Courseiva

Computer Hacking Forensic Investigator CHFI (CHFI) — Questions 601–675

745 questions total · 10pages · All types, answers revealed

Page 8

Page 9 of 10

Page 10
601
Multi-Selecteasy

During a Windows forensic investigation, an analyst finds prefetch files with the .pf extension. Which TWO pieces of information can the analyst obtain from analyzing prefetch files?

Select 2 answers
A.The number of times the application has been executed
B.The exact date and time of each execution
C.The username that executed the application
D.The command-line arguments used to launch the program
E.The IP addresses the application connected to
AnswersA, B

Prefetch files record an execution count in their header, incremented each time the associated application runs. This directly satisfies the stem's requirement for execution frequency, letting the analyst establish how often a suspect binary or tool was launched on the Windows system under investigation.

Why this answer

Prefetch files (.pf) in Windows record execution metadata for applications, and option A is correct because each prefetch file stores an execution count showing how many times the application has been run. Option B is also correct because prefetch files contain timestamps, including the last execution time and, in many versions, up to eight previous execution times, allowing an analyst to determine when the application was executed. These timestamps are stored in the prefetch file's metadata and are a core reason prefetch analysis is valuable in forensics.

Option C is not correct because prefetch files do not record the username that executed the application; that information is typically found in other artifacts such as Security event logs or UserAssist. Option D is not correct because command-line arguments are not stored in prefetch files; they are more commonly recovered from process execution artifacts like ShimCache, AmCache, or event logs. Option E is not correct because prefetch files do not contain network connection data such as IP addresses; those would be found in network artifacts or logs.

Exam trap

A common misconception is that prefetch files contain user-specific data or command-line arguments, but they only store execution count and timestamps, not user identity or process invocation details.

602
MCQeasy

Which of the following tools is designed specifically for dynamic analysis of malware by executing it in a controlled, isolated environment?

A.PEiD
B.Ghidra
C.Cuckoo Sandbox
D.IDA Pro
AnswerC

Cuckoo Sandbox executes suspect binaries inside an isolated virtual machine, then records process, file, registry and network activity. That runtime behavioural monitoring is dynamic analysis, distinguishing it from static tools that inspect code or signatures without executing the sample.

Why this answer

Cuckoo Sandbox is an open-source automated malware analysis system designed specifically for dynamic analysis. It executes suspicious files in a controlled, isolated environment (a virtual machine) and monitors their behavior, including system calls, file system changes, registry modifications, and network traffic, to produce a comprehensive report without risking the host system.

Exam trap

EC-Council often tests the distinction between static analysis tools (like PEiD, Ghidra, IDA Pro) and dynamic analysis sandboxes (like Cuckoo), so the trap is that candidates may confuse a debugger or disassembler (which can execute code step-by-step) with a fully automated, isolated sandbox environment.

How to eliminate wrong answers

Option A (PEiD) is wrong because it is a static analysis tool that detects packers, cryptors, and compilers in PE files by scanning signatures; it does not execute malware. Option B (Ghidra) is wrong because it is a reverse-engineering framework focused on static analysis and disassembly/decompilation of binaries, not on executing malware in an isolated environment. Option D (IDA Pro) is wrong because it is an interactive disassembler and debugger used for static and limited dynamic analysis (via its debugger), but it is not designed as a sandbox for automated, isolated execution of malware.

603
Multi-Selectmedium

A forensic analyst is examining a Google Cloud Platform (GCP) environment after a security incident. Which TWO GCP services should the analyst use to audit API activity and resource changes? (Select TWO.)

Select 2 answers
A.Cloud Asset Inventory
B.Cloud Audit Logs
C.Cloud Storage Object Change Notification
D.Cloud Monitoring
E.Cloud Functions
AnswersA, B

Cloud Asset Inventory is the correct answer because it maintains a comprehensive, historical record of resource metadata and configuration across Google Cloud. It periodically captures and snapshots the state of resources such as compute instances, IAM policies, and storage buckets, allowing forensic analysts to query for previous configurations and detect unintended changes. This service supports exports to BigQuery for long-term retention and analysis, making it the ideal tool for reconstructing resource drift or unauthorized modifications.

Why this answer

Cloud Audit Logs record API calls and resource changes, while Cloud Asset Inventory tracks resource history and configuration changes.

604
MCQeasy

In Linux forensics, which file contains user account information including the user ID, group ID, home directory, and default shell?

A./etc/passwd
B./var/log/auth.log
C./etc/shadow
D./proc/cpuinfo
AnswerA

The /etc/passwd file is the traditional system account database in Linux, containing one colon-delimited entry per user account. Each line includes the username, a password placeholder (usually x), user ID, group ID, GECOS description, home directory, and default login shell. This file is the authoritative source for identifying which accounts exist on a system during forensic analysis. Password hashes themselves are stored separately in /etc/shadow, not here.

Why this answer

The /etc/passwd file is the standard Linux user database that stores essential account details, including the username, user ID (UID), group ID (GID), home directory path, and default shell. Each line in this file corresponds to a user account and uses a colon-delimited format (e.g., username:x:UID:GID:comment:home:shell). This file is world-readable because it does not contain passwords (which are stored in /etc/shadow), making it the correct source for the information listed in the question.

Exam trap

EC-CHFI often tests the distinction between /etc/passwd and /etc/shadow, trapping candidates who confuse the password storage location with the account information file, leading them to incorrectly select /etc/shadow because they associate it with user accounts.

How to eliminate wrong answers

Option B is wrong because /var/log/auth.log is a log file that records authentication-related events (e.g., login attempts, sudo usage) and does not contain static user account information like UID, GID, home directory, or default shell. Option C is wrong because /etc/shadow stores encrypted password hashes and password policy data (e.g., expiration dates), not the user ID, group ID, home directory, or shell; it is also readable only by root. Option D is wrong because /proc/cpuinfo is a virtual file that provides CPU hardware details (e.g., model, cores, flags) and has no relation to user account configuration.

605
MCQmedium

During a mobile forensic investigation, an examiner finds that the seized iPhone is locked with a passcode but is running iOS 11. Which acquisition method should the examiner prioritize to obtain the most data without bypassing the passcode?

A.Physical acquisition using a JTAG tool
B.Logical acquisition via iTunes backup
C.File system acquisition using Cellebrite UFED
D.Manual acquisition by photographing the screen
AnswerB

iTunes backup can be initiated without passcode if device is trusted, and provides access to many artefacts including SMS, contacts, and call history.

Why this answer

For a locked iPhone running iOS 11, physical and file system acquisitions are typically blocked by hardware encryption and the Secure Enclave unless the passcode is bypassed. However, if the device has been previously trusted with a computer, a logical acquisition via iTunes backup can be performed without entering the passcode, as the trust relationship authorizes the backup. This method extracts the most data (contacts, messages, photos, etc.) without bypassing the passcode.

If no trust relationship exists, logical acquisition is not possible without the passcode, but the CHFI exam often assumes a previously trusted computer for this scenario.

Exam trap

The CHFI exam often tests the misconception that physical acquisition is always superior, but on modern iOS devices, logical acquisition via iTunes backup is the only viable method for locked devices without bypassing the passcode.

How to eliminate wrong answers

Option A is wrong because JTAG physical acquisition requires physical access to the device's circuit board and is typically used for older devices or when the device is disabled; on iOS 11, the Secure Enclave and full-disk encryption make JTAG impractical for locked devices without passcode bypass. Option C is wrong because file system acquisition using Cellebrite UFED on iOS 11 requires either a jailbreak or a known passcode to decrypt the file system; without bypassing the passcode, UFED cannot access the encrypted file system. Option D is wrong because manual acquisition by photographing the screen only captures visible data and is not a forensic acquisition method; it fails to retrieve deleted data, metadata, or data not currently displayed.

606
MCQeasy

A security analyst arrives at a crime scene where a computer is turned on and the screen shows a document. What is the FIRST action the analyst should take according to forensic best practices?

A.Create a forensic image of the hard drive using a write blocker.
B.Open the Task Manager to check for suspicious processes.
C.Immediately unplug the power cord to preserve volatile data.
D.Photograph the screen and surroundings, then proceed to document the scene.
AnswerD

Photographing the screen and surroundings is the correct first action because it captures the live visual state of the system without any interaction that could change it. This documentation preserves evidence of on-screen content, open applications, connected peripherals, and environmental context—vital for reconstructing the incident and establishing chain of custody. It also serves as a baseline for every subsequent action, ensuring the investigation is legally defensible. Only after this non-invasive step should any data collection or system interaction begin.

Why this answer

The first priority at a live crime scene is to preserve the state of the system and its environment through documentation. Photographing the screen and surroundings captures volatile data (e.g., open documents, running processes, network connections) before any interaction alters the system. This aligns with the order of volatility and the principle of minimizing changes to the evidence.

Exam trap

EC-Council often tests the misconception that preserving volatile data means immediately pulling the plug, when in fact the correct first step is to document the live state to avoid destroying evidence that cannot be recovered.

How to eliminate wrong answers

Option A is wrong because creating a forensic image with a write blocker is a later step after documenting the live state; connecting a write blocker or imaging tool could modify the system’s memory or storage. Option B is wrong because opening Task Manager alters the system state (e.g., changes process metadata, modifies memory) and may destroy volatile evidence like running processes or network connections. Option C is wrong because immediately unplugging the power cord destroys volatile data (RAM, network connections, process lists) and can cause file system corruption or loss of encryption keys, violating the order of volatility.

607
MCQeasy

A forensic analyst is performing timeline analysis on a compromised system. Which tool is specifically designed to parse multiple log sources and create a super timeline?

A.Sleuth Kit
B.log2timeline
C.Volatility
D.Wireshark
AnswerB

log2timeline parses disparate artefacts — event logs, file system metadata, registry hives — into a single bodyfile, which Plaso then sorts into a super timeline. This satisfies the requirement to correlate multiple log sources chronologically.

Why this answer

log2timeline (now part of the plaso framework) is specifically designed to parse multiple log sources—such as Windows Event Logs, syslog, web server logs, and file system metadata—and aggregate them into a single super timeline. This enables forensic analysts to correlate events across disparate logs for timeline analysis, which is exactly the requirement in the question.

Exam trap

EC-Council often tests the distinction between disk forensics tools (Sleuth Kit), memory forensics tools (Volatility), network forensics tools (Wireshark), and timeline/log analysis tools (log2timeline), so candidates mistakenly choose a tool they recognize from other forensics domains without reading the specific requirement for parsing multiple log sources.

How to eliminate wrong answers

Option A is wrong because Sleuth Kit is a collection of command-line tools for analyzing disk images and file system structures (e.g., extracting deleted files, viewing MFT entries), not for parsing multiple log sources to create a super timeline. Option C is wrong because Volatility is a memory forensics framework used to analyze RAM dumps (e.g., processes, network connections, registry hives in memory), not for parsing log files from disk. Option D is wrong because Wireshark is a network protocol analyzer that captures and inspects live or recorded packet captures (pcap files), not for parsing system or application logs into a timeline.

608
MCQhard

A forensic analyst is investigating a compromised Microsoft Exchange Server 2019. The attacker gained access to a mailbox and exfiltrated emails. The analyst needs to determine the exact time and IP address from which the attacker accessed the mailbox via Outlook Web App (OWA). Which Exchange log should the analyst examine to find this information?

A.Message tracking logs
B.IIS logs on the Exchange server
C.Exchange audit logs
D.Windows Security event logs
AnswerB

OWA is hosted in IIS, and IIS logs record HTTP requests to OWA virtual directories, including the client IP address, timestamp, username, and requested URL. By analyzing IIS logs, the analyst can identify successful logins and mailbox access, including the source IP and time. This makes IIS logs the correct source for this scenario.

Why this answer

IIS logs on the Exchange server capture HTTP requests to OWA, including the client IP address, timestamp, and username. This directly provides the time and IP address of the attacker's mailbox access. Other logs either lack IP address information or do not focus on OWA access.

Therefore, IIS logs are the correct source.

Exam trap

The trap here is confusing mailbox audit logs with IIS logs; audit logs show actions but not the client IP address.

609
MCQmedium

During a forensic examination of a Windows 10 system, you find a file with an ADS named `:hidden.txt` attached to `legal.docx`. Using FTK Imager, you extract the ADS and discover it contains a list of passwords. Which tool or technique could also be used to identify this hidden data?

A.Analyzing the $MFT using Autopsy
B.Running `strings` on the raw partition
C.Using `lsof` on a live system
D.Performing file carving with PhotoRec
AnswerA

Autopsy's NTFS parser ingests the Master File Table, enumerating every file and its attributes, including the $DATA attribute's named streams. When a file has an alternate data stream, Autopsy displays it (e.g., file.txt:stream.txt) in the tree and the file properties, allowing the examiner to see both the stream's name and its content. This is correct because ADS entries are metadata stored in the MFT, not separate files, so they are only discoverable through filesystem metadata parsing.

Why this answer

The $MFT (Master File Table) in NTFS stores metadata for every file and directory, including entries for Alternate Data Streams (ADS). By analyzing the $MFT with a tool like Autopsy, you can directly view the ADS names and their associated data, such as the `:hidden.txt` stream attached to `legal.docx`. This is a reliable forensic method because the $MFT is a critical file system structure that records all streams, even if the file system explorer hides them.

Exam trap

The trap here is that candidates often assume ADS can only be detected via command-line tools like `dir /r` or `streams.exe`, but the EC-Council's CHFI exam tests understanding that the $MFT is the definitive source for all file metadata, including hidden streams, and that forensic tools like Autopsy leverage this for analysis.

How to eliminate wrong answers

Option B is wrong because `strings` on a raw partition extracts readable text from binary data but does not specifically parse NTFS structures like the $MFT to identify ADS; it might miss streams or produce noisy output. Option C is wrong because `lsof` is a Unix/Linux command for listing open files on a live system, not for analyzing a forensic image of a Windows 10 NTFS volume. Option D is wrong because file carving with PhotoRec recovers files based on signatures, ignoring file system metadata like ADS; it would not extract the hidden stream attached to `legal.docx`.

610
Multi-Selecteasy

A network forensic investigator is analyzing traffic from a compromised web server. Which TWO artifacts are MOST likely to indicate the presence of a web shell? (Select TWO.)

Select 2 answers
A.Multiple DNS queries to external domains
B.Excessive SYN-ACK packets
C.Presence of a suspicious .aspx or .php file in web directories
D.Unusual HTTP POST requests to non-standard scripts
E.High volume of ICMP traffic
AnswersC, D

A web shell is a server-side script that executes commands on the host, and attackers commonly upload it with an executable extension such as .php, .aspx, .jsp, or .cgi into a web-accessible directory. Uncovering an unexpected script file in the web root—especially one with recent creation time or placed in a writable uploads folder—is a direct file-system artifact of a web shell infection. This is the strongest and most specific indicator among the choices, as it represents the actual payload left behind by the attacker.

