Courseiva

CCNA Mobile and Malware Forensics Questions

75 of 119 questions · Page 1/2 · Mobile and Malware Forensics · Answers revealed

1
MCQhard

An analyst runs 'regshot' before and after executing a suspicious binary. The report shows that the binary added a value to HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to C:\Windows\system32\malware.exe and 'Start' set to 2. What is the MOST likely purpose?

A.Hiding network connections
B.Encrypting files
C.Disabling a legitimate service
D.Persistence as a service
AnswerD

The Start value of 2 (SERVICE_AUTO_START) in a newly created service registry key instructs the Service Control Manager to launch the service automatically during system startup, before a user logs on. This is a well-known persistence technique because the malicious binary is executed with SYSTEM privileges on every boot, surviving reboots. The presence of this service key, with its image path pointing to the suspect executable, is direct evidence that the malware has installed a persistent service. This matches the observed change exactly and explains why the analyst sees a new service entry rather than a modification to an existing one.

Why this answer

The binary added a service entry under HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to malware.exe and 'Start' set to 2 (SERVICE_AUTO_START). This ensures the malware launches automatically at system boot, which is a classic persistence mechanism. The 'Start' value of 2 specifically configures the service to start automatically, making it persist across reboots.

Exam trap

EC-Council often tests the distinction between creating a new service for persistence versus modifying an existing service's startup type or disabling it, and candidates may confuse the 'Start' value of 2 (auto-start) with a disabled state (value 4).

How to eliminate wrong answers

Option A is wrong because hiding network connections is typically achieved by rootkits, API hooking, or manipulating network stack components (e.g., NDIS drivers), not by simply adding a service entry. Option B is wrong because encrypting files is a ransomware behavior that would involve file system operations or cryptographic API calls, not merely creating a service with an ImagePath. Option C is wrong because disabling a legitimate service would involve modifying the 'Start' value of an existing service (e.g., setting it to 4 for disabled) or deleting it, not creating a new service with a malicious ImagePath.

2
MCQmedium

During an iOS forensic examination, an analyst extracts the iTunes backup of a suspect iPhone. The analyst wants to review deleted SMS messages. Which SQLite database file should be examined?

A.AddressBook.db
B.Keyboard.db
C.SMS.db
D.call_history.db
AnswerC

This is the primary database in iOS that stores both SMS (via cellular) and iMessage (via Apple's push service) conversations. It contains tables such as 'message' and 'chat' that record the full message text, timestamps (in Apple's Core Data format), phone numbers/identifiers, and flags for read/delivered status. Even deleted messages can sometimes be recovered from unused or free pages within the SQLite file until those blocks are overwritten, making it the key artifact for forensic message analysis.

Why this answer

In iOS forensics, deleted SMS messages are stored in the SMS.db SQLite database located within the iTunes backup. This database contains the `message` table, which retains deleted messages until overwritten by new data, making it the primary target for recovering deleted iMessages and SMS texts.

Exam trap

EC-Council often tests the misconception that deleted SMS messages are stored in a separate 'deleted items' database or that call_history.db contains SMS data, leading candidates to overlook the primary SMS.db file.

How to eliminate wrong answers

Option A is wrong because AddressBook.db stores contact information (names, phone numbers, emails), not SMS message content. Option B is wrong because Keyboard.db stores keyboard usage data (e.g., learned words, autocorrect entries), not SMS messages. Option D is wrong because call_history.db contains call logs (incoming, outgoing, missed calls), not SMS text messages.

3
MCQhard

During malware analysis, an analyst discovers that a sample uses a technique to modify its own code at runtime to evade signature detection. Which anti-forensic technique does this describe?

A.Log wiping
B.Packing/Obfuscation
C.Encryption
D.Timestomping
AnswerB

Self-modifying code is a hallmark of packing and obfuscation, as malicious samples often decrypt, decompress, or rewrite their own instruction stream in memory before execution. This runtime mutation is exactly what packers like UPX or custom crypters achieve by using a stub that unpacks the original code into memory, so the on-disk representation appears static while the executing image evolves. Such behavior directly matches the analyst's observation, making packing/obfuscation the correct answer because the code's self-modification is a deliberate obfuscation technique designed to evade static signatures and hinder analysis.

Why this answer

The technique of modifying code at runtime to evade signature detection is known as packing or obfuscation. Packers compress or encrypt the original executable and wrap it with a small stub that decompresses or decrypts the code in memory during execution, thereby altering the static file signature. This runtime modification allows the malware to bypass signature-based antivirus and forensic tools that rely on static analysis of the binary on disk.

Exam trap

The CHFI exam often tests the distinction between encryption as a general concept and packing/obfuscation as a specific anti-forensic technique that combines encryption with runtime code modification to evade static signature detection.

How to eliminate wrong answers

Option A is wrong because log wiping refers to the deliberate deletion or alteration of system, application, or security logs (e.g., clearing Windows Event Logs or /var/log/messages) to cover tracks, not to modifying code at runtime. Option C is wrong because encryption, while used in packing, is a broader cryptographic concept that protects data confidentiality; the specific anti-forensic technique described here is packing/obfuscation, which combines encryption/compression with a runtime stub to alter the executable's static signature. Option D is wrong because timestomping is the act of modifying file timestamps (e.g., using SetFileTime on Windows or touch -t on Linux) to mislead timeline analysis, not modifying code at runtime.

4
MCQhard

An examiner acquires a full file system image from an Android device running Android 11. While parsing the image, they need to identify which application was used to send a specific SMS message that was deleted shortly after being sent. The device uses Google Messages as the default SMS app. Which artefact location is MOST likely to contain remnants of the deleted SMS content?

A.The mmssms.db SQLite database in /data/data/com.android.providers.telephony/databases/
B.The WhatsApp msgstore.db in /data/data/com.whatsapp/databases/
C.The contacts2.db database in /data/data/com.android.providers.contacts/databases/
D.The com.google.android.gms database in /data/data/com.google.android.gms/databases/
AnswerA

The mmssms.db database stores SMS and MMS messages for the default messaging provider. Even when a message is deleted from the user interface, the underlying SQLite pages may retain deleted records until vacuumed. Google Messages writes to this provider database, so remnants of the deleted SMS can often be carved from freelist pages or recovered via WAL/journal files, making this the most direct artefact for the scenario.

Why this answer

SMS messages on Android are stored by the telephony provider in mmssms.db, regardless of which messaging app is used as the default. When a message is deleted, the SQLite record may remain in freelist pages or write-ahead log files until a vacuum operation occurs. The examiner should target this database and attempt carving or journal analysis to recover the deleted content.

Other databases serve different purposes and would not contain the SMS body.

Exam trap

The trap here is assuming that because Google Messages is a Google app, its data resides in a Google-specific database rather than the standard Android telephony provider.

5
MCQhard

A forensic analyst is examining a malware sample that uses packing to obfuscate its code. Which static analysis tool is BEST suited to identify the packer used and potentially unpack the executable?

A.PEiD
B.Cuckoo Sandbox
C.Ghidra
D.IDA Pro
AnswerA

PEiD uses signatures to detect packers, cryptors, and compilers. It can also assist in unpacking by identifying the entry point.

Why this answer

PEiD (Portable Executable Identifier) is specifically designed to detect packers, cryptors, and compilers used in PE files by scanning for known signatures in the executable's entry point. It is the best static analysis tool for identifying the packer and can often unpack the executable using its built-in generic unpacker or by invoking the packer's own unpacking stub. This makes it ideal for the initial triage of packed malware samples.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates may confuse a dynamic analysis sandbox (Cuckoo) or a general-purpose disassembler (Ghidra, IDA Pro) with a specialized static packer identifier like PEiD.

How to eliminate wrong answers

Option B is wrong because Cuckoo Sandbox is a dynamic analysis tool that executes the malware in a controlled environment to observe behavior, not a static analysis tool for identifying packers. Option C is wrong because Ghidra is a reverse engineering framework focused on disassembly and decompilation, but it lacks a dedicated packer signature database and automated unpacking capabilities like PEiD. Option D is wrong because IDA Pro is a powerful interactive disassembler and debugger, but it does not have a built-in packer identification database; while plugins can add this functionality, it is not the best-suited tool out of the box for this specific task.

6
MCQhard

A security analyst runs the command `regshot64.exe compare` after executing malware. Regshot reports that the following registry key was created: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate`. Which conclusion is MOST likely?

A.The malware encrypted the user's documents
B.The malware installed a persistence mechanism
C.The malware deleted a system file
D.The malware modified a network configuration
AnswerB

A persistence mechanism is commonly implemented by creating a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or the corresponding HKLM key. When regshot64.exe compare shows a new 'Run' value pointing to a suspicious executable, that is direct evidence the malware installed an auto-start mechanism. Registry modifications of this type are exactly what regshot is designed to detect, so this is the correct conclusion.

Why this answer

The registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate` is a standard Windows Run key, which automatically executes the specified program at user logon. By creating this key, the malware ensures it runs every time the user logs in, establishing persistence. This is a classic persistence mechanism, not an action related to encryption, file deletion, or network changes.

Exam trap

The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and other malware behaviors (like encryption or network changes), trapping candidates who assume any registry change indicates data destruction or system modification rather than survival.

How to eliminate wrong answers

Option A is wrong because encryption of user documents would typically involve file system changes (e.g., appending .encrypted extensions) or cryptographic API calls, not the creation of a Run registry key. Option C is wrong because deleting a system file would leave evidence in file system logs or cause immediate system instability, not create a Run key for persistence. Option D is wrong because modifying a network configuration (e.g., changing DNS settings, proxy, or firewall rules) involves different registry paths (e.g., `HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters`) or netsh commands, not the user-level Run key.

7
Multi-Selectmedium

A forensic examiner is analyzing an Android device that was factory reset. Which TWO artefacts or methods could the examiner use to potentially recover or identify data from before the reset?

Select 2 answers
A.Performing a logical extraction via ADB
B.Recovering deleted apps via ADB backup
C.Examining the device manually through the UI
D.Analyzing Google account artefacts synced to the cloud
E.Using a physical extraction tool like Cellebrite UFED
AnswersD, E

Analyzing the associated Google account's cloud artefacts is a valid approach because the user's sync history may contain contacts, calendar entries, Chrome browsing data, and app-specific backups that were uploaded prior to the reset. Cloud data is independent of the device's storage, so even though the device is wiped, the forensic examiner can obtain a trove of evidence by accessing the account with proper legal authority. This method does not depend on device configuration or flash-memory recovery, thus providing a reliable and often commercially supported avenue for evidence acquisition.

Why this answer

Option D is correct because data synced to the user's Google account (e.g., Gmail, Contacts, Calendar, Drive, Photos, and Android backups) resides in Google's cloud infrastructure and is not erased by a local factory reset, so the examiner can obtain pre-reset artefacts via the account or legal process. Option E is correct because a physical extraction tool such as Cellebrite UFED reads the underlying flash memory (often via ISP, JTAG, or chip-off) and can recover residual data, including remnants in unallocated space that survive a factory reset if not securely wiped. Option A does not belong because ADB logical extraction only exposes data accessible to the running OS or a debug-enabled device, and a factory reset removes user data and typically disables USB debugging.

Option B does not belong because ADB backup cannot recover deleted apps and requires debugging authorization that a reset device will not grant. Option C does not belong because manual UI examination only shows the post-reset state and cannot surface pre-reset data.

Exam trap

EC-Council often tests the misconception that a factory reset permanently destroys all data, but candidates must recognize that cloud-synced artifacts and physical extraction methods can recover pre-reset data, while logical methods (ADB, UI) are rendered useless by the reset.

8
MCQeasy

During a mobile forensic investigation of an iPhone, an examiner needs to recover deleted SMS messages. Which acquisition method provides the highest likelihood of retrieving deleted data from the device's flash memory?

A.Manual acquisition by taking screenshots
B.File system acquisition via iOS file system extraction
C.Physical acquisition via JTAG or chip-off
D.Logical acquisition via iTunes backup
AnswerC

Physical acquisition via JTAG (Joint Test Action Group) or chip-off directly images the device's raw NAND flash memory, providing a complete bit-for-bit copy of all storage—including allocated, unallocated, and deleted areas. This level of extraction bypasses the operating system's file abstraction layers and allows forensic tools to reconstruct files, including deleted messages, from raw data remnants. JTAG requires hardware-level connections to the device's test ports, while chip-off involves desoldering the memory chip, both yielding the most comprehensive evidence.

Why this answer

Physical acquisition via JTAG or chip-off provides the highest likelihood of recovering deleted SMS messages because it accesses the raw NAND flash memory at the hardware level, bypassing the iOS file system and logical abstractions. Deleted data on flash storage remains in unallocated blocks until overwritten, and physical imaging captures these remnants, including deleted SQLite records from the SMS database. In contrast, logical and file system methods only retrieve active files, missing the unallocated space where deleted messages reside.

