actively running, the system is irretrievably destroying digital evidence with every passing moment. In this exigent circumstance, immediately cutting power—preferably through the suggested panic button in the imaging software or a hard power-off—halts the destructive process and preserves whatever data remains. This is a valid first-responder exception because the lesser harm (losing volatile data) is outweighed by the greater harm (complete destruction of all data). The responder should note the exact time of shutdown to document what was preserved.

Why this answer

Option C is correct because if a system is actively destroying evidence—such as a running data-wiping utility, a secure-delete routine, or malware with a timed deletion payload—the first responder must immediately remove power to halt the ongoing destruction, since normal shutdown procedures would allow the process to continue and complete. Option E is correct because when a computer poses an immediate physical danger to responders, such as being part of a bomb trigger circuit or located in a hazardous environment (fire, toxic gas, explosive atmosphere), life safety overrides evidence preservation and the system should be powered off. Option A is not a valid reason because speed or convenience never justifies altering a crime scene, and proper evidence handling takes precedence over saving time.

Option B is not valid because transportability is irrelevant to the decision to power off; systems can be transported while powered or properly packaged without using shutdown as a transport aid. Option D is incorrect because it is factually backwards: powering off destroys volatile data (RAM contents, running processes, network connections, encryption keys in memory), whereas capturing volatile data requires the system to remain powered on and follow the order of volatility.

Exam trap

The trap here is that candidates confuse 'preventing destruction of volatile data' (which requires live acquisition, not shutdown) with 'preventing destruction of non-volatile data' (which may justify a hard power-off when a wiping program is active).

545
MCQmedium

An analyst executed the commands shown in the exhibit on a Windows system to prepare a forensic image for analysis. What is the most likely reason for the error message from e2fsck?

A.The analyst failed to properly dismount the source volume before imaging, leading to filesystem inconsistencies.
B.The forensic image was not acquired with a write-blocker, causing data corruption.
C.The image file contains an NTFS filesystem, but e2fsck is designed for ext filesystems.
D.The e2fsck command syntax is incorrect; it should be 'e2fsck -f -n' instead.
AnswerA

The sequence shows `fsutil dismount` being run on C:, but a forensic image taken afterward—especially after Windows remounts the volume or during a live acquisition—will capture the volume in an inconsistent state. When Windows later performs recovery on the dirty volume, metadata updates begin immediately, so e2fsck in the analyst's analysis environment will legitimately report superblock, group descriptor, or inode inconsistencies that were never present in the source. This is the classic 'dirty volume' imaging error, not a problem with the image tool.

Why this answer

The error message from e2fsck indicates that the filesystem has inconsistencies, which typically occur when a volume is imaged while it is still mounted and actively being written to. The analyst likely did not dismount the source volume before acquiring the forensic image, resulting in a snapshot that reflects an inconsistent state (e.g., dirty journal, unflushed writes). This is a common chain-of-custody and acquisition procedure error in forensic imaging.

Exam trap

EC-Council often tests the misconception that a write-blocker alone guarantees a forensically sound image, but the trap here is that even with a write-blocker, imaging a mounted volume can produce an inconsistent filesystem because the OS may have pending writes in cache.

How to eliminate wrong answers

Option B is wrong because a write-blocker prevents writes to the source drive during acquisition, but it does not affect the consistency of the filesystem on the source volume if the volume was mounted and active; the error is about filesystem state, not write-blocker usage. Option C is wrong because the exhibit shows the analyst used 'dd' to create a raw image, and e2fsck is designed for ext2/3/4 filesystems; if the image contained NTFS, e2fsck would produce a different error (e.g., 'bad magic number') rather than a filesystem inconsistency error. Option D is wrong because the syntax 'e2fsck -f -n' is valid (force check and non-interactive), but the error message shown is about filesystem inconsistencies, not a command syntax error; the command executed correctly and detected the issue.

546
MCQeasy

A first responder arrives at a crime scene where a computer is turned on. What should the responder do FIRST?

A.Run antivirus software to check for malware
B.Immediately disconnect the power cord
C.Copy all files from the hard drive
D.Photograph the scene and document everything
AnswerD

Photographing the scene and thoroughly documenting the computer's configuration—including the screen display, attached peripherals, cable connections, power state, and visible indicators—establishes a legally defensible baseline before any forensically relevant action is taken. This initial documentation preserves the original spatial and temporal context of the system, supports the chain of custody, and is indispensable if the scene must be reconstructed or the impact of subsequent steps is questioned. Without such records, even a perfectly performed forensic acquisition may fail admissibility because the examiner cannot prove the scene was preserved.

Why this answer

The first priority at a live crime scene is to preserve the state of the evidence through proper documentation and photography. This ensures an accurate record of the computer's condition, including screen contents, peripheral connections, and environmental context, before any volatile data is lost or altered. The CHFI methodology emphasizes that documentation precedes any seizure or data acquisition steps to maintain chain of custody and evidentiary integrity.

Exam trap

EC-Council often tests the misconception that immediate power disconnection is the safest action to prevent data alteration, but the trap is that this destroys volatile evidence and can trigger encryption lockouts, whereas proper documentation and live response preserve the most fragile data first.

How to eliminate wrong answers

Option A is wrong because running antivirus software modifies the system state by writing logs, updating signatures, and potentially altering malware artifacts, which violates forensic integrity principles. Option B is wrong because immediately disconnecting the power cord on a running system causes loss of volatile data (RAM contents, network connections, running processes) and may trigger anti-forensic mechanisms like encryption key destruction or disk wiping. Option C is wrong because copying files from the hard drive before proper imaging and write-blocking can modify file metadata (access timestamps) and does not capture unallocated space or slack space, compromising the forensic soundness of the evidence.

547
MCQmedium

During a forensic examination of a Linux ext4 file system, an investigator runs the `ls -i` command and sees inode numbers. They need to examine the inode structure. Which command should they use to display detailed inode information?

A.dd if=/dev/sda1 of=output.img
B.debugfs -R 'stat <inode>' /dev/sda1
C.mount -o loop image.img /mnt
D.fsck /dev/sda1
AnswerB

debugfs is the standard ext2/ext3/ext4 filesystem debugger, and the -R option lets you execute a single request in non-interactive mode. The 'stat <inode>' command within debugfs prints the complete inode record, including file mode, UID/GID, size, access/change/modification times, link count, and block allocation data. This makes it the correct choice for directly querying inode information on a live device or an acquired image without mounting or modifying the filesystem.

Why this answer

The `debugfs` command is a native ext2/ext3/ext4 file system debugger that allows direct inode inspection. The `-R 'stat <inode>'` flag runs the `stat` command in debugfs to display the full inode structure, including permissions, timestamps, block pointers, and extended attributes, which is exactly what the investigator needs after seeing inode numbers from `ls -i`.

Exam trap

EC-CHFI often tests the distinction between file system analysis tools (debugfs) and general-purpose disk utilities (dd, mount, fsck), trapping candidates who confuse imaging or mounting with inode-level inspection.

How to eliminate wrong answers

Option A is wrong because `dd` is a low-level block copy tool used for imaging or cloning a partition; it does not parse or display inode metadata. Option C is wrong because `mount -o loop` attaches a disk image to the file system tree for access as a mounted volume, but it does not provide a command to dump raw inode details—it only makes files accessible via standard file operations. Option D is wrong because `fsck` is a file system consistency check and repair tool; it does not display inode structures and is not designed for forensic inode examination.

548
MCQhard

During a forensic investigation, the analyst needs to verify the integrity of a forensic image. The analyst originally computed MD5 and SHA-1 hashes of the source drive. Which action BEST ensures the image has not been altered?

A.Recompute MD5 and SHA-1 hashes of the image and compare with the original
B.Check that the image was created using a write blocker
C.Compare the file size of the image with the original drive's capacity
D.Open the image in FTK Imager and browse a few files
AnswerA

Cryptographic hash algorithms such as MD5 and SHA-1 generate a fixed-size digest that is computationally infeasible to reverse, so recomputing these hashes over the entire image and matching them against the original acquisition hashes confirms that every bit of the image remains unchanged since capture. Because MD5 and SHA-1 use different mathematical constructions, matching both simultaneously makes an accidental collision astronomically unlikely, and this is the standard integrity verification method accepted in forensic practice.

Why this answer

Recomputing the MD5 and SHA-1 hashes of the forensic image and comparing them to the original values is the definitive method to verify integrity. Hash functions produce a fixed-size digest that changes completely if even a single bit of the image is altered, providing cryptographic assurance that the image is an exact bit-for-bit copy of the source drive. This process directly validates data integrity, which is a core requirement in forensic acquisition.

Exam trap

EC-Council often tests the misconception that using a write blocker or checking file size is sufficient for integrity verification, but the trap is that only cryptographic hash comparison provides the mathematical proof required to detect any alteration.

How to eliminate wrong answers

Option B is wrong because using a write blocker ensures the source drive is not modified during acquisition, but it does not verify that the resulting image file has remained unchanged after creation. Option C is wrong because file size alone is not a reliable integrity check; two different data sets can have the same size, and size does not detect bit-level corruption or intentional tampering. Option D is wrong because browsing a few files in FTK Imager only checks that the image is mountable and some files appear intact, but it does not provide a cryptographic guarantee that every byte of the image matches the original.

549
Multi-Selectmedium

A forensic analyst is examining an Android device for evidence of a specific app's usage. Which TWO locations are MOST likely to contain app-specific data that can be recovered through a logical acquisition?

Select 2 answers
A./system/bin/
B./data/data/
C./mnt/sdcard/Android/data/
D./proc/
E./init.rc
AnswersB, C

/data/data/ is the definitive internal storage directory for each installed Android app, where the system creates a package-owned folder containing databases, shared_prefs, files, cache, and code-cache. This location is protected by the app's UID and Linux file permissions, and it is where applications persist user-generated content, login tokens, and SQLite databases that are prime forensic evidence. For both physical and logical acquisitions, this directory is the primary target for recovering app artifacts.

Why this answer

Option B (/data/data/) is correct because this is the primary internal storage path where Android stores each app's private data, including databases, shared preferences, and cache files, and on a rooted or debuggable device it can be captured during a logical acquisition. Option C (/mnt/sdcard/Android/data/) is correct because it is the app-specific external storage directory (also referenced as /sdcard/Android/data/ or /storage/emulated/0/Android/data/) where apps place user- and app-generated files such as downloads, media, and OBB assets that are recoverable via logical extraction. Option A (/system/bin/) is not app-specific data but the read-only system partition containing OS binaries and shell tools.

Option D (/proc/) is a virtual kernel filesystem exposing runtime process and system state, not persistent app evidence. Option E (/init.rc) is the Android init startup script defining boot-time services and actions, not user app data.

Exam trap

The CHFI exam often tests the misconception that /system/bin/ or /proc/ contain app-specific data because they sound like common storage locations, but in Android forensics, only /data/data/ and external storage paths like /mnt/sdcard/Android/data/ hold recoverable app artifacts during logical acquisition.

550
MCQeasy

A forensic investigator is analyzing a Microsoft SQL Server instance that was compromised. The investigator wants to identify all login attempts that failed due to incorrect passwords. Which system function or view should be queried?

A.sys.dm_exec_sessions
B.sys.dm_tran_locks
C.xp_readerrorlog with filter for 'Login failed'
D.sys.dm_exec_requests
AnswerC

The correct approach is to query the SQL Server error log via xp_readerrorlog with a filter for the error message text '%Login failed%'. SQL Server writes failure audit events, including error 18456 with detail such as the login name and reason, to the error log; xp_readerrorlog is an undocumented extended stored procedure that reads the current or archived logs and accepts parameters to filter by text, which makes it effective for forensic analysis of failed logins.

Why this answer

The xp_readerrorlog extended stored procedure reads the SQL Server error log, which records all login attempts, including failures. By filtering for 'Login failed', the investigator can retrieve the exact entries where authentication failed due to incorrect passwords. This is the standard method for auditing failed logins in SQL Server.

Exam trap

EC-Council often tests the misconception that dynamic management views (DMVs) like sys.dm_exec_sessions store historical authentication data, when in fact they only reflect current state, not past events.