Why this answer

Option C is correct because web shells are typically deployed as malicious script files (e.g., .aspx, .php, .jsp) placed in web-accessible directories, so finding an unexpected or suspicious script file there is a strong indicator of a web shell. Option D is correct because web shells are commonly invoked through HTTP POST requests to unusual or non-standard script paths, allowing attackers to send commands and receive output over the web channel. Options A, B, and E are not the most likely indicators: DNS queries to external domains, excessive SYN-ACK packets, and high ICMP traffic can reflect other activities such as command-and-control, scanning, or tunneling, but they are not specific artifacts of a web shell on a compromised web server.

Exam trap

In EC-CHFI, the focus is on identifying web shells through application-layer artifacts such as suspicious script files in web directories and unusual HTTP POST requests. Network-level anomalies like DNS queries or SYN floods are not as specific to web shells.

611
MCQmedium

A forensic examiner is testifying in a U.S. court about a disk image acquired from a suspect's computer. The defense attorney argues that the image is not admissible because it is a copy, not the original. The examiner explains that the image was created using a write-blocker and verified with SHA-256 hashes. Which legal principle supports the admissibility of the disk image?

A.The Federal Rules of Evidence, specifically Rule 1003 (Admissibility of Duplicates)
B.The Chain of Custody Doctrine
C.The Best Evidence Rule
D.The Hearsay Rule
AnswerA

Federal Rule of Evidence 1003 allows a duplicate to be admitted to the same extent as an original unless a genuine question is raised about the original's authenticity or the circumstances make it unfair to admit the duplicate. Here, the disk image is a duplicate created with a write-blocker and verified by SHA-256 hashes, ensuring its accuracy. The defense has not raised a specific authenticity challenge, so the duplicate is admissible.

Why this answer

Federal Rule of Evidence 1003 permits duplicates to be admitted unless there is a genuine dispute about the original's authenticity or fairness concerns. The disk image, created with a write-blocker and verified by SHA-256 hashes, qualifies as a duplicate. Because the defense has not raised a specific authenticity challenge, the image can serve as evidence, provided the examiner can authenticate it and demonstrate the imaging process was reliable.

Exam trap

The trap here is assuming the Best Evidence Rule absolutely requires the original drive in court, overlooking that Rule 1003 allows duplicates under specific conditions.

612
MCQhard

During a Linux forensic investigation, you find that the file /etc/cron.d/evil contains the entry: '* * * * * root /bin/bash /root/backdoor.sh'. What persistence mechanism is being used?

A.Systemd service
B.Init script
C.Cron job
D.At job
AnswerC

Cron jobs are defined in /etc/cron.d, /etc/crontab, or a user's crontab and are executed by the cron daemon according to a schedule specified with time fields (minute, hour, day of month, month, day of week). A file in /etc/cron.d is a standard location for system cron jobs, and the syntax often includes the user account to run the job as well as the command. This matches the scenario where a file found during a Linux forensic investigation is executed on a schedule, making cron the correct classification. The five-field time specification is a unique characteristic that distinguishes cron from systemd services or init scripts.

Why this answer

The entry in /etc/cron.d/evil follows the standard crontab format (minute, hour, day, month, weekday, user, command) and is placed in a system cron directory, making it a cron job. Cron jobs are a common Linux persistence mechanism that execute commands at scheduled intervals, and this one runs /root/backdoor.sh every minute as root.

Exam trap

EC-Council often tests the distinction between cron jobs (recurring, in /etc/cron.d/ or crontab) and at jobs (one-time, in /var/spool/at/), so candidates mistakenly choose 'At job' because both involve scheduled execution, but the repeating asterisk syntax and file location clearly indicate a cron job.

How to eliminate wrong answers

Option A is wrong because systemd services are defined in .service unit files (typically in /etc/systemd/system/) and managed by systemctl, not by entries in /etc/cron.d/. Option B is wrong because init scripts are shell scripts placed in /etc/init.d/ and controlled by the SysV init system (or symlinked via update-rc.d), not by cron directory entries. Option D is wrong because at jobs are scheduled for one-time execution using the 'at' command and stored in /var/spool/at/ or /var/spool/cron/atjobs/, not in /etc/cron.d/ with a repeating crontab syntax.

613
Multi-Selecthard

A cloud forensic investigator is analyzing a GCP audit log entry for a Compute Engine instance. Which THREE fields are essential for identifying the user and operation performed?

Select 3 answers
A.requestMetadata.callerIp
B.methodName
C.resourceName
D.requestMetadata.userAgent
E.authenticationInfo.principalEmail
AnswersB, C, E

methodName is the fully qualified name of the API method invoked, such as v1.compute.instances.delete. This field is essential because it directly answers the investigator's primary question of what operation was performed on the resource. In Cloud Audit Logs, the methodName is what allows filtering for specific actions (e.g., deleting instances, modifying IAM policies) and is indispensable for reconstructing the sequence of events during an incident.

Why this answer

GCP audit logs include the principal email (authenticationInfo), operation type (methodName), and resource name (resourceName). IP address and user agent may be in requestMetadata but not always in every log entry.

614
MCQmedium

An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT department is instructed to preserve all relevant electronic data. Which of the following actions should be taken FIRST to comply with the legal hold?

A.Delete all data that is not relevant to the lawsuit to reduce storage.
B.Immediately preserve all potentially relevant data, including backups and archives, and suspend automatic deletion policies.
C.Notify all employees to ignore the hold and continue normal operations.
D.Conduct a forensic analysis of the data to determine relevance before preservation.
AnswerB

Upon receiving a litigation hold notice, a legally defensible response is to immediately issue a legal hold that suspends all normal retention, deletion, backup rotation/recycling, and archive destruction schedules across all media—including email servers, file shares, SharePoint/cloud repositories, and offline backups. Preserving backups and archives can prevent loss of older or metadata-rich versions of documents that may be responsive. The hold must be communicated to custodians and IT administrators, and its implementation should be documented to demonstrate reasonable, good-faith compliance.

Why this answer

The first step in responding to a litigation hold is to immediately preserve all potentially relevant data, including backups and archives, and suspend any automatic deletion or rotation policies. This ensures that no spoliation of evidence occurs, which could lead to legal sanctions. The preservation order must be broad to cover all data that might be relevant, as determining exact relevance comes later in the e-discovery process.

Exam trap

The CHFI exam often tests the misconception that you can first analyze data to determine relevance before preserving it, but in legal hold scenarios, the correct order is always preserve first, then analyze, to avoid any risk of spoliation.

How to eliminate wrong answers

Option A is wrong because deleting data, even if believed to be irrelevant, risks destroying potentially relevant evidence and violates the duty to preserve, which can result in severe legal penalties for spoliation. Option C is wrong because notifying employees to ignore the hold and continue normal operations directly contradicts the legal hold requirement and would likely lead to the destruction of relevant data through routine operations. Option D is wrong because conducting a forensic analysis to determine relevance before preservation is premature and risky; the priority is to freeze the data in place to prevent any alteration or loss, with analysis performed only after a proper preservation hold is in place.

615
MCQeasy

Which type of evidence is based on information that is not directly from an eyewitness but is reported by someone else?

A.Direct evidence
B.Circumstantial evidence
C.Best evidence
D.Hearsay evidence
AnswerD

Hearsay is an out-of-court statement offered to prove the truth of the matter asserted, meaning the trier of fact must rely on the declarant's credibility without having observed the declarant's demeanor. This matches evidence 'based on information that is not directly known' because the witness repeating the statement lacks personal knowledge of the underlying fact. Under the Federal Rules of Evidence, such statements are generally inadmissible unless an exception or exclusion applies.

Why this answer

Hearsay evidence is defined as a statement made outside of court that is presented to prove the truth of the matter asserted. In digital forensics, this applies when a witness testifies about what another person said regarding an event, rather than recounting their own direct observation. The CHFI exam categorizes this under evidence types because it is not based on the witness's firsthand knowledge, making it generally inadmissible unless an exception applies.

Exam trap

EC-Council often tests the distinction between hearsay and circumstantial evidence, where candidates mistakenly choose circumstantial because they think any indirect information is circumstantial, but the key differentiator is that hearsay specifically involves a secondhand statement, not an inference from physical evidence.

How to eliminate wrong answers

Option A is wrong because direct evidence is based on firsthand observation or direct knowledge, such as an eyewitness account or a log file that directly records an event, not a report from someone else. Option B is wrong because circumstantial evidence relies on inference to connect a fact to a conclusion, such as a fingerprint at a crime scene, but it does not involve a secondhand report of an event. Option C is wrong because best evidence refers to the original source of evidence (e.g., the original hard drive or document) rather than a copy, and it is a rule of admissibility, not a category based on how the information is obtained.

616
MCQeasy

A forensic analyst is examining a disk image and needs to identify the file system structure. She looks for the Master File Table ($MFT) to begin analysis. Which file system is she most likely dealing with?

A.FAT32
B.NTFS
C.HFS+
D.ext4
AnswerB

NTFS is the only common filesystem that uses a Master File Table ($MFT) as its core metadata repository. Each file and directory is represented by a file record in the $MFT with attributes such as $STANDARD_INFORMATION, $FILE_NAME, and $DATA. Forensic examiners often locate the $MFT entry to identify timestamps, file ownership, and data runs, making this the correct answer.

Why this answer

The Master File Table ($MFT) is a core component of the NTFS file system, storing metadata about every file and directory on the volume. When a forensic analyst locates the $MFT, they are definitively working with an NTFS volume, as no other common file system uses this structure.

Exam trap

EC-CHFI often tests the misconception that $MFT is a generic file system structure, but it is exclusive to NTFS; candidates may confuse it with the FAT table or superblock equivalents in other file systems.

How to eliminate wrong answers

Option A is wrong because FAT32 uses a File Allocation Table (FAT) to manage clusters, not a Master File Table; it has no $MFT. Option C is wrong because HFS+ (Hierarchical File System Plus) uses a Catalog File (B-tree) and Extents Overflow File, not an $MFT. Option D is wrong because ext4 uses inode tables and block groups, with no concept of a Master File Table.

617
Multi-Selecteasy

Which TWO of the following are examples of circumstantial evidence in a digital forensics investigation? (Select TWO)

Select 2 answers
A.A witness testifying they saw the suspect commit the crime
B.A video recording of the suspect typing a password
C.Metadata showing a file was created on the suspect's computer during the incident timeframe
D.A signed confession from the suspect
E.Server logs showing the suspect's IP address connected at the time of the incident
AnswersC, E

File-creation metadata, such as $STANDARD_INFORMATION timestamps, only records when an entry was added to the filesystem; it reveals nothing about who executed the creation or whether the account owner was present. Demonstrating the suspect created the file requires inferring identity from custody, login records, and behavioral patterns, so it is circumstantial evidence that supports a conclusion only after reasoning.

Why this answer

Option C is correct because file metadata (such as MAC times — Modified, Accessed, Created/Changed timestamps) is generated automatically by the file system and does not directly prove the suspect performed the criminal act; it only supports an inference that the file was created on the suspect's machine during the incident window, which is the essence of circumstantial evidence. Option E is correct because server logs recording the suspect's IP address at the time of the incident are system-generated artifacts that, by themselves, only suggest a connection between the suspect's address and the event; they require inference (and corroboration, since IP addresses can be spoofed or shared via NAT) to link the suspect to the crime, making them circumstantial. Option A is not circumstantial but direct testimonial evidence, since the witness claims firsthand observation of the crime.

Option B is direct evidence because the recording itself shows the suspect performing the incriminating act of typing the password. Option D is direct evidence as a signed confession is an admission by the suspect of the act itself, not an inferential link.

Exam trap

EC-Council often tests the distinction between direct and circumstantial evidence by presenting seemingly conclusive items (like a video or confession) as traps, leading candidates to overlook that circumstantial evidence requires inference, not direct observation.

618
Multi-Selecthard

Which THREE of the following present unique challenges for forensic analysis of solid-state drives (SSDs) compared to traditional hard disk drives (HDDs)? (Select THREE.)

Select 3 answers
A.Slack space analysis due to 512-byte sector emulation
B.Wear leveling that moves data around the NAND chips
C.Fragmentation due to file system aging
D.Garbage collection that consolidates valid data and erases stale blocks
E.TRIM command that erases deleted data blocks
AnswersB, D, E

Wear levelling spreads writes across NAND chips by relocating data to fresh blocks, so a file's physical location changes independently of the file system. This breaks the assumption that logical addresses map predictably to physical ones, complicating data recovery and timeline reconstruction.

Why this answer

Option B is correct because SSD controllers implement wear leveling, which continuously relocates logical blocks across physical NAND pages to spread erase cycles, so a logical address no longer maps predictably to a fixed physical location and traditional imaging/address-based recovery assumptions break down. Option D is correct because garbage collection runs in the background, copying valid pages into new blocks and erasing blocks containing stale data, which can destroy deleted-file remnants before an examiner images the drive and can alter the drive contents after acquisition. Option E is correct because the TRIM command (ATA DATA SET MANAGEMENT / SCSI UNMAP) notifies the SSD that deleted LBAs are no longer needed, prompting the controller to erase those NAND blocks and making deleted data unrecoverable, unlike HDDs where deleted clusters typically persist until overwritten.

Option A is not a unique SSD challenge, since 512-byte sector emulation (512e/4Kn) and slack space issues also arise on modern HDDs and are not specific to flash media. Option C is not unique either, as fragmentation from file system aging occurs on HDDs as well and is actually mitigated on SSDs by the flash translation layer.

Exam trap

A common misconception is that TRIM, garbage collection, and wear leveling are the only SSD-specific challenges, while candidates may incorrectly assume that slack space analysis or fragmentation are also unique to SSDs, when in fact they are common to both HDDs and SSDs.

619
MCQeasy

A first responder arrives at a crime scene involving a suspected hacking incident. The suspect's computer is powered on and logged in. The responder needs to decide the first action to preserve evidence. According to the order of volatility, which of the following should be collected first?

A.The hard drive contents
B.The contents of RAM
C.The system's event logs
D.The temporary files in the user's profile
AnswerB

RAM is the most volatile evidence and is lost immediately upon power loss. It can contain running processes, open network connections, encryption keys, and unsaved data that may be crucial to the investigation. According to the order of volatility, RAM should be captured before any other action. First responders should use a memory capture tool to preserve this data without altering the system significantly.

Why this answer

The order of volatility dictates that the most perishable evidence be collected first. RAM loses its contents when power is removed, making it the highest priority. Hard drives, event logs, and temporary files are stored on persistent media and can be acquired later.

First responders should capture RAM before any other action to preserve critical volatile data.

Exam trap

The trap here is assuming that persistent storage like the hard drive should be collected first because it contains the most data, ignoring that RAM is far more volatile and easily lost.

620
Multi-Selectmedium

Which TWO Windows Event IDs are associated with successful and failed logon events? (Select two.)

Select 2 answers
A.4720
B.7045
C.4625
D.4648
E.4624
AnswersC, E

4625 is the security event ID for a failed logon attempt, logged when a user presents incorrect credentials or the logon otherwise fails. This event is a core part of Windows authentication auditing, enabling analysts to spot brute-force attacks and lockout thresholds. It is correct for this question because it is one of the two primary logon event IDs, complementing 4624 for successful logon to cover the full authentication picture.