Exam trap

EC-Council often tests the misconception that file system acquisition (Option B) can recover deleted data because it extracts the entire file system, but in iOS, the file system extraction does not include unallocated space due to the HFSX/APFS design and sandboxing, making physical acquisition the only method that accesses raw NAND for deleted SMS recovery.

How to eliminate wrong answers

Option A is wrong because manual acquisition via screenshots only captures visible, on-screen content and cannot access deleted data stored in unallocated flash memory. Option B is wrong because file system acquisition via iOS file system extraction retrieves only active files and metadata, not the raw NAND blocks containing deleted SMS records that have been marked as free but not yet overwritten. Option D is wrong because logical acquisition via iTunes backup only extracts files that are part of the backup manifest, which excludes deleted data that has been removed from the SQLite WAL or journal files and is not present in the backup snapshot.

9
Multi-Selecthard

During dynamic analysis of a malware sample in a sandbox, an analyst observes the following behaviours: (1) A file is created at C:\Windows\System32\drivers\etc\hosts, (2) A registry key is set at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateSvc, (3) Outbound TCP connections to 198.51.100.10 on port 8080. Which THREE of the following IoCs are MOST relevant to share with the threat intelligence team?

Select 3 answers
A.MD5 hash of the original malware file
B.Network connection to 198.51.100.10:8080
C.Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateSvc
D.Mutex name created by the malware
E.File path C:\Windows\System32\drivers\etc\hosts
AnswersB, C, E

This is a network-based IoC indicating C2.

Why this answer

The outbound TCP connection to 198.51.100.10 on port 8080 is a direct network-based indicator of compromise (IoC) that threat intelligence teams can use to block or monitor malicious C2 traffic. This IP and port combination represents a specific command-and-control endpoint, making it highly actionable for network defense and threat hunting.

Exam trap

EC-Council often tests the distinction between observed behaviors (file creation, registry modification, network connections) and derived IoCs (hashes, mutexes), tricking candidates into selecting all listed options rather than only those directly tied to the observed actions.

10
Multi-Selecteasy

Which THREE of the following are common indicators of compromise (IoCs) that can be used to detect malware infections?

Select 3 answers
A.The user's favorite color
B.The brand of the victim's computer
C.Registry key created by malware for persistence
D.MD5 or SHA-256 hash of the malware file
E.IP address of the command and control server
AnswersC, D, E

Malware often writes or modifies registry keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run to achieve persistence across reboots. This registry modification is a concrete host-based indicator of compromise, because it represents an unauthorized change to the system by the attacker. Security analysts can correlate the key path and subkeys with known malware names or command-line parameters to confirm an infection and determine where to mount a defense.

Why this answer

Option C is correct because malware frequently establishes persistence by creating or modifying registry keys (for example, under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or as a service entry), and such unauthorized registry changes are a classic host-based IoC. Option D is correct because cryptographic file hashes such as MD5 or SHA-256 uniquely identify known malicious files, allowing defenders to scan endpoints and compare against threat-intelligence hash feeds. Option E is correct because the IP address of a command-and-control (C2) server is a network-based IoC that can be blocked at the firewall or detected in proxy, DNS, and NetFlow logs to reveal infected hosts beaconing out.

Options A and B are not IoCs: a user's favorite color and the brand of a victim's computer are irrelevant personal or hardware attributes that provide no technical evidence of malware activity.

Exam trap

EC-Council often tests the distinction between user-specific or hardware-specific attributes (like favorite color or computer brand) and actual system-level artifacts that indicate compromise, leading candidates to mistakenly include irrelevant options if they do not focus on technical IoCs.

11
MCQmedium

In iOS forensics, which database file typically contains the call history, including incoming, outgoing, and missed calls?

A.Notes.db
B.call_history.db
C.AddressBook.db
D.SMS.db
AnswerB

call_history.db, typically under /private/var/mobile/Library/CallHistoryDB/, is the system SQLite database populated by the telephony daemon for all incoming, outgoing, and missed calls. It preserves fields such as the peer phone number, call date, duration, call status, and unique identifiers. In iOS forensics, this is the authoritative source for call records.

Why this answer

In iOS forensics, the call history (incoming, outgoing, and missed calls) is stored in the SQLite database file named `call_history.db`. This database is located within the root domain of the iOS file system (typically under `/private/var/mobile/Library/CallHistoryDB/`) and contains tables such as `call` and `call_history` that record each call's direction, duration, timestamp, and associated contact identifier. The CHFI exam specifically tests this file as the authoritative source for call log evidence.

Exam trap

EC-Council often tests the misconception that `AddressBook.db` or `SMS.db` might contain call logs because they store contact names and message threads, but the trap is that call history is stored in a separate, dedicated database (`call_history.db`) that is not linked to the address book or SMS databases.

How to eliminate wrong answers

Option A is wrong because `Notes.db` stores user notes and not call history; it is located in the `/private/var/mobile/Library/Notes/` directory and contains tables like `ZNOTE` and `ZNOTEBODY`. Option C is wrong because `AddressBook.db` (now `Contacts.db` in newer iOS versions) stores contact information (names, phone numbers, email addresses) but does not contain call log records; it is used for address book data, not call history. Option D is wrong because `SMS.db` stores SMS and iMessage conversations, including text messages and attachments, but not call history; it is found in `/private/var/mobile/Library/SMS/` and contains tables like `message` and `chat`.

12
MCQmedium

An Android device is found with factory reset performed. The forensic examiner wants to recover as much data as possible. Which of the following artefacts is MOST likely to survive a factory reset and provide useful evidence?

A.Deleted SQLite records from /data/data/
B.Data stored on the external SD card
C.Google account authentication tokens stored in AccountManager
D.Wi-Fi passwords from wpa_supplicant.conf
AnswerB

An Android factory reset deliberately preserves the user-accessible external SD card (e.g., /storage/emulated/0/ or an actual removable microSD) because it is considered user data separate from the system and app data partitions. During a reset, only the /data, /cache, and sometimes /system partitions are wiped; the external SD card remains intact unless the user explicitly chooses to format it. Forensic examiners should image the external SD card immediately, as it often contains photos, documents, downloads, and application-exported files that survive the reset. This persistence makes external SD card data the only viable option for recovery.

Why this answer

Factory reset wipes the /data partition, which includes /data/data/ (app data), AccountManager tokens, and system configuration files like wpa_supplicant.conf. However, external SD cards are typically not formatted during a factory reset because they are user-removable storage. Therefore, data stored on the external SD card (e.g., photos, videos, app backups) often survives intact and can provide valuable forensic evidence.

Exam trap

The CHFI exam often tests the misconception that factory reset wipes all storage, including external SD cards, but the standard Android factory reset only targets internal partitions, leaving external storage untouched unless the user selects the additional 'Erase SD card' option.

How to eliminate wrong answers

Option A is wrong because /data/data/ is part of the internal storage that is securely wiped during a factory reset, making deleted SQLite records unrecoverable via standard forensic tools. Option C is wrong because Google account authentication tokens are stored in AccountManager within the /data/system/ partition, which is erased on factory reset. Option D is wrong because wpa_supplicant.conf resides in /data/misc/wifi/, which is also wiped during factory reset, so Wi-Fi passwords are lost.

13
MCQhard

A security analyst observes a process on a Windows system creating a mutex named "Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}" shortly after execution. The analyst also notes outbound connections to an IP address 203.0.113.50 on port 4444. Which malware behaviour indicator is MOST clearly demonstrated?

A.Anti-debugging technique through timing checks
B.Single-instance execution safeguard and command and control communication
C.File encryption using a hardcoded AES key
D.Persistence mechanism via registry run keys
AnswerB

The named mutex is a classic single-instance safeguard: malware creates a distinctive mutex (e.g., a hardcoded name) so that if a second copy starts, it detects the existing mutex and exits, preventing duplicate infections or conflicting state. The concurrent outbound network connection is a strong indicator of command-and-control communication, as the process attempts to establish a channel to an external server for instructions or data exfiltration. Together, these two behaviors align with the observed evidence, making this the correct interpretation.

Why this answer

The mutex name 'Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}' is a well-known technique used by malware to ensure only one instance of itself runs on the system, preventing conflicts or multiple infections. The outbound connection to 203.0.113.50 on TCP port 4444 is a classic indicator of command and control (C2) communication, as port 4444 is commonly associated with reverse shells and C2 traffic (e.g., Metasploit default). Together, these two behaviors directly demonstrate single-instance execution safeguard and C2 communication.

Exam trap

EC-Council often tests the distinction between behavioral indicators (like mutex and network connections) and specific malware capabilities (like encryption or persistence), leading candidates to confuse a single-instance safeguard with anti-debugging or persistence techniques.

How to eliminate wrong answers

Option A is wrong because anti-debugging through timing checks involves measuring code execution time to detect debugger presence, not mutex creation or outbound connections. Option C is wrong because file encryption with a hardcoded AES key would manifest as file I/O operations and cryptographic API calls, not a mutex or a network connection on port 4444. Option D is wrong because persistence via registry run keys involves writing to 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run' or similar, which is not indicated by the mutex or the outbound connection.

14
MCQeasy

Which tool is specifically designed to perform physical extraction of data from mobile devices, including bypassing lock screens on many iOS and Android devices?

A.SIFT Workstation
B.FTK Imager
C.Cellebrite UFED
D.Wireshark
AnswerC

Cellebrite UFED (Universal Forensic Extraction Device) is a purpose-built mobile forensic tool specifically engineered to perform physical extraction from smartphones, tablets, and feature phones. It covers bootloader-level and exploit-based acquisition paths, enabling full filesystem images even when the screen is locked, and it also supports logical, file system, and chip-off/ISP extractions across thousands of device models. Its proprietary hardware and continuously updated breakout software make it the industry standard for extracting evidence from mobile devices when physical acquisition is required.

Why this answer

Cellebrite UFED (Universal Forensic Extraction Device) is a specialized hardware and software tool designed for physical extraction of data from mobile devices, including bypassing lock screen security on iOS and Android devices. It uses advanced techniques such as bootloader exploits, JTAG, chip-off, and proprietary software-based methods to acquire full file system images, even when the device is locked or encrypted.

Exam trap

EC-Council often tests the distinction between logical extraction (e.g., via ADB or iTunes backup) and physical extraction, and candidates may confuse FTK Imager (a computer forensics tool) with mobile extraction tools, missing that Cellebrite UFED is the only option capable of bypassing lock screens via hardware-level exploits.

How to eliminate wrong answers

Option A is wrong because SIFT Workstation is a forensic analysis platform for disk and memory analysis, not a mobile device extraction tool, and it cannot bypass lock screens. Option B is wrong because FTK Imager is a disk imaging tool for computers and storage media, lacking the hardware interfaces and exploit capabilities needed for mobile device physical extraction. Option D is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting network traffic, not for physical data extraction from mobile devices.

15
MCQmedium

A security analyst notices a process named 'svchost.exe' running from the directory 'C:\Users\Public\svchost.exe'. This is suspicious because legitimate svchost.exe runs from 'C:\Windows\System32'. What type of indicator is this?

A.Network indicator
B.Behavioural indicator
C.File hash indicator
D.Registry key indicator
AnswerB

The correct classification is a behavioral indicator because the security analyst is observing an execution pattern—svchost.exe running from a path other than its legitimate C:\Windows\System32 location. Behavioral indicators focus on deviations from known-good baseline activities, such as unusual process paths, command-line arguments, or parent-child process relationships. This process's anomalous path is a classic sign of masquerading or binary planting, making it a host-based behavioral red flag.

Why this answer

B is correct because the presence of svchost.exe in C:\Users\Public\ instead of C:\Windows\System32 indicates a deviation from the expected execution path, which is a classic behavioral indicator. Behavioral indicators focus on anomalous actions or file placements rather than static attributes like hashes or network traffic.

Exam trap

EC-Council often tests the distinction between static indicators (file hash, registry key) and dynamic indicators (behavioral, network), and the trap here is that candidates confuse a file path anomaly with a network or registry indicator because they associate svchost.exe with system-level activity.

How to eliminate wrong answers

Option A is wrong because a network indicator would involve IP addresses, domain names, or communication patterns (e.g., DNS queries to a C2 server), not the file path of a running process. Option C is wrong because a file hash indicator is a static signature (e.g., MD5/SHA-1 hash) used to identify known malware, not the location or behavior of a process. Option D is wrong because a registry key indicator involves modifications to Windows Registry keys (e.g., Run keys for persistence), not the file system path of an executable.

16
Multi-Selectmedium

A forensic analyst is examining an Android device using ADB extraction. Which TWO statements about ADB extraction are true?

Select 2 answers
A.ADB extraction requires USB debugging to be enabled on the device
B.ADB extraction allows full file system access without root
C.ADB extraction can acquire a physical image of the device
D.ADB extraction can recover deleted files from unallocated space
E.ADB extraction requires the device to be authorized to the computer
AnswersA, E

ADB cannot communicate with an Android device unless USB debugging is enabled in Developer Options, which starts and configures the adbd daemon to accept commands over the USB transport; without it, the device appears offline to the host. For a forensic analyst, toggling this setting modifies system settings, so its status and any resulting evidence-integrity impact must be documented before beginning logical acquisition.