How to eliminate wrong answers

Option A is wrong because sys.dm_exec_sessions shows current active sessions, not historical login failures; it only reflects successful connections. Option B is wrong because sys.dm_tran_locks provides information about current lock states and transactions, not authentication events. Option D is wrong because sys.dm_exec_requests displays currently executing requests, not past login attempts or failures.

551
MCQmedium

Which of the following best describes the purpose of the Host Protected Area (HPA) on a hard disk drive?

A.To accelerate read/write operations using flash cache
B.To store the file system journal
C.To provide a hidden storage area that is inaccessible through standard OS commands
D.To store the Master Boot Record
AnswerC

HPA is a hidden storage area defined by the ATA/ATAPI specification, created by reducing the maximum LBA reported to the OS. Standard OS commands, including disk management utilities and forensic tools that do not issue ATA native-max address queries, cannot see or access these sectors. This makes HPA a potential location for covert data hiding or vendor-specific recovery data.

Why this answer

The Host Protected Area (HPA) is a reserved region on a hard disk drive defined by the ATA/ATAPI standards. It is hidden from the operating system and standard disk utilities, making it inaccessible through normal OS commands, which is why it is used for forensic purposes or vendor-specific recovery tools.

Exam trap

EC-Council often tests the misconception that HPA is a software-based hidden partition (like a volume shadow copy or a system reserved partition), rather than a hardware-level feature defined by ATA commands that persists even after reformatting or OS reinstallation.

How to eliminate wrong answers

Option A is wrong because HPA does not accelerate read/write operations; that is the function of technologies like Intel Optane or hybrid drives with NAND flash cache. Option B is wrong because the file system journal is stored within the active file system (e.g., NTFS $LogFile or ext3/4 journal), not in a hidden hardware region like HPA. Option D is wrong because the Master Boot Record (MBR) resides in the first sector (LBA 0) of the disk, which is part of the user-accessible area, not the HPA.

552
MCQeasy

A security analyst is reviewing Windows Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this most likely indicate?

A.Successful user logins
B.Account creation events
C.A brute-force password guessing attack
D.Service installation
AnswerC

A brute-force password guessing attack is characterized by a high volume of Event ID 4625 (failed logon) records in a short window, often for the same target user account, and frequently originating from multiple source IP addresses or repeated attempts with varying passwords. The Failure Reason on these events typically shows 'Unknown user name or bad password' (status code 0xC000006D) or 'the specified account's password has expired' when lockout policies exist. This pattern is the classic signature of an automated tool cycling through passwords, making it the correct interpretation of a surge in 4625 events.

Why this answer

Event ID 4625 is the Windows security log event for a failed logon attempt. A high frequency of these events for the same user account within a short time frame is a classic indicator of an automated brute-force password guessing attack, where an attacker tries multiple passwords against a single account.

Exam trap

The trap here is that candidates confuse Event ID 4625 (failed logon) with Event ID 4624 (successful logon) or assume any repeated event indicates a system error rather than an active attack.

How to eliminate wrong answers

Option A is wrong because Event ID 4625 specifically records failed logon attempts, not successful ones (successful logins generate Event ID 4624). Option B is wrong because account creation events are logged under Event ID 4720, not 4625. Option D is wrong because service installation events are recorded under Event ID 4697 (or 7045 in the System log), not 4625.

553
MCQmedium

During a forensic investigation, you find a file named ntuser.dat.LOG1 in a user's profile directory. What is the primary purpose of this file?

A.It contains the user's Internet browsing history
B.It logs changes to the user's registry hive for recovery purposes
C.It is a backup copy of the user's registry hive
D.It stores the user's recently accessed files
AnswerB

NTUSER.DAT.LOG1 is a transactional log file that records pending modifications to the NTUSER.DAT registry hive before they are committed to the main hive file. Windows uses these logs, along with .LOG2 and .REGISTRYMACHINE files, to replay incomplete writes and recover registry integrity after a crash or power failure. Forensically, the .LOG1 file can contain data that was never fully written to NTUSER.DAT, capturing recent changes that might not be present in the main hive. This is why the correct interpretation is that it logs changes for recovery, not a simple backup.

Why this answer

The ntuser.dat.LOG1 file is a transactional log file used by the Windows registry to record changes made to the corresponding user's registry hive (ntuser.dat). Its primary purpose is to ensure data integrity and enable recovery of the hive in case of a system crash or power failure during a write operation, by allowing the registry to replay or roll back incomplete transactions.

Exam trap

The trap here is that candidates often confuse the LOG1 file with a simple backup or a log of user activity like browsing history, when in fact it is a low-level transactional log for registry integrity, not a user-visible log file.

How to eliminate wrong answers

Option A is wrong because Internet browsing history is stored in separate files such as the WebCacheV01.dat or history files within the user's AppData folder, not in registry log files. Option C is wrong because ntuser.dat.LOG1 is not a backup copy; it is a transactional log that records changes, whereas a backup copy would be a separate file like ntuser.dat.regback or a System Restore point. Option D is wrong because recently accessed files are tracked in the user's Jump Lists, the Recent folder, or the MRU (Most Recently Used) lists within the registry itself, not specifically in the LOG1 file.

554
MCQmedium

A security analyst suspects a mobile device is infected with malware that exfiltrates data via DNS queries. Which tool or technique would be MOST effective for detecting this behavior during dynamic analysis?

A.PEiD to detect packers in the mobile app binary
B.Regshot to compare registry snapshots before and after execution
C.Process Monitor to observe registry and file system changes
D.Wireshark to capture and analyze network packets for anomalous DNS queries
AnswerD

Wireshark is a packet analyzer that captures raw frames and reassembles DNS messages, letting an analyst filter for dns.qry.name, spot repeated NXDOMAIN responses, or identify DGA subdomains typical of mobile malware. On Android, remote capture via USB tethering or a dedicated access point gives visibility into all app DNS lookups without modifying the device. Correlating query timing and volume can confirm an infection when static analysis is inconclusive.

Why this answer

D is correct because DNS exfiltration involves encoding stolen data into DNS query fields (e.g., subdomains or TXT records) and sending them to a malicious server. Wireshark captures and analyzes raw network packets, allowing the analyst to inspect DNS query payloads for anomalous patterns such as unusually long hostnames, high query volume, or queries to suspicious domains, which are hallmarks of DNS tunneling.

Exam trap

EC-Council often tests the misconception that dynamic analysis of malware behavior requires host-based monitoring (like Process Monitor) rather than network-based analysis, but for data exfiltration via DNS, packet capture is essential.

How to eliminate wrong answers

Option A is wrong because PEiD is a tool for detecting packers and compilers in Windows PE files, not for analyzing mobile app binaries or network behavior; it cannot capture DNS queries. Option B is wrong because Regshot compares Windows registry snapshots, which is irrelevant for mobile device analysis and does not monitor network traffic. Option C is wrong because Process Monitor (Procmon) monitors Windows registry, file system, and process activity on a local system, not network packets; it cannot detect DNS exfiltration over the wire.

555
MCQeasy

Which mobile forensic tool is commonly used to perform a physical extraction of an iOS device, including bypassing the lock screen on certain models?

A.Magnet AXIOM
B.GrayKey
C.Oxygen Forensic Detective
D.FTK Imager
AnswerB

GrayKey is a hardware-software system developed by Grayshift specifically for law enforcement and forensic use, designed to perform passcode bypass and physical extraction from iOS devices. It exploits bootrom or Secure Enclave vulnerabilities to derive the passcode and decrypt the file system, yielding a full filesystem image, keychain, and app data even from locked devices. This capability makes it the de facto standard for iOS physical extraction in many criminal investigations, distinguishing it from general-purpose mobile forensic platforms.

Why this answer

GrayKey is a specialized hardware tool designed by Grayshift that performs physical extraction of iOS devices, including bypassing the lock screen on certain models (e.g., iPhone 5 through iPhone X) by exploiting bootrom vulnerabilities or using brute-force techniques. It is widely used in law enforcement for forensic acquisition of iOS devices where logical extraction is insufficient.

Exam trap

EC-Council often tests the distinction between logical extraction tools (like Magnet AXIOM or Oxygen Forensic Detective) and hardware-based physical extraction tools (like GrayKey), leading candidates to mistakenly choose a familiar forensic suite that cannot bypass iOS lock screens.

How to eliminate wrong answers

Option A is wrong because Magnet AXIOM is a comprehensive digital forensics platform that supports logical and file system extractions from iOS devices but does not natively perform physical extraction or lock screen bypass; it relies on other tools (like GrayKey or checkra1n) for that capability. Option C is wrong because Oxygen Forensic Detective is a forensic suite that can extract data from iOS devices via logical or advanced logical methods, but it does not include hardware-based physical extraction or lock screen bypass; it depends on third-party tools or jailbreaks for deeper access. Option D is wrong because FTK Imager is a disk imaging tool for creating forensic images of storage media (e.g., hard drives, SD cards) and does not support mobile device extraction, let alone iOS physical extraction or lock screen bypass.

556
Multi-Selecthard

Which THREE of the following are indicators of a web shell on a web server? (Select three.)

Select 3 answers
A.Unexpected file modifications in web directories, especially .php, .asp, or .jsp files
B.Presence of processes like cmd.exe or /bin/bash running under the web server user
C.An increase in 404 errors due to directory traversal attempts
D.Regular successful logins from multiple IP addresses
E.Atypical HTTP requests containing system commands (e.g., ?cmd=whoami)
AnswersA, B, E

Web shells are typically script files placed in web-accessible directories, and their presence is often revealed by changes to file integrity—new files appearing or existing files altered with PHP/ASP/JSP content. A file integrity monitoring system would flag these modifications, and during forensic analysis, file hashes and timestamps can correlate with the attack timeline. This is a strong indicator because legitimate content management processes rarely modify executable scripts in web root directories without corresponding change-control records.

Why this answer

Option A is correct because web shells are typically dropped as script files in web-accessible directories, so unexpected creation or modification of .php, .asp, or .jsp files is a strong indicator of compromise. Option B is correct because a web shell often executes OS commands, causing processes such as cmd.exe on Windows or /bin/bash on Linux to run under the web server's service account (e.g., www-data, apache, or IIS APPPOOL), which is abnormal for normal web serving. Option E is correct because web shells commonly accept commands via HTTP parameters like ?cmd=whoami, so atypical requests embedding system commands in URLs or POST bodies are a direct sign of web shell activity.

Option C is not correct because a rise in 404 errors from directory traversal attempts indicates scanning or probing, not necessarily an installed web shell. Option D is not correct because regular successful logins from multiple IP addresses may indicate credential sharing or other account misuse, but it is not a specific indicator of a web shell on the server.

Exam trap

The trap here is that candidates confuse the symptoms of a web shell's activity (like directory traversal attempts or login anomalies) with the definitive artifacts of the web shell itself, leading them to select options that indicate attack vectors rather than the web shell's presence.

557
MCQmedium

A security analyst is investigating a potential intrusion and finds a webshell on a Linux web server. Which of the following logs would be MOST useful to determine how the webshell was uploaded?

A./var/log/syslog
B./var/log/apache2/access.log
C./var/log/auth.log
D./var/log/kern.log
AnswerB

/var/log/apache2/access.log is the canonical location for Apache web server request logging, typically using the combined log format to capture source IP, timestamp, HTTP method, URI, response status, user agent, and request bytes. A file upload manifests as a POST request to a specific endpoint, often with a large request size, and the access log provides the definitive timeline and source information needed for intrusion analysis. This log is the first stop for correlating suspicious upload activity with a specific client and session.

Why this answer

The Apache access log (/var/log/apache2/access.log) records every HTTP request made to the web server, including the method (e.g., POST), URI, source IP, and user-agent. A webshell is typically uploaded via a file upload vulnerability or a crafted HTTP request (e.g., PUT or POST with multipart/form-data), so the access log will show the exact request that transferred the malicious file to the server, making it the most useful for determining the upload vector.

Exam trap

EC-Council often tests the misconception that syslog or auth.log would capture web-based attacks, but the trap here is that candidates confuse system-level logs (auth, syslog, kern) with application-level logs (Apache access log), which are the only ones that record HTTP request details needed to trace a webshell upload.