Why this answer

Event ID 4625 [CORRECT] is the Security log entry generated when a logon attempt fails, recording details such as the account name, logon type, and failure reason, so it directly answers the failed-logon half of the question. Event ID 4624 [CORRECT] is the Security log entry generated when a logon attempt succeeds, capturing the new logon's account, logon type, and authentication package, so it answers the successful-logon half. Together these two IDs are the canonical pair for tracking successful and failed interactive, network, and service logons.

The other options do not belong: 4720 is logged when a user account is created, 7045 is a System log entry recording a new service being installed, and 4648 records a logon attempt using explicit credentials (such as RunAs), not a standard success or failure logon event.

Exam trap

The trap here is that candidates often confuse Event ID 4648 (explicit credential usage) with a successful logon, but it only logs when credentials are explicitly supplied for a secondary logon, not the primary authentication event.

621
MCQmedium

During a forensic investigation, an analyst uses a tool to capture the contents of RAM from a live Linux system. Which tool is specifically designed for this purpose and can acquire memory over a network or via a local kernel module?

A.WinPmem
B.LiME
C.FTK Imager
D.Volatility
AnswerB

LiME is a Linux Memory Extractor loadable kernel module that captures RAM from live Linux systems, supporting acquisition over a network or locally. This matches the stem's requirement for a tool designed specifically for live Linux memory capture.

Why this answer

LiME (Linux Memory Extractor) is specifically designed to capture RAM from live Linux systems. It can acquire memory either by loading a kernel module locally or by transmitting the memory dump over a network, making it the correct choice for this scenario.

Exam trap

CHFI often tests the distinction between memory acquisition tools and memory analysis tools, leading candidates to mistakenly select Volatility (a post-acquisition analyzer) instead of LiME (the actual acquisition tool).

How to eliminate wrong answers

Option A is wrong because WinPmem is a memory acquisition tool for Windows systems, not Linux. Option C is wrong because FTK Imager is a disk imaging and forensic tool that does not natively capture RAM from a live Linux system via a kernel module or network. Option D is wrong because Volatility is a memory analysis framework, not an acquisition tool; it requires a pre-existing memory dump to analyze.

622
MCQmedium

An examiner acquires a forensic image of an SSD from a suspect's laptop. The SSD was connected to a system with TRIM enabled. What challenge will the examiner most likely face when trying to recover deleted files?

A.Wear leveling complicates data location
B.RAID striping interferes with imaging
C.The SSD is encrypted and cannot be imaged
D.Deleted files may have been physically erased by TRIM
AnswerD

Upon file deletion, modern operating systems send TRIM commands to the SSD, which instructs the controller to mark the affected NAND blocks as invalid and subsequently erase them during garbage collection. Consequently, the original file data is physically removed from the flash memory, not merely marked as free space like on a hard drive. This makes deleted-file recovery and carving from unallocated SSD space far less reliable, so the artifacts may truly be gone.

Why this answer

When TRIM is enabled on an SSD, the operating system sends ATA DATA SET MANAGEMENT commands to the drive to immediately erase the physical blocks corresponding to deleted files. This means the deleted file data is permanently and irreversibly erased at the flash memory level, making recovery via traditional file carving or forensic tools impossible. Option D correctly identifies this as the primary challenge.

Exam trap

The trap here is that candidates often confuse TRIM with wear leveling or encryption, assuming that wear leveling (Option A) is the main obstacle, when in fact TRIM's immediate physical erasure of deleted data is the far more critical and specific challenge for SSD forensics in the CHFI exam context.

How to eliminate wrong answers

Option A is wrong because wear leveling is a technique to extend SSD lifespan by distributing writes across memory cells, but it does not prevent forensic imaging or data recovery; it only affects the logical-to-physical mapping, which can be handled by the controller. Option B is wrong because RAID striping is a data distribution method across multiple drives, and the question specifies a single SSD from a laptop, not a RAID array. Option C is wrong because while some SSDs may be encrypted, the question does not state that encryption is enabled, and even if it were, imaging the drive is still possible (though decryption would be a separate challenge); the core issue here is TRIM, not encryption.

623
MCQhard

Refer to the exhibit. An investigator is examining a disk image using TSK. The output from 'fls' shows the directory structure. What is the significance of the entry 'V/V 113-128-1: $OrphanFiles'?

A.It is a sign that a rootkit has hidden files in the image
B.It indicates the location of the Master File Table (MFT) mirror
C.It is a virtual directory that contains files with no parent directory, often from deleted files
D.It is a standard NTFS metadata file that stores file permissions
AnswerC

In tools like The Sleuth Kit (tsk) and Autopsy, the virtual directory named $OrphanFiles (or displayed as 'V/V') is not a literal directory stored on the disk. It is dynamically generated to represent files whose MFT entries exist but whose parent directory references were lost, typically because the directory entry was deleted, overwritten, or corrupted while the file record itself remains in the MFT. This commonly occurs after a file is deleted, when the directory index entry is removed but the file's MFT record is not yet reused, or after a malformed directory entry prevents normal linkage in the tree.

Why this answer

In The Sleuth Kit (TSK), the 'fls' command lists files and directories within a disk image. The entry 'V/V 113-128-1: $OrphanFiles' is a virtual directory that contains files that have no parent directory in the file system, typically because their directory entries were deleted or corrupted. This is a common artifact when recovering deleted files from NTFS volumes, as TSK collects such orphaned MFT entries into this virtual container.

Exam trap

The CHFI exam often tests the distinction between native NTFS metadata files (like $MFT, $Bitmap) and TSK virtual artifacts (like $OrphanFiles), so candidates mistakenly treat $OrphanFiles as a real NTFS system file rather than a forensic tool's reconstruction.

How to eliminate wrong answers

Option A is wrong because a rootkit hiding files would not manifest as a standard TSK virtual directory; rootkits typically use techniques like DKOM or hooking to conceal files, and $OrphanFiles is a normal TSK artifact for orphaned entries, not a sign of rootkit activity. Option B is wrong because the Master File Table (MFT) mirror is stored at the end of the NTFS volume (usually the last few clusters) and is not represented by a 'V/V' virtual directory in TSK; the MFT mirror is a metadata file ($MFTMirr), not a virtual directory. Option D is wrong because $OrphanFiles is not a standard NTFS metadata file; NTFS metadata files include $MFT, $LogFile, $Volume, etc., and $OrphanFiles is a TSK construct for forensic analysis, not a native NTFS file.

624
Multi-Selectmedium

Which TWO of the following are common challenges specific to cloud forensics? (Select TWO)

Select 2 answers
A.Volatile memory acquisition
B.Inability to image hard drives
C.Data jurisdiction and legal compliance
D.Multi-tenancy and separation of data
E.Lack of proper tools
AnswersC, D

Data jurisdiction and legal compliance are central cloud-specific challenges because cloud providers distribute data across data centers in multiple countries, and each jurisdiction has its own data protection laws, cross-border data transfer rules, and government-access rights. Investigators may need to obtain evidence from a server in another nation, requiring mutual legal assistance treaties (MLATs) or statutory mechanisms like the U.S. CLOUD Act, and this can conflict with privacy regulations such as GDPR. These legal constraints affect what data can be legally accessed, preserved, and admitted as evidence, making jurisdiction a uniquely difficult issue for cloud investigations.

Why this answer

Option C (Data jurisdiction and legal compliance) is correct because cloud data is often stored across multiple geographic regions and controlled by different providers, so forensic investigators must navigate varying laws, privacy regulations (e.g., GDPR), and cross-border data-access rules that complicate evidence collection and chain of custody. Option D (Multi-tenancy and separation of data) is correct because cloud resources are shared among multiple customers on the same physical infrastructure, making it difficult to isolate one tenant's data and artifacts without affecting or exposing others, which is a challenge unique to cloud environments. Options A and B are not specific to cloud forensics: volatile memory acquisition is a general digital-forensics challenge present on any live system, and the inability to image hard drives is generally false since providers and customers can often snapshot or image volumes (though access may be restricted).

Option E is also not cloud-specific, as lack of proper tools is a generic limitation across many forensic domains rather than a challenge unique to cloud forensics.

Exam trap

EC-Council often tests the distinction between general forensic challenges and those unique to cloud environments, so candidates mistakenly select volatile memory acquisition (A) or lack of proper tools (E) because they are common in on-premises forensics, but they are not specific to the cloud's shared responsibility and multi-tenant model.

625
Multi-Selecthard

A first responder is handling a compromised Linux server that is still powered on and actively communicating with an unknown external IP. The responder needs to collect volatile evidence while minimizing disruption. Which TWO actions should be performed to preserve the most volatile data in the correct order? (Choose two.)

Select 2 answers
A.Run 'netstat -antp' to capture current network connections and associated processes.
B.Immediately pull the power plug to prevent further data exfiltration.
C.Run 'chmod -R 000 /var/log' to protect log files from tampering.
D.Run 'ps aux' to capture the list of running processes.
E.Run 'dd if=/dev/sda of=/mnt/external/disk.img' to image the entire disk.
AnswersA, D

Capturing network connections and associated processes is a high-priority volatile data source. netstat -antp shows active TCP connections, listening ports, and the PID/program name, which can reveal command-and-control channels. This should be done before any shutdown or service restart, as the information disappears once connections close. It aligns with the order of volatility by capturing network state early.

Why this answer

The most volatile data on a running Linux system includes network connections and running processes. Capturing netstat -antp and ps aux first preserves this time-sensitive evidence. Full disk imaging and permission changes are either non-volatile or destructive and should not be performed before volatile data is secured.

Following the order of volatility ensures critical evidence is not lost.

Exam trap

The trap here is thinking that pulling the plug or imaging the disk first is acceptable, when volatile network and process data must be captured before any such actions.

626
MCQmedium

During an iOS forensic examination, an analyst extracts an iTunes backup and finds a file named 'SMS.db'. Which of the following tools is BEST suited to parse and analyze this SQLite database for SMS and iMessage content?

A.GrayKey
B.Oxygen Forensic Detective
C.Cellebrite UFED
D.SQLite Browser
AnswerD

SQLite Browser is a free, open-source graphical tool that opens SQLite databases directly, allowing the examiner to browse table structures, execute SQL queries, and export results. For an iOS SMS.db file, it lets the analyst immediately inspect messages, timestamps, and associated metadata by running SELECT statements across the relevant tables. This makes it ideal for targeted database examination rather than relying on extraction hardware or a full analysis suite.

Why this answer

SQLite Browser is the best tool for parsing and analyzing the 'SMS.db' file because it is a free, open-source SQLite database viewer that allows direct querying and inspection of the database schema, tables, and records. Since 'SMS.db' is a standard SQLite database containing SMS and iMessage data in iOS backups, SQLite Browser provides the most straightforward and cost-effective method for manual forensic analysis without relying on proprietary extraction tools.

Exam trap

EC-Council often tests the misconception that commercial forensic suites like Cellebrite or GrayKey are always the best tools for every forensic task, when in fact a simple, free database browser is more appropriate for analyzing a standard SQLite file after extraction.

How to eliminate wrong answers

Option A is wrong because GrayKey is a specialized hardware tool for bypassing iOS passcodes and extracting full file system images, not for parsing individual SQLite databases like 'SMS.db' after extraction. Option B is wrong because Oxygen Forensic Detective is a comprehensive forensic suite that can parse SMS.db, but it is overkill for simply analyzing a single extracted database file and is not the 'best suited' tool for this specific task due to its cost and complexity. Option C is wrong because Cellebrite UFED is primarily a physical extraction and decoding tool for mobile devices, not a dedicated SQLite database browser; while it can parse SMS data from extractions, it is not the optimal choice for directly opening and querying an already extracted 'SMS.db' file.

627
MCQmedium

A CHFI analyst is preparing a forensic workstation to image a suspect's USB flash drive. The analyst needs to ensure that the write-blocker is functioning correctly before connecting the drive. Which of the following is the most appropriate method to verify that the write-blocker is preventing write operations?

A.Connect the suspect's USB drive directly to the forensic workstation and attempt to write a test file; if the write succeeds, the write-blocker is not needed.
B.Connect the write-blocker to the forensic workstation, then use a known clean USB drive and attempt to write a file to it; if the write fails, the write-blocker is working.
C.Use a software write-blocker on the forensic workstation instead of a hardware write-blocker, as software blockers are more reliable and do not require validation.
D.Check the write-blocker's LED indicators; if the power light is on and the read/write switch is set to read-only, the write-blocker is functioning correctly.
AnswerB

This method directly tests the write-blocker's function by attempting a write operation to a known clean drive. If the write is blocked, it confirms the write-blocker is operational. It is safe because the drive is not evidence, and the test does not alter the original evidence. This is a standard validation procedure recommended in forensics.

Why this answer

The correct method is to test the write-blocker with a known clean drive by attempting a write operation. If the write is blocked, the write-blocker is functioning. This ensures the suspect's drive remains unaltered.

Other methods either rely on indicators, which are insufficient, or risk contaminating evidence. Proper validation is a key step in the forensic process.

Exam trap

The trap here is assuming that LED indicators or software write-blockers provide sufficient assurance without functional testing.

628
MCQeasy

Which of the following tools is specifically designed to analyze email headers and track the path of an email, providing information about delays and potential spoofing?

A.EmailTracker
B.Wireshark
C.FTK Imager
D.Autopsy
AnswerA

EmailTracker is purpose-built for email header analysis, with automated parsing of Received, Message-ID, and Authentication-Results fields to trace routing paths and detect spoofing. It decodes the raw header chain into a visual map of mail transfer, making it the only listed option that directly analyzes email headers as its primary function.

Why this answer

EmailTracker is a tool that analyzes email headers, visualizes the path, and helps identify spoofing and delivery delays.

629
MCQmedium

During a database forensic investigation, you need to review Microsoft SQL Server transaction logs to identify unauthorized data modifications. Which of the following SQL Server functions or commands is used to read the transaction log?

A.SELECT * FROM sys.dm_tran_database_transactions
B.DBCC LOG
C.fn_dblog
D.BACKUP LOG
AnswerC

fn_dblog is a table-valued function that accepts a starting and ending LSN and returns every transaction log record in that range, with columns such as Current LSN, Operation, Context, Transaction ID, Description, AllocUnitName, Page ID, and decoded row data. It allows an investigator to filter by operation type, transaction ID, or database object to reconstruct insert/update/delete activity, page allocations, and schema changes directly from the log. This makes it the standard, structured method for reviewing the actual log records during a database forensic investigation.

Why this answer

The fn_dblog function is the correct choice because it is the undocumented but widely used SQL Server function that reads the transaction log (LDF file) directly, allowing forensic examiners to view every logged operation including data modifications, schema changes, and transaction details. Unlike other DMVs or commands, fn_dblog provides a row-by-row dump of the log records, making it essential for identifying unauthorized changes at the transaction level.

Exam trap

EC-Council often tests the distinction between deprecated commands (DBCC LOG) and their modern replacements (fn_dblog), leading candidates to choose the familiar but outdated option B instead of the correct function C.