Why this answer

Option A is correct because ADB (Android Debug Bridge) communication over USB is only possible when the device has USB debugging enabled in Developer Options; without it, the adb daemon on the host cannot establish a session with the device. Option E is correct because, once USB debugging is on, the device presents an RSA key fingerprint prompt and the host must be authorized (the device stores the host's public key in adb_keys); an unauthorized host is rejected, so the analyst must accept the prompt or pre-provision the key. Option B is wrong because non-rooted ADB access is confined to the shell user's permissions and cannot read protected app data or system partitions.

Option C is wrong because ADB extraction is a logical acquisition (e.g., adb pull, adb backup) and cannot produce a bit-for-bit physical image of the flash storage. Option D is wrong because deleted files in unallocated space are only recoverable from a physical image or raw flash dump, not through ADB's logical file-level access.

Exam trap

The CHFI exam often tests the misconception that ADB extraction provides full file system or physical access, but the trap is that ADB is a logical extraction method with significant privilege restrictions, and candidates confuse 'ADB backup' or 'ADB pull' with physical imaging capabilities.

17
MCQmedium

During a malware analysis, an analyst uses a tool to monitor registry changes, file system modifications, and process activity simultaneously. Which tool is BEST suited for this integrated monitoring?

A.Wireshark
B.Process Monitor
C.Regshot
D.Process Explorer
AnswerB

Process Monitor is the correct choice because it uses kernel-mode registry callbacks, a file-system minifilter, and ETW process/thread/network providers to record real-time operations with full paths, operation types, results, durations, and call stacks. It lets an analyst filter by process name, PID, registry key, file path, or operation, and preserve the event timeline in a PML log for detailed malware-behavior reconstruction. This makes it a true dynamic behavioral monitor rather than a packet capture or state-snapshot utility.

Why this answer

Process Monitor (ProcMon) is the correct tool because it integrates real-time monitoring of registry changes, file system modifications, and process/thread activity into a single interface. It combines the legacy tools Regmon (registry) and Filemon (file system) with process monitoring, allowing an analyst to correlate events across all three subsystems simultaneously, which is essential for dynamic malware analysis.

Exam trap

EC-Council often tests the distinction between tools that perform real-time integrated monitoring (Process Monitor) versus tools that offer only snapshot comparisons (Regshot) or specialize in a single subsystem (Process Explorer), leading candidates to confuse Regshot's registry snapshot capability with live monitoring.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects network traffic (e.g., packets over Ethernet, Wi-Fi), not registry, file system, or process activity. Option C is wrong because Regshot is a registry comparison tool that takes before-and-after snapshots of the registry and optionally the file system, but it does not monitor process activity or provide real-time, integrated monitoring. Option D is wrong because Process Explorer is a task manager and process analysis tool that shows detailed information about running processes, handles, and DLLs, but it does not monitor registry or file system changes in real time.

18
MCQmedium

A security analyst discovers a suspicious registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate. The key points to a file in AppData. What is the most likely purpose of this registry key?

A.It logs the user's keystrokes
B.It ensures the malware runs every time the user logs in
C.It is a legitimate Windows update configuration
D.It stores the malware's configuration settings
AnswerB

HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard per-user autostart location. When a user signs in, the Winlogon/userinit process reads every value under this key and executes the associated command line. Malware writes a value pointing to its executable in AppData so the payload is relaunched automatically on every successful login, establishing persistence.

Why this answer

The registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard Windows autostart location. Malware commonly adds an entry here to achieve persistence, ensuring it executes every time the user logs in. The suspicious name 'WindowsUpdate' is a common masquerade tactic to hide malicious intent.

Exam trap

The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and actual malware functionality; the trap here is assuming the key name 'WindowsUpdate' implies legitimate system behavior, when in fact it is a classic masquerade technique.

How to eliminate wrong answers

Option A is wrong because keystroke logging is a specific function of malware, not a property of the Run registry key itself; the key only specifies an executable to launch. Option C is wrong because legitimate Windows Update configuration is stored in system-level registry paths (e.g., HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate) and never in HKCU\...\Run. Option D is wrong because the Run key stores a command line to execute a program, not configuration settings; malware configuration is typically stored in separate files or other registry keys.

19
MCQmedium

A security analyst detects that a system's 'SeDebugPrivilege' is enabled for a suspicious process. Which technique is the malware MOST likely attempting to use?

A.Persistence through service
B.Anti-debugging
C.Network sniffing
D.Process injection
AnswerD

SeDebugPrivilege is a high-impact privilege that permits a process to obtain full access to other processes, including those running at higher integrity levels. Attackers commonly use it to enable process injection: with this privilege, they can call OpenProcess(PROCESS_ALL_ACCESS) on a victim process, then use WriteProcessMemory and CreateRemoteThread to inject and execute malicious code. The privilege is often present in admin or SYSTEM token but disabled by default, meaning the attacker must call AdjustTokenPrivileges to enable it before injection. This requirement directly explains why a security analyst would observe SeDebugPrivilege being manipulated in conjunction with process injection.

Why this answer

SeDebugPrivilege allows a process to debug other processes, including accessing and modifying their memory. Malware often enables this privilege to perform process injection, where malicious code is written into the memory of a legitimate process (e.g., via WriteProcessMemory and CreateRemoteThread) to evade detection and execute under the target process's context.

Exam trap

EC-Council often tests the misconception that SeDebugPrivilege is only for debugging or anti-debugging, but the exam trap is that it directly enables process injection and memory manipulation, not just debugging tools.

How to eliminate wrong answers

Option A is wrong because persistence through service typically involves creating or modifying Windows services (e.g., via sc.exe or registry keys like HKLM\SYSTEM\CurrentControlSet\Services), not enabling SeDebugPrivilege. Option B is wrong because anti-debugging techniques (e.g., IsDebuggerPresent, NtQueryInformationProcess) aim to prevent analysis, not leverage a debug privilege for code execution. Option C is wrong because network sniffing requires raw socket access or WinPcap/Npcap, not SeDebugPrivilege, which is a security privilege for process debugging.

20
MCQhard

During static analysis of a PE file, an analyst uses PEiD and detects the signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What should the analyst do next?

A.The file is clean; no further analysis needed
B.Unpack the file using a UPX unpacker or manual unpacking
C.Delete the file as it is definitely malware
D.Run the file in a sandbox immediately
AnswerB

Because UPX modifies the PE structure and replaces the original entry point with an unpacking stub, the file must first be unpacked to recover the original code for static analysis. If the sample retains a standard UPX header, running `upx -d` can restore it; otherwise, manual unpacking (e.g., OEP tracing via the pushad/popad pair, memory dump, and import reconstruction with Scylla or ImportREC) is required. Only then can strings, imports, and code logic be truly analyzed.

Why this answer

The signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' indicates the file is packed with UPX (Ultimate Packer for eXecutables). Packing is a common technique used by malware authors to obfuscate the original code and evade signature-based detection. The analyst must unpack the file using a UPX unpacker or manual unpacking to reveal the actual executable code for further static or dynamic analysis.

Exam trap

The CHFI exam often tests the misconception that a packer signature automatically indicates malware, when in fact packing is a legitimate software distribution technique and the analyst must unpack the file to determine its true nature.

How to eliminate wrong answers

Option A is wrong because the presence of a packer signature like UPX does not mean the file is clean; packing is often used to hide malicious code. Option C is wrong because deleting the file without analysis destroys potential evidence and may be premature—packed files can be legitimate software, and the analyst must verify. Option D is wrong because running a packed file in a sandbox may not reveal the true behavior, as the unpacking routine must execute first; static unpacking is the proper next step to obtain the unpacked binary for analysis.

21
MCQmedium

An investigator recovers a suspicious file from a compromised system. Using PEiD, the file is detected as 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What is the MOST appropriate next step in the analysis?

A.Delete the file as it is likely a false positive from a legitimate UPX-packed application.
B.Unpack the file using the UPX tool or manual unpacking to obtain the original executable.
C.Submit the packed file to VirusTotal to obtain a hash-based detection report.
D.Run the file in a sandbox without unpacking to observe dynamic behavior.
AnswerB

Unpacking is the correct next step because UPX is a reversible packer: the `upx -d` command can usually reconstruct the original executable, exposing the real code, import table, and resources for static analysis. Even if the UPX header is intentionally malformed or modified to resist automatic unpacking, a manual unpacking approach—using memory dumps, Scylla or ImpRec for import reconstruction—can recover the original logic. Analyzing the unpacked binary allows the investigator to identify malicious behavior without executing it, which is critical for understanding the threat and preserving integrity. This approach directly addresses the core investigative need to analyze the true payload, not just the packing stub.

Why this answer

The PEiD detection of 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' confirms the file is packed with UPX (Ultimate Packer for eXecutables). Packing obfuscates the original code and often evades static analysis. The most appropriate next step is to unpack the file using the UPX tool (with the -d switch) or manual unpacking to recover the original executable for deeper static and dynamic analysis.

Exam trap

EC-Council often tests the misconception that a packer detection alone indicates a false positive or that dynamic analysis without unpacking is sufficient, when in fact unpacking is the foundational step to reveal the true executable for both static and dynamic analysis.

How to eliminate wrong answers

Option A is wrong because deleting the file based solely on a UPX packer detection is premature; UPX is commonly used by malware to compress and obfuscate code, and a legitimate application does not preclude malicious intent. Option C is wrong because submitting the packed file to VirusTotal may yield a hash that differs from the unpacked malware, potentially missing detection signatures that rely on the unpacked code. Option D is wrong because running the packed file in a sandbox without unpacking may cause the unpacking stub to execute and then the malware to run, but the packed state prevents proper static analysis and may not trigger all dynamic behaviors if the unpacking fails or is environment-aware.

22
MCQmedium

A security analyst is reviewing the output from a forensic tool examining an iOS Keychain. The analyst finds an entry with the attribute 'kSecAttrAccessible' set to 'kSecAttrAccessibleWhenUnlockedThisDeviceOnly'. What does this indicate?

A.The item is backed up to iCloud and can be restored to another device
B.The item is accessible even when the device is locked
C.The item is only accessible when the device is unlocked and is not backed up to iCloud
D.The item is stored in the Secure Enclave and cannot be extracted
AnswerC

This is the accurate reading of kSecAttrAccessibleWhenUnlockedThisDeviceOnly: it couples a time-based access gate (only after device unlock) with a device-scoped protection boundary (no iCloud backup and no restoration to another device). Keychain items with this attribute are available to apps only while the user has unlocked the device, and they do not appear in encrypted backups. A forensic examiner needs the unlocked device or the passcode to obtain the item.

Why this answer

The attribute 'kSecAttrAccessibleWhenUnlockedThisDeviceOnly' in iOS Keychain indicates that the item can only be accessed when the device is unlocked and is not included in any backup (iCloud or iTunes). This is because the 'ThisDeviceOnly' suffix ties the encryption key to the device's UID, preventing migration to another device or restoration from backup. Option C correctly captures both conditions: accessibility only when unlocked and exclusion from backups.

Exam trap

EC-Council often tests the misconception that 'ThisDeviceOnly' only affects backup behavior, when in fact it also prevents restoration to another device, and candidates may confuse 'WhenUnlocked' with 'AfterFirstUnlock' or 'Always', which have different lock-state requirements.

How to eliminate wrong answers

Option A is wrong because 'ThisDeviceOnly' explicitly prevents the item from being backed up to iCloud or restored to another device; only items without that suffix can be migrated. Option B is wrong because 'WhenUnlocked' means the item is only accessible when the device is unlocked, not when locked; the 'kSecAttrAccessibleWhenUnlocked' class requires the device to be unlocked for decryption. Option D is wrong because the Keychain item is encrypted with a key derived from the device's UID and the user's passcode, but it is not stored in the Secure Enclave; the Secure Enclave handles cryptographic operations but does not store Keychain items directly.

23
Multi-Selectmedium

An analyst is performing dynamic analysis of a malware sample in Cuckoo Sandbox. Which TWO of the following are typical indicators of command and control (C2) communication?

Select 2 answers
A.The malware creates a registry run key for persistence
B.The malware performs DNS queries to a domain that resolves to a known malicious IP
C.The malware modifies system files in C:\Windows\System32
D.The malware creates a mutex named 'Global\MyMutex'
E.The malware makes HTTP POST requests to a domain registered 2 days ago
AnswersB, E

DNS queries to a domain that resolves to a known malicious IP are a classic C2 beaconing signature because the malware must resolve the hostname of its command-and-control server before establishing a session. During dynamic analysis, repeated DNS lookups to a domain tied to a malicious address indicate that the sample is attempting to reach infrastructure controlled by the attacker. The reputation correlation of the resolved IP raises the confidence that this is C2 communication rather than unrelated background traffic.