How to eliminate wrong answers

Option A is wrong because /var/log/syslog is a general system log that records kernel messages, daemon events, and system services, but it does not log individual HTTP requests or file uploads to a web server. Option C is wrong because /var/log/auth.log records authentication attempts (e.g., SSH logins, sudo commands) and is irrelevant to webshell uploads that occur through the web application layer. Option D is wrong because /var/log/kern.log contains kernel-level messages (e.g., hardware drivers, system calls) and has no visibility into HTTP traffic or web application file operations.

558
Multi-Selectmedium

A forensic analyst is investigating a Windows system and wants to identify recently executed programs. Which TWO artifacts should the analyst examine?

Select 2 answers
A.MRU lists
B.Prefetch files
C.UserAssist
D.ShellBags
E.Jump lists
AnswersB, C

Prefetch files are created in C:\Windows\Prefetch when an application executes on Windows, serving as a performance optimization. Each .pf file contains the executable path, run count, last run timestamp, and a list of loaded modules (DLLs), making it a primary artifact for directly recording program execution. This is the strongest evidence for determining which applications were launched, including historically executed programs, though it may be disabled on SSDs or under certain configurations.

Why this answer

Prefetch files (B) are correct because Windows stores execution metadata in C:\Windows\Prefetch as .pf files, recording the executable name, run count, and last-run timestamps, making them a primary artifact for proving program execution. UserAssist (C) is correct because it tracks GUI-based program launches via ROT13-encoded entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist, including run counts and last-execution times for user-initiated applications. MRU lists (A) only show recently accessed files or commands, not necessarily executed programs, so they are weaker execution evidence.

ShellBags (D) record folder view settings and window positions, reflecting folder navigation rather than program execution. Jump lists (E) are tied to taskbar/application recent-item history and indicate files opened by an application, but they do not directly prove that a program itself was executed.

Exam trap

Candidates often confuse artifacts that track file access (MRU lists, Jump lists) with those that track program execution (Prefetch, UserAssist), leading to incorrect selection of MRU lists or Jump lists as evidence of program execution.

559
Multi-Selecthard

Which TWO of the following are challenges specific to SSD forensics compared to HDD forensics?

Select 2 answers
A.Wear leveling distributes writes, complicating data location
B.File system metadata may be overwritten
C.Magnetic remanence allows data recovery
D.Slack space contains remnants of deleted files
E.TRIM command erases deleted data
AnswersA, E

Wear leveling is inherent to NAND flash: because each block can endure only a limited number of program/erase cycles, the SSD controller continually remaps logical block addresses to different physical NAND cells and performs garbage collection. This dynamic mapping means a file's data is scattered and relocated over time, so traditional HDD-style forensic analysis that expects fixed sectors or known physical locations cannot reliably locate the original data.

Why this answer

Option A is correct because SSD controllers use wear leveling to spread writes across flash blocks, so logical block addresses no longer map predictably to physical NAND locations, making it hard to determine where data actually resides. Option E is correct because the ATA TRIM command (and SCSI UNMAP) tells the SSD controller that deleted blocks are no longer needed, allowing them to be erased during garbage collection, which can destroy evidence that would persist on an HDD. Option B is not SSD-specific, since file system metadata can be overwritten on any storage medium.

Option C is incorrect because magnetic remanence is a property of magnetic HDD platters, not SSDs. Option D is not SSD-specific either, as slack space remnants of deleted files exist in file systems on both HDDs and SSDs.

Exam trap

CHFI often tests the distinction between challenges that are universal to all storage forensics versus those that are unique to SSD technology, so candidates mistakenly select options like 'file system metadata overwritten' or 'slack space' which are common to both HDDs and SSDs.

560
Multi-Selectmedium

A forensic analyst is examining MySQL binary logs to identify a data exfiltration event. Which TWO fields are most critical for reconstructing the stolen data?

Select 2 answers
A.Error code
B.Timestamp
C.Server ID
D.SQL statement
E.Thread ID
AnswersB, E

Binlog event headers include a timestamp (in seconds since epoch) that enables forensic reconstruction of the exact order in which transactions occurred. This chronology is essential for correlating binlog events with other logs (e.g., access logs) to pinpoint when data was accessed and exfiltrated, and for establishing a timeline of an attacker's actions.

Why this answer

Timestamp (B) is critical for reconstructing the stolen data because it establishes the exact sequence of events, allowing correlation with other logs (e.g., general query log) to pinpoint when exfiltration occurred. Thread ID (E) uniquely identifies the database connection; by correlating thread IDs across binary logs and general query logs, the analyst can trace all queries (including SELECTs) executed by the same connection, revealing the exfiltration queries that are not recorded in binary logs. Together, these fields enable chronological and connection-based reconstruction, compensating for the binary log's lack of SELECT logging.

Exam trap

EC-Council often tests the misconception that SQL statements are always present in binary logs. However, binary logs only record data-changing operations (INSERT, UPDATE, DELETE, DDL), not SELECT queries used for typical data exfiltration. The critical fields for reconstructing stolen data from binary logs are timestamp and thread ID, which allow correlation with other logs that capture the actual SELECT statements.

561
MCQmedium

Based on the ARP table exhibit, what is the most likely security issue?

A.The gateway is unreachable
B.Duplicate IP addresses on the network
C.ARP poisoning attack
D.MAC address filtering is enabled
AnswerC

ARP poisoning (ARP spoofing) is the only explanation that matches the exhibit: the attacker sends forged ARP replies claiming their MAC address is associated with the gateway and numerous other hosts, overwriting the victim's ARP cache. Once the victim's cache is poisoned, all outbound traffic destined for those IPs is sent to the attacker's MAC, enabling man-in-the-middle sniffing, session hijacking, or denial of service. The presence of one unique MAC address across many IP entries is a classic forensic indicator of an ongoing ARP spoofing attack, especially when the duplicate MAC belongs to the attacker's interface.

Why this answer

The ARP table exhibit shows a single IP address (192.168.1.1) mapped to two different MAC addresses (00:11:22:33:44:55 and AA:BB:CC:DD:EE:FF). This is a classic indicator of an ARP poisoning attack, where an attacker sends forged ARP replies to associate their MAC address with the gateway's IP, enabling man-in-the-middle interception of traffic.

Exam trap

The trap here is that candidates may confuse ARP poisoning with duplicate IP addresses, but duplicate IPs cause a 'conflict' message and only one MAC survives in the ARP table, whereas ARP poisoning shows two distinct MACs for the same IP simultaneously.

How to eliminate wrong answers

Option A is wrong because the gateway being unreachable would result in no ARP entry or an incomplete entry, not multiple MAC addresses for the same IP. Option B is wrong because duplicate IP addresses cause address conflicts and connectivity issues, but the ARP table would typically show only one MAC per IP (the last to respond), not two simultaneous entries. Option D is wrong because MAC address filtering restricts which devices can connect, but it does not cause multiple MAC addresses to appear for a single IP in the ARP table.

562
MCQmedium

During a forensic investigation, the analyst needs to create a forensic image of a hard drive that also hashes the data during acquisition. Which command-line tool would be MOST appropriate for this task?

A.dd
B.fdisk
C.memdump
D.dcfldd
AnswerD

dcfldd is an enhanced version of dd developed by the US DoD Computer Forensic Lab that embeds on-the-fly hashing using algorithms like md5, sha1, sha256, sha384, or sha512. It computes one or more hashes simultaneously while writing the image, and can also hash the input and output independently, providing immediate verification that the acquired image is identical to the source. With built-in hash logging, progress reporting, and the ability to write to multiple outputs, dcfldd is purpose-built for forensic imaging where integrity must be proven contemporaneously, making it the correct choice.

Why this answer

dcfldd is a modified version of dd that includes built-in hashing (e.g., MD5, SHA-1, SHA-256) during the imaging process, allowing the analyst to verify data integrity in real time without a separate hashing step. This makes it the most appropriate tool for creating a forensic image that also hashes the data during acquisition.

Exam trap

The CHFI exam often tests the distinction between dd and dcfldd, trapping candidates who assume dd is sufficient because it can create a raw image, ignoring the explicit requirement for integrated hashing during acquisition.

How to eliminate wrong answers

Option A (dd) is wrong because while dd can create a bit-for-bit copy, it does not natively compute or embed a hash during acquisition; any hashing must be done as a separate post-processing step, which is less efficient and can introduce integrity gaps. Option B (fdisk) is wrong because it is a partitioning tool used to manipulate partition tables, not to create forensic images or compute hashes. Option C (memdump) is wrong because it is designed to capture volatile memory (RAM), not to image a hard drive, and it does not provide hashing capabilities.

563
MCQeasy

Which Wireshark filter should an analyst use to display only TCP packets that have the SYN flag set and the ACK flag not set?

A.tcp.flags.syn == 1 or tcp.flags.ack == 0
B.tcp.flags.syn == 1 and tcp.flags.ack == 0
C.tcp.flags.syn == 1
D.tcp.flags == 0x002
AnswerB

This filter requires both conditions to be true: SYN=1 and ACK=0, which precisely identifies the initial SYN segment sent by the host initiating a TCP connection. During the three-way handshake, a SYN-ACK response has SYN=1 but also ACK=1, so it is excluded by the ACK=0 requirement. This is the standard, readable Wireshark filter for finding connection attempts, and it reliably distinguishes the connection initiator from the responder.

Why this answer

The filter `tcp.flags.syn == 1 and tcp.flags.ack == 0` uses the logical AND operator to require that the SYN flag is set (value 1) and the ACK flag is not set (value 0). This precisely matches the condition for a TCP SYN packet that is not part of a SYN-ACK handshake response, which is exactly what the analyst needs to isolate.

Exam trap

The trap here is that candidates often confuse the logical OR with AND, or assume that checking only the SYN flag is sufficient, forgetting that SYN-ACK packets also have SYN set and must be explicitly excluded.

How to eliminate wrong answers

Option A is wrong because using the OR operator (`tcp.flags.syn == 1 or tcp.flags.ack == 0`) will display packets where either the SYN flag is set OR the ACK flag is not set, which includes many packets that do not meet the requirement (e.g., packets with only ACK=0 but SYN=0, or packets with SYN=1 and ACK=1). Option C is wrong because `tcp.flags.syn == 1` alone will display all packets with the SYN flag set, including SYN-ACK packets (where both SYN and ACK are set), which fails to exclude those with ACK set. Option D is wrong because `tcp.flags == 0x002` matches only the SYN flag in the TCP flags byte (bit 1), but this filter does not check the ACK flag (bit 4, value 0x010); it will still capture SYN-ACK packets if the ACK flag is also set, since the filter only checks the SYN bit and ignores other flags.

564
MCQeasy

Which tool is commonly used for timeline analysis in digital forensics, combining multiple artifacts into a super timeline?

A.Plaso
B.Autopsy
C.Sleuth Kit
D.Wireshark
AnswerA

Plaso (formerly log2timeline) is the de facto standard for creating comprehensive 'super timelines' in digital forensics. It recursively parses file system metadata, system logs, browser history, registry hives, and numerous application artifacts, normalizing timestamps to UTC and exporting them into a unified SQLite or CSV timeline. This aggregated, holistic view of system activity is what makes Plaso the benchmark tool for timeline analysis.

Why this answer

Plaso (log2timeline) is the correct tool for timeline analysis because it ingests multiple forensic artifacts (e.g., registry hives, event logs, file system metadata, browser history) and correlates them into a single, unified super timeline. This allows investigators to reconstruct events across different data sources in chronological order, which is essential for timeline analysis in digital forensics.

Exam trap

EC-Council often tests the distinction between a tool that performs a specific function (Plaso for super timeline creation) versus a platform that integrates multiple tools (Autopsy), leading candidates to mistakenly choose Autopsy because it is a more familiar, all-in-one forensic suite.

How to eliminate wrong answers

Option B (Autopsy) is wrong because Autopsy is a GUI-based digital forensics platform that uses The Sleuth Kit and other modules for analysis, but it does not natively create a super timeline from multiple artifacts; it relies on Plaso or other tools for that specific function. Option C (Sleuth Kit) is wrong because Sleuth Kit is a collection of command-line tools for low-level file system analysis (e.g., extracting MFT entries, recovering deleted files) and does not combine artifacts from disparate sources into a unified timeline. Option D (Wireshark) is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting live or recorded network traffic (e.g., TCP/IP packets), not for analyzing local forensic artifacts or building timelines.