How to eliminate wrong answers

Option A is wrong because sys.dm_tran_database_transactions is a dynamic management view that shows metadata about currently active transactions (e.g., transaction ID, state, log space usage), but it does not read the actual transaction log records or provide historical log content. Option B is wrong because DBCC LOG is an undocumented command that was used in older SQL Server versions (prior to 2005) to read the transaction log, but it has been deprecated and replaced by fn_dblog; in modern SQL Server, DBCC LOG is no longer available or functional. Option D is wrong because BACKUP LOG is a command used to back up the transaction log to a file for point-in-time recovery, not to read or inspect the log contents for forensic analysis.

630
Multi-Selecteasy

Which TWO of the following are persistence mechanisms commonly found in Windows forensics? (Select two.)

Select 2 answers
A.Jump lists
B.ShellBags
C.Scheduled Tasks
D.Prefetch files
E.Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)
AnswersC, E

Scheduled Tasks are a built-in persistence mechanism managed by the Task Scheduler service (svchost.exe running Schedule) and exposed via schtasks.exe or the XML-based task folders under %SystemRoot%\System32\Tasks. An attacker can create a task with a trigger such as logon, system startup, idle, or a specific event, and specify an action that executes a malicious binary, often with SYSTEM privileges if configured. Unlike jump lists or prefetch files, scheduled tasks are first-class operating system facilities for executing code at defined times, making them a common and persistent malware foothold.

Why this answer

Scheduled Tasks (C) are a well-known Windows persistence mechanism because an attacker can register a task via schtasks.exe or the Task Scheduler that launches malware at logon, on a schedule, or on system events, and these tasks survive reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that execute listed programs at user logon, making them a common persistence technique. By contrast, Jump lists (A) are artifacts recording recently accessed files and applications for forensic reconstruction, not autostart mechanisms.

ShellBags (B) store folder view settings and window preferences in the registry to show user navigation history, and Prefetch files (D) are performance artifacts in C:\Windows\Prefetch that record executed program traces, neither of which causes programs to run automatically at startup.

Exam trap

EC-Council often tests the distinction between forensic artifacts that record past activity (like Jump lists, ShellBags, and Prefetch) versus those that actively cause code execution on system startup (like Scheduled Tasks and Registry Run keys), leading candidates to confuse evidence of execution with persistence mechanisms.

631
MCQhard

A forensic lab is designing a network architecture to ensure the integrity of evidence during acquisition. What is the most critical design consideration?

A.Deploy multiple forensic workstations to parallelize tasks
B.Use a segmented network to isolate forensic tools
C.Encrypt all data in transit over the network
D.Implement hardware write-blockers on all acquisition stations
AnswerD

A hardware write-blocker is inserted between the source drive and the forensic workstation, electrically or logically blocking write commands at the SATA/USB/IDE interface, so the operating system and forensic software cannot modify the original media under any circumstances. This is the direct technical control that preserves bit-for-bit integrity and enables valid cryptographic hash matching before and after acquisition. Using a write-blocker on every acquisition station is considered best practice in digital forensics and is required for standardized forensic imaging workflows.

Why this answer

Hardware write-blockers are the most critical design consideration because they physically prevent any write operations to the source drive at the ATA/SCSI command level, ensuring that the evidence remains bit-for-bit unchanged during acquisition. Without a hardware write-blocker, even a single read operation from a forensic workstation could inadvertently modify metadata (e.g., last access timestamps) or trigger anti-forensic mechanisms, compromising the integrity of the evidence and its admissibility in court.

Exam trap

The trap here is that candidates often confuse network security measures (segmentation, encryption) with evidence integrity controls, failing to recognize that the most critical design consideration is preventing any write access to the source media at the hardware level during acquisition.

How to eliminate wrong answers

Option A is wrong because deploying multiple forensic workstations to parallelize tasks improves throughput but does not address the fundamental requirement of preserving evidence integrity; it can even introduce chain-of-custody issues if not properly managed. Option B is wrong because using a segmented network to isolate forensic tools enhances security and prevents unauthorized access, but it does not prevent write operations to the source drive during acquisition, which is the primary integrity concern. Option C is wrong because encrypting data in transit over the network protects confidentiality and integrity during transfer, but it does not prevent the acquisition station from writing to the source drive; the evidence could be altered before encryption even occurs.

632
MCQmedium

During a forensic investigation, the analyst runs netstat -ano on a compromised workstation. Based on the exhibit, which connection is MOST suspicious and should be investigated further?

A.The established HTTPS connection to 203.0.113.5:443 (PID 5678).
B.The DNS query to 192.168.1.1:53 in TIME_WAIT state.
C.The UDP listener on port 5353 (mDNS) with PID 910.
D.The listening RDP service on port 3389 (PID 1234).
AnswerA

An established HTTPS connection to 203.0.113.5:443 is the clearest anomaly because 203.0.113.0/24 is TEST-NET-3, a documentation-only range that real internet services never legitimately use. An outbound connection to that test address over the standard TLS port strongly suggests C2 traffic, data exfiltration, or a covert tunnel masquerading as HTTPS. PID 5678 enables triage to the responsible process, but the destination alone warrants immediate isolation and memory capture.

Why this answer

The established HTTPS connection to 203.0.113.5:443 (PID 5678) is most suspicious because it is an external IP address (not in the private RFC 1918 range) with an established TCP connection, indicating active data transfer. In a forensic context, an outbound HTTPS connection to an unknown external IP is a common indicator of command-and-control (C2) communication or data exfiltration, especially when the PID can be traced to an unknown or malicious process.

Exam trap

EC-Council often tests the misconception that any listening service (like RDP or mDNS) is inherently suspicious, when in fact established external connections to unknown IPs are far more indicative of active compromise.

How to eliminate wrong answers

Option B is wrong because a DNS query to 192.168.1.1:53 in TIME_WAIT state is normal internal network traffic; DNS queries are expected to resolve names, and TIME_WAIT indicates the connection has ended, not active malicious activity. Option C is wrong because a UDP listener on port 5353 (mDNS) with PID 910 is a standard service for local network discovery (RFC 6762) and is not inherently suspicious unless the PID is known to be malicious. Option D is wrong because the listening RDP service on port 3389 (PID 1234) is a common administrative service; while RDP can be exploited, a listening state alone does not indicate compromise without evidence of unauthorized access or unusual source IPs.

633
MCQmedium

A forensic analyst is preparing to acquire an image from a suspect's hard drive. The analyst connects the drive to a write blocker, then uses FTK Imager to create a forensic image. Which hashing algorithm is commonly used by FTK Imager to verify image integrity?

A.AES
B.RSA
C.Blowfish
D.MD5
AnswerD

MD5 is the default integrity hash FTK Imager applies to forensic images, generating a 128-bit digest recorded alongside the image for later verification. It satisfies the stem's requirement for confirming image integrity during acquisition, detecting any alteration between the source drive and the captured copy.

Why this answer

FTK Imager uses MD5 (Message Digest 5) as its default hashing algorithm to verify the integrity of forensic images. MD5 produces a 128-bit hash value that uniquely represents the data, allowing the analyst to confirm that the acquired image is an exact bit-for-bit copy of the original drive. While SHA-1 is also supported, MD5 is the algorithm most commonly associated with FTK Imager's verification process.

Exam trap

The trap here is that candidates confuse encryption algorithms (AES, RSA, Blowfish) with hashing algorithms, because both are used in cryptography, but only hashing algorithms like MD5 or SHA-1 are employed for integrity verification in forensic imaging tools like FTK Imager.

How to eliminate wrong answers

Option A is wrong because AES (Advanced Encryption Standard) is a symmetric encryption algorithm used to protect data confidentiality, not a hashing algorithm for integrity verification. Option B is wrong because RSA is an asymmetric cryptographic algorithm used for encryption and digital signatures, not for generating fixed-length hash values to verify image integrity. Option C is wrong because Blowfish is a symmetric block cipher designed for encryption, not a hashing algorithm; it cannot produce a digest for integrity checks.

634
MCQhard

Based on the acquisition log, what can be concluded about the integrity of the acquired image?

A.The image is not forensically sound because the verification passed
B.The source and image have different data
C.The image is corrupted because only one hash algorithm was used
D.The image is an exact copy of the source
AnswerD

The acquisition log documents that the hash of the source and the hash of the acquired image are identical, and the subsequent verification step confirms these values still match. Identical hash digests plus a verified match provide strong cryptographic proof that the image is a precise, bit-for-bit duplicate of the source, which is the definition of a forensically sound copy.

Why this answer

The acquisition log shows that the hash values computed for the source drive and the acquired image match exactly. A matching hash (e.g., MD5 or SHA-1) verifies that the image is a bit-for-bit identical copy of the original evidence, confirming forensic soundness. Therefore, the image is an exact copy of the source, making option D correct.

Exam trap

EC-Council often tests the misconception that a passed verification indicates the image is not forensically sound, or that using only one hash algorithm implies corruption, when in fact a matching hash confirms integrity regardless of the number of algorithms used.

How to eliminate wrong answers

Option A is wrong because a verification that passes (hash match) confirms forensic soundness, not the opposite; a failed verification would indicate the image is not forensically sound. Option B is wrong because matching hash values prove the source and image have identical data, not different data. Option C is wrong because using a single hash algorithm (e.g., MD5 or SHA-1) is standard practice and does not indicate corruption; corruption would cause a hash mismatch, not be caused by the number of algorithms used.

635
MCQhard

During a forensic examination of a Windows 10 system, you find a file named "chrome_000001.jumplist" in the user's AppData directory. What does the presence of this file indicate?

A.The file is a Chrome extension
B.The user has installed Chrome via a jump list installer
C.The file contains Chrome bookmarks
D.The file stores recent items accessed through Chrome, such as downloaded files
AnswerD

Chrome's jumplist files record recently accessed items surfaced through the taskbar jump list, including downloaded files and recent pages. Their presence evidences user activity tied to Chrome, providing forensic artefacts of accessed content rather than cache or credential data.

Why this answer

Jump lists in Windows store recently accessed items for applications pinned to the taskbar or recently used. The file 'chrome_000001.jumplist' is a Windows-generated binary file that logs recent documents, downloads, or URLs opened via Google Chrome. Its presence indicates the user has recently accessed files or links through Chrome, making D correct.

Exam trap

EC-Council CHFI often tests the misconception that jump lists are browser-specific data files (like bookmarks or extensions) rather than recognizing them as a Windows OS feature for tracking recent application usage, leading candidates to confuse them with Chrome's internal storage formats.

How to eliminate wrong answers

Option A is wrong because Chrome extensions have a '.crx' or '.crx3' extension and are stored in the Extensions subfolder of the Chrome profile, not as a .jumplist file. Option B is wrong because there is no such concept as a 'jump list installer'; jump lists are a Windows shell feature for tracking recent items, unrelated to installation processes. Option C is wrong because Chrome bookmarks are stored in a JSON file named 'Bookmarks' within the user's Chrome profile directory, not in a .jumplist file.

636
MCQmedium

A security analyst is using Wireshark during a malware analysis session. The analyst observes a series of DNS queries to a domain 'malware-c2.example.com' every 60 seconds. This behavior is indicative of which malware characteristic?

A.Data exfiltration
B.DNS tunneling
C.Command and control (C2) communication
D.Propagation via network scanning
AnswerC

This is characteristic of command and control (C2) communication, specifically beaconing, where compromised hosts send regular, low-volume queries to a domain controlled by the attacker to receive instructions or report status. The periodic nature, consistent destination, and absence of payload data are hallmarks of a C2 beacon, distinguishing it from data transfer or network scanning. DNS is a preferred C2 channel because it often bypasses firewalls and proxy filters.

Why this answer

The periodic DNS queries to 'malware-c2.example.com' every 60 seconds are a classic heartbeat or beaconing mechanism used by malware to maintain persistent communication with its command and control (C2) server. This regular check-in allows the attacker to send commands or receive stolen data without requiring the malware to initiate a direct connection, which could be blocked by firewalls. The fixed interval and specific domain indicate a programmed C2 channel rather than a one-time data transfer or tunneling technique.

Exam trap

EC-Council often tests the distinction between DNS tunneling and C2 beaconing, where candidates mistakenly choose DNS tunneling because they see DNS queries, but the key differentiator is the regular, low-frequency pattern (beaconing) versus high-volume or encoded data in queries (tunneling).

How to eliminate wrong answers

Option A is wrong because data exfiltration typically involves sending stolen data (e.g., files, credentials) to an external server, often using HTTP POST, FTP, or DNS tunneling, but the periodic DNS queries alone do not indicate data transfer; they are just keep-alive signals. Option B is wrong because DNS tunneling encodes data within DNS query and response fields (e.g., subdomains or TXT records) to bypass network filters, but the described behavior—simple queries every 60 seconds—lacks the high volume or encoded payloads characteristic of tunneling. Option D is wrong because propagation via network scanning involves probing for vulnerable hosts using protocols like SMB, RDP, or SSH, not sending DNS queries to a fixed domain at regular intervals.

637
MCQeasy

Which of the following tools is BEST suited for performing static analysis of a malware binary to identify strings, headers, and imported functions without executing the file?

A.Cuckoo Sandbox
B.Any.run
C.Process Monitor
D.IDA Pro
AnswerD

IDA Pro is the industry-standard static interactive disassembler, capable of performing offline binary analysis without ever executing the code. It generates assembly-level listings, reconstructs control flow graphs, and can recover data structures, function boundaries, and API calls through its powerful FLIRT signatures and plugin extensibility. This is precisely the static analysis required for reverse engineering and vulnerability research, distinguishing it from dynamic sandboxes or runtime monitors.

Why this answer

IDA Pro is the correct choice because it is a disassembler and debugger specifically designed for static analysis of binary executables. It allows an analyst to examine strings, PE/ELF headers, and imported functions without executing the file, making it ideal for malware reverse engineering. In contrast, the other options require execution or focus on runtime behavior.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse sandbox tools (Cuckoo, Any.run) or process monitors (Procmon) with static analysis because they are commonly used in malware forensics, but they all require execution.

How to eliminate wrong answers

Option A is wrong because Cuckoo Sandbox is an automated dynamic analysis system that executes the malware in a sandboxed environment, not a static analysis tool. Option B is wrong because Any.run is a cloud-based interactive malware analysis platform that also executes samples to observe behavior, not a static analyzer. Option C is wrong because Process Monitor (Procmon) is a real-time system monitoring tool that captures file system, registry, and process activity during execution, requiring the malware to run.

638
MCQeasy

During a forensic investigation, an analyst needs to preserve the integrity of evidence on a hard drive. Which of the following is the best practice for acquiring an image of the drive?

A.Use the 'dd' command to create a raw image without a write blocker.
B.Connect the drive to a forensic workstation and use the operating system's copy command.
C.Use a hardware write blocker and create a bit-stream image.
D.Format the drive before imaging to ensure no hidden data is missed.
AnswerC

A hardware write blocker is the definitive forensic safeguard: it sits between the drive and the workstation and physically intercepts any write command at the ATA/SATA/USB interface, allowing only read operations. Creating a bit-stream image (e.g., using 'dd' or FTK Imager) then captures a sector-by-sector, bit-identical copy of the entire drive, including partition tables, unused sectors, slack space, and deleted files, ensuring the original evidence remains pristine and admissible in court.