Why this answer

Option B is correct because DNS queries to a domain resolving to a known malicious IP are a classic C2 indicator: the malware must locate its controller, and threat-intel feeds flag such resolutions as beaconing to adversary infrastructure. Option E is correct because HTTP POST requests to a newly registered domain (2 days old) fit the C2 profile of exfiltrating victim data or receiving tasking over web protocols, and domain age is a strong reputation signal for malicious infrastructure. Option A is not a C2 indicator but a persistence technique via the Registry Run key.

Option C describes system file modification, which indicates tampering or defense evasion rather than network C2. Option D describes mutex creation, which is typically used for single-instance checks or host-based sandbox-evasion markers, not command-and-control traffic.

Exam trap

EC-Council often tests the distinction between local host artifacts (persistence, mutexes, file modifications) and network-based C2 indicators, tricking candidates into selecting any suspicious behavior rather than focusing specifically on outbound communication patterns.

24
Multi-Selecthard

A malware analyst is analyzing a suspicious executable. Which THREE of the following are valid indicators of compromise (IoCs) that can be extracted from static analysis of the PE file? (Select THREE)

Select 3 answers
A.IP addresses from embedded strings
B.Registry keys modified during execution
C.MD5 hash of the file
D.File paths created during execution
E.List of imported DLLs and functions
AnswersA, C, E

IP addresses embedded in the binary are static indicators because a strings extraction (e.g., `strings` or `floss`) can reveal them directly from the file bytes without executing the sample. These addresses often point to hardcoded command-and-control servers, and can be correlated with threat-intel feeds or observed network traffic. The malware analyst can triage the sample purely from static artifacts, making this a valid static IoC.

Why this answer

Option A is correct because static analysis of a PE file routinely includes extracting embedded strings, and hardcoded IP addresses or URLs found in the binary are classic network-based IoCs that can be used for blocking and detection. Option C is correct because the MD5 hash of the file is a cryptographic file-based IoC computed directly from the sample without executing it, allowing analysts to pivot in threat-intelligence platforms and write hash-based detection rules. Option E is correct because the PE import table is parsed statically, and the list of imported DLLs and functions (e.g., CreateRemoteThread, VirtualAllocEx, WinINet APIs) reveals capabilities and is a valid host/behavioral IoC used in YARA and hunting rules.

Option B is not correct because registry keys modified during execution can only be observed through dynamic analysis (e.g., Procmon, Regshot), not from static inspection of the PE file. Option D is not correct because file paths created during execution are also runtime artifacts revealed by dynamic analysis or sandboxing, not extractable from the static structure of the executable.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse runtime artifacts (like registry or file system changes) with data extractable from the PE file itself without execution.

25
MCQmedium

During an iOS forensic examination, an analyst extracts the SMS.db file from an iTunes backup. Which table within this database contains the actual message content and associated metadata such as timestamps and sender/recipient information?

A.chat
B.message
C.attachment
D.handle
AnswerB

The 'message' table is the core target because each row represents a single SMS or iMessage, with columns such as 'text' (the message body), 'date' (absolute Unix time), 'is_from_me', and 'handle_id' linking to the sender. Logical forensic extraction typically includes this table to recover the actual words exchanged. Even when attachments or group metadata are involved, the text originates here, making it the correct choice.

Why this answer

The `message` table in SMS.db stores the actual message content (the `text` field) along with critical metadata such as `date` (Unix timestamp), `is_from_me` (sender/recipient indicator), and `handle_id` (foreign key to the `handle` table). This is the primary table for message body and timestamp data in iOS SMS/MMS forensics.

Exam trap

EC-Council often tests the distinction between the `message` table (content + timestamps) and the `handle` table (contact identifiers), leading candidates to confuse the `handle` table as containing message data when it only stores address book references.

How to eliminate wrong answers

Option A is wrong because the `chat` table stores conversation groupings (chat rooms) and references to messages via the `chat_message_join` table, not the message content itself. Option C is wrong because the `attachment` table stores metadata about file attachments (e.g., filename, MIME type, transfer state) but not the text content of messages. Option D is wrong because the `handle` table stores contact identifiers (phone numbers, email addresses) and their service types (iMessage, SMS), not the message body or timestamps.

26
MCQmedium

During a malware analysis session, an analyst uses Process Monitor (Procmon) to observe a suspicious executable. Which of the following behavioral indicators would MOST strongly suggest the malware is attempting to establish persistence?

A.Making outbound TCP connections to an IP address
B.Creating a named mutex
C.Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run
D.Creating files in the %TEMP% directory
AnswerC

Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence technique because entries under this key are executed automatically each time the logged-in user starts a Windows session. This location is attractive to malware since it requires no elevated privileges to modify and survives reboots, allowing the malicious payload to re-launch on every user logon. Removing the registry value eliminates the persistence, which is why it is monitored by tools like Sysinternals Autoruns.

Why this answer

Writing to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism because Windows automatically launches programs listed in this registry key at user logon. Process Monitor capturing a write to this key directly indicates the malware is configuring itself to run on startup, which is the strongest evidence of persistence among the options.

Exam trap

EC-Council often tests the distinction between runtime indicators (network connections, mutexes, temp files) and persistence mechanisms (registry Run keys, scheduled tasks, startup folders), so candidates mistakenly pick outbound connections or mutexes as persistence when they are not.

How to eliminate wrong answers

Option A is wrong because making outbound TCP connections indicates network communication (e.g., C2 beaconing), not persistence. Option B is wrong because creating a named mutex is a synchronization primitive used to prevent multiple instances of a process, not a persistence mechanism. Option D is wrong because creating files in %TEMP% is typical for temporary data extraction or staging, but does not ensure the malware runs again after reboot.

27
Multi-Selectmedium

During an iOS forensics investigation, an examiner extracts an iTunes backup and finds the SQLite database files. Which TWO of the following databases are LEAST likely to contain forensically relevant artefacts for a communication analysis?

Select 2 answers
A.SMS.db
B.data_ark.db
C.AddressBook.db
D.tmp.db
E.call_history.db
AnswersB, D

Not a standard iOS backup database; likely not present or relevant.

Why this answer

B is correct because data_ark.db is not a standard iOS SQLite database; it does not exist in typical iOS backups or file systems. The name suggests a fabricated or non-standard artefact, making it least likely to contain forensically relevant communication data. In contrast, databases like SMS.db and call_history.db are well-documented repositories for SMS messages and call logs, respectively.

Exam trap

EC-Council often tests candidates' familiarity with standard iOS database filenames, and the trap here is that 'data_ark.db' sounds plausible (like an 'ark' for data) but is not a real iOS database, leading examinees to overlook it as a distractor.

28
Multi-Selectmedium

A malware analyst is performing dynamic analysis of a suspicious executable in a Cuckoo Sandbox environment. Which THREE of the following behavioural indicators would be considered suspicious and warrant further investigation?

Select 3 answers
A.Creating a mutex with a hardcoded name
B.Reading registry keys under HKLM\HARDWARE
C.Modifying the hosts file to redirect a domain
D.Writing a temporary file to %TEMP%
E.Connecting to an IP address associated with a known command-and-control server
AnswersA, C, E

A Windows mutex is a kernel synchronization object that malware commonly creates with a fixed, family-specific name to enforce single-instance execution. Because the name is deterministic across samples of the same family, dynamic analysis capturing this API call yields a stable behavioral signature, and analysts can query kernel object namespaces to discover it. Legitimate applications rarely use such distinctive hardcoded mutex names, making this a strong IoC.

Why this answer

Option A is correct because creating a mutex with a hardcoded name is a classic malware behavior used to prevent multiple instances of the same infection from running simultaneously, and the specific name can serve as a host-based indicator of compromise (IOC) for detection and family identification. Option C is correct because modifying the hosts file to redirect a domain is a common technique for DNS hijacking, blocking security vendor updates, or redirecting legitimate traffic to attacker-controlled infrastructure, and it is highly suspicious in a sandbox run. Option E is correct because connecting to an IP address associated with a known command-and-control (C2) server is a direct indicator of malicious beaconing and exfiltration activity, and it is one of the strongest network-level IOCs in dynamic analysis.

Option B is not suspicious because reading registry keys under HKLM\HARDWARE is a routine operation performed by many legitimate applications and drivers to enumerate hardware configuration. Option D is not suspicious because writing a temporary file to %TEMP% is normal behavior for a wide range of benign installers, updaters, and applications, so it does not by itself warrant further investigation.

Exam trap

The CHFI exam often tests the distinction between common benign operations (like reading hardware registry keys or writing to %TEMP%) and truly malicious indicators, so candidates mistakenly flag normal system activities as suspicious without considering context.

29
MCQmedium

A forensic analyst is examining a SQLite database from an iOS device backup. The database contains a table named 'message' with columns 'ROWID', 'text', 'handle_id', and 'date'. This database is MOST likely part of which iOS system database?

A.SMS.db
B.call_history.db
C.Calendar.db
D.AddressBook.db
AnswerA

SMS.db is the iOS SQLite database that stores both SMS text messages and iMessage conversations. The 'message' table contains core evidence such as message text, ROWID, handle_id (linking to the phone number or email), date as Apple epoch nanoseconds, and the 'is_from_me' flag. The 'handle' table maps handles to actual addresses, and the 'service' column distinguishes between iMessage and SMS, making SMS.db the authoritative source for messaging forensics.

Why this answer

The 'message' table with columns 'ROWID', 'text', 'handle_id', and 'date' is the core schema of the SMS.db database on iOS devices. This database stores iMessage and SMS/MMS messages, where 'handle_id' links to the 'handle' table for contact identifiers and 'date' stores the timestamp in Apple's absolute time (seconds since 2001-01-01). The presence of these specific columns confirms it is the SMS/Message database.

Exam trap

The CHFI exam often tests the misconception that 'message' tables are found in AddressBook.db or Calendar.db, but the specific column set (ROWID, text, handle_id, date) is unique to SMS.db in iOS forensics.

How to eliminate wrong answers

Option B is wrong because call_history.db stores call logs with columns like 'Z_PK', 'ZADDRESS', 'ZDATE', and 'ZDURATION', not a 'message' table with 'text' and 'handle_id'. Option C is wrong because Calendar.db uses tables like 'CalendarItem' and 'Recurrence' with columns for event dates and titles, not a 'message' table. Option D is wrong because AddressBook.db (now Contacts.sqlite) uses tables like 'ABPerson' and 'ABMultiValue' for contact data, not a 'message' table for text conversations.

30
MCQeasy

In mobile forensics, which acquisition method preserves the highest level of data integrity and captures the most data from an iOS device?

A.File system acquisition
B.Physical acquisition
C.Logical acquisition
D.Manual acquisition
AnswerB

Physical acquisition creates a bit-for-bit, forensically sound image of the entire flash memory chip, including unallocated sectors, deleted file fragments, file system slack, and even data remnants from previous partitions. This method is the only approach that preserves the full forensic data set without relying on the device's operating system to filter or sanitize the output. By capturing the complete NAND image, it maximizes data integrity and completeness, making it unequivocally the correct choice for a preservation-focused acquisition.

Why this answer

Physical acquisition is correct because it creates a bit-for-bit copy of the entire flash storage, including unallocated space, deleted files, and system partitions. This method bypasses the iOS file system abstraction, preserving the highest data integrity and capturing all recoverable data, unlike higher-level acquisitions that only retrieve accessible files.

Exam trap

EC-Council often tests the misconception that 'file system acquisition' is the most thorough because it includes system files, but the trap is that physical acquisition alone captures unallocated space and deleted data, which file system acquisition cannot access due to iOS sandboxing and file system abstraction.

How to eliminate wrong answers

Option A is wrong because file system acquisition only copies allocated files and metadata visible through the iOS file system (e.g., via AFC or iTunes backup), missing deleted data and unallocated space, thus providing lower integrity and less data. Option C is wrong because logical acquisition extracts only user-accessible data (e.g., contacts, messages) via APIs like iTunes backup or libimobiledevice, ignoring system files and deleted artifacts, resulting in the least data capture. Option D is wrong because manual acquisition involves physically interacting with the device screen to capture data (e.g., screenshots or notes), which is highly operator-dependent, alters the device state, and cannot recover hidden or deleted data, offering the lowest integrity and data completeness.

31
MCQhard

In an iOS forensic examination, an analyst extracts an encrypted iTunes backup. The backup contains a file named 'manifest.plist' which lists the backup version and encryption state. Which tool is specifically designed to brute-force the backup password using GPU acceleration?

A.Hashcat
B.Oxygen Forensic Detective
C.Cellebrite UFED
D.GrayKey
AnswerA

Hashcat is the only listed tool designed for GPU-accelerated offline password recovery, and mode 14700 specifically targets iTunes backup password hashes extracted from Manifest.plist. An examiner converts the encrypted backup metadata into a hash format that Hashcat can attack, then uses dictionary, rule-based, or brute-force attacks on GPUs. This makes it uniquely suited for recovering the backup encryption password when the device passcode is unknown or when legal authority permits an offline attack.

Why this answer

Hashcat is the correct tool because it is a password recovery utility that leverages GPU acceleration to perform high-speed brute-force attacks on encrypted iTunes backup passwords. It can directly process the password hash extracted from the 'manifest.plist' file, which contains the backup version and encryption state, allowing efficient cracking of the backup password.