565
Multi-Selecthard

Which THREE of the following are essential steps in the digital forensics investigation process? (Select three.)

Select 3 answers
A.Examination
B.Analysis
C.Encryption
D.Collection
E.Destruction
AnswersA, B, D

Examination is the forensic phase where collected data is systematically processed to locate and extract potentially relevant information, such as deleted files, hidden partitions, and unallocated space. Examiners use specialized software, keyword filters, file-signature analysis, and write-blockers to ensure the original evidence is not altered. This step is essential because it converts raw acquired data into a focused set of artifacts that can later be interpreted.

Why this answer

The digital forensics investigation process follows a defined sequence of phases, and Collection (D) is essential because it is the phase where potentially relevant data is identified, preserved, and acquired from sources such as disks, memory, and logs using write-blockers and hashing to maintain integrity. Examination (A) is essential because it is where the collected data is filtered, extracted, and reduced to identify only the information relevant to the case, using forensic tools and techniques. Analysis (B) is essential because it is where the examined data is interpreted to answer the investigative questions, establish timelines, attribute actions, and draw conclusions supported by the evidence.

Encryption (C) is not a forensic process phase; it is a data-protection technique that may be encountered as an obstacle during examination, not a required step. Destruction (E) is not part of the investigation process either, since evidence must be preserved and retained per legal and chain-of-custody requirements rather than destroyed.

Exam trap

EC-Council often tests the distinction between the forensic process steps and unrelated technical concepts like encryption or destruction, so candidates may mistakenly select 'Encryption' because they confuse a common obstacle with a required phase, or 'Destruction' because they think evidence must be destroyed after analysis.

566
MCQeasy

You are a forensic investigator responding to an incident on a Windows 10 workstation used by a finance manager. The user reports that a critical spreadsheet containing quarterly budget data was accidentally deleted from the Desktop yesterday at approximately 3:00 PM. The system has been used normally since then, and the user has not emptied the Recycle Bin. You have created a forensic image of the drive using FTK Imager. The Recycle Bin contains a file named 'Quarterly_Budget.xlsx', but it appears to be a shortcut (size 1 KB). The user insists the original file was several megabytes. You need to recover the original file. Which action should you take next?

A.Search the $Recycle.Bin folder on the forensic image to locate the original file data, which may be stored under a different name.
B.Restore a previous version of the Desktop folder from Volume Shadow Copy.
C.Use file carving techniques to recover the file from unallocated space on the Desktop.
D.Check the Recycle Bin on the live system; the file should be there and can be restored.
AnswerA

On the forensic image, the $Recycle.Bin folder contains the original file data in a renamed storage file (typically $R...) while a companion $I... file preserves the original name and metadata; relying on the live Recycle Bin UI is insufficient because it only exposes a virtual view of these entries. Searching this hidden system folder directly is the correct first step because the file is still fully allocated and recoverable without carving or relying on volume snapshots.

Why this answer

When a file is moved to the Recycle Bin on Windows 10, the original file data is not stored in the Recycle Bin itself; instead, a hidden file (with a random name) is created in the `$Recycle.Bin` folder on the volume, and a shortcut (the visible entry) is placed in the Recycle Bin. The shortcut points to the hidden file, which retains the original data. Since the visible entry is only 1 KB, the actual file content must be located in the `$Recycle.Bin` folder under a different name, making option A the correct next step.

Exam trap

The trap is that candidates assume the Recycle Bin contains the actual file data, but the question tests the understanding that the Recycle Bin only stores a shortcut, and the real data is hidden in the `$Recycle.Bin` folder under a different name.

How to eliminate wrong answers

Option B is wrong because restoring a previous version from Volume Shadow Copy would only work if the file was deleted via a system restore point or if the Desktop folder had versioning enabled, which is not guaranteed and is not the primary mechanism for Recycle Bin recovery. Option C is wrong because file carving from unallocated space is a last-resort technique for when the file is not recoverable via the Recycle Bin or file system metadata; here, the file is still logically present in the Recycle Bin structure, so carving is unnecessary and less reliable. Option D is wrong because the user has already created a forensic image, and checking the live system could alter evidence; moreover, the Recycle Bin on the live system would show the same shortcut, not the original data.

567
MCQeasy

During a mobile device investigation, an examiner needs to acquire the maximum amount of data from a locked iOS device without modifying it. Which acquisition type should be used?

A.Manual acquisition
B.Physical acquisition
C.Logical acquisition
D.File system acquisition
AnswerB

Physical acquisition is the most comprehensive forensic method, creating a bit-for-bit image of the device's raw flash memory. This allows recovery of deleted files, unallocated space, and hidden partitions that logical or file system methods would miss. On locked devices, specialized tools like GrayKey or Cellebrite UFED leverage hardware or bootrom exploits (e.g., checkm8) to bypass the lock screen and extract the full memory image without needing the user's passcode. Because it operates below the operating system layer, physical acquisition is the only method that can fully preserve and recover data from a locked device.

Why this answer

Physical acquisition is the correct choice because it creates a bit-for-bit copy of the entire flash storage, including the operating system, user data, and deleted file remnants, without relying on the iOS operating system to be unlocked or cooperative. This method bypasses the lock screen by exploiting hardware or software vulnerabilities (e.g., checkm8 bootrom exploit) or using advanced forensic tools (e.g., Cellebrite, GrayKey) to read the raw NAND memory, ensuring maximum data extraction while maintaining forensic integrity.

Exam trap

EC-Council often tests the misconception that logical acquisition is sufficient for locked devices because it can extract backups, but the trap is that logical acquisition still requires the device to be unlocked or have a trusted relationship established, whereas physical acquisition is the only method that can bypass the lock screen to capture the entire storage image.

How to eliminate wrong answers

Option A is wrong because manual acquisition requires the device to be unlocked and interactive, which is impossible with a locked iOS device and only captures visible data on the screen, not the full storage. Option C is wrong because logical acquisition only extracts files and databases accessible through the iOS operating system’s APIs (e.g., via iTunes backup or libimobiledevice), which requires the device to be unlocked and does not capture deleted data or system partitions. Option D is wrong because file system acquisition, while more detailed than logical, still requires the device to be unlocked (e.g., via jailbreak or trusted connection) and only retrieves the file system hierarchy, not the raw blocks of the storage, missing unallocated space and hidden partitions.

568
MCQeasy

A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?

A.Cross-site scripting (XSS)
B.Path traversal
C.Remote file inclusion
D.SQL injection
AnswerD

The presence of UNION SELECT in the request parameter is a hallmark of in-band SQL injection. By injecting a quote to close the original SQL string and then using UNION, the attacker can append arbitrary columns to the result set and exfiltrate data from other tables. The server-side SQL query executes the combined statement, and the output is reflected in the HTTP response, allowing non-blind data extraction. This is why the log entry is correctly classified as SQL injection.

Why this answer

The log entry shows a UNION SELECT statement appended to the id parameter, which is a classic SQL injection attempt.

569
MCQmedium

An investigator finds a suspicious LNK file on a Windows desktop pointing to an executable in the Temp folder. What is the significance of LNK files in forensic analysis?

A.They provide evidence of file access and execution
B.They store network share credentials in plaintext
C.They contain the full content of the target file
D.They are used exclusively for system files
AnswerA

LNK files are Windows shortcut binaries that persist in user profile directories such as Recent Items when a file is opened or a program is launched. They store the target's absolute path, working directory, and shell item ID list, which can include volume serial numbers and NTFS file reference numbers. A forensic examiner can correlate the link's LastWrite time and embedded timestamps to prove the specific user accessed the target on that system. Thus, LNK files serve as strong indicators of file access and program execution.

Why this answer

LNK files (Windows shortcuts) contain metadata about the target file, including its path, creation/modification timestamps, and volume information. When a user double-clicks an LNK file, Windows follows the link to execute the target, so the presence of an LNK file pointing to an executable in the Temp folder is strong evidence that the executable was accessed or executed from that location. This is critical in forensic analysis for reconstructing user activity and identifying potential malware execution.

Exam trap

EC-Council often tests the misconception that LNK files contain the actual file content or credentials, leading candidates to choose options B or C, but the key is that LNK files are metadata-only references to the target file's location and execution history.

How to eliminate wrong answers

Option B is wrong because LNK files do not store network share credentials in plaintext; they may contain a target path to a network share, but credentials are never embedded. Option C is wrong because LNK files are shortcuts that only store a reference (path and metadata) to the target file, not the full content of the target file. Option D is wrong because LNK files are used for any file or application, not exclusively for system files; they are commonly created by users and applications for all types of files.

570
MCQmedium

A forensic analyst needs to create a forensic image of a suspect's hard drive using FTK Imager. Which of the following image formats is MOST appropriate for maintaining evidence integrity and allowing compression?

A.ISO image format (.iso)
B.EnCase image format (.E01)
C.Advanced Forensic Format (AFF)
D.Raw/DD image (.dd)
AnswerB

EnCase image format (.E01) is a forensic evidence file format that stores bit-for-bit data while supporting compression, per-block CRC32 integrity checks, and case metadata such as examiner name, date, and acquisition notes. It also incorporates MD5 or SHA-1 hash values in the file header, enabling verification that the image exactly matches the original media. Because E01 is widely recognized and accepted by courts and forensic tools, it is the standard choice for FTK Imager acquisitions.

Why this answer

FTK Imager natively supports the EnCase image format (.E01), which is the most appropriate choice because it maintains evidence integrity through embedded CRC32 and MD5/SHA-1 hash verification while also supporting optional compression. Unlike raw/DD images, .E01 files can be segmented and compressed without losing forensic integrity, making them ideal for both storage efficiency and court-admissible evidence.

Exam trap

The trap here is that candidates often choose Raw/DD (.dd) because it is the simplest and most universally accepted format, but they overlook that FTK Imager's .E01 format provides built-in compression and hash verification, which are critical for both integrity and practical storage management in forensic acquisitions.

How to eliminate wrong answers

Option A is wrong because ISO image format (.iso) is designed for optical disc images and does not support forensic metadata, hash integrity checks, or compression in a forensically sound manner; it is not a forensic image format. Option C is wrong because Advanced Forensic Format (AFF) is an open-source format that supports compression and metadata, but it is not natively supported by FTK Imager for image creation; FTK Imager primarily uses .E01 and raw/DD formats. Option D is wrong because Raw/DD image (.dd) is a bit-for-bit copy that preserves integrity but does not support built-in compression or embedded hash verification, requiring separate hash files and lacking the efficiency of .E01 for large drives.

571
MCQeasy

You are a forensic examiner at a corporate security firm. You receive a laptop from the HR department that belonged to a terminated employee. The laptop was used for company business and is suspected of containing unauthorized file-sharing software. The laptop is running Windows 10 with BitLocker drive encryption enabled. Before shutdown, the employee was logged into the system. HR claims the laptop was shut down properly and then handed over within an hour. You are asked to acquire a forensic image of the hard drive for analysis. However, when you boot the laptop, you are prompted for the BitLocker recovery key. HR does not have the key, and the employee refuses to cooperate. The laptop also has a TPM chip. Which of the following is the most appropriate course of action to acquire the data?

A.Contact IT to obtain the BitLocker recovery key from Active Directory.
B.Perform a cold boot attack to extract the BitLocker key from memory.
C.Boot from a Linux live USB and use tools to bypass BitLocker.
D.Boot the laptop normally and let BitLocker unlock the drive using the TPM.
AnswerA

This is the correct first step because corporate BitLocker recovery keys are often backed up to Active Directory. Retrieving it is the most straightforward method to access the drive.

Why this answer

The laptop was shut down properly, but the boot-time recovery key prompt indicates that the TPM did not automatically release the BitLocker key. In an enterprise environment, the most appropriate first action is to obtain the BitLocker recovery key from Active Directory, where BitLocker recovery information is commonly escrowed. Cold boot attacks and Linux live USB bypass tools are not reliable or authorized first steps, and booting normally again would not resolve the failed TPM unlock and could alter evidence.