Why this answer

Using a hardware write blocker ensures that no write commands from the forensic workstation reach the suspect drive, preserving its integrity at the physical level. Creating a bit-stream image (sector-by-sector copy) captures all data, including slack space and unallocated clusters, which is essential for thorough forensic analysis. This combination is the gold standard in digital forensics, as mandated by best practices like those from NIST and the ACPO principles.

Exam trap

The CHFI exam often tests the misconception that a software-based approach (like dd) is sufficient for imaging, but the trap is that without a hardware write blocker, the forensic workstation's OS may inadvertently write to the suspect drive (e.g., via automount or journaling), compromising evidence integrity.

How to eliminate wrong answers

Option A is wrong because using the 'dd' command without a write blocker risks modifying the evidence drive (e.g., by the OS mounting it or writing temporary files), which breaks chain of custody and can render evidence inadmissible. Option B is wrong because the operating system's copy command (e.g., cp or copy) only copies visible files and does not capture deleted data, slack space, or file system metadata; it also does not prevent write operations to the source drive. Option D is wrong because formatting the drive destroys all existing data, including evidence, and is the antithesis of preservation; it would permanently eliminate any chance of recovering hidden or deleted information.

639
Multi-Selecthard

A forensic examiner is preparing to acquire a forensic image of a running Windows 10 laptop suspected of containing evidence of intellectual property theft. The examiner must capture volatile data that could be lost if the system is shut down. Which TWO of the following actions should the examiner take to preserve volatile evidence before imaging? (Choose two.)

Select 2 answers
A.Run the command 'netstat -an' to record active network connections.
B.Run 'chkdsk /f' to ensure the file system is consistent before imaging.
C.Create a forensic image of the hard drive using FTK Imager before capturing RAM.
D.Immediately shut down the laptop to prevent remote wipe or tampering.
E.Capture the contents of RAM using a tool such as WinPmem or Magnet RAM Capture.
AnswersA, E

The 'netstat -an' command displays active network connections and listening ports, which are volatile and lost upon shutdown. This information can reveal remote access, data exfiltration, or command-and-control communications. Recording it before imaging ensures the examiner captures a snapshot of network activity. While not as comprehensive as a full memory dump, it is a quick, low-impact way to preserve a key piece of volatile evidence.

Why this answer

Volatile data such as RAM contents and active network connections are lost when a system is powered off. Capturing RAM with a specialized tool preserves running processes, encryption keys, and other memory-resident evidence. Recording network connections with 'netstat -an' captures a snapshot of current communications.

These steps must be taken before any disk imaging or shutdown to comply with the order of volatility.

Exam trap

The trap here is prioritizing disk imaging or system shutdown over volatile data capture, which would irreversibly lose critical evidence like RAM contents.

640
MCQeasy

During a forensic investigation, an analyst needs to recover recently deleted files from a FAT32 partition. Which of the following techniques is MOST effective for recovering files whose directory entries have been marked as deleted but the clusters have not yet been overwritten?

A.Running 'scalpel' to extract fragments and reassemble based on metadata
B.Using the 'foremost' tool to perform file carving based on file headers and footers
C.Using 'dd' to create a raw image and then 'photorec' to recover based on file signatures
D.Editing the directory entry's first byte from 0xE5 to the original character and recalculating the FAT chain
AnswerC

PhotoRec is a carving tool, used when file system metadata is damaged or missing.

Why this answer

In FAT32, deleting a file normally marks the directory entry's first byte as 0xE5 while the data clusters may remain intact. The preferred recovery approach is to use forensic tools that parse the file system metadata (directory entries and FAT), such as Autopsy, FTK, EnCase, or a specialized FAT recovery utility. Manual editing of the directory entry and recalculation of the FAT chain is not a standard CHFI technique and can damage evidence.

Among the listed options, creating a raw image with dd and using Photorec is the most forensically sound workflow; Photorec recovers file content by file signatures. It is not as ideal as metadata-based tools when directory entries are available, but it is better than manually modifying the file system structures.

Exam trap

This exam often tests the misconception that file carving tools such as foremost or photorec are always the only or best recovery method. In CHFI, when file system metadata remains intact, the preferred method is metadata-based recovery using forensic tools such as Autopsy, FTK, or EnCase. Manual hex editing of directory entries and FAT chains is a risky, non-standard practice and should not be chosen as the most effective technique.

How to eliminate wrong answers

Option A is wrong because 'scalpel' is a file carving tool that extracts fragments based on headers/footers and reassembles them, but it does not leverage the existing directory entry or FAT chain, making it less efficient for recovering files with intact metadata. Option B is wrong because 'foremost' performs file carving using file headers and footers, which is useful when directory entries are corrupted or overwritten, but here the directory entry is merely marked deleted and can be directly restored, making carving unnecessary and less precise. Option C is wrong because 'dd' creates a raw image and 'photorec' recovers files via signature-based carving, which ignores the file system metadata and can produce fragmented or incomplete results; it is a fallback method, not the most effective when the directory entry and FAT chain are recoverable.

641
MCQeasy

A forensic examiner is analyzing a Windows system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log artifact should the examiner review?

A.Application event log, Event ID 1000 indicating an application error.
B.Security event log, Event ID 4624 with Logon Type 2.
C.Security event log, Event ID 4634 indicating a logoff.
D.System event log, Event ID 6005 indicating the Event Log service started.
AnswerB

Event ID 4624 is logged for successful logons, and Logon Type 2 indicates an interactive logon at the console. This directly answers the question of when a user last logged on interactively. The event includes the date and time, user account, and other details. It is the primary artifact for interactive logon history in Windows Security logs.

Why this answer

Interactive logons are recorded in the Security event log as Event ID 4624 with Logon Type 2. This event includes the timestamp, user account, and other details necessary to determine when the logon occurred. Other event IDs and logs either record different activities or are not related to user logons, making them unsuitable for this purpose.

Exam trap

The trap here is confusing logon events with logoff events or system events, and overlooking that Logon Type 2 specifically denotes an interactive logon at the console.

642
Multi-Selecteasy

Which TWO of the following are types of write blockers used in forensic imaging? (Select two.)

Select 2 answers
A.Encryption write blocker
B.Network write blocker
C.Hash write blocker
D.Hardware write blocker
E.Software write blocker
AnswersD, E

Hardware write blockers are physical devices installed inline between the suspect drive and the forensic workstation, such as a Tableau bridge or a forensic SATA dock. They operate at the ATA, SATA, or USB command level to allow only read commands to pass while blocking write commands at the hardware interface. This provides an OS-independent, tamper-resistant method for preserving the original evidence bit-for-bit during imaging.

Why this answer

Hardware write blockers (D) are physical devices that sit between the suspect drive and the forensic workstation, intercepting the ATA/SCSI/NVMe command set and permitting only read commands to pass through, which prevents any modification of the evidence drive. Software write blockers (E) are drivers or kernel modules (for example, on Linux, mounting with the read-only option or using tools like the 'blockdev --setro' command) that intercept I/O requests at the OS level and block write operations to the protected device. These two are the recognized categories of write blockers in forensic imaging because they operate at the hardware and software layers respectively.

Encryption write blockers (A) are not a write-blocking type — encryption is a data protection mechanism, not a means of preventing writes during acquisition. Network write blockers (B) do not exist as a forensic write-blocker category, since network interfaces are not the medium being protected during imaging. Hash write blockers (C) are also not a real category; hashing (e.g., MD5/SHA-256) is used to verify integrity after imaging, not to block writes.

Exam trap

EC-Council often tests the distinction between integrity verification (hashing) and write prevention, leading candidates to mistakenly select 'Hash write blocker' as a valid type.

643
Multi-Selecteasy

Which TWO of the following are types of slack space that can contain forensic evidence?

Select 2 answers
A.Volume slack
B.Index slack
C.Swap space
D.Buffered slack
E.RAM slack
AnswersA, E

Volume slack is the unused space at the end of a filesystem volume that is not mapped to any allocated cluster. Because the volume's total size is rarely an exact multiple of the cluster size, a residual area remains after the last cluster. This area may retain remnants of old data from a previous filesystem or partition, making it valuable in forensic investigations.

Why this answer

Volume slack (A) is correct because it is the unused space remaining at the end of a volume after the last allocated cluster, which can retain residual data from deleted or resized partitions and is a recognized forensic artifact. RAM slack (E) is correct because it is the portion of the final sector of a file that is padded with data from memory when the file does not fill the sector, potentially capturing volatile memory contents that persist on disk. Index slack (B) is not a standard slack-space type; index entries are metadata structures, not slack areas.

Swap space (C) is a paging file area, not a category of file-system slack, though it can hold evidence it is not classified as slack space. Buffered slack (D) is not a recognized forensic slack-space term.

Exam trap

EC-Council often tests the distinction between 'volume slack' and 'RAM slack' as the two correct types, while distractors like 'swap space' or 'index slack' are common misconceptions that candidates mistake for legitimate slack space categories.

644
Multi-Selectmedium

An incident responder is analyzing a compromised Windows workstation. Which TWO artifacts would provide the STRONGEST evidence of a malware persistence mechanism?

Select 2 answers
A.Event log entry for user login
B.Registry Run key referencing a suspicious path
C.Scheduled Task entry pointing to a malicious executable
D.Network share access logs
E.Browser history showing download of a suspicious file
AnswersB, C

The Registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is a standard autorun location that launches specified executables at user logon. A suspicious path, particularly one outside standard program directories or with randomized naming, is a strong indicator of malware persistence. By writing a value here, the attacker ensures the payload executes automatically on every logon, making it a definitive persistence artifact. This is exactly the kind of evidence an incident responder would flag as critical.

Why this answer

Option B is correct because the Windows Registry Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run) are a classic autostart location that causes a program to execute automatically at user logon or system boot, so a Run key referencing a suspicious path is direct evidence of a persistence mechanism. Option C is correct because a Scheduled Task (stored under C:\Windows\System32\Tasks and managed via schtasks.exe or the Task Scheduler service) configured to launch a malicious executable is an explicit, recurring persistence technique that survives reboots and often runs with elevated privileges. Option A is not the strongest evidence because a user login event (e.g., Event ID 4624 in the Security log) only shows authentication activity and does not itself establish persistence.

Option D is not the strongest evidence because network share access logs record file access over SMB and do not demonstrate an autostart or persistence configuration. Option E is not the strongest evidence because browser history showing a suspicious download indicates possible initial infection or delivery, not an established persistence mechanism.

Exam trap

The CHFI exam often tests the distinction between infection vector artifacts (like browser history) and persistence mechanism artifacts (like Run keys or scheduled tasks), trapping candidates who confuse how malware arrives with how it survives a reboot.

645
MCQhard

An analyst extracts an iTunes backup from a Windows computer. The backup contains a file manifest.plist with cryptographic hashes. What is the primary purpose of these hashes in the backup process?

A.To compress the backup data
B.To verify the integrity of the backup files
C.To index the backup for faster searching
D.To encrypt the backup files
AnswerB

Computing a cryptographic hash (e.g., SHA-1 or MD5) of each backup file and comparing it against a known-good value confirms that the file's contents have not been modified, corrupted, or tampered with since the hash was created. This is the standard integrity-checking mechanism: any single-bit change in the file produces a completely different hash, allowing the analyst to detect accidental corruption or intentional alteration. In forensic examinations, verifying hashes ensures the extracted backup is an exact, trustworthy copy of the original evidence.

Why this answer

The cryptographic hashes in an iTunes backup's manifest.plist file are used to verify the integrity of the backup files. Each hash corresponds to a file in the backup, allowing the system to detect any corruption or tampering by comparing the stored hash against a newly computed hash of the file data.

Exam trap

EC-Council often tests the distinction between integrity verification (hashing) and confidentiality (encryption), so candidates may confuse the purpose of hashes with encryption or compression.

How to eliminate wrong answers

Option A is wrong because hashes do not compress data; compression is achieved through algorithms like zlib or LZMA, not cryptographic hashing. Option C is wrong because hashes are not used for indexing or searching; indexing is typically handled by separate metadata or database files (e.g., Manifest.db). Option D is wrong because hashes do not encrypt data; encryption in iTunes backups is performed using AES-256 with a key derived from the user's password, while hashes only provide integrity verification.

646
MCQhard

An analyst is examining a USB drive that appears to have a smaller capacity than expected. The drive is detected as 8 GB but only 7 GB is accessible. Which of the following is the most likely cause?

A.The file system uses a cluster size that wastes space
B.The drive is formatted with FAT32 which has a 4 GB file size limit
C.The drive has a Host Protected Area (HPA) hiding 1 GB
D.The drive contains a hidden partition
AnswerC

A Host Protected Area (HPA) is a region at the end of a hard drive defined via the ATA SET MAX ADDRESS command that reduces the reported LBA count, making the disk appear smaller to the operating system. If an 8 GB drive reports only 7 GB, an HPA can hide exactly 1 GB of sectors, which remain inaccessible to the OS and typical file system tools. This precisely matches the observed discrepancy, and forensic examiners can detect it using ATA commands (e.g., hdparm -N) or specialized tools that compare the reported and actual maximum addresses.

Why this answer

The difference between detected capacity (8 GB) and accessible space (7 GB) is most likely due to a Host Protected Area (HPA). HPA uses the ATA SET MAX ADDRESS command to reduce the total capacity reported by the drive, effectively hiding 1 GB from the operating system. A hidden partition does not change the total reported capacity; it only makes a portion of the space inaccessible by not assigning a drive letter.

Therefore, only HPA directly reduces the total capacity, making option C the most likely cause.

Exam trap

The CHFI exam often tests the distinction between HPA (reduces total reported capacity) and hidden partitions (allocate space but do not change total reported capacity). Candidates may mistakenly think both apply, but the key is that only HPA causes a discrepancy in total detected capacity.

How to eliminate wrong answers

Option A is wrong because cluster size waste (slack space) reduces usable space for file storage but does not change the total accessible capacity reported by the operating system; the drive would still show as 8 GB total. Option B is wrong because FAT32's 4 GB file size limit affects individual file storage, not the total volume capacity; an 8 GB drive formatted with FAT32 can still show its full 8 GB capacity. Option D is wrong because a hidden partition would still be counted in the total capacity reported by the OS (e.g., Disk Management would show the partition as hidden but the drive's total size would remain 8 GB); the question states the drive is detected as 8 GB but only 7 GB is accessible, meaning the OS sees 8 GB total but cannot access 1 GB, which matches HPA behavior.

647
MCQhard

An analyst recovers a disk image from a Linux server that used ext4. The image shows a superblock backup at multiple offsets. Which dd command would correctly extract the backup superblock located at offset 32768 bytes?

A.dd if=image.dd of=superblock.bin bs=4096 skip=8 count=1
B.dd if=image.dd of=superblock.bin bs=512 skip=64 count=2
C.dd if=image.dd of=superblock.bin bs=1024 skip=32 count=1
D.dd if=image.dd of=superblock.bin bs=32768 skip=1 count=1
AnswerB, C

Using bs=512 with skip=64 also lands at 64 * 512 = 32,768 bytes, the same superblock offset, but count=2 reads two 512-byte sectors for a total of 1,024 bytes. This approach is explicitly correct because it compensates for the smaller block size by incrementing the count, thereby extracting exactly the superblock without including adjacent sectors. It demonstrates that dd can achieve the same forensic extraction using any divisor of the superblock size, as long as the offset and byte count equal 32,768 and 1,024 respectively.