Exam trap

The CHFI exam often tests the distinction between tools used for physical device extraction (like Cellebrite UFED or GrayKey) versus those used for password cracking (like Hashcat), and the trap here is that candidates may confuse GrayKey's passcode bypass capability with backup password cracking, even though GrayKey does not use GPU acceleration for brute-forcing encrypted backups.

How to eliminate wrong answers

Option B (Oxygen Forensic Detective) is wrong because it is a forensic analysis suite for extracting and analyzing mobile device data, not a dedicated password cracking tool with GPU acceleration. Option C (Cellebrite UFED) is wrong because it is a physical extraction and forensic imaging tool for mobile devices, not designed for brute-forcing encrypted backup passwords using GPU acceleration. Option D (GrayKey) is wrong because it is a specialized device for bypassing iOS passcodes via hardware exploits or software vulnerabilities, not for cracking encrypted iTunes backup passwords with GPU-accelerated brute-force attacks.

32
MCQmedium

An incident responder receives an alert that a workstation is beaconing to a known malicious IP address. The responder captures network traffic and analyzes it with Wireshark. Which of the following would be an immediate indicator of compromise (IoC) visible in the traffic capture?

A.Large file transfers during off-hours
B.ARP requests from unknown MAC addresses
C.Encrypted payloads using TLS 1.3
D.Repeated connections to a known malicious IP address on a non-standard port
AnswerD

Repeated connections to a known malicious IP address on a non-standard port is a high-fidelity indicator of compromise because it combines an established threat reputation with observable behavior that matches command-and-control (C2) beaconing. Non-standard ports are often used by malware to evade simple port-based filters, and the recurrence suggests a persistent callback rather than an accidental or one-time connection. This pattern directly aligns with the MITRE ATT&CK technique T1071 for application-layer C2 traffic.

Why this answer

Repeated connections to a known malicious IP address on a non-standard port directly match the definition of a beaconing indicator of compromise (IoC). In network traffic analysis, beaconing is characterized by periodic, outbound connections to a command-and-control (C2) server, often using a non-standard port to evade detection. This pattern is a primary IoC in malware forensics and is immediately visible in Wireshark as a series of TCP SYN packets to the same IP and port at regular intervals.

Exam trap

The CHFI exam often tests the distinction between a direct IoC (like beaconing to a known malicious IP) and secondary indicators (like large file transfers or ARP anomalies) that require additional context to confirm compromise.

How to eliminate wrong answers

Option A is wrong because large file transfers during off-hours may indicate data exfiltration but are not an immediate indicator of beaconing; they are a secondary behavioral anomaly that requires correlation with other evidence. Option B is wrong because ARP requests from unknown MAC addresses indicate local network scanning or spoofing, not beaconing to a remote malicious IP; ARP operates at Layer 2 and does not reveal C2 communication patterns. Option C is wrong because encrypted payloads using TLS 1.3 are not inherently malicious; TLS 1.3 is a standard security protocol used by legitimate services, and its presence alone does not indicate compromise—beaconing is defined by connection patterns, not encryption.

33
MCQhard

An incident responder analyzes a compromised system and finds evidence of timestomping: the Modified timestamp of a malicious DLL is earlier than the Creation timestamp. Additionally, the DLL is encrypted with an XOR key. Which anti-forensic techniques are being employed?

A.Timestomping and obfuscation
B.Packer and anti-debugging
C.Rootkit installation and process hiding
D.Log wiping and data hiding
AnswerA

Timestomping is the deliberate modification of file system timestamps (MAC times) to disrupt forensic timeline reconstruction and hide when malware was deployed or accessed. The presence of XOR-encoded strings constitutes obfuscation, a common evasion method used to complicate static signature detection and reverse engineering. Together, these artifacts indicate a deliberate anti-forensic effort to hinder incident response analysis.

Why this answer

Timestomping is confirmed because the Modified timestamp (which tracks file content changes) is earlier than the Creation timestamp, which is logically impossible under normal file system operations—this indicates an attacker deliberately set the Modified timestamp backward to evade timeline analysis. The XOR encryption of the DLL is a form of obfuscation, a technique used to hide the true content of the file from static analysis tools and signature-based detection. Together, these two actions represent the anti-forensic techniques of timestomping and obfuscation.

Exam trap

EC-Council often tests the distinction between obfuscation (e.g., XOR encryption) and packing (e.g., UPX compression), where candidates mistakenly equate any encryption with a packer, but a packer specifically alters the PE structure and includes a decompression stub, while XOR obfuscation is a simpler, non-structural transformation.

How to eliminate wrong answers

Option B is wrong because a packer compresses or encrypts an executable to reduce size or evade signature detection, but it does not alter timestamps, and anti-debugging techniques (e.g., IsDebuggerPresent API calls) are runtime defenses, not file-level obfuscation or timestamp manipulation. Option C is wrong because rootkit installation involves modifying the OS kernel or system calls to hide processes or files, and process hiding is a runtime concealment method—neither directly relates to timestamp manipulation or XOR encryption of a single DLL. Option D is wrong because log wiping targets system or application logs (e.g., clearing Event Logs or /var/log files), and data hiding typically refers to steganography or alternate data streams, not XOR encryption of a DLL.

34
MCQmedium

During a mobile forensic investigation, an analyst uses Cellebrite UFED to extract data from a locked iOS device. The extraction successfully retrieves the device's passcode, call logs, SMS messages, and application data. Which extraction method did the analyst MOST likely use?

A.File system extraction
B.Physical extraction
C.Advanced logical extraction
D.Logical extraction
AnswerC

Advanced logical extraction, as performed by tools such as Cellebrite UFED, leverages bootload-level exploits like Checkm8 to temporarily bypass the lock screen and prompt the device to trust the forensic workstation. This grants access to keychain items, including passcode hashes, and permits extraction of app data by reading the encrypted filesystem with the user's decryption keys while the device is powered. It is the correct answer because it is specifically designed to recover passcode-related and application data from locked iOS devices in a non-invasive manner, preserving data integrity without needing a full chip image.

Why this answer

C is correct because Advanced Logical Extraction (ALE) on Cellebrite UFED leverages a combination of file system parsing, agent-based extraction, and exploit techniques to retrieve the device passcode, call logs, SMS messages, and application data from a locked iOS device without requiring a full physical dump. This method bypasses the logical extraction limitations by using a custom agent or AFC (Apple File Conduit) to access protected data, making it the most likely method for the described successful extraction.

Exam trap

The CHFI exam often tests the misconception that 'physical extraction' is the most powerful method for locked iOS devices, but the trap here is that physical extraction is rarely achievable on modern iOS due to hardware encryption, whereas Advanced Logical Extraction is the practical method used by tools like Cellebrite UFED to retrieve passcodes and application data from locked devices.

How to eliminate wrong answers

Option A is wrong because file system extraction typically requires the device to be jailbroken or have an unlocked state to mount the file system and retrieve raw files; it does not inherently retrieve the passcode from a locked device. Option B is wrong because physical extraction on iOS devices is extremely limited due to hardware encryption and secure enclave protections, and it rarely succeeds on locked devices without advanced bootrom exploits (e.g., checkm8), which are not standard in Cellebrite UFED for passcode retrieval. Option D is wrong because logical extraction only retrieves data that the device's operating system exposes via standard APIs (e.g., iTunes backup), which does not include the passcode or deep application data from a locked device.

35
Multi-Selectmedium

During a mobile forensic investigation, an examiner wants to recover deleted WhatsApp messages from an Android device. Which of the following artefacts should the examiner examine? (Select TWO.)

Select 2 answers
A./data/media/0/Android/data/com.whatsapp/
B./data/data/com.android.providers.telephony/databases/mmssms.db
C./data/data/com.whatsapp/databases/msgstore.db
D./data/data/com.whatsapp/files/Avatars/
E./data/data/com.google.android.gms/databases/
AnswersA, C

This path is the app-specific external storage directory for WhatsApp on shared storage, exposed via FUSE and sometimes accessible to forensic tools even without root. It holds user-visible artifacts such as transmitted images, videos, voice notes, and document files, and may also contain encrypted database backups (e.g., msgstore.db.crypt14) that, when credentialed or decrypted, can reveal message history. In a logical acquisition, this location is a priority because it often survives app data clearing and can corroborate messages recovered from the internal database. It is correct because it is a designated app-owned location on external media where WhatsApp materializes attachments with metadata like file names and timestamps.

Why this answer

WhatsApp stores media files (images, videos, voice notes) in the external app-specific directory `/data/media/0/Android/data/com.whatsapp/`. Even after a message is deleted from the chat, the media file may remain in this directory if it was not explicitly removed, allowing recovery. Option C is correct because the primary SQLite database `msgstore.db` in `/data/data/com.whatsapp/databases/` contains the chat messages, including deleted entries that are often only marked as deleted but not physically removed until a vacuum operation.

Exam trap

The CHFI exam often tests the distinction between the app-specific data directory (`/data/data/`) and the external media directory (`/data/media/0/`), tricking candidates into thinking only the internal database holds deleted messages, while media files in the external directory are also recoverable artefacts.

36
MCQmedium

An analyst is performing malware analysis and executes a suspicious binary in a sandbox. The sandbox reports that the binary creates a mutex named 'Global\DRIVER_UPDATE_MTX' before attempting to connect to 'http://malicious.com/update'. Which tool would BEST capture the network traffic during dynamic analysis?

A.Regshot
B.Wireshark
C.Process Explorer
D.Process Monitor
AnswerB

Wireshark is a full-featured network protocol analyzer that captures raw frames on a network interface and decodes hundreds of protocols, from Ethernet through application layers. For malware analysis, it is the standard tool for observing live command-and-control (C2) sessions, exfiltration attempts, or scanning activity. Analysts can filter for suspicious IPs, follow TCP streams to reconstruct payloads, and read pre-recorded packet capture (PCAP) files, making it ideal for this scenario.

Why this answer

Wireshark is the correct tool because it captures and analyzes network packets at the protocol level, allowing the analyst to inspect the HTTP request to 'http://malicious.com/update', including headers, payload, and any subsequent data exfiltration. Dynamic analysis of malware requires monitoring network traffic to identify command-and-control (C2) communications, and Wireshark provides full packet capture (PCAP) for this purpose.

Exam trap

EC-Council often tests the distinction between host-based monitoring tools (like Process Monitor and Process Explorer) and network-based capture tools (like Wireshark), leading candidates to choose a host-based tool when the question explicitly asks for network traffic capture.

How to eliminate wrong answers

Option A is wrong because Regshot is a registry and file system snapshot comparison tool, not a network traffic capture tool; it cannot capture HTTP or TCP/IP packets. Option C is wrong because Process Explorer is a process management and analysis utility that shows handles, DLLs, and threads, but it does not capture network traffic at the packet level. Option D is wrong because Process Monitor monitors file system, registry, and process/thread activity in real time, but it does not capture raw network packets or HTTP traffic.

37
MCQeasy

Which of the following is an example of an indicator of compromise (IoC) that can be used to detect malware on a network?

A.A mutex name
B.A known malicious IP address
C.A registry key modification
D.A file's MD5 hash
AnswerB

A known malicious IP address is a network-based indicator of compromise because it is observed in network telemetry, such as connections to a command-and-control (C2) server, phishing infrastructure, or malware distribution points. Analysts identify it through flow logs, DNS queries, or proxy logs, and it reflects external communication from the victim environment. Because it is a network artifact rather than an endpoint artifact, it is the correct answer for a network-level IoC.

Why this answer

A known malicious IP address is a classic indicator of compromise (IoC) because it directly identifies a command-and-control (C2) server or a source of malicious traffic. Network monitoring tools can match outbound or inbound connections against threat intelligence feeds of known bad IPs, triggering an alert. This is a network-based IoC that requires no host-level analysis, making it ideal for initial detection.

Exam trap

EC-Council often tests the distinction between network-based and host-based IoCs, and the trap here is that candidates mistakenly classify host-level artifacts (mutex, registry, hash) as network IoCs because they are common in malware analysis, but the question explicitly asks for an indicator 'on a network'.

How to eliminate wrong answers

Option A is wrong because a mutex name is a host-based artifact used to detect malware on an infected system (e.g., ensuring only one instance runs), not a network-based IoC. Option C is wrong because a registry key modification is a host-based forensic artifact indicating persistence or configuration changes on a Windows system, not a network-level indicator. Option D is wrong because a file's MD5 hash is a host-based file integrity check or malware signature, used to identify known malicious files on disk, not to detect malware on the network.

38
Multi-Selecthard

A malware analyst is performing static analysis on a packed executable. Which THREE techniques are effective for unpacking or analyzing packed malware? (Select THREE.)

Select 3 answers
A.Renaming the file to .txt
B.Performing strings analysis on the packed binary
C.Running PEiD to identify the packer
D.Executing the sample in Cuckoo Sandbox
E.Using OllyDbg to step through the unpacking routine
AnswersB, C, E

Strings may reveal embedded data or unpacked code regions.