Exam trap

EC-Council often tests the misconception that a properly shut-down system with TPM will always unlock automatically via TPM. However, the question explicitly states that booting prompts for a recovery key, indicating TPM unlock failed. The trap is to assume D is still correct, but the correct first step is to retrieve the recovery key from Active Directory.

How to eliminate wrong answers

Option A is wrong because contacting IT to obtain the BitLocker recovery key from Active Directory is a valid step only if the key was escrowed, but the question states HR does not have the key and the employee refuses to cooperate; however, the most appropriate immediate action is to boot normally first, as the TPM will unlock the drive without needing the recovery key. Option B is wrong because a cold boot attack is a specialized technique used to extract memory contents from a system that was recently running, but here the laptop was shut down properly an hour ago, so the memory contents (including any BitLocker key remnants) are long gone; this attack is impractical and not the most appropriate course. Option C is wrong because booting from a Linux live USB and using tools to bypass BitLocker is not feasible against a fully encrypted drive with TPM-bound keys; BitLocker with TPM protection cannot be bypassed by simply booting an alternate OS, as the TPM will not release the key to an untrusted boot environment.

572
MCQmedium

An expert witness is preparing to testify in a computer forensics case. Which of the following is a key requirement for the expert's testimony to be admissible under the Daubert standard?

A.The expert's methods must be generally accepted in the scientific community
B.The expert's techniques must be based on reliable principles and methods
C.The expert must have personally examined all evidence
D.The expert must have a law degree
AnswerB

Under Federal Rule of Evidence 702 and the Supreme Court’s Daubert ruling, an expert’s testimony must be grounded in reliable principles and methods, which are then applied reliably to the facts of the case. The court evaluates reliability through factors such as whether the technique has been empirically tested, subjected to peer review, has a known or potential error rate, and is governed by standards controlling its operation. This gatekeeping role ensures that the jury receives only scientifically valid and relevant expert testimony, making this statement the correct standard for admissibility.

Why this answer

Under the Daubert standard, the admissibility of expert testimony hinges on whether the expert's techniques are based on reliable principles and methods, not merely on general acceptance. This standard, established in Daubert v. Merrell Dow Pharmaceuticals, requires the trial judge to act as a gatekeeper, evaluating the scientific validity and reliability of the methodology used.

In computer forensics, this means the expert must demonstrate that their acquisition, preservation, and analysis methods (e.g., using write-blockers, cryptographic hashing like SHA-256, and chain-of-custody documentation) are scientifically sound and consistently applied.

Exam trap

The CHFI exam often tests the distinction between the Daubert and Frye standards, and the trap here is that candidates mistakenly choose 'general acceptance' (Option A) because it was the historical standard, but Daubert requires a more rigorous focus on the reliability and scientific validity of the methodology itself.

How to eliminate wrong answers

Option A is wrong because while general acceptance (the Frye standard) is a factor under Daubert, it is not the sole or key requirement; Daubert emphasizes reliability and relevance over mere acceptance. Option C is wrong because the expert witness does not need to personally examine all evidence; they can rely on reports, logs, and data provided by other qualified personnel, as long as the underlying methodology is reliable. Option D is wrong because a law degree is not a requirement for expert testimony in computer forensics; the expert's qualification comes from technical expertise, certifications (e.g., CHFI, EnCE), and practical experience, not legal credentials.

573
MCQmedium

During a forensic examination of a Windows system, an analyst finds a file that appears to be zero bytes in size when viewed in Windows Explorer, but the file's properties show a size on disk of 4 KB. What is the most likely explanation?

A.The file contains only slack space
B.The file is compressed using NTFS compression
C.The file is stored in an alternate data stream (ADS)
D.The file is a sparse file
AnswerC

NTFS supports alternate data streams (ADS), which are named data streams attached to a file in addition to the default unnamed stream. The file's logical size, as displayed in Explorer or via standard APIs, reflects only the unnamed main stream, so a file with an empty main stream but data written into a named ADS will show 0 bytes while still consuming allocated clusters on disk for the ADS content. Forensic examiners must enumerate all data streams (e.g., using `dir /R` or specialized tools) to detect hidden data.

Why this answer

An alternate data stream (ADS) allows additional data to be stored with a file in NTFS. Windows Explorer typically displays only the size of the main file stream, not the ADS. Therefore, a file with a zero-byte main stream but an ADS containing data will show a logical size of 0 bytes, while the 'size on disk' reflects the allocated clusters for the ADS data (e.g., 4 KB).

This is a common technique used to hide data.

Exam trap

Candidates often confuse the discrepancy between logical size and size on disk. They may attribute it to sparse files or compression, but the key clue is a zero-byte logical size with non-zero disk allocation, which is a classic indicator of an alternate data stream.

How to eliminate wrong answers

Option A is wrong because slack space is unused space in a cluster after the end of a file's data, not a file itself; a file cannot 'contain only slack space' as a file type. Option B is wrong because NTFS compression reduces the physical size on disk below the logical size, but the logical size in Explorer would still show the uncompressed size, not zero bytes. Option C is wrong because an alternate data stream (ADS) is a hidden data stream attached to a file; the main file's size would still be visible in Explorer, and ADS does not cause the main file to appear as zero bytes with a 4 KB size on disk.

574
Multi-Selecthard

Which three of the following are common techniques used to hide data on a storage device? (Choose THREE.)

Select 3 answers
A.File system journaling
B.Host Protected Area (HPA)
C.Alternate Data Streams (ADS) in NTFS
D.TRIM command
E.Slack space (file slack, volume slack)
AnswersB, C, E

A Host Protected Area (HPA) is a reserved region on ATA/IDE hard disk drives that is set via the SET MAX ADDRESS ATA command. The standard OS and BIOS address space excludes this area, making it invisible to normal disk access and common forensic imaging tools, yet the data physically remains on the platters. Specialized forensic software or low-level ATA commands are required to detect, access, or image an HPA, which is why it is a recognized anti-forensic hiding location.

Why this answer

Host Protected Area (HPA) (B) is a hidden region of a hard disk defined by the ATA standard outside the addressable range reported to the OS, commonly used to conceal data from normal file access. Alternate Data Streams (ADS) in NTFS (C) allow additional data to be attached to a file without appearing in directory listings or standard file size, making them a classic hiding technique. Slack space (E), including file slack and volume slack, is leftover storage between the logical end of a file and the end of its allocated cluster or partition, and can be used to stash data invisible to normal file reads.

File system journaling (A) is a reliability feature that logs metadata changes for crash recovery, not a concealment method, and the TRIM command (D) is an SSD maintenance operation that informs the drive which blocks are no longer in use, so neither hides data.

Exam trap

The CHFI exam often tests the distinction between legitimate storage management features (like journaling and TRIM) and actual data hiding techniques, leading candidates to confuse journaling or TRIM with covert storage methods.

575
MCQhard

While investigating a compromised web server, you discover a file named 'shell.php' in the web root. The file contains the following code: <?php system($_GET['cmd']); ?>. Which of the following best describes this file?

A.A SQL injection script
B.A file upload vulnerability exploit
C.A backdoor trojan
D.A web shell
AnswerD

The artifact is a web shell: a server-side script (often PHP, ASPX, or JSP) that takes command strings from HTTP request parameters and executes them through functions such as system(), exec(), or Process.Start, then returns the output in the HTTP response. This gives the attacker a persistent, remote command-line interface on the web server whenever the script is accessible. Web shells are commonly uploaded via file upload vulnerabilities, then used for further compromise, credential harvesting, or pivoting inside the network.

Why this answer

The file 'shell.php' contains code that uses the PHP system() function to execute arbitrary operating system commands passed via the 'cmd' GET parameter. This is the classic definition of a web shell, which provides remote command execution on the server. It is not a SQL injection script, a file upload exploit, or a trojan in the traditional sense, as it directly accepts and runs system commands through HTTP requests.

Exam trap

EC-Council often tests the distinction between the tool used to gain access (e.g., a file upload exploit) and the payload left behind (e.g., a web shell), causing candidates to confuse the exploit method with the resulting backdoor artifact.

How to eliminate wrong answers

Option A is wrong because a SQL injection script exploits vulnerabilities in database queries, not system command execution via HTTP parameters. Option B is wrong because a file upload vulnerability exploit is a technique used to upload malicious files, not the malicious file itself. Option C is wrong because a backdoor trojan is typically a standalone executable that provides unauthorized remote access, whereas this is a server-side script that executes commands via HTTP GET requests.

576
MCQhard

During a forensic examination, an analyst runs `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=1G` on a suspect drive. What is the PRIMARY advantage of using `hashwindow=1G` over a single hash at the end?

A.It enables the image to be mounted as a loop device.
B.It allows verification of the image in 1GB segments, so errors can be pinpointed.
C.It encrypts the image file for security.
D.It reduces the total time to create the image.
AnswerB

Using dcfldd's hashwindow parameter, the examiner can define a segment size (e.g., 1GB) and have a hash computed and stored for each segment as the image is written. During a subsequent verification pass, each segment's hash is recalculated and compared against the recorded value, so a mismatch immediately isolates the specific 1GB block that contains the error. This allows precise pinpointing of corrupted data rather than forcing a whole-image hash comparison that only indicates a failure somewhere in the large file.

Why this answer

The `hashwindow=1G` option in `dcfldd` computes a SHA-256 hash for every 1 GB segment of the input data, rather than a single hash for the entire image. This allows the analyst to verify the integrity of each segment independently, so if a hash mismatch occurs during later verification, the exact 1 GB block containing the error can be identified and reacquired without reimaging the entire drive.

Exam trap

The trap here is that candidates confuse `hashwindow` with a performance optimization or encryption feature, when in fact it is an integrity verification mechanism that trades slight performance overhead for granular error detection.

How to eliminate wrong answers

Option A is wrong because `hashwindow` does not affect the ability to mount the image as a loop device; mounting requires a filesystem-aware tool like `mount` with `-o loop`, not a hashing parameter. Option C is wrong because `hashwindow` provides integrity verification, not encryption; `dcfldd` does not encrypt output, and encryption would require separate tools like `openssl` or `LUKS`. Option D is wrong because computing multiple hashes during imaging actually increases CPU overhead and can slightly increase total imaging time compared to a single hash at the end.

577
MCQhard

During dynamic analysis of a Windows malware sample, Process Monitor shows repeated writes to 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. What does this behaviour indicate?

A.The malware is disabling Windows Defender
B.The malware is establishing persistence to run at system startup
C.The malware is modifying network configuration
D.The malware is performing log wiping
AnswerB

The Run key is a standard Windows auto-start repository: under HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run, each value specifies a command line that the Winlogon process executes when a user logs on. Malware writing a new value here with its full path is a classic persistence technique, ensuring the malicious process is re-launched after a reboot or logon. Dynamic analysis often catches this write because the sample modifies the registry at runtime to survive, not just to alter a one-time setting.

Why this answer

The registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' is a standard Windows autorun location. Malware writing to this key ensures that its executable is launched automatically every time the system boots, which is a classic persistence mechanism. Process Monitor capturing repeated writes confirms the malware is actively establishing this startup persistence.

Exam trap

EC-Council often tests the distinction between persistence mechanisms (like Run keys) and other malware behaviors (like disabling security or log wiping), so the trap here is that candidates confuse the Run key's purpose with system configuration changes or defensive countermeasures.

How to eliminate wrong answers

Option A is wrong because disabling Windows Defender typically involves modifying security center settings or stopping services (e.g., via 'sc stop WinDefend' or writing to 'HKLM\SOFTWARE\Policies\Microsoft\Windows Defender'), not writing to the Run key. Option C is wrong because modifying network configuration involves changes to TCP/IP parameters, DNS settings, or firewall rules (e.g., via netsh or registry keys under 'HKLM\SYSTEM\CurrentControlSet\Services\Tcpip'), not the Run key. Option D is wrong because log wiping involves clearing event logs (e.g., via 'wevtutil cl' or 'Clear-EventLog') or deleting log files, not writing to the Run registry key.

578
MCQmedium

A network forensics analyst captures traffic from a suspected data exfiltration. In Wireshark, filtering for DNS queries containing a long subdomain with base64-encoded text suggests which technique?