Why this answer

Both options B and C correctly extract the backup superblock from the disk image. The ext4 superblock is 1024 bytes and starts at offset 32768 bytes. With bs=512, skip=64 gives offset 32768 (64*512=32768), and count=2 reads 1024 bytes (2*512=1024).

With bs=1024, skip=32 gives offset 32768 (32*1024=32768), and count=1 reads 1024 bytes. Both commands extract exactly the superblock. Option A uses bs=4096 and count=1, reading 4096 bytes, which is too much and may include adjacent data.

Option D uses bs=32768 and count=1, reading 32768 bytes, far exceeding the superblock size.

Exam trap

Candidates may incorrectly assume that only one command is correct, or they may miscalculate skip values for different block sizes. Both B and C produce the same result; the key is to correctly compute skip and count to read exactly the superblock size (1024 bytes) at the given offset.

How to eliminate wrong answers

Option A is wrong because bs=4096 with skip=8 gives an offset of 32768 bytes (4096 × 8 = 32768), but count=1 reads only 4096 bytes, which is too large and would include data beyond the 1024-byte superblock, potentially corrupting the extracted data. Option C is wrong because bs=1024 with skip=32 gives an offset of 32768 bytes (1024 × 32 = 32768), but count=1 reads only 1024 bytes, which is correct for the superblock size; however, the skip value is incorrect because the superblock backup at offset 32768 is the first backup, but the primary superblock is at offset 1024, and the backup at 32768 is the second superblock; the skip=32 is actually correct for the offset, but the command would extract the superblock correctly; the issue is that the question asks for the backup superblock at offset 32768, and this option would work, but it is not listed as correct because the exam expects the bs=512 approach; however, the trap is that bs=1024 skip=32 count=1 is technically valid but not the intended answer because the CHFI exam often tests the standard dd syntax with bs=512 for disk images. Option D is wrong because bs=32768 with skip=1 gives an offset of 32768 bytes (32768 × 1 = 32768), but count=1 reads 32768 bytes, which is far larger than the 1024-byte superblock and would extract a huge chunk of data, not just the superblock.

648
Multi-Selecthard

Which THREE of the following are challenges specific to forensic analysis of solid-state drives (SSDs) compared to traditional hard disk drives? (Select 3)

Select 3 answers
A.TRIM command may permanently erase deleted data
B.SSDs have platters that can be degaussed to destroy data
C.SSDs are slower to image because of rotational latency
D.Garbage collection can erase blocks containing deleted files before acquisition
E.Wear leveling moves data across blocks, complicating file system analysis
AnswersA, D, E

The TRIM command instructs the SSD controller to immediately erase blocks of data marked for deletion, bypassing the file system’s logical deletion. This destroys residual data at the physical NAND flash level, unlike HDDs where deleted files remain on platters until overwritten. This satisfies the stem’s constraint of a challenge specific to SSD forensic analysis, as TRIM prevents recovery of deleted files.

Why this answer

Option A is correct because the ATA TRIM command (and SCSI UNMAP) tells the SSD controller which LBAs are no longer in use, allowing those flash pages to be erased during idle garbage collection, so deleted data may be irrecoverably gone rather than merely unallocated as on an HDD. Option D is correct because garbage collection operates autonomously in the background, erasing whole flash blocks that still contain remnants of deleted files, so evidence can disappear between the time of seizure and acquisition. Option E is correct because wear leveling transparently relocates logical blocks to different physical NAND pages to spread erase cycles, breaking the fixed LBA-to-physical-sector mapping that forensic tools rely on and complicating file-system and deleted-file reconstruction.

Option B is wrong because SSDs use NAND flash memory, not magnetic platters, so degaussing is inapplicable (and would not affect flash). Option C is wrong because SSDs have no rotating platters or actuator arms, so rotational latency is not a factor; they are generally faster to image than HDDs.

Exam trap

The CHFI exam often tests the misconception that SSDs behave like HDDs in terms of data persistence and imaging speed, leading candidates to incorrectly select options about platters or rotational latency instead of recognizing the unique firmware-level challenges of TRIM, garbage collection, and wear leveling.

649
MCQmedium

In cloud forensics, which AWS service logs API calls for governance, compliance, and operational auditing, and is the primary source for detecting unauthorized access?

A.AWS CloudTrail
B.AWS Config
C.Amazon CloudWatch
D.AWS GuardDuty
AnswerA

AWS CloudTrail is the correct service for logging API calls in cloud forensics. It captures every management-plane API request and response across AWS services, recording the user identity, source IP address, timestamp, and request parameters. This immutable audit trail enables investigators to reconstruct exactly what actions were taken and by whom, satisfying both auditing and security analysis requirements.

Why this answer

AWS CloudTrail is the correct answer because it is the dedicated AWS service that records all API calls made to the AWS environment, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. This log data is essential for governance, compliance, and operational auditing, and it serves as the primary forensic source for detecting unauthorized access or suspicious activities by providing an immutable record of who did what and when.

Exam trap

EC-CHFI often tests the distinction between services that generate logs (CloudTrail) versus services that analyze or monitor logs (GuardDuty, CloudWatch), leading candidates to mistakenly choose GuardDuty because it is associated with threat detection, even though it does not directly log API calls.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it focuses on evaluating and recording configuration changes to AWS resources against desired policies, not on logging API calls; it is used for compliance auditing of resource configurations, not for capturing API-level activity. Option C (Amazon CloudWatch) is wrong because it is a monitoring service for metrics, logs, and alarms, primarily used for operational health and performance monitoring, not for recording API calls for governance or forensic auditing. Option D (AWS GuardDuty) is wrong because it is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify malicious activity, but it does not itself log API calls; it consumes logs from other sources to generate findings.

650
MCQhard

During a Linux forensic investigation, you find that the /var/log/auth.log file contains log entries showing multiple 'Failed password for root' messages from a single IP address, followed by a 'Accepted password for root' entry. What is the MOST likely conclusion?

A.An attacker successfully brute-forced the root password
B.The root user accidentally mistyped the password multiple times
C.The system was compromised via a privilege escalation exploit
D.The root account has been locked out due to multiple failures
AnswerA

Repeated 'Failed password for root' entries from one source, immediately followed by 'Accepted password for root', indicate sustained password guessing that eventually succeeded. The single IP and root-targeted pattern distinguish brute force from a legitimate login or configuration error.

Why this answer

The sequence of multiple 'Failed password for root' entries followed by an 'Accepted password for root' entry from the same IP address is the classic signature of a successful brute-force attack against the root account. SSH authentication logs record each attempt, and a successful login after repeated failures indicates that the attacker guessed or cracked the password, not that a privilege escalation or lockout occurred.

Exam trap

EC-Council CHFI often tests the distinction between authentication log patterns and exploit-based compromise, so the trap here is assuming that any successful login after failures must be a privilege escalation, when the log entries explicitly show password-based authentication succeeded.

How to eliminate wrong answers

Option B is wrong because accidental mistyping by the legitimate root user would not produce a pattern of multiple failures from a single remote IP address; root typically logs in locally or via a console, and repeated typos are unlikely to be followed by a correct entry from the same remote source. Option C is wrong because privilege escalation exploits (e.g., CVE-2021-3156) do not generate 'Failed password' or 'Accepted password' entries in auth.log; they bypass authentication entirely or exploit a vulnerability after login. Option D is wrong because account lockout policies (e.g., pam_tally2 or faillock) would prevent any further login attempts after a threshold of failures, making an 'Accepted password' entry impossible without administrative intervention.

651
MCQmedium

A security team detects exfiltration via HTTP POST requests to a suspicious domain. Which network forensic technique would BEST identify the data being sent in these requests?

A.Firewall log review
B.IDS alert correlation
C.Wireshark packet capture with HTTP follow stream
D.NetFlow analysis
AnswerC

Wireshark performs full packet capture at the NIC and saves complete frames, including TCP payloads. Its 'Follow HTTP Stream' feature reassembles individual TCP segments in sequence order and applies HTTP decoding, presenting the entire POST body — e.g., a form field, file content, or encrypted data — in plaintext or raw hex. This is the only option listed that provides direct, forensic-grade evidence of what was transmitted in the exfiltration POST. (Note that capturing must occur on the affected segment; if HTTPS, TLS decryption requires keys.)

Why this answer

Wireshark packet capture with HTTP follow stream allows the investigator to reassemble the full HTTP conversation, including the body of POST requests. By following the TCP stream, the exact payload (e.g., exfiltrated data) is reconstructed in plain text, making it the best technique to identify the data being sent. This method directly captures and decodes the application-layer content, unlike log-based or flow-based analysis.

Exam trap

The trap here is that candidates often choose NetFlow analysis (Option D) because they confuse flow-level metadata with full packet capture, not realizing that NetFlow cannot reconstruct payload content.

How to eliminate wrong answers

Option A is wrong because firewall logs typically record only header-level metadata (source/destination IP, port, protocol, timestamp) and do not capture the HTTP request body or payload content. Option B is wrong because IDS alert correlation focuses on matching network traffic against signatures or anomalies to generate alerts, but it does not provide the raw, reassembled data stream needed to see the actual exfiltrated content. Option D is wrong because NetFlow analysis provides aggregated flow statistics (e.g., bytes transferred, duration, IP pairs) but lacks the packet-level detail required to reconstruct HTTP POST bodies.

652
MCQhard

During an incident response, a first responder needs to collect evidence from a Linux server that is still running. The server has sensitive data and cannot be shut down. Which technique is BEST for acquiring a forensic image of the hard disk?

A.Use dd if=/dev/sda of=/mnt/evidence/image.dd conv=noerror,sync
B.Use dd if=/dev/sda of=/mnt/evidence/image.dd bs=4M
C.Use dd if=/dev/mapper/root of=/mnt/evidence/image.dd
D.Use dd if=/dev/sda1 of=/mnt/evidence/image.dd
AnswerB

Imaging the entire block device /dev/sda with bs=4M captures the complete physical disk, including the master boot record, partition tables, each partition, and unallocated space. The bs=4M argument is only a performance optimization that increases the read/write buffer size; it does not change the output data, so the result is still a bit-for-bit forensically sound copy. This is the correct first-responder action because it preserves all potential evidence on the drive.

Why this answer

It uses dd with a 4M block size, which improves acquisition speed while still producing a bit-for-bit forensic image of the entire disk (/dev/sda). The conv=noerror,sync option in A is unnecessary for a live acquisition from a healthy disk and can mask read errors, while B's larger block size is more efficient for imaging a running system without shutdown.

Exam trap

EC-Council often tests the misconception that conv=noerror,sync is always required for forensic imaging, but in a live, healthy server scenario, it can introduce artifacts and is not the best practice.

How to eliminate wrong answers

Option A is wrong because conv=noerror,sync pads bad blocks with zeros, which can hide read errors and corrupt the forensic integrity of the image; it is typically used for failing disks, not for a live, healthy server. Option C is wrong because /dev/mapper/root targets a logical volume (LVM) rather than the physical disk, missing partition tables, boot sectors, and unallocated space essential for a complete forensic image. Option D is wrong because /dev/sda1 is only the first partition, not the entire disk, so it omits other partitions, MBR/GPT, and unallocated areas.

653
MCQeasy

Which cloud service log is most appropriate for tracking API calls and resource changes in an AWS environment?

A.AWS VPC Flow Logs
B.AWS Config
C.AWS CloudTrail
D.AWS CloudWatch Logs
AnswerC

CloudTrail records AWS API activity and resource changes across the account, capturing who did what, when and from where. This directly satisfies the need to track API calls and resource modifications, unlike flow logs or CloudWatch metrics.

Why this answer

AWS CloudTrail is the service that records API activity and resource changes.

654
MCQhard

An analyst reviews Windows Registry for USB device usage history. Which registry hive and key contain the 'USBSTOR' key that logs unique serial numbers of connected USB drives?

A.HKLM\SAM\SAM\Domains\Account\Users
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
D.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
AnswerC

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive Windows Plug and Play key for USB storage devices, where each subkey is named with the device instance ID (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) and a unique serial number. These subkeys persist even after the device is removed, and their LastWriteTime can estimate when the device was last connected, while the FriendlyName and ParentIdPrefix values enrich the picture. Being under the SYSTEM hive, it is machine-wide rather than user-specific, making it the first place investigators query to build a timeline of external storage devices that touched a system.

Why this answer

The USBSTOR key is located under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR and logs each unique USB device by its serial number. This hive is part of the SYSTEM registry, which maintains device enumeration data used by the Plug and Play manager to track connected hardware. Forensic analysts examine this key to identify USB drive insertion history, including first and last connection timestamps.

Exam trap

EC-CHFI often tests the misconception that USB device history is stored in user-specific hives (HKCU) or in the SAM hive, when in fact the SYSTEM hive's Enum\USBSTOR key is the authoritative source for device serial numbers and connection metadata.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM\Domains\Account\Users stores local user account security identifiers (SIDs) and password hashes, not USB device history. Option B is wrong because HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 records drive letter mappings and volume GUIDs for the current user, but it does not contain the USBSTOR key or device serial numbers. Option D is wrong because HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList stores user profile paths and SIDs, not USB device enumeration data.

655
MCQmedium

During a Linux forensic investigation, you find that the file /var/log/auth.log has been deleted. Which of the following artefacts would BEST help determine recent SSH login attempts?

A.Contents of /etc/shadow
B.Bash history from /root/.bash_history
C.Cron job entries in /etc/crontab
D.Output of the 'last' command
AnswerD

The 'last' command parses the binary wtmp log (/var/log/wtmp) to display session records, including user, terminal, source IP, and login/logout timestamps. This directly captures successful local and SSH logins, making it the standard artifact for identifying recent successful authentication events. Concatenating the output with the 'last' command's default format provides a timeline of who accessed the system.

Why this answer

The 'last' command reads the /var/log/wtmp binary log file, which records all login and logout events, including SSH sessions. Even if /var/log/auth.log is deleted, the wtmp file persists and provides a reliable record of recent SSH login attempts, making option D the best choice.

Exam trap

The trap here is that candidates assume auth.log is the only source for SSH login data, overlooking the wtmp file that the 'last' command queries, which is a separate and more persistent artefact.

How to eliminate wrong answers

Option A is wrong because /etc/shadow stores hashed user passwords and password aging information, not login attempt records. Option B is wrong because /root/.bash_history logs only commands executed in a bash shell, not SSH authentication events. Option C is wrong because cron job entries in /etc/crontab schedule periodic tasks and do not record login attempts.

656
MCQmedium

Which type of evidence is a witness's statement that they saw someone log into a computer?

A.Hearsay evidence
B.Best evidence
C.Circumstantial evidence
D.Direct evidence
AnswerD

Direct evidence proves a fact without inference. A witness testifying that they personally saw someone log into a computer directly establishes that act, unlike circumstantial evidence, which would require reasoning from other facts to reach the same conclusion.