Why this answer

Performing strings analysis on a packed binary can reveal embedded strings, such as import hints, configuration data, or the original entry point (OEP), which may survive packing. While packing obfuscates many strings, some packers leave remnants that static analysis tools like `strings` can extract, providing initial clues about the malware's functionality without execution.

Exam trap

The trap is that candidates may assume the question only allows static analysis techniques, but dynamic methods like using a debugger (OllyDbg) are also effective for unpacking. Do not exclude valid dynamic options just because they involve execution.

39
Multi-Selecthard

A security analyst observes a process making repeated network connections to an IP address 192.168.1.100 on TCP port 4444, and the process writes a DLL file to C:\Users\Public\. Which THREE actions should the analyst take immediately as part of dynamic analysis?

Select 3 answers
A.Isolate the host from the network to prevent further C2 communication
B.Capture a memory dump using FTK Imager or similar
C.Delete the DLL file to stop the malware
D.Monitor process creation and file system activity with Process Monitor
E.Reimage the hard drive to remove the malware
AnswersA, B, D

Network isolation is the immediate containment step that severs the host's ability to reach the C2 infrastructure, cutting off incoming commands and blocking on-going data exfiltration. It also prevents the malware from propagating to adjacent systems via SMB, RDP, or other protocols. However, isolation must be performed in a way that preserves volatile evidence for later collection.

Why this answer

Option A is correct because the repeated TCP connections to 192.168.1.100 on port 4444 strongly indicate command-and-control (C2) traffic, and isolating the host from the network immediately contains the incident and prevents further data exfiltration or remote instructions. Option B is correct because capturing a memory dump with FTK Imager (or an equivalent tool like WinPmem or DumpIt) preserves volatile evidence such as injected code, running processes, network connections, and encryption keys that would be lost on shutdown or reboot. Option D is correct because Process Monitor (Procmon) provides real-time visibility into process creation, file system writes (such as the DLL dropped in C:\Users\Public\), registry changes, and network activity, which is essential for dynamic analysis of the malware's behavior.

Option C is not appropriate because deleting the DLL destroys forensic evidence and may not stop the running process, which could simply re-drop the file; the analyst should preserve and analyze it first. Option E is not appropriate at this stage because reimaging the hard drive destroys all volatile and non-volatile evidence needed for dynamic and forensic analysis, and should only occur after evidence collection and containment.

Exam trap

EC-Council often tests the distinction between immediate dynamic analysis actions (containment, monitoring, memory capture) versus destructive or premature remediation steps (deleting files, reimaging), and the trap here is that candidates mistakenly choose to delete the DLL or reimage the drive, thinking it will stop the malware, when in fact it destroys evidence and bypasses the forensic process.

40
MCQmedium

An examiner is analyzing an Android device using Cellebrite UFED. The device is locked with a PIN, and the examiner has no PIN. Which acquisition type should the examiner attempt FIRST to maximize data recovery without destroying evidence?

A.Logical extraction via ADB backup
B.Manual extraction by photographing the screen
C.File system extraction via ADB root shell
D.Physical extraction using a bootloader exploit
AnswerA

ADB backup is a logical extraction that communicates with the Android system over USB to create a tar archive of app data and shared storage. Because it works through the running OS rather than requiring physical access to the flash chip, it can succeed on a locked device if USB debugging has already been enabled and the computer's RSA key is authorized. It does not require root, preserves the device's original state, and is a non-invasive first step before attempting more intrusive acquisition.

Why this answer

When an Android device is locked with a PIN and no PIN is known, a logical extraction via ADB backup is the safest first step. ADB backup (adb backup) can capture app data and system settings without requiring root or unlocking the bootloader, and it does not modify the device state, preserving evidence integrity. This method works if USB debugging was previously enabled, which is common in forensic acquisitions, and it avoids the risk of triggering lockout or data wiping that physical methods might cause.

Exam trap

EC-Council often tests the misconception that physical extraction is always the best first step for locked devices, but the trap here is that bootloader exploits or physical methods can trigger data wiping or require unlocking, whereas ADB backup is a non-invasive logical method that preserves evidence integrity when USB debugging is enabled.

How to eliminate wrong answers

Option B is wrong because manual extraction by photographing the screen is a non-acquisition technique that only captures visible content, not underlying data like deleted files or app databases, and it is not a standard forensic acquisition method for maximizing data recovery. Option C is wrong because file system extraction via ADB root shell requires root access, which is not available on a locked device without a PIN; attempting to root the device could modify system partitions and destroy evidence. Option D is wrong because physical extraction using a bootloader exploit often requires unlocking the bootloader, which wipes the device (factory reset) as a security measure, destroying all user data and making it unsuitable as a first attempt.

41
Multi-Selectmedium

Which TWO tools are commonly used for static analysis of malware binaries?

Select 2 answers
A.Cuckoo Sandbox
B.Wireshark
C.IDA Pro
D.Ghidra
E.Process Monitor
AnswersC, D

IDA Pro is a disassembler and debugger for static analysis.

Why this answer

IDA Pro is a leading interactive disassembler and debugger used for static analysis of malware binaries. It allows analysts to examine executable code without executing it, by disassembling machine code into assembly language and providing cross-references, function graphs, and decompilation capabilities. This makes it essential for reverse engineering malicious software to understand its logic, embedded strings, and control flow.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse tools that monitor live behavior (like Cuckoo Sandbox or Process Monitor) with those that analyze code without execution, leading them to select dynamic analysis tools for a static analysis question.

42
MCQeasy

Which tool is specifically designed for dynamic analysis of malware by executing it in a controlled, isolated environment and logging its behavior?

A.PEiD
B.IDA Pro
C.Ghidra
D.Cuckoo Sandbox
AnswerD

Cuckoo Sandbox is a dedicated automated malware analysis system that executes suspicious files in isolated virtual machines and records low-level API calls, file system modifications, registry changes, and network activity during runtime. It is explicitly designed for dynamic analysis, enabling analysts to observe a sample's real behavior without infecting a production host.

Why this answer

Cuckoo Sandbox is the correct answer because it is an open-source automated malware analysis system specifically designed to execute suspicious files in a controlled, isolated environment (a sandbox) and log their behavior, including system calls, file system changes, network traffic, and memory dumps. Unlike static analysis tools, Cuckoo performs dynamic analysis by actually running the malware and observing its runtime actions.

Exam trap

The CHFI exam often tests the distinction between static analysis tools (like PEiD, IDA Pro, Ghidra) and dynamic analysis tools (like Cuckoo Sandbox), trapping candidates who confuse reverse engineering with automated behavioral analysis in a sandbox.

How to eliminate wrong answers

Option A is wrong because PEiD is a static analysis tool that detects packers, cryptors, and compilers in PE files by scanning file signatures; it does not execute malware or log runtime behavior. Option B is wrong because IDA Pro is a disassembler and debugger used for static and interactive reverse engineering of binary code, not for automated dynamic analysis in an isolated sandbox environment. Option C is wrong because Ghidra is a reverse engineering framework developed by the NSA that focuses on static analysis and decompilation, lacking the sandboxed execution and behavior logging capabilities of a dedicated dynamic analysis tool like Cuckoo.

43
MCQhard

During an Android forensic examination, the analyst uses ADB to run 'adb shell dumpsys batterystats --reset' before acquiring data. What is the MOST likely purpose of this command?

A.To clear battery logs that may contain evidence of app activity
B.This command is not recommended in forensic acquisition as it may destroy potential evidence
C.To ensure the device is in a low-power state for safe extraction
D.To optimize device performance during imaging
AnswerB

In Android forensic acquisition, state-changing commands such as `adb shell dumpsys batterystats --reset` are strictly avoided because they permanently delete historical battery and wake-lock data that may corroborate user behavior, malware activity, or spyware persistence. Sound methodology requires read-only or write-protected acquisition, and any command that writes to system files risks spoliation and breaks the chain of custody. Since resetting battery stats has no legitimate role in a defensible acquisition workflow, this command must not be recommended.

Why this answer

The 'adb shell dumpsys batterystats --reset' command clears the battery statistics logs on the device. In forensic acquisition, any command that modifies or deletes data on the device is considered destructive to evidence. The reset operation removes historical battery data that may contain timestamps and app usage patterns, which could be critical evidence.

Therefore, this command is not recommended in forensic acquisition as it may destroy potential evidence.

Exam trap

EC-Council often tests the misconception that clearing logs is a benign or preparatory step, when in fact any command that modifies device state during acquisition violates forensic best practices and may be considered evidence spoliation.

How to eliminate wrong answers

Option A is wrong because clearing battery logs is precisely what the command does, and while those logs may contain evidence of app activity, the purpose of the command is to reset them, not to preserve them; the question asks for the 'most likely purpose' in a forensic context, which is that it is destructive. Option C is wrong because the command does not affect the device's power state; it only resets battery statistics data, and ensuring a low-power state is achieved through other means like disabling radios or using airplane mode. Option D is wrong because the command does not optimize device performance during imaging; it only clears battery stats, and performance optimization is irrelevant to forensic acquisition.

44
MCQhard

During a malware investigation, an analyst identifies a suspicious file that appears to be a Windows executable. Using PEiD, the analyst detects the file is packed with UPX. After unpacking, the analyst runs the file in a sandbox and observes it modifies the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService. What behavioural indicator is primarily demonstrated?

A.Persistence mechanism
B.Command and control communication
C.Anti-forensic technique (timestomping)
D.Privilege escalation attempt
AnswerA

Adding a value to the Run or RunOnce registry key is a classic persistence mechanism because those keys are automatically processed at user logon. The shell (explorer.exe) reads entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, executing the specified command without requiring any additional user interaction. This ensures the malware re-launches after a reboot, making it a strong indicator of an autostart persistence technique.

Why this answer

The modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService is a classic persistence mechanism. By adding an entry to the Run key, the malware ensures that it executes automatically every time the user logs into the system, maintaining its presence across reboots.

Exam trap

EC-Council often tests the distinction between persistence and privilege escalation, where candidates mistakenly think modifying HKCU\Run requires administrative rights, but it only requires user-level access and is a persistence technique, not an escalation attempt.

How to eliminate wrong answers

Option B is wrong because command and control communication involves network traffic to an external server (e.g., HTTP, DNS, or IRC), not a local registry modification. Option C is wrong because anti-forensic techniques like timestomping alter file timestamps (e.g., using SetFileTime or touch), not registry keys. Option D is wrong because privilege escalation attempts typically target security tokens or exploit vulnerabilities to gain higher access (e.g., SeDebugPrivilege or UAC bypass), not setting a user-level Run key.

45
MCQmedium

An Android forensic analyst connects a suspect device to their workstation and issues the command "adb backup -apk -shared -all -f backup.ab". Which type of acquisition is being performed?

A.Manual acquisition through device UI
B.Physical acquisition via JTAG
C.Logical acquisition via ADB backup
D.File system acquisition via dd
AnswerC

`adb backup` is a logical acquisition method because it leverages Android's Backup Service to request that each app's internal data, settings, and databases be serialized into a single .ab archive, excluding hidden regions and unallocated clusters. This high-level extraction is governed by the app's `backupAgent` and the device's backup policy, meaning some apps may opt out entirely or omit sensitive files. Unlike a physical or file system image, it yields no deleted remnants or raw partitions—so while it is a valid ADB-based forensic export, it does not produce a bit-for-bit copy of the storage medium.

Why this answer

The command `adb backup -apk -shared -all -f backup.ab` creates a full Android backup via the Android Debug Bridge (ADB) protocol. This is a logical acquisition because it requests user data and installed APKs through the high-level backup service, not a bit-for-bit copy of the storage. The resulting `.ab` file is an Android Backup archive, which contains files and directories that the device’s backup manager chooses to export, making it a logical extraction.

Exam trap

The CHFI exam often tests the distinction between logical and physical acquisition by presenting a command that looks like it might be low-level (e.g., containing 'backup' or 'all') but is actually a logical method, leading candidates to mistakenly choose physical or file system acquisition.

How to eliminate wrong answers

Option A is wrong because manual acquisition through the device UI involves navigating menus and copying data manually, not using ADB commands. Option B is wrong because physical acquisition via JTAG requires hardware-level access to the device’s JTAG interface to dump raw flash memory, not a software command over USB. Option D is wrong because file system acquisition via `dd` creates a bit-for-bit image of a partition or block device, whereas `adb backup` only extracts logical files and does not capture deleted data or unallocated space.

46
MCQmedium

During a malware analysis, an analyst runs a suspicious executable in a Cuckoo Sandbox and observes that the process creates a mutex named 'Global\XPSS-1.0.0' and writes a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What do these actions MOST likely indicate?

A.The malware is performing privilege escalation by exploiting a known vulnerability.
B.The malware is communicating with a command-and-control server to receive further instructions.
C.The malware is attempting to hide its presence by using a system mutex name and a legitimate registry location.
D.The malware is establishing persistence and ensuring only one instance of itself runs.
AnswerD

The Run registry key is a standard persistence mechanism that causes the malware to execute automatically every time the user logs on, ensuring it survives reboots. The named mutex provides a global lock that prevents multiple instances of the malware from running concurrently, which is crucial for avoiding detection through duplicate processes and for maintaining stable infection. Together, these artifacts conclusively indicate the malware's goal of persistent residency and single-instance control.