A.DNS tunneling
B.DNS hijacking
C.DNS poisoning
D.DNS amplification
AnswerA

DNS tunneling is a covert channel in which an attacker embeds data payloads into DNS query labels and response records (commonly TXT) and exchanges that data with a domain the attacker controls. Unlike a simple resolution failure, these queries form a bidirectional communication stream that bypasses typical egress filters because UDP port 53 is almost always allowed to leave the network. In the captured traffic, this pattern appears as a high volume of unique subdomains or unusually large TXT responses, making it the correct diagnosis over the other choices.

Why this answer

DNS tunneling encodes data (often base64) into DNS query subdomains to bypass network controls and exfiltrate information. Wireshark filtering for unusually long DNS queries with encoded text directly reveals this technique, as legitimate DNS queries rarely contain such payloads.

Exam trap

EC-Council often tests the distinction between data exfiltration techniques (tunneling) and network abuse attacks (amplification, poisoning, hijacking), so candidates mistakenly pick DNS amplification because it also involves unusual DNS traffic patterns.

How to eliminate wrong answers

Option B is wrong because DNS hijacking redirects DNS resolution to malicious servers, not exfiltrate data via query content. Option C is wrong because DNS poisoning corrupts resolver caches with false records, not encode data in queries. Option D is wrong because DNS amplification is a DDoS attack that uses small queries to generate large responses, not a data exfiltration method.

579
MCQeasy

In static malware analysis, what is the purpose of using a tool like PEiD?

A.To monitor registry changes during execution
B.To detect packers or compilers used in the PE file
C.To disassemble the binary into assembly code
D.To analyze network traffic generated by the malware
AnswerB

The tool in question is a static file inspector that examines a PE binary's section names, raw header fields, and byte patterns without executing it. By matching those signatures against known cryptors, packers, and compilers, it identifies protections such as UPX or ASPack, giving the analyst an immediate hint about obfuscation before deeper reverse engineering. That detection directly guides whether unpacking is necessary before disassembly.

Why this answer

PEiD is a static analysis tool that identifies packers, cryptors, and compilers embedded in Portable Executable (PE) files by scanning for known signatures in the file's entry point and section headers. This helps an analyst understand whether the malware is packed (obfuscated) and what tool was used to create or compress it, which is critical before attempting dynamic analysis or unpacking.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse PEiD with a disassembler or a runtime monitor, because they see 'analysis' and assume it covers all phases of malware examination.

How to eliminate wrong answers

Option A is wrong because monitoring registry changes during execution is a dynamic analysis technique, not static; tools like Regshot or Process Monitor are used for that purpose. Option C is wrong because disassembling a binary into assembly code is the function of a disassembler such as IDA Pro or Ghidra, not PEiD, which only identifies packers/compilers. Option D is wrong because analyzing network traffic generated by malware is a dynamic analysis task performed with tools like Wireshark or tcpdump, not a static analysis tool like PEiD.

580
MCQeasy

Which of the following is a primary challenge in cloud forensics due to the shared responsibility model?

A.Inability to perform live acquisition of volatile data without cooperation from the cloud provider
B.Data is always stored in a single jurisdiction
C.Lack of encryption support
D.Cloud logs are immutable and cannot be altered
AnswerA

In IaaS and PaaS cloud models, forensic investigators lack direct physical or administrative access to the hypervisor, host OS, or physical memory. Capturing volatile data such as RAM, kernel structures, and active network connections must therefore occur through the cloud provider's APIs, which often require explicit cooperation, credential delegation, or legal process. When the VM is stopped or terminated, that volatile evidence is irrevocably lost, making the inability to perform live acquisition without provider assistance a primary challenge and a critical violation of the order of volatility.

Why this answer

The shared responsibility model means the cloud provider controls the infrastructure, limiting the investigator's ability to acquire volatile data without provider support.

581
MCQhard

An investigator seizes a computer that was involved in a crime. The suspect claims that the evidence was planted. Which forensic principle best helps to refute this claim by demonstrating that the evidence could only have been left by the suspect?

A.Locard's exchange principle
B.Hearsay rule
C.Best evidence rule
D.Chain of custody
AnswerA

Locard's exchange principle states that every contact leaves a trace, so evidence transferred onto the seized computer demonstrates physical contact between suspect and system. This refutes the planting claim by linking the traceable exchange directly to the suspect's actions.

Why this answer

Locard's exchange principle states that every contact leaves a trace. In digital forensics, this means the suspect's interaction with the computer—such as typing, accessing files, or connecting peripherals—will leave unique digital artifacts (e.g., registry keys, prefetch files, USB device serial numbers, or browser history). By demonstrating that these artifacts could only have been created by the suspect's specific actions or device, the investigator refutes the claim of planting.

Exam trap

EC-Council often tests whether candidates confuse chain of custody (a procedural safeguard) with Locard's principle (a scientific concept about trace evidence), leading them to pick chain of custody when the question asks about how evidence was left by the suspect.

How to eliminate wrong answers

Option B (Hearsay rule) is wrong because it is a legal rule governing the admissibility of out-of-court statements as evidence, not a forensic principle about physical or digital trace transfer. Option C (Best evidence rule) is wrong because it requires the original document or recording as evidence, not a principle explaining how evidence is left by a suspect. Option D (Chain of custody) is wrong because it documents the handling and integrity of evidence from seizure to court, but does not itself demonstrate that the evidence was left by the suspect.

582
MCQhard

In a UK-based investigation, law enforcement officers seize a computer without a warrant. The suspect argues the seizure violated his rights under the Police and Criminal Evidence Act 1984 (PACE). Which of the following is a key consideration under PACE regarding the admissibility of the seized evidence?

A.The evidence is automatically admissible because it was seized during an investigation.
B.The evidence is admissible because it is circumstantial.
C.The evidence is admissible only if the suspect signed a consent form.
D.The court may exclude the evidence if its admission would be unfair to the suspect.
AnswerD

PACE section 78 gives the court discretion to exclude prosecution evidence where its admission would have such an adverse effect on the fairness of proceedings that it ought not to be admitted, so unlawfully seized material may still be excluded on that fairness ground.

Why this answer

Under Section 78 of PACE, the court has discretion to exclude prosecution evidence if its admission would have such an adverse effect on the fairness of the proceedings that it ought not to be admitted. Since the computer was seized without a warrant, the court must weigh the potential breach of PACE safeguards against the probative value of the digital evidence. This is not automatic exclusion, but a judicial balancing test specific to the circumstances of the seizure.

Exam trap

EC-Council often tests the misconception that any procedural violation automatically excludes evidence, whereas PACE Section 78 gives the court discretion to admit evidence if the breach does not render the trial unfair.

How to eliminate wrong answers

Option A is wrong because PACE does not provide automatic admissibility for evidence seized without a warrant; the court retains discretion under Section 78 to exclude evidence obtained in breach of PACE codes. Option B is wrong because the classification of evidence as circumstantial or direct has no bearing on admissibility under PACE; the key factor is the fairness of the proceedings, not the type of evidence. Option C is wrong because PACE does not require a suspect's signed consent for admissibility; consent relates to lawful search and seizure under PACE Code B, but even without consent, evidence may still be admissible if the court deems it fair to admit.

583
Multi-Selecthard

During a forensic analysis of a compromised web server, an investigator identifies the following log entries. Which THREE entries are the strongest indicators of a successful web shell upload? (Choose three.)

Select 3 answers
A.POST /upload.php HTTP/1.1 200 0
B.POST /uploads/shell.aspx HTTP/1.1 200 - -
C.GET /uploads/shell.aspx?cmd=dir HTTP/1.1 200 - -
D.GET /../../windows/system32/cmd.exe HTTP/1.1 404 - -
E.GET /images/logo.png HTTP/1.1 304 - -
AnswersA, B, C

A POST request to /upload.php that returns HTTP 200 with a zero-byte response body indicates the server accepted a client upload even though the reply was empty. In Apache access logs, the trailing '0' is the response size in bytes, so this record is consistent with a PHP upload handler completing successfully and not returning content. Combined with the known purpose of upload.php, this is a strong forensic foothold for a web shell planted through the application's file-upload feature.

Why this answer

Successful uploads of aspx or php files that contain web shell code (e.g., with cmd parameter) and subsequent access to those files are strong indicators. The 404 for cmd.exe indicates a path traversal attempt, not a web shell.

584
Multi-Selecthard

During the initial response to a suspected data exfiltration, which THREE pieces of volatile data should be collected first? (Choose three.)

Select 3 answers
A.Current network connections.
B.List of running processes.
C.Contents of system memory (RAM).
D.Windows registry hives.
E.Forensic image of the hard drive.
AnswersA, B, C

Network connections are transient and may disappear.

Why this answer

Current network connections (A) are volatile because they show active communication channels that could indicate data exfiltration in progress. If the system is shut down or disconnected, this evidence is lost immediately, making it a top priority for collection during initial response.

Exam trap

EC-Council often tests the Order of Volatility principle, and the trap here is that candidates mistakenly prioritize persistent data like registry hives or disk images over transient evidence that disappears immediately upon shutdown.

585
MCQhard

A security analyst discovers unauthorized access to a server. The incident response team decides to preserve evidence. Which of the following actions is MOST critical to ensure the admissibility of evidence in court?

A.Disconnecting the server from the network
B.Documenting the chain of custody
C.Running a full antivirus scan on the server
D.Taking screenshots of the server's screen
AnswerB

Documenting the chain of custody is the foundational act that makes digital evidence legally admissible because it establishes an unbroken record of who handled the evidence, when, how, and where it was stored. This record demonstrates that the evidence cannot have been substituted, tampered with, or contaminated between the moment of discovery and its presentation in court. Without it, the evidence is subject to exclusion on the grounds that its authenticity cannot be verified, regardless of how technically sound the other forensic steps were.

Why this answer

Chain of custody documentation is the most critical action for evidence admissibility because it establishes a verifiable record of who handled the evidence, when, and under what conditions, ensuring the evidence has not been tampered with. Without a proper chain of custody, even technically sound evidence can be ruled inadmissible under rules like Federal Rule of Evidence 901. In forensic practice, this involves logging every access with timestamps, digital signatures, and hash values (e.g., SHA-256) to maintain integrity.

Exam trap

EC-Council often tests the misconception that immediate network disconnection is the top priority, but the CHFI exam emphasizes that preserving the integrity and admissibility of evidence through chain of custody outweighs technical containment actions.

How to eliminate wrong answers

Option A is wrong because disconnecting the server from the network may cause loss of volatile data (e.g., active network connections, memory contents) and can trigger anti-forensic mechanisms; the proper forensic step is to capture a memory dump and network state before isolation. Option C is wrong because running a full antivirus scan modifies file access times, potentially overwrites deleted files, and alters the system state, which violates forensic integrity principles (e.g., not altering original evidence). Option D is wrong because screenshots are easily manipulated and lack metadata integrity; they do not provide a verifiable, hash-authenticated record like a forensic image or chain-of-custody log.

586
Multi-Selecthard

Which THREE of the following are challenges specific to container forensics? (Select THREE.)

Select 3 answers
A.Containers share the same kernel as the host, limiting isolation for forensic acquisition
B.Network isolation prevents packet capture
C.Ephemeral nature of containers leads to volatile evidence
D.Standard forensic imaging tools can be directly applied
E.Need to analyze layered image filesystem instead of a single disk image
AnswersA, C, E

Because containers execute as isolated processes on the host kernel rather than as separate operating systems, forensic acquisition of a container is effectively a host-level live response. Capturing process memory requires interacting with the host's /proc, which can alter state for the container, and kernel memory artifacts are shared across all containers, undermining a clean acquisition boundary. This limited isolation also means your imaging commands may be visible to or affect the target container, necessitating careful coordination.

Why this answer

Containers are ephemeral (volatile evidence), they share the host kernel (limited isolation), and they rely on layered images that must be analyzed. Standard disk imaging tools may not work; network isolation is not a specific challenge.

587
MCQmedium

A network analyst captures traffic and sees an HTTP request containing: GET /wp-content/uploads/evil.php?cmd=id HTTP/1.1. Which of the following is MOST likely occurring?