Why this answer

Direct evidence is testimony or other proof that directly proves a fact without requiring any inference. A witness's statement that they saw someone log into a computer is direct evidence because it is based on the witness's firsthand observation of the act itself, not on any deduction or assumption. In digital forensics, direct evidence can include eyewitness accounts of specific actions on a system, such as entering credentials or accessing files.

Exam trap

EC-Council often tests the distinction between direct and circumstantial evidence by presenting a scenario where a witness sees a result (e.g., a screen displaying a file) and candidates mistakenly classify it as direct evidence of the action (e.g., file access) when it is actually circumstantial evidence requiring an inference.

How to eliminate wrong answers

Option A is wrong because hearsay evidence is an out-of-court statement offered to prove the truth of the matter asserted, and a witness's firsthand observation of a login is not hearsay—it is a statement based on personal knowledge, not a secondhand report. Option B is wrong because best evidence refers to the original document or recording (e.g., the actual log file) rather than a witness's testimony; the best evidence rule typically applies to writings, recordings, or photographs, not to live testimony about an observed event. Option C is wrong because circumstantial evidence requires an inference to connect it to a fact (e.g., finding a log entry at a certain time implies someone logged in), whereas the witness directly observed the login, so no inference is needed.

657
MCQmedium

A forensic examiner finds a suspicious entry in the Linux file /etc/passwd: 'backdoor:x:0:0:root:/root:/bin/bash'. What is the MOST significant security issue with this entry?

A.The entry has no password hash
B.The home directory is set to /root
C.The UID is 0, granting root privileges
D.The shell is /bin/bash
AnswerC

In Linux, UID 0 is reserved for root and any process or user with UID 0 bypasses all permission checks. A passwd entry with UID 0 means that logging into that account immediately grants full root control, regardless of the username appearing in the entry. This is a well-known backdoor technique, making it the most critical indicator in the passwd file.

Why this answer

The UID (user ID) of 0 is the root user identifier in Linux. Any account with UID 0 is granted the same privileges as the root user, regardless of the account name. This entry effectively creates a backdoor account with full administrative control over the system, bypassing normal authentication and accountability measures.

Exam trap

The CHFI exam often tests the misconception that the password hash field or the shell choice is the primary security concern, when in fact the UID of 0 is the critical indicator of root-level access.

How to eliminate wrong answers

Option A is wrong because the 'x' in the password field indicates that the password hash is stored in /etc/shadow, which is standard and not a security issue by itself. Option B is wrong because setting the home directory to /root is unusual for a non-root account but does not inherently grant elevated privileges; it is a configuration choice, not a security vulnerability. Option D is wrong because /bin/bash is a standard shell and does not confer any special privileges; the shell choice does not affect the account's permission level.

658
MCQeasy

Which tool is specifically designed for file carving and can recover files based on headers and footers without relying on file system metadata?

A.FTK Imager
B.Foremost
C.Autopsy
D.Volatility
AnswerB

Foremost is a dedicated command-line file carver that recovers files by scanning raw disk images and matching known binary signatures for file headers, footers, and internal data structures. It was originally developed from the Air Force Office of Special Investigations' carving tool and is configured via a customizable configuration file (foremost.conf), allowing investigators to add custom signatures. Its sole purpose is to extract data based on file structure, making it the classic, focused file-carving utility rather than a general forensic suite.

Why this answer

Foremost is a file carving tool that recovers files by scanning raw data for known header and footer signatures, such as JPEG headers (0xFFD8) and footers (0xFFD9), without relying on file system metadata like MFT entries or inodes. This makes it ideal for data recovery from damaged or formatted volumes where the file system structure is unavailable.

Exam trap

The CHFI exam often tests the distinction between file carving tools (like Foremost) and forensic analysis suites (like Autopsy or FTK Imager), expecting candidates to know that carving operates at the raw data level without file system metadata.

How to eliminate wrong answers

Option A (FTK Imager) is wrong because it is primarily a forensic imaging and preview tool that acquires disk images and mounts them for analysis, not a dedicated file carver; while it can export files, it relies on file system metadata for logical file extraction. Option C (Autopsy) is wrong because it is a digital forensics platform that provides a GUI for analyzing disk images and file systems, but its file carving capabilities are limited and typically rely on external tools like Foremost or Scalpel; it is not specifically designed for header/footer-based carving. Option D (Volatility) is wrong because it is a memory forensics framework for analyzing RAM dumps (e.g., processes, network connections), not a tool for file carving from disk images.

659
Multi-Selecthard

Which TWO of the following are essential components of a computer forensics lab according to CHFI best practices?

Select 2 answers
A.Server farm for data processing
B.Evidence storage area with controlled access
C.Public-facing website for case management
D.Coffee machine for staff convenience
E.Forensic workstation with specialized software
AnswersB, E

Evidence storage area with controlled access is essential to a forensic lab because it establishes a physically secure, restricted environment where seized media can be preserved, inventoried, and protected from tampering, environmental damage, or unauthorized access. This directly supports the chain of custody and evidentiary integrity that courts require for admissibility, and is a core component per forensic laboratory best-practice standards. Without such an area, the entire examination process loses its evidentiary foundation.

Why this answer

Option B is correct because CHFI best practices require a physically secure evidence storage area with controlled access to preserve the chain of custody and prevent tampering, theft, or contamination of digital evidence. Option E is correct because a forensic workstation loaded with specialized tools (e.g., EnCase, FTK, write blockers, and hashing utilities) is the core hardware/software platform needed to acquire, image, and analyze evidence without altering it. The other options are not essential lab components: a server farm (A) is unnecessary for typical forensic analysis, a public-facing website (C) would actually create security and confidentiality risks, and a coffee machine (D) is merely a convenience item with no forensic function.

Exam trap

EC-Council often tests the distinction between 'nice-to-have' items (like coffee machines) and mandatory security components (like controlled-access evidence storage), leading candidates to select convenience over critical infrastructure.

660
MCQeasy

A forensic analyst is investigating a Windows system and needs to examine the contents of the Recycle Bin. Which file artifact contains metadata about deleted files, including original file paths and deletion times?

A.$Recycle.bin\$I
B.C:\Windows\System32\winevt\Logs
C.$Recycle.bin\$R
D.C:\Windows\Prefetch
AnswerA

The $I file in the Recycle Bin is the metadata companion for a deleted item, and on Windows (Vista and later) it stores the original fully-qualified path, the deletion date/time as a FILETIME value, the file size, and a unique identifier that ties it to the corresponding $R data file. This makes it the authoritative source for reconstructing where a file came from and when it was trashed, exactly what the analyst needs. Without the $I file, you would have to guess the original location from timestamps on the $R file alone.

Why this answer

The $I file in the $Recycle.bin folder stores metadata about deleted files, including the original file path, deletion timestamp, and file size. This is the index file that the Recycle Bin uses to restore items to their original locations, making it the correct artifact for examining deletion metadata.

Exam trap

The CHFI exam often tests the distinction between $I (metadata) and $R (data) files, and candidates mistakenly choose $R because they think the 'R' stands for 'record' or 'recycle' instead of 'renamed data file'.

How to eliminate wrong answers

Option B is wrong because C:\Windows\System32\winevt\Logs contains Windows Event Logs (e.g., Security.evtx), which record system events but do not store Recycle Bin metadata like original paths or deletion times. Option C is wrong because $Recycle.bin\$R contains the actual deleted file data (the renamed file itself), not metadata about the deletion. Option D is wrong because C:\Windows\Prefetch stores prefetch files (.pf) for application startup optimization, not Recycle Bin deletion records.

661
MCQeasy

What is the primary purpose of the Host Protected Area (HPA) on a hard disk drive?

A.To provide a write-cache for improved performance
B.To store diagnostic data or allow vendors to hide data from the OS
C.To store the partition table when using GPT
D.To store the operating system boot loader
AnswerB

The HPA is defined by the ATA/ATAPI specification as a reserved region beyond the normal maximum address reported to the host, created and modified with the SET MAX ADDRESS and DEVICE CONFIGURATION OVERLAY commands. Because operating systems enumerate only the accessible LBA range, the HPA is invisible to the OS, allowing vendors to store diagnostic firmware, crash dumps, or recovery utilities without consuming ordinary user-visible space. In forensic practice, the HPA must be checked and disabled to see the true full capacity of the drive and recover hidden data.

Why this answer

HPA is a reserved area on the disk that is not visible to the operating system, intended for vendor-specific data. It can be used to hide data from forensic acquisition.

662
MCQmedium

During an investigation of a suspected data exfiltration, a forensic analyst examines MySQL general query logs and finds a large number of SELECT queries retrieving customer records, followed by DELETE queries. Which of the following is the most likely conclusion?

A.An attacker exfiltrating data and then deleting the records to cover tracks
B.An attempted SQL injection attack
C.A misconfigured replication process
D.Normal database maintenance operations
AnswerA

An attacker executing a SELECT to retrieve sensitive rows and then a DELETE on those exact rows is a classic data-exfiltration pattern. The sequential query log shows the attacker reading the data (SELECT) and then destroying the evidence of that read by removing the rows (DELETE), often using a WHERE clause matching the same primary keys or filters. This deliberate read-then-purge sequence is highly anomalous compared to normal application behavior and indicates an attempt to both steal data and cover forensic traces.

Why this answer

The combination of bulk SELECT (exfiltration) followed by DELETE (cover tracks) is a classic pattern of data theft.

663
Multi-Selecthard

Which THREE of the following are common indicators of a web shell presence on a compromised IIS web server? (Select THREE.)

Select 3 answers
A.Increased 404 errors in HTTP logs
B.Process w3wp.exe making outbound connections to an unknown IP
C.Scheduled tasks that execute cmd.exe or powershell.exe
D.Anomalous files with .asp or .aspx extensions in the wwwroot directory
E.Normal GET requests to static .html pages
AnswersB, C, D

Process w3wp.exe making outbound connections to an unknown IP is a strong indicator because w3wp.exe is the IIS worker process that normally only receives inbound HTTP requests and responds to them; it should not initiate outbound connections to arbitrary external addresses. When a web shell is uploaded and invoked, the attacker can use it to run commands, exfiltrate data, or create a reverse shell via the compromised worker process, causing the trusted w3wp.exe process to beacon to an external IP. Such unexpected outbound traffic from a known server-side process is frequently missed by simple HTTP log review, making it a high-value network-based IOC that pairs with file-based web shell detection.

Why this answer

Option B is correct because w3wp.exe is the IIS worker process that normally serves web content and should not initiate outbound network connections; seeing it connect to an unknown external IP is a strong indicator that a web shell is being used for command-and-control or data exfiltration. Option C is correct because attackers commonly establish persistence alongside a web shell by creating scheduled tasks that invoke cmd.exe or powershell.exe, which is abnormal for a standard IIS server. Option D is correct because web shells are typically dropped as .asp or .aspx files in the wwwroot directory so they can be executed by IIS, and unexpected files with those extensions in that location are a classic compromise artifact.

Option A is not a reliable indicator because increased 404 errors simply reflect missing resources or scanning noise and do not by themselves indicate a web shell. Option E is not an indicator because normal GET requests for static .html pages are ordinary benign web traffic.

Exam trap

A common misconception is that HTTP error codes like 404 are direct signs of compromise, when in reality they are more indicative of reconnaissance or misconfiguration, not the active presence of a web shell.

664
MCQmedium

A forensic examiner needs to create a bit-for-bit copy of a suspect's hard drive for analysis. Which tool is specifically designed for this purpose and can also verify integrity using hashing?

A.Wireshark
B.Metasploit
C.Nmap
D.dd
AnswerD

dd is the standard Unix/Linux utility for low-level data replication, and it creates a bit-for-bit image by reading every sector of the source device and writing it verbatim to an output destination. For example, `dd if=/dev/sda of=/evidence/disk.img bs=4K conv=noerror,sync` copies all blocks including slack space and deleted files, which is essential for forensic preservation. Combined with hashing tools like sha256sum, dd allows the examiner to verify the integrity of the copy, making it the correct choice for this task.

Why this answer

The `dd` command is a Unix/Linux utility that performs low-level bit-for-bit copying of storage devices, creating an exact forensic image (e.g., raw .dd or .img format). It can verify integrity by piping the output through a hashing tool like `md5sum` or `sha256sum`, or by using `dd` with `conv=noerror,sync` and later comparing hash values of the source and destination.

Exam trap

EC-Council CHFI often tests the distinction between general-purpose tools (like `dd`) and specialized forensic tools (like FTK Imager), but here the trap is that candidates may confuse network or exploitation tools (Wireshark, Metasploit, Nmap) with disk imaging utilities, assuming any 'analysis' tool can create a bit-for-bit copy.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting packets, not for creating disk images. Option B is wrong because Metasploit is a penetration testing framework for developing and executing exploit code, not a disk imaging tool. Option C is wrong because Nmap is a network scanning utility used for host discovery and port enumeration, not for bit-for-bit disk duplication.

665
MCQmedium

In a cloud forensic investigation, the analyst needs to obtain a memory dump of a virtual machine. Which method is considered forensically sound?

A.Log into the VM and use a tool to create a crash dump
B.Copy the virtual disk file (.vmdk) and extract memory from it
C.Use a live forensic tool inside the VM to capture memory
D.Take a snapshot of the VM via the hypervisor and export the .vmem file
AnswerD

Taking a snapshot of the VM at the hypervisor level and exporting the .vmem file is the proper cloud-forensic technique because the hypervisor, operating below the guest OS, accesses the VM's volatile memory directly without injecting any code into the guest. This point-in-time snapshot suspends or copies the RAM state transparently, preserving the exact contents of memory in a forensically sound format, and the .vmem file represents the guest's full physical address space — including kernel, processes, and any in-memory encryption keys or malware.

Why this answer

Forensically sound because taking a snapshot of the VM via the hypervisor and exporting the .vmem file captures the entire volatile memory state from outside the guest OS, without altering any data inside the VM. This method preserves the memory in its pristine state and avoids the contamination that occurs when executing tools inside the suspect VM.

Exam trap

The CHFI exam often tests the misconception that a virtual disk file (.vmdk) contains memory data, when in fact it only stores persistent storage, and that live tools inside the VM are acceptable despite violating forensic soundness by altering the evidence.

How to eliminate wrong answers

Option A is wrong because logging into the VM and creating a crash dump modifies the guest OS state (e.g., writing to disk, altering page tables) and may trigger anti-forensic mechanisms, violating the principle of minimal interaction. Option B is wrong because the virtual disk file (.vmdk) contains only persistent storage data, not volatile memory; memory contents are stored in a separate .vmem or .vmsn file, and extracting memory from a disk image is technically impossible. Option C is wrong because using a live forensic tool inside the VM requires executing code within the compromised environment, which alters memory contents (e.g., overwriting pages, changing process states) and risks triggering malware or tampering with evidence.

666
Multi-Selectmedium

Which TWO Windows Event IDs are associated with successful logon or explicit credential usage? (Choose TWO.)