Why this answer

The mutex 'Global\XPSS-1.0.0' is used to prevent multiple instances of the malware from running simultaneously, which is a common anti-analysis and stability technique. Writing a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard method for achieving persistence, ensuring the malware executes automatically at user logon. Together, these actions directly indicate persistence and single-instance control, not privilege escalation, C2 communication, or hiding.

Exam trap

EC-Council often tests the distinction between persistence mechanisms and hiding techniques, trapping candidates who confuse a standard persistence location (Run key) with a stealth or concealment method, when hiding typically involves alternate data streams, registry run keys under Policies, or rootkit-level hooks.

How to eliminate wrong answers

Option A is wrong because creating a mutex and writing a Run key are not techniques for privilege escalation; privilege escalation typically involves exploiting vulnerabilities (e.g., via token manipulation or kernel exploits) to gain higher access rights, not mutex or registry operations. Option B is wrong because mutex creation and Run key persistence are local system actions; communication with a command-and-control server would involve network connections (e.g., HTTP, DNS, or IRC traffic) and is not directly indicated by these artifacts. Option C is wrong because the mutex name 'Global\XPSS-1.0.0' is not a standard system mutex (system mutexes often use 'Global\' prefix with well-known names like 'Global\MSCTF.CtfMonitor') and the Run key is a well-known persistence location, not a hiding technique; hiding would involve rootkits, fileless techniques, or stealthy registry locations like HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run.

47
Multi-Selecteasy

A forensic analyst is performing static analysis of a Windows PE file. Which TWO of the following tools are specifically designed for static analysis of malware?

Select 2 answers
A.Wireshark
B.Cuckoo Sandbox
C.IDA Pro
D.Ghidra
E.Process Monitor
AnswersC, D

IDA Pro is an interactive disassembler that converts raw machine code into assembly mnemonics and constructs control-flow and cross-reference graphs, allowing an analyst to understand the binary's logic without running it. It parses the PE/ELF/Mach-O file formats, resolves imports and exports, and identifies function boundaries and string references directly from the file's static content. This aligns exactly with static analysis of a Windows binary because no code is executed; the tool operates solely on the on-disk representation.

Why this answer

IDA Pro (C) is a disassembler and debugger specifically built for reverse engineering binary executables, allowing an analyst to statically examine a PE file's code, imports, and structure without executing it. Ghidra (D) is the NSA's open-source software reverse engineering suite that likewise performs static disassembly and decompilation of PE files, making it a core static malware analysis tool. Both operate on the file on disk, matching the scenario's requirement for static analysis.

Wireshark (A) is a network protocol analyzer that inspects captured traffic, not PE binaries. Cuckoo Sandbox (B) is a dynamic analysis platform that executes malware in an isolated VM and observes behavior, so it is not static. Process Monitor (E) is a live runtime monitoring tool for file, registry, and process activity, also dynamic rather than static.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse network or process monitoring tools (Wireshark, Process Monitor) with static analysis, or mistake sandboxing (Cuckoo) for static analysis when it is inherently dynamic.

48
Multi-Selectmedium

A forensic examiner is analyzing an iOS device backup and wants to extract the user's iCloud-related artefacts. Which TWO of the following are typical sources of iCloud artefacts in an iTunes backup?

Select 2 answers
A.AddressBook.db
B.com.apple.accounts.plist
C.Call_history.db
D.Keychain database (keychain-backup.plist)
E.SMS.db
AnswersB, D

This preference plist (located at Library/Preferences/com.apple.accounts.plist in the backup's root domain) is the authoritative store for Accounts framework data, including iCloud (ACAccount). It records the user's Apple ID, account UUIDs, enabled iCloud services (e.g., Mail, Contacts, Calendars), and account status. A forensic examiner should parse this binary plist to identify iCloud account configuration and associated metadata, which directly answers the question.

Why this answer

Option B, com.apple.accounts.plist, is correct because this property list stores the device's configured account information, including iCloud account identifiers and settings, making it a primary source of iCloud-related artefacts in an iTunes backup. Option D, the Keychain database (keychain-backup.plist), is correct because iCloud credentials and tokens are protected within the keychain, and the backup's keychain-backup.plist preserves these secrets for forensic examination. Option A, AddressBook.db, is incorrect because it holds local contact data rather than iCloud account artefacts.

Option C, Call_history.db, is incorrect because it contains call log records, not iCloud configuration or credential data. Option E, SMS.db, is incorrect because it stores text message data, which is unrelated to iCloud account artefacts.

Exam trap

EC-Council often tests the misconception that iCloud artefacts are found in user-facing databases like SMS.db or AddressBook.db, when in fact they reside in system configuration files like plists and the Keychain database.

49
MCQhard

A security analyst runs a dynamic analysis of a suspected malware sample using Cuckoo Sandbox. The report shows that the sample created a mutex named 'Global\MyMaliciousMutex', added a registry run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and attempted to communicate with an IP address 185.10.68.12 on port 443. Which of the following is the BEST immediate indicator of compromise (IoC) to share with the threat intelligence team?

A.The registry run key location
B.The sample's MD5 hash
C.The IP address 185.10.68.12
D.The mutex name 'Global\MyMaliciousMutex'
AnswerC

The IP address 185.10.68.12 is the command-and-control endpoint that the malware dials out to, so it is the most immediately actionable indicator for containment. An analyst can block this IP at the firewall or proxy, add it to a threat intelligence feed, and alert on any matching egress traffic. This directly severs the malware's ability to receive commands or exfiltrate data, unlike host-based artifacts. In a live engagement, isolating this network indicator is a critical first step before deeper host remediation.

Why this answer

The IP address 185.10.68.12 on port 443 is the best immediate indicator of compromise (IoC) because it is a network-based artifact that can be directly blocked at the firewall or monitored for outbound connections. Network-based IoCs are often prioritized in threat intelligence sharing because they enable proactive perimeter defense and are actionable across multiple systems, unlike host-based artifacts (mutexes, registry keys) that require endpoint-level detection. Additionally, the IP address is independent of file hashes and can be used to detect or block communications even when the malware binary changes.

Exam trap

The CHFI exam often tests the concept that network-based IoCs (IP addresses, domains) are considered more immediate and actionable for threat intelligence sharing than host-based artifacts (mutexes, registry keys) because they enable perimeter defense and are less dependent on specific file hashes that change with each variant.

How to eliminate wrong answers

Option A is wrong because the registry run key location (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is a standard persistence mechanism used by many legitimate applications, making it a weak IoC without additional context; it is not unique to this malware and can be easily changed by the attacker. Option B is wrong because the sample's MD5 hash is a file-based hash that can be trivially modified by recompiling or packing the malware, and it is not immediately actionable for network defense or threat intelligence sharing compared to a network indicator. Option D is wrong because the mutex name 'Global\MyMaliciousMutex' is a host-based artifact that can be easily altered by the malware author in a new variant, and it is not directly observable from network traffic or useful for blocking at the perimeter.

50
Multi-Selectmedium

A malware analyst is performing static analysis on a suspicious PE file. Which TWO of the following are examples of anti-forensic techniques that the malware might use to hinder analysis? (Select TWO.)

Select 2 answers
A.Using TLS encryption for network communication
B.Packing or obfuscating the malicious code
C.Creating registry keys for persistence
D.Writing temporary files to the %TEMP% directory
E.Timestomping to modify file creation and modification timestamps
AnswersB, E

Packing or obfuscating the malicious code is a core anti-forensic technique because it compresses, encrypts, or otherwise transforms the executable's original machine code, rendering it opaque to static signature-based detection and manual reverse engineering. The malware's true payload is only revealed at runtime when it unpacks itself in memory, forcing analysts to use dynamic analysis or memory forensics. This deliberate obfuscation directly impedes the malware analyst's ability to inspect the code, making it the correct answer.

Why this answer

Option B is correct because packing or obfuscating the malicious code (e.g., with UPX, Themida, or custom crypter) hides the true code and strings from static analysis tools, forcing the analyst to unpack or emulate before meaningful inspection is possible. Option E is correct because timestomping deliberately alters a file's $STANDARD_INFORMATION and/or $FILE_NAME timestamps (creation, modification, access, MFT entry change) to mislead investigators about when the malware was placed or executed, which is a classic anti-forensic technique. Option A is not an anti-forensic technique against static analysis; TLS is simply an encrypted transport that hinders network traffic inspection, not examination of the PE file itself.

Option C is a persistence mechanism (e.g., Run keys, Services), not an anti-forensic measure. Option D is normal runtime behavior for many programs and does not specifically hinder static analysis of the PE file.

Exam trap

EC-Council often tests the distinction between anti-forensic techniques (which actively hinder analysis) and common malware behaviors (which are forensic artifacts themselves), so candidates mistakenly select persistence or file-writing options as anti-forensic when they are actually evidence-creating actions.

51
MCQeasy

During an iOS forensics investigation, an examiner wants to extract call history records from an iPhone backup. Which SQLite database file should be examined?

A.SMS.db
B.AddressBook.db
C.call_history.db
D.Calendar.sqlitedb
AnswerC

call_history.db is the correct source for call records on iOS devices. This SQLite database, commonly found under /private/var/mobile/Library/CallHistoryDB/, stores recent calls with fields such as the caller/called number, timestamp, duration, and call status (incoming, outgoing, missed). The database is periodically flushed or pruned, but deleted records may remain in free pages or the WAL file until overwritten. Its schema directly answers the examiner's question about call history.

Why this answer

In iOS forensics, call history records are stored in the SQLite database file named 'call_history.db' (or 'CallHistory.storedata' in newer iOS versions). This database contains tables such as 'call' and 'ZCALLRECORD' that log incoming, outgoing, and missed calls along with timestamps and durations. Examining this file directly from an iTunes backup or device extraction provides the examiner with the complete call log.

Exam trap

EC-Council often tests the specific naming of iOS forensic artifacts; the trap here is that candidates confuse 'SMS.db' (which stores messages) with call logs, or assume call history is stored in a more generic database like 'AddressBook.db'.

How to eliminate wrong answers

Option A is wrong because SMS.db stores SMS and iMessage conversations, not call history records. Option B is wrong because AddressBook.db (or Contacts.sqlitedb) stores contact names, phone numbers, and email addresses, but does not contain call logs. Option D is wrong because Calendar.sqlitedb stores calendar events and reminders, not telephony call records.

52
MCQeasy

Which of the following is a key difference between static analysis and dynamic analysis in malware forensics?

A.Static analysis requires the malware to be executed, while dynamic analysis does not.
B.Static analysis is used only for packed malware, while dynamic analysis is used for unpacked.
C.Dynamic analysis uses tools like IDA Pro, while static uses Cuckoo Sandbox.
D.Static analyzes the code without execution; dynamic executes the malware.
AnswerD

This is the core distinction: static analysis inspects the binary's code, structure, strings, and imports without ever running the file, whereas dynamic analysis executes the malware in a controlled, monitored environment to observe its behavior, such as file modifications, registry changes, and network connections. The two approaches are complementary, with static shedding light on intent and dynamic revealing actual side effects.

Why this answer

Static analysis involves examining the malware's code (e.g., disassembly, string extraction, hash analysis) without executing it, while dynamic analysis runs the malware in a controlled sandbox environment to observe its runtime behavior, such as file system changes, registry modifications, and network connections. This fundamental distinction is critical in malware forensics to safely understand the threat without risking infection.

Exam trap

EC-Council often tests the reversal of definitions (execution vs. non-execution) to catch candidates who confuse static and dynamic analysis roles.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: static analysis does NOT require execution, while dynamic analysis does. Option B is wrong because static analysis can be applied to both packed and unpacked malware (though packing complicates static analysis), and dynamic analysis works regardless of packing by observing runtime behavior. Option C is wrong because IDA Pro is a static analysis tool (disassembler/decompiler), while Cuckoo Sandbox is a dynamic analysis tool (automated malware execution environment); the option swaps their correct classifications.

53
MCQeasy

An Android phone is seized, and the forensic examiner needs to acquire the device in a forensically sound manner. The phone is running Android 12 and has USB debugging enabled. Which acquisition method provides the most complete data without physically modifying the device?

A.File system acquisition via Cellebrite UFED
B.Physical acquisition via ADB with appropriate exploit
C.Logical acquisition through ADB backup
D.Manual extraction using screen captures
AnswerB

Physical acquisition via ADB leverages a custom recovery or a privilege-escalation exploit to execute a low-level block device read, such as dd if=/dev/block/mmcblk0 of=/image.dd, yielding a complete bit-for-bit replica of the flash storage. This preserves deleted files, unallocated clusters, file system slack, and application remnants that are absent from logical or file-system extractions, making it the most comprehensive and forensically defensible approach for Android devices when feasible.