A.Webshell access
B.SQL injection attack
C.Cross-site scripting (XSS) attack
D.Directory traversal attack
AnswerA

The request to a PHP file carrying a 'cmd' parameter is the hallmark of a webshell: the script accepts the parameter and passes it to a server-side command execution function such as system(), exec(), or passthru(). This gives the attacker a remote command prompt on the web server, so the observed traffic is direct evidence of webshell access rather than any of the other attack classes.

Why this answer

The HTTP request `GET /wp-content/uploads/evil.php?cmd=id HTTP/1.1` indicates that the attacker is accessing a PHP file (`evil.php`) in the WordPress uploads directory and passing a command (`cmd=id`) to it. This is a classic indicator of a webshell — a malicious script uploaded to the server that allows remote command execution. The `id` command is a common Unix command used to verify the current user context, confirming the attacker has achieved interactive shell-like access.

Exam trap

The CHFI exam often tests the distinction between webshell (command execution) and code injection (SQLi/XSS). The trap here is that candidates see a parameter (`cmd=id`) and mistakenly think it is SQL injection, but the absence of SQL syntax and the presence of a system command (`id`) clearly point to a webshell.

How to eliminate wrong answers

Option B (SQL injection attack) is wrong because the request does not include SQL syntax (e.g., `' OR 1=1--`) or target a database query parameter; it directly executes a system command via `cmd=id`. Option C (Cross-site scripting (XSS) attack) is wrong because XSS involves injecting client-side scripts (e.g., JavaScript) into web pages viewed by other users, not executing server-side commands. Option D (Directory traversal attack) is wrong because the path `/wp-content/uploads/evil.php` does not contain traversal sequences like `../` to escape the web root; instead, it accesses a file within the expected uploads directory.

588
MCQmedium

An investigator is analyzing a Windows 10 system suspected of malware persistence. Which registry key is commonly used by malware to achieve persistence by running a program at every user logon?

A.HKLM\SAM\SAM
B.HKLM\SYSTEM\CurrentControlSet\Services
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall
AnswerC

This is the canonical per-user Autorun key: when the user logs in, Winlogon/Explorer enumerates values under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and launches each command line, making it the exact location an investigator should inspect for a user-specific startup program. The HKCU hive is loaded from the user's NTUSER.DAT, so findings here are tied to a single profile. Because the question asks about a Windows 10 user logon startup, this key is the correct answer.

Why this answer

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard autostart location that Windows checks at every user logon. Malware commonly writes a value here pointing to its executable path, ensuring it runs automatically each time the user logs into their account. This is a well-documented persistence mechanism in Windows forensics.

Exam trap

The trap here is that candidates confuse the Run key with the Services key (Option B), thinking that any service can achieve per-user logon persistence, but services run under the SYSTEM account and are not triggered by user logon unless specifically configured with a trigger-start service or by setting the service to 'Automatic' and relying on delayed start, which is not the standard per-user logon mechanism.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM stores the Security Account Manager database containing user password hashes and local account information, not autostart locations; it is unrelated to program persistence at logon. Option B is wrong because HKLM\SYSTEM\CurrentControlSet\Services is used to register Windows services that start automatically with the system (e.g., at boot), not specifically at every user logon; while services can be configured for delayed start or automatic start, the Run key is the direct per-user logon mechanism. Option D is wrong because HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall stores uninstallation metadata for installed applications, not autostart entries; malware would not use this key to achieve persistence.

589
MCQeasy

What is the primary difference between MBR and GPT partition tables?

A.MBR is used only on Linux; GPT is used on Windows
B.GPT uses a cyclic redundancy check (CRC) for integrity; MBR does not
C.MBR supports larger disks than GPT
D.GPT stores the partition table only in the first sector
AnswerB

The key integrity advantage of GPT is its use of CRC32 checksums over the protective MBR, the primary GPT header, and each partition entry. These checksums allow firmware and operating systems to detect corruption or accidental overwriting of the partition table, enabling error reporting or automatic recovery from the backup table. MBR, by contrast, has no built-in integrity check, so a damaged partition table can render the disk unreadable with no indication that corruption occurred.

Why this answer

GPT (GUID Partition Table) uses a cyclic redundancy check (CRC32) to verify the integrity of the partition table header and entries, detecting corruption or tampering. MBR (Master Boot Record) lacks any such integrity check, making it vulnerable to undetected corruption. This CRC mechanism is a fundamental design improvement in GPT over MBR.

Exam trap

EC-CHFI often tests the misconception that MBR is older and therefore inferior in all aspects, but the specific trap here is that candidates confuse 'supports larger disks' (MBR does not) with 'integrity checking' (GPT has it, MBR lacks it), leading them to pick Option C or D instead of the correct CRC-based distinction.

How to eliminate wrong answers

Option A is wrong because MBR is used on both Windows and Linux (and other OSes) for legacy compatibility, while GPT is used on both as well for modern systems; neither is exclusive to a single OS. Option C is wrong because MBR supports a maximum disk size of 2 TiB (due to 32-bit logical block addressing), whereas GPT supports disks larger than 2 TiB (up to 9.4 ZB with 64-bit LBA). Option D is wrong because GPT stores a primary partition table in the first sector (LBA 0) and a backup partition table at the end of the disk, providing redundancy; MBR stores its partition table only in the first sector.

590
Multi-Selecthard

According to the US Fourth Amendment, which of the following THREE conditions generally allow law enforcement to search and seize digital evidence without a warrant? (Select THREE)

Select 3 answers
A.Consent given voluntarily by the owner of the device
B.The suspect is a minor
C.Exigent circumstances where evidence is likely to be destroyed
D.The data is encrypted and the key is not provided
E.The evidence is in plain view during a lawful search
AnswersA, C, E

Voluntary consent is a recognized exception to the Fourth Amendment's warrant requirement, provided it is given freely and intelligently and not the product of coercion. Under Schneckloth v. Bustamonte (412 U.S. 218), the government must prove by a preponderance of the evidence that consent was voluntary, considering factors such as age, intelligence, and the circumstances of the encounter. Additionally, the owner may limit the scope of consent, and law enforcement must stay within that scope during any search of the device.

Why this answer

Option A is correct because voluntary consent from a person with authority over the device (owner or someone with common authority) is a well-established exception to the Fourth Amendment warrant requirement, provided the consent is freely and voluntarily given. Option C is correct because exigent circumstances, such as the imminent destruction of digital evidence (e.g., a suspect wiping a drive or remote-wiping a phone), permit warrantless seizure or search when obtaining a warrant would be impracticable and the officers did not create the exigency. Option E is correct because the plain view doctrine allows warrantless seizure of evidence when an officer is lawfully present, the incriminating character of the item is immediately apparent, and the officer has a lawful right of access to the item.

Option B is incorrect because being a minor does not by itself create a warrant exception; juveniles retain Fourth Amendment protections and typically require a warrant, parental consent, or another recognized exception. Option D is incorrect because encryption and refusal to provide a key do not authorize a warrantless search; instead, they may trigger compelled decryption litigation or other legal process, and the Fifth Amendment may even protect against self-incrimination.

Exam trap

EC-Council often tests the misconception that encryption or a minor's status automatically creates a warrant exception, when in fact neither condition alone satisfies the Fourth Amendment's requirements for a warrantless search.

591
MCQmedium

An attacker has compromised a Linux server and edited the /etc/passwd file to change a user's UID to 0. What is the likely goal of this modification?

A.To lock the user account
B.To escalate privileges to root
C.To enable password-less login
D.To hide the user account from the system
AnswerB

The attacker changes the UID field to 0 because Linux kernels treat UID 0 as the root superuser and give it unrestricted access to all files, processes, and system calls. When the compromised user logs in, the session adopts that UID and inherits full root capabilities without needing su or sudo. This is a classic privilege‑escalation persistence: the account effectively becomes an alternate root entry.

Why this answer

In Linux, the UID 0 is reserved for the root user, who has unrestricted access to the system. By changing a user's UID to 0, the attacker grants that user the same privileges as root, effectively escalating their access to the highest level. This is a classic privilege escalation technique because the kernel identifies root by UID, not by the username.

Exam trap

A common misconception tested on the EC-CHFI exam is that changing the UID to 0 only affects the user's group or that it is equivalent to adding the user to the root group, when in fact UID 0 grants full root privileges regardless of group membership.

How to eliminate wrong answers

Option A is wrong because locking a user account is done by placing an exclamation mark or asterisk in the password hash field of /etc/shadow, not by changing the UID in /etc/passwd. Option C is wrong because password-less login is typically configured by setting an empty password hash in /etc/shadow or using SSH keys, not by modifying the UID. Option D is wrong because hiding a user account from the system is not achieved by changing the UID; accounts are hidden by using a UID below 1000 (or the defined system UID range) or by manipulating /etc/login.defs, but UID 0 is the most visible and privileged identifier.

592
MCQhard

A forensic examiner is analyzing a compromised Linux server and notices that /etc/cron.daily contains a script named 'sysupdate.sh' that runs a base64-encoded command. Which persistence mechanism is being used?

A.LD_PRELOAD library injection
B.Cron job for daily execution
C.Systemd service
D.SSH authorized_keys backdoor
AnswerB

A script located in /etc/cron.daily is a clear indicator of a cron-based persistence mechanism, since this directory is executed daily by cron (or anacron) on most Linux distributions. The contents of the script are run with the privileges of the user who owns it, often root, making it a powerful backdoor for maintaining access. Forensic examiners should inspect the script for malicious commands, check its permissions, and correlate the file creation timestamp with the initial compromise window.

Why this answer

The presence of a script named 'sysupdate.sh' inside /etc/cron.daily indicates that the system's cron daemon is configured to execute this script once per day. Cron jobs are a standard Linux persistence mechanism, and placing a script in /etc/cron.daily ensures it runs automatically on a daily schedule, making option B correct.

Exam trap

The trap here is that candidates may confuse cron directories with other persistence mechanisms like systemd timers or SSH backdoors, but the specific path /etc/cron.daily directly points to a cron-based daily job.

How to eliminate wrong answers

Option A is wrong because LD_PRELOAD library injection is a runtime technique that forces a process to load a shared library before others, not a scheduled execution mechanism like a cron job. Option C is wrong because a Systemd service requires a .service unit file in /etc/systemd/system or similar, not a script in /etc/cron.daily. Option D is wrong because an SSH authorized_keys backdoor involves adding an attacker's public key to ~/.ssh/authorized_keys for remote access, not a scheduled script execution.

593
MCQeasy

Which of the following is a key difference between static and dynamic malware analysis?

A.Static analysis executes the malware, dynamic does not
B.Static analysis requires an internet connection, dynamic does not
C.Static analysis examines code without execution, dynamic analysis executes the sample
D.Static analysis is always automated, dynamic is manual
AnswerC

This is the fundamental distinction between the two analysis categories. Static analysis inspects the binary's code and structure without ever executing it, using techniques like disassembly, decompilation, and string extraction to infer behavior. Dynamic analysis executes the sample in a monitored environment, capturing its actual runtime actions such as API calls, process injection, and file operations, which often reveals behaviors that static analysis alone cannot see.

Why this answer

Static malware analysis involves examining the malware's code (e.g., disassembly, strings, headers) without executing it, while dynamic analysis runs the sample in a controlled environment (e.g., sandbox, debugger) to observe its runtime behavior. Option C correctly captures this fundamental distinction: static analysis is code-centric and non-executional, whereas dynamic analysis is behavior-centric and executional.

Exam trap

The trap here is that candidates often confuse the terms 'static' and 'dynamic' by associating 'static' with 'not moving' (incorrectly thinking it means no analysis) or misremembering which one involves execution, leading them to pick Option A.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: static analysis does NOT execute the malware, while dynamic analysis does. Option B is wrong because neither analysis inherently requires an internet connection; dynamic analysis often uses simulated network services (e.g., INetSim) to avoid real internet traffic, and static analysis can be performed offline. Option D is wrong because both static and dynamic analysis can be automated (e.g., YARA rules for static, Cuckoo Sandbox for dynamic) or performed manually, so automation is not a distinguishing factor.

594
MCQeasy

Which of the following is an example of an anti-forensics technique used to hide malicious activity?