Select 2 answers
A.4648
B.4720
C.4624
D.4625
E.7045
AnswersA, C

Event ID 4648 records a logon attempt using explicit credentials, such as when a user runs a process with `runas` or supplies alternate domain credentials for a network connection. This satisfies the stem’s constraint of “explicit credential usage” because the event logs the target account and the source process, distinguishing it from interactive logon events like 4624.

Why this answer

Event ID 4624 [CORRECT] is logged in the Windows Security log when a logon attempt succeeds, recording details such as logon type, account name, and authentication package, so it directly matches the 'successful logon' part of the question. Event ID 4648 [CORRECT] is generated when a process attempts an explicit logon using credentials other than those of the current logged-on user (for example, RunAs or passing alternate credentials), which matches the 'explicit credential usage' part. By contrast, 4720 is logged when a new user account is created, 4625 records a failed logon attempt, and 7045 is a System log event indicating a new service was installed — none of these represent a successful logon or explicit credential use.

Exam trap

The trap here is that candidates often confuse Event ID 4625 (failed logon) with 4624 (successful logon), or mistakenly associate 4720 (account creation) with logon activity, while overlooking the specific purpose of 4648 for explicit credential usage.

667
Multi-Selectmedium

In a Mac forensic investigation, which TWO artifacts are valuable for determining the timeline of file access? (Select two.)

Select 2 answers
A.ShellBags
B.Prefetch files
C.Unified logging
D.NTUSER.DAT
E.FSEvents
AnswersC, E

Unified logging is a macOS subsystem that captures structured, timestamped diagnostic messages from the kernel, processes, and user applications into binary .tracev3 stores under /var/db/diagnostics and /var/db/uuidtext. Investigators query it with log show or log stream to reconstruct file access, process execution, network activity, and system errors. It is a core native artifact on modern Macs and one of the two valid items in this question.

Why this answer

Unified logging (C) is correct because macOS's unified logging system (introduced in 10.12) stores system and application activity in .tracev3 files under /var/db/diagnostics, and its timestamps can establish when processes ran or files were touched, supporting timeline reconstruction. FSEvents (E) is correct because the FSEvents database (.fseventsd) records directory-level filesystem change events with timestamps, which is a core artifact for building a macOS file-access timeline. ShellBags (A) and NTUSER.DAT (D) are Windows artifacts (registry-based folder view settings and per-user registry hive, respectively) and do not exist on macOS.

Prefetch files (B) are also a Windows artifact (C:\Windows\Prefetch) used for program execution analysis, not macOS file-access timelines.

Exam trap

CHFI often tests the distinction between Windows-specific artifacts (ShellBags, Prefetch, NTUSER.DAT) and macOS-specific artifacts (Unified logging, FSEvents), so the trap here is assuming all forensic artifacts are cross-platform or that registry-based artifacts apply to macOS.

668
Multi-Selecthard

A malware analyst is performing dynamic analysis of a suspected trojan in a sandbox environment. Which of the following behaviours are strong indicators that the malware is establishing persistence on the infected system? (Select THREE.)

Select 3 answers
A.Creating a scheduled task that runs at system startup
B.Creating a Windows service named 'UpdateService'
C.Connecting to an IP address on port 443
D.Writing a value to HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E.Creating a mutex named 'Global\MyMutex'
AnswersA, B, D

Scheduled tasks provide persistence by registering a trigger that activates the malware at system startup, before any user logs on. Using tools like schtasks.exe or by dropping an XML task into C:\Windows\System32\Tasks, an attacker can run arbitrary code with SYSTEM privileges on every boot. Because the task is stored on disk and loaded by the Task Scheduler service, it satisfies the definition of an auto-start extension point (ASEP) and is a common persistence mechanism.

Why this answer

Option A is correct because creating a scheduled task configured to trigger at system startup (e.g., via schtasks or the Task Scheduler COM API with a boot/logon trigger) is a classic persistence mechanism that ensures the trojan executes automatically after reboots. Option B is correct because registering a Windows service (e.g., through CreateService or sc.exe) allows the malware to be launched by the Service Control Manager at boot, providing durable, privileged persistence. Option D is correct because writing a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run causes the referenced executable to be launched automatically at user logon, a well-known autostart persistence location.

Option C is not a persistence indicator; an outbound connection to port 443 typically reflects command-and-control or exfiltration activity, not survival across reboots. Option E is not a persistence indicator either; creating a named mutex such as Global\MyMutex is commonly used for single-instance enforcement or anti-analysis/anti-sandbox checks, not for maintaining execution on the host.

Exam trap

EC-Council often tests the distinction between persistence mechanisms and other malware behaviors (like network communication or inter-process synchronization), so the trap here is confusing network activity (C) or mutex creation (E) with persistence, when only startup-modifying actions (A, B, D) qualify.

669
Multi-Selecteasy

Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)

Select 2 answers
A.AES
B.SHA-1
C.Blowfish
D.RSA
E.MD5
AnswersB, E

SHA-1 (Secure Hash Algorithm 1) is a cryptographic hash function that generates a 160-bit (20-byte) message digest from arbitrary input data. It is widely used in digital forensics to hash evidence images and files, ensuring integrity throughout the chain of custody. Although collision attacks (e.g., the SHAttered example) have weakened its suitability for digital signatures, SHA-1 is still accepted for integrity verification in many forensic workflows. Its deterministic, one-way nature makes it a proper hashing algorithm, not an encryption or signing scheme.

Why this answer

SHA-1 (B) is a cryptographic hash function that produces a 160-bit digest and is widely used in forensic imaging tools to verify that a disk image has not been altered, making it correct here. MD5 (E) is likewise a common hashing algorithm producing a 128-bit digest, and it is routinely paired with SHA-1 to validate the integrity of forensic images, so it is also correct. AES (A) is a symmetric block cipher used for encryption, not a hashing algorithm, so it does not verify integrity.

Blowfish (C) is also a symmetric encryption cipher, not a hash function. RSA (D) is an asymmetric public-key algorithm used for encryption and digital signatures, not for generating integrity hashes.

Exam trap

The CHFI exam often tests the distinction between encryption algorithms (AES, Blowfish, RSA) and hashing algorithms (MD5, SHA-1), trapping candidates who confuse confidentiality functions with integrity verification functions.

670
MCQmedium

During a forensic analysis of a drive, the examiner discovers a Host Protected Area (HPA). What is the primary purpose of an HPA?

A.To store the file system journal
B.To accelerate disk read/write operations
C.To provide a hidden storage area not visible to the OS
D.To store backup copies of the MBR
AnswerC

The HPA is a deliberately reserved area of a disk that is hidden by reducing the total reported sector count, so the OS and standard tools see a smaller drive and cannot access the hidden region through normal commands. This permits storage of diagnostic utilities, recovery images, or other data that should remain invisible, and it is not formatted or mounted unless special ATA commands are issued to restore full address space.

Why this answer

The Host Protected Area (HPA) is a reserved region on an ATA/ATAPI hard drive that is not accessible through standard operating system interfaces. Its primary purpose is to provide a hidden storage area that remains invisible to the OS, often used by manufacturers for diagnostic tools, system recovery images, or other vendor-specific data. This is defined by the ATA-4 standard (ANSI NCITS 317-1998) and is accessed via the SET MAX ADDRESS command.

Exam trap

The CHFI exam often tests the misconception that the HPA is used for storing backup copies of the MBR or boot-critical data, but the HPA is actually a vendor-reserved area for utilities and recovery tools, not for boot records.

How to eliminate wrong answers

Option A is wrong because the file system journal is stored in a regular partition (e.g., NTFS $LogFile or ext3/4 journal) and is visible to the OS, not in the HPA. Option B is wrong because HPA does not accelerate read/write operations; it is a reserved area that reduces the total addressable space, potentially slightly decreasing performance due to reduced LBA range. Option D is wrong because backup copies of the Master Boot Record (MBR) are typically stored in the last sector of the disk or in a separate partition (e.g., GPT backup header), not in the HPA, which is a separate ATA feature.

671
MCQeasy

A forensic investigator is examining a MySQL database server that was compromised. The investigator needs to determine which user account was used to perform unauthorized modifications to a critical table. The MySQL server has the general query log enabled. Which of the following should the investigator review to find the user account associated with the modifications?

A.The MySQL slow query log
B.The MySQL general query log
C.The MySQL error log
D.The MySQL binary log
AnswerB

The MySQL general query log records all SQL statements received from clients, along with the user account and connection details. By reviewing this log, the investigator can identify the exact queries that modified the table and the user account that executed them. This is the correct source for this information.

Why this answer

The MySQL general query log captures all SQL statements along with the user account and connection information. This makes it the ideal source for determining which user executed specific modifications. Other logs like the error log, binary log, and slow query log do not provide the user account context needed for this forensic task.

Exam trap

The trap here is assuming that the binary log contains user information because it records data changes.

672
Multi-Selecthard

During dynamic analysis of a malware sample, an analyst observes the following: creation of a mutex named `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`, a registry key under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` named `WindowsUpdate`, and outbound TCP traffic to `203.0.113.5:443`. Which THREE of the following indicators of compromise (IoCs) should be documented?

Select 3 answers
A.Outbound TCP to `203.0.113.5:443`
B.SHA256 hash of the malware sample
C.Mutex name `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`
D.File path `C:\Windows\System32\notepad.exe`
E.Registry key `HKCU\...\Run\WindowsUpdate`
AnswersA, C, E

The outbound TCP connection to 203.0.113.5 on port 443 is a classic command-and-control indicator observed during network-level monitoring. Even though this IP falls in the RFC 5737 TEST-NET-3 range often used for documentation, it represents the actual endpoint the malware contacted in the sandbox, demonstrating the value of capturing live connections for threat hunting.

Why this answer

Option A is correct because the observed outbound TCP connection to 203.0.113.5:443 is a network-based IoC that can be used for detection, blocking, and threat hunting, and the specific IP and port should be documented exactly as observed. Option C is correct because the mutex name Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C} is a host-based IoC; mutexes are often unique to a malware family or campaign and can be used to identify infection or prevent reinfection. Option E is correct because the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate is a persistence IoC, since the Run key causes the named value to execute at user logon and should be documented for detection and remediation.

Option B is not among the observed dynamic behaviors listed in the scenario, even though a sample hash is useful context, and Option D is a legitimate Windows system file path that is not an IoC in this scenario.

Exam trap

The CHFI exam often tests the distinction between static IoCs (like file hashes) and dynamic IoCs (like network traffic, mutex names, and registry modifications) to see if candidates understand that dynamic analysis focuses on behavioral artifacts, not file-level attributes.

673
Multi-Selectmedium

Which TWO of the following tools are commonly used for file carving in forensic investigations?

Select 2 answers
A.Autopsy
B.PhotoRec
C.Foremost
D.EnCase
E.Wireshark
AnswersB, C

PhotoRec is a purpose-built file carving utility that operates by reading raw disk blocks and identifying known file signatures, independent of the filesystem metadata. It recovers a wide range of file types (e.g., JPEG, PDF, Office documents, archives) by scanning for magic numbers and reconstructing data based on internal structure. PhotoRec is part of the TestDisk suite and is widely used in data recovery and forensic investigations because it works on corrupted or formatted media. Its design as a standalone carving engine makes it a canonical example of a file carving tool.

Why this answer

PhotoRec (B) is a free, open-source file carving utility from the TestDisk suite that recovers files by scanning raw disk images or devices for known file signatures (headers/footers), ignoring the filesystem, which is exactly what file carving means. Foremost (C) is another classic carving tool originally developed for the U.S. Air Force OSI, which uses a configurable header/footer signature database (foremost.conf) to extract files from disk images and is widely cited in forensic curricula.

Autopsy (A) is a full digital forensics platform (a GUI front-end to The Sleuth Kit) that performs timeline, keyword, and artifact analysis; although it can invoke carving, it is not primarily a carving tool. EnCase (D) is a commercial forensic suite for imaging and analysis rather than a dedicated carver. Wireshark (E) is a network protocol analyzer that captures and inspects packet traffic, unrelated to recovering files from storage media.

Exam trap

EC-Council often tests the distinction between tools that perform file carving natively (PhotoRec, Foremost) versus tools that are forensic suites or network analyzers, leading candidates to mistakenly select Autopsy or EnCase because they associate them with forensic analysis in general.

674
Multi-Selectmedium

Which TWO of the following are requirements for evidence to be admissible in court? (Select two.)

Select 2 answers
A.Evidence must be reliable
B.Evidence must be encrypted
C.Evidence must be stored on a write-blocked drive
D.Evidence must be obtained by the police
E.Evidence must be relevant
AnswersA, E

Reliability for digital evidence means the court can trust the accuracy and integrity of the data, which requires proving that the evidence is authentic, unaltered, and traceable through a verifiable chain of custody. Under standards such as Daubert or FRE 901, the proponent must show that the forensic tools and methods used were generally accepted and correctly applied. If the data's integrity cannot be demonstrated, the evidence is inadmissible no matter how pertinent it may be to the case.

Why this answer

The rules of evidence require that evidence be admissible, reliable, complete, and authentic. In many jurisdictions, evidence must be relevant and reliable to be admissible. Completeness and authenticity are also key.

675
MCQeasy

During the first response to a computer incident, which of the following actions is MOST critical for preserving evidence?

A.Run antivirus software to remove any malware
B.Disconnect the power to prevent data alteration
C.Photograph the scene including all visible cables and connections
D.Immediately boot the system to verify it is operational
AnswerC

Photographing the scene is a non-invasive, evidence-preserving action that documents the original physical and logical configuration of the system before any other activity occurs. These photographs capture cable connections, external peripherals, hardware settings, and visible on-screen data, which are critical for reconstructing the incident and proving chain of custody. Unlike software execution or power cycling, photography introduces no changes to the system and creates a permanent, timestamped record that is admissible in court. This alone makes it the correct first response in a computer incident.

Why this answer

Photographing the scene, including all visible cables and connections, is the most critical first step in preserving the chain of custody and documenting the exact physical state of the system before any changes occur. This visual record captures port assignments, device connections, and cable orientations that could be altered by subsequent actions, ensuring that the original configuration is preserved for forensic analysis. Without this documentation, later evidence of network topology or peripheral involvement may be lost or disputed.

Exam trap

The CHFI exam often tests the misconception that immediately disconnecting power (Option B) is the safest action, but the trap is that this destroys volatile evidence and may cause unintended writes, whereas photographing the scene is the least intrusive and most defensible first step for preserving the physical state of evidence.

How to eliminate wrong answers

Option A is wrong because running antivirus software modifies the system by scanning, quarantining, or deleting files, which alters the original data and violates forensic integrity principles (e.g., overwriting slack space or modifying timestamps). Option B is wrong because disconnecting power on a running system can cause loss of volatile data (e.g., RAM contents, open network connections, process lists) and may trigger write operations during shutdown, potentially corrupting evidence. Option D is wrong because immediately booting the system writes new data to the disk (e.g., log files, temporary files, registry changes) and overwrites unallocated space, destroying potential evidence and violating the 'do not modify the original' forensic rule.

Page 8

Page 9 of 10

Page 10

All pages