A.Timestomping
B.Running a sandbox
C.Creating a mutex
D.Generating a hash
AnswerA

Timestomping is a deliberate anti-forensic technique that alters file system timestamps — specifically the MAC times (modification, access, and change) — using tools like SetMACE or timestomp. By adjusting these metadata values to a false past or future date, an attacker destroys the temporal correlation that investigators rely on to reconstruct a sequence of events. This directly obfuscates the digital trail and impedes timeline analysis, making it a textbook example of anti-forensics.

Why this answer

Timestomping is an anti-forensics technique that deliberately modifies file timestamps (e.g., MAC times: Modified, Accessed, Created) using tools like `touch` on Linux or `SetFileTime` on Windows. By altering these timestamps, an attacker can hide the true timeline of malicious file creation, modification, or access, thereby evading forensic timeline analysis and making it appear that malicious activity occurred at a different time or was part of legitimate system operations.

Exam trap

The CHFI exam often tests the misconception that any technique used by malware (like creating a mutex) is automatically an anti-forensics technique, when in fact anti-forensics specifically targets the forensic process itself (e.g., data hiding, evidence destruction, or timeline manipulation).

How to eliminate wrong answers

Option B is wrong because running a sandbox is a security analysis technique used to execute suspicious code in an isolated environment to observe its behavior, not an anti-forensics technique to hide malicious activity. Option C is wrong because creating a mutex (mutual exclusion object) is a common programming construct used by both legitimate software and malware for synchronization or to prevent multiple instances, but it is not inherently an anti-forensics technique; while some malware uses mutexes as infection markers, this does not hide activity from forensic tools. Option D is wrong because generating a hash (e.g., MD5, SHA-1) is a standard integrity verification method used in forensics to ensure evidence has not been altered, not a technique to conceal malicious activity.

595
MCQmedium

A forensic analyst receives a mobile device that has been factory reset. Which of the following types of data is MOST likely to be recoverable using advanced forensic techniques?

A.Deleted text messages and call logs, but not app data
B.All user data, as factory reset only deletes file pointers
C.Google account tokens and cached credentials
D.No data is recoverable after a factory reset on modern devices
AnswerC

Google account tokens and cached credentials can remain recoverable because they are not always stored solely in the encrypted userdata partition. Some authentication tokens are cached in reserved flash areas, NVRAM, or the TrustZone secure world, which the factory reset routine may not fully overwrite. Advanced physical forensics, such as chip-off imaging and JTAG extraction, can recover these residual token blobs, and if combined with a known or brute-forced key, they may allow account access even though normal app and media data is destroyed.

Why this answer

A factory reset typically does not overwrite the flash memory where Google account tokens and cached credentials are stored. Advanced forensic techniques, such as chip-off or JTAG, can recover these remnants from the NAND flash memory, as the reset only marks the storage blocks as available for reuse without physically erasing the data.

Exam trap

EC-Council often tests the misconception that a factory reset is equivalent to a secure wipe, but in reality, it only deletes file pointers and leaves residual data in unallocated flash memory, which advanced forensic techniques can recover.

How to eliminate wrong answers

Option A is wrong because deleted text messages and call logs are also stored in unallocated flash memory and can be recovered alongside app data using advanced techniques, not exclusively excluded. Option B is wrong because a factory reset does not preserve all user data; it clears user data partitions and file pointers, but some residual data may remain in unallocated space, not the entire dataset. Option D is wrong because modern devices still leave recoverable data in unallocated NAND flash blocks after a factory reset, especially tokens and credentials, due to the lack of secure erase commands like eMMC sanitize being executed.

596
MCQeasy

Which Windows Event ID is generated when a new service is installed on the system?

A.4648
B.4720
C.7045
D.4624
AnswerC

Event ID 7045 is the correct answer. It is a System log event emitted by the Service Control Manager whenever a new service is installed on the machine. The event details include the service name, executable path, service type (e.g., kernel driver or own process), start type, and the service account. This event is generated at the time of installation, making it the definitive indicator of a new service being added.

Why this answer

Windows Event ID 7045 is specifically logged in the System event log when a new service is installed on the system. This event records the service name, image path, service type, and start mode, making it a critical artifact for forensic investigators tracking unauthorized service installations or persistence mechanisms.

Exam trap

The trap here is that candidates often confuse Event ID 7045 with Security log events like 4720 (user creation) or 4624 (logon), because they assume service installation is logged in the Security log, but it is actually recorded in the System log under a different event source.

How to eliminate wrong answers

Option A is wrong because Event ID 4648 is used to log explicit credential usage (e.g., when a user runs a task with alternate credentials via RunAs), not service installation. Option B is wrong because Event ID 4720 is a Security event that logs the creation of a new user account in Active Directory, not a service installation. Option D is wrong because Event ID 4624 is a Security event that logs successful user logon events, not service installation.

597
MCQeasy

Which of the following best describes the purpose of the Master File Table (MFT) in the NTFS filesystem?

A.It manages the file allocation table for cluster chains
B.It stores the partition table and boot sector
C.It contains metadata and file attribute records for all files and directories
D.It maintains a journal of all filesystem changes
AnswerC

The MFT is the heart of NTFS: each file and directory is represented by at least one MFT record (typically 1024 bytes) that stores a set of attributes, including $STANDARD_INFORMATION (timestamps, flags), $FILE_NAME, security descriptors, and $DATA. For small files, the data may reside resident within the MFT record; larger files are referenced via data runs or extents. Because the MFT is a relational table indexed by file reference numbers, it provides the master catalog of every object on the volume.

Why this answer

The Master File Table (MFT) is the core of the NTFS filesystem, storing a record for every file and directory on the volume. Each MFT record contains metadata such as timestamps, security descriptors, and file attributes, including the data itself for small files (resident data). This makes C correct because the MFT is fundamentally a database of file and directory metadata.

Exam trap

The trap here is that candidates confuse the MFT with the NTFS Log File ($LogFile) or the FAT filesystem's File Allocation Table, leading them to select options A or D instead of recognizing the MFT's role as the central metadata repository.

How to eliminate wrong answers

Option A is wrong because the File Allocation Table (FAT) is a legacy filesystem structure used by FAT16/FAT32, not NTFS; NTFS uses the MFT and cluster bitmaps instead of a file allocation table for cluster chains. Option B is wrong because the partition table is stored in the Master Boot Record (MBR) or GPT header, and the boot sector is a separate structure at the beginning of the volume; the MFT does not store these. Option D is wrong because the journal of filesystem changes is maintained by the NTFS Log File ($LogFile), not the MFT; the MFT stores metadata records, not a transaction log.

598
MCQmedium

An investigator uses the `volatility -f mem.dump netscan` command on a memory dump from a Windows 10 system. What information is this command primarily intended to reveal?

A.Network connections and listening ports
B.List of running processes
C.File handles opened by each process
D.Registry hives loaded in memory
AnswerA

The Volatility `netscan` plugin enumerates active network artifacts by scanning memory pools for `_TCP_ENDPOINT`, `_TCP_LISTENER`, and `_UDP_ENDPOINT` structures. It outputs established connections, listening ports, remote and local IP addresses, and connection states, functioning like `netstat` but reading directly from a physical memory dump. This is why it correctly identifies network connections and listening ports.

Why this answer

The `volatility -f mem.dump netscan` command is specifically designed to extract network connection artifacts from a memory dump, including active TCP/UDP connections, listening ports, and associated process identifiers (PIDs). It parses Windows network data structures such as `_TCPT_OBJECT` and `_UDP_HEADER` to reconstruct the network state at the time of acquisition, making it the correct tool for revealing network connections and listening ports.

Exam trap

The CHFI exam often tests the distinction between `netscan` and `connscan` (which only shows connections, not listeners), and candidates mistakenly choose a process-listing option because they confuse the 'net' prefix with network enumeration of processes.

How to eliminate wrong answers

Option B is wrong because listing running processes is the function of the `pslist` or `psscan` plugin, not `netscan`. Option C is wrong because enumerating file handles opened by each process is performed by the `handles` plugin, which scans the `_OBJECT_HANDLE_TABLE` structure. Option D is wrong because extracting registry hives loaded in memory is the purpose of the `hivelist` or `printkey` plugins, which parse the `_CMHIVE` structures.

599
MCQhard

During a forensic investigation, you encounter a RAID 5 array consisting of three 1 TB disks. The array is failed, and you need to reconstruct the original data. Which of the following approaches is MOST appropriate for data recovery?

A.Mount each disk individually and copy files
B.Run `mdadm --assemble --scan` on the images
C.Use `dd` to image each disk and then XOR the three images together
D.Use EnCase to perform a RAID rebuild with known parameters
AnswerD

EnCase (and similar forensic tools like X-Ways or FTK Imager) can reconstruct a logical RAID 5 volume from disk images by letting you specify the disk order, stripe size, and parity rotation scheme. Once the parameters are set, the tool virtually reassembles the array in memory or as a new image, making the filesystem visible for standard forensic analysis. This is the correct approach when the original RAID metadata is unavailable or partially damaged, as the tool can also parse controller metadata or accept manual input to recover the array.

Why this answer

EnCase Forensic has a built-in RAID reconstruction feature that can automatically rebuild a RAID 5 array from disk images when the RAID parameters (stripe size, parity rotation, disk order) are known or can be detected. This is the most appropriate approach for a failed RAID 5 array, as it handles the parity-based striping and reassembles the logical volume without requiring manual XOR operations or risking data corruption.

Exam trap

The CHFI exam often tests the misconception that a simple XOR of all disk images (Option C) is sufficient for RAID 5 recovery, but this fails because the parity is distributed and not a simple XOR of the entire disk; the correct approach requires knowing the RAID geometry and using a tool that handles stripe-level reconstruction.

How to eliminate wrong answers

Option A is wrong because mounting each disk individually in a RAID 5 array will only show partial, fragmented data (stripes and parity), not the complete logical volume; files are striped across all disks, so individual mounts yield unusable data. Option B is wrong because `mdadm --assemble --scan` is a Linux software RAID command that works only if the array metadata is intact and the disks are still part of a functional RAID set; in a failed array with corrupted metadata, this command cannot reconstruct the data. Option C is wrong because XORing three raw disk images together without knowing the exact stripe size, parity layout, and disk order will produce garbage; RAID 5 uses distributed parity, so a simple XOR of all three images does not account for stripe boundaries or parity rotation.

600
MCQeasy

A forensic examiner needs to acquire the RAM from a Windows 10 system without altering the contents. Which tool is MOST appropriate for this task?

A.WinPmem
B.FTK Imager
C.LiME
D.dd
AnswerA

WinPmem is a dedicated memory acquisition driver and command-line tool from the Rekall/pmem project, built to capture physical memory from 32- and 64-bit Windows systems. It loads a kernel-mode driver that maps the physical address space, allowing the tool to read RAM into a raw or AFF4 image without intentionally triggering a crash or modifying the target's contents beyond the unavoidable side effects of running software. This driver-based access is exactly what makes it forensically sound and appropriate for Windows 10 live memory acquisition.

Why this answer

WinPmem is the most appropriate tool for acquiring RAM from a Windows 10 system because it is specifically designed for memory acquisition on Windows platforms, using the WinPmem driver to access physical memory without modifying the contents. It supports both 32-bit and 64-bit systems and can output raw memory images or other formats, ensuring forensic soundness by minimizing interaction with the target system.

Exam trap

The trap here is that candidates may confuse FTK Imager's ability to capture a memory dump via a crash dump option with proper live RAM acquisition, but FTK Imager does not provide a forensically sound method for full physical memory capture on a live Windows system.

How to eliminate wrong answers

Option B (FTK Imager) is wrong because FTK Imager is primarily a disk imaging and forensic acquisition tool for storage media, not designed for live memory acquisition; it can capture a crash dump or pagefile but not a full RAM image without altering system state. Option C (LiME) is wrong because LiME (Linux Memory Extractor) is a tool for acquiring RAM from Linux systems, not Windows 10, as it relies on Linux kernel modules. Option D (dd) is wrong because dd is a low-level disk cloning tool that operates on block devices and is not suitable for acquiring RAM on Windows; it lacks the necessary driver support to access physical memory safely and can cause system instability or data corruption.

Page 7

Page 8 of 10

Page 9

All pages