Why this answer

Physical acquisition via ADB with an appropriate exploit allows the examiner to obtain a complete bit-for-bit copy of the device's flash memory, including deleted data and unallocated space, without physically modifying the device. Since Android 12 has USB debugging enabled, ADB can be used to push an exploit that bypasses security restrictions to perform a physical dump, which is the most comprehensive method available for this scenario.

Exam trap

EC-Council often tests the misconception that file system acquisition via Cellebrite UFED is the most complete method, but candidates must remember that physical acquisition captures raw flash memory including deleted data, whereas file system acquisition only retrieves active files.

How to eliminate wrong answers

Option A is wrong because Cellebrite UFED file system acquisition typically extracts only the file system structure (files and directories) and does not capture raw flash memory or unallocated space, missing deleted data and hidden partitions. Option C is wrong because logical acquisition through ADB backup only retrieves app data and system settings specified by the backup API, not the entire device storage, and it cannot recover deleted files or raw disk images. Option D is wrong because manual extraction using screen captures is not a forensic acquisition method; it only captures visible screen content and provides no access to underlying data, making it forensically unsound and incomplete.

54
MCQmedium

A forensic analyst is examining an Android device that was factory reset before seizure. Which Google account artefacts are MOST likely still recoverable from the device's storage?

A.All installed application APK files
B.Full SMS message history
C.Google account authentication tokens and cached account data
D.Encryption keys for user data partition
AnswerC

Google account authentication tokens and cached account data are written by the AccountManager service to /data/system/users/0/accounts.db and an encrypted credential store; after a factory reset, the /data partition is formatted but the underlying NAND blocks are not necessarily zeroized, allowing forensic recovery of deleted SQLite pages and token blobs. On many Android builds, the primary Google account username and its OAuth token are also cached in the Google Services Framework and can survive in unallocated space or even in a persistent FRP/device-protection partition. This combination of flash-memory remnants plus a designated persistent location makes account tokens the artifact most likely to be recovered after a reset compared to APKs, SMS, or encryption keys.

Why this answer

Factory reset on Android typically wipes user data partitions (e.g., /data) but does not securely overwrite the entire flash storage. Google account authentication tokens (e.g., OAuth 2.0 tokens) and cached account data (e.g., account names, sync settings) are often stored in system-level databases or encrypted key stores that may persist in unallocated or residual flash blocks, especially if TRIM or secure erase was not executed. These artefacts can be recovered via forensic imaging and carving of the raw NAND or eMMC.

Exam trap

EC-Council often tests the misconception that a factory reset securely erases all user data, when in reality residual artefacts like authentication tokens can persist in unallocated flash storage due to incomplete overwrite or lack of TRIM execution.

How to eliminate wrong answers

Option A is wrong because APK files are stored in the /data/app directory, which is part of the user data partition that is wiped during a factory reset; residual APK fragments are rarely recoverable in a complete, installable form. Option B is wrong because SMS messages are stored in the /data/data/com.android.providers.telephony/databases/mmssms.db file, which is also on the user data partition and is deleted during reset; while some fragments may remain in unallocated space, full message history is not reliably recoverable. Option D is wrong because encryption keys for the user data partition (e.g., FBE or FDE keys) are stored in the device's hardware-backed keystore or TEE and are cryptographically invalidated or wiped during factory reset, making them unrecoverable.

55
MCQmedium

A security analyst suspects malware infection on a Windows workstation. They run Process Monitor and observe that a process named 'svch0st.exe' creates a mutex named 'Global\Mutex_1234' and writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which malware persistence mechanism is being used?

A.Scheduled task creation
B.Service installation
C.DLL search order hijacking
D.Run key persistence
AnswerD

Run key persistence is an established autostart extensibility point where malware creates a value in the HKCU or HKLM Run key so that the associated program executes automatically at user logon. Both HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run are commonly monitored, but malware often abuses them because they are simple and reliable, often without requiring elevated privileges for the HKCU variant. From an analyst's perspective, finding an unexpected value in these keys is a strong indicator of persistence, and the command or path of the value can be used for further triage.

Why this answer

The process 'svch0st.exe' writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run', which is a classic Run key used for automatic program execution at user logon. This is the most common malware persistence mechanism, as any executable referenced there will start each time the user logs in. The creation of a mutex named 'Global\Mutex_1234' is a common anti-reinfection technique to ensure only one instance of the malware runs, but the persistence is established via the Run key.

Exam trap

EC-Council often tests the distinction between user-level persistence (HKCU Run key) and system-level persistence (HKLM Run key or service installation), and candidates may confuse the 'Run' key with scheduled tasks or services because all three can launch executables at startup.

How to eliminate wrong answers

Option A is wrong because scheduled task creation uses the Task Scheduler service and writes to the '\Windows\System32\Tasks' directory or the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache' registry key, not to the 'Run' key. Option B is wrong because service installation requires writing to 'HKLM\SYSTEM\CurrentControlSet\Services' and typically uses the 'CreateService' API, not the 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' key. Option C is wrong because DLL search order hijacking involves placing a malicious DLL in a directory searched before the legitimate DLL (e.g., the application's directory or the current working directory) and does not involve writing to a Run registry key or creating a mutex.

56
MCQmedium

A malware analyst runs a suspicious executable in Cuckoo Sandbox. The report shows that the process created a mutex named 'Global\MyMalwareMutex'. What is the significance of this mutex?

A.It is used to communicate with a remote command and control server
B.It prevents multiple instances of the malware from running simultaneously
C.It indicates the malware is packed with UPX
D.It stores encrypted configuration data
AnswerB

This is the correct interpretation: when a process creates a named mutex and then checks for its existence before proceeding, it is using the object as a global, system-wide flag. If the mutex already exists, the malware terminates itself or exits its main thread, ensuring that only one copy of the malware is active at any time. Analysts see this in Cuckoo sandbox when the sample creates a uniquely named mutex and later attempts to open the same mutex again; this behavior prevents duplicate infections, avoids file-corruption conflicts, and preserves the integrity of the malware's own state.

Why this answer

The mutex named 'Global\MyMalwareMutex' is a named synchronization object used by the malware to ensure only one instance of its process runs at a time. This prevents conflicts in operations like file writing or network communication that could occur if multiple copies executed simultaneously. In Cuckoo Sandbox, detecting such a mutex is a common indicator of single-instance malware behavior.

Exam trap

EC-Council often tests the misconception that any named object with 'Global' implies network or cross-system communication, but in Windows, 'Global\' simply refers to the kernel object namespace accessible to all sessions on the same machine.

How to eliminate wrong answers

Option A is wrong because mutexes are local synchronization primitives within the Windows kernel, not network communication channels; C2 communication typically uses sockets, HTTP, or DNS. Option C is wrong because UPX packing is detected by analyzing the executable's section names (e.g., 'UPX0', 'UPX1') or entropy, not by mutex creation. Option D is wrong because mutexes do not store data; they are kernel objects with a name and state (signaled/non-signaled), whereas encrypted configuration is usually stored in files, registry keys, or memory.

57
Multi-Selectmedium

A malware analyst is examining a suspicious Windows executable that appears to be packed. During static analysis, the analyst notices that the PE file has a small number of imports, a high entropy in the .text section, and a section named UPX0. The analyst suspects the sample is packed with UPX. Which TWO of the following techniques would BEST allow the analyst to unpack the sample and continue analysis? (Choose two.)

Select 2 answers
A.Use a debugger to set a breakpoint at the entry point and manually reconstruct the import address table.
B.Run the sample in a sandbox and dump the process memory after it unpacks itself.
C.Use the UPX utility with the -d option to decompress the executable.
D.Perform a strings analysis on the packed binary to extract the original source code.
E.Use a PE editing tool to change the section name from UPX0 to .text and then run the sample.
AnswersB, C

If the sample is UPX-packed, it will unpack itself in memory during execution. By running it in a controlled sandbox and dumping the process memory after the unpacking stub completes, the analyst can capture the original unpacked code. This technique works even if the UPX utility fails due to modified headers or custom packing, and it provides a memory image that can be analyzed with tools like Volatility or PE-scan.

Why this answer

UPX-packed executables can be unpacked either by using the UPX utility with the decompress option or by allowing the sample to unpack in memory and then dumping the process. The UPX utility directly reverses the compression if the file is unmodified. Memory dumping captures the unpacked code after the stub runs, which is effective even if the packer was customized.

Other methods like strings analysis or section renaming do not achieve unpacking.

Exam trap

The trap here is believing that renaming a packer section or performing strings analysis can unpack the binary, when unpacking requires either the packer's own decompression routine or runtime memory extraction.

58
MCQeasy

During a mobile forensic examination of an iPhone, the examiner wants to acquire the most data possible, including deleted files and unallocated space. Which acquisition type should be used?

A.File system acquisition
B.Logical acquisition
C.Physical acquisition
D.Manual acquisition
AnswerC

Physical acquisition is the only method that produces a bit-for-bit image of the device's storage, including allocated files, deleted file remnants, and unallocated space, by reading the raw NAND or a block device representation. On iPhones this is technically challenging because modern devices implement full-disk encryption and a Secure Enclave; physical imaging is usually feasible only with bootrom exploits (e.g., checkm8 on A7–A11 chips) or decapsulation/chip-off methods. Once acquired, the raw image allows deep data carving and, if decryption keys are available, complete logical recovery.

Why this answer

Physical acquisition creates a bit-for-bit copy of the entire flash storage, including unallocated space and deleted file remnants. This is the only method that captures the raw NAND memory, allowing recovery of data from unallocated blocks and slack space that logical and file system acquisitions skip.

Exam trap

The CHFI exam often tests the misconception that logical acquisition (Option B) captures deleted data because it includes the iTunes backup, but backups exclude unallocated space and deleted file remnants.

How to eliminate wrong answers

Option A is wrong because file system acquisition only retrieves allocated files and metadata visible to the operating system, ignoring unallocated space and deleted data. Option B is wrong because logical acquisition extracts files and directories via the iOS API (e.g., iTunes backup), which excludes unallocated space and deleted file remnants. Option D is wrong because manual acquisition involves physically interacting with the device screen to capture visible data, providing no access to the underlying storage or deleted content.

59
MCQmedium

A forensic examiner is analyzing an Android device that has been factory reset. Which artefact is MOST likely to persist after a factory reset, providing potential evidence of prior usage?

A.Google account artefacts
B.App installation logs
C.Deleted SMS messages
D.Wi-Fi passwords
AnswerA

On modern Android builds, factory reset intentionally preserves Factory Reset Protection (FRP) data—the last verified Google account identifier (and often an authentication token sealed with device-bound keys) is retained in dedicated persistent storage or in Google's cloud-side device registry. Even if the userdata partition is reformatted, a forensic examiner can extract the FRP Google account from a physical image of protected/persistent blocks or obtain it via Google Takeout/Google Dashboard log retrieval, making this the only listed item that survives by design.

Why this answer

Google account artefacts, such as the Google Services Framework (GSF) ID and the device's Google Account (GAIA) ID, may persist after a factory reset because they are often stored on a dedicated persistent partition (e.g., /persist or /misc) that is not erased by a standard reset. Forensic tools can recover these identifiers from that partition, providing evidence of prior usage. This is unlike user-generated data such as SMS, Wi-Fi passwords, or app logs, which reside in the /data partition and are typically wiped.

Exam trap

The trap is that a factory reset does not completely erase all data; certain system-level identifiers like Google account artefacts survive because they reside on partitions that are not formatted during a standard reset. Candidates often assume all user-related data is wiped, but persistent partitions retain these identifiers.

How to eliminate wrong answers

Option B is wrong because app installation logs are stored in /data/log/ or /data/system/packages.xml, which are cleared during a factory reset that reformats the /data partition, leaving no persistent trace. Option C is wrong because deleted SMS messages reside in the /data/data/com.android.providers.telephony/databases/mmssms.db file, which is fully wiped when the /data partition is reformatted during a factory reset, and they are not backed up to Google servers by default. Option D is wrong because Wi-Fi passwords are stored in /data/misc/wifi/wpa_supplicant.conf, which is deleted when the /data partition is wiped, and while some devices may retain them in a separate persist partition, a standard factory reset removes them.

60
MCQhard

An analyst suspects a Windows executable is packed. They run `strings` on the file and see few readable strings, and PEiD reports 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. Which static analysis technique should the analyst use NEXT to extract the original code?

A.Use UPX with the -d flag to decompress the executable
B.Search for known YARA rules matching UPX
C.Run the executable in Cuckoo Sandbox to obtain dynamic analysis
D.Load the file into IDA Pro and attempt to disassemble directly
AnswerA

UPX is a widely used open-source packer that stores a compressed executable and a self-extracting stub. Running `upx -d file.exe` invokes UPX's decompression routine, which reconstructs the original Portable Executable (PE) sections, restores the original entry point, and simplifies subsequent static analysis. This is the intended static analysis answer because it directly reverses the packing transformation, unlike dynamic execution. If the file were packed with a different tool, `upx -d` would fail with a validation error, but the question specifically indicates UPX.

Why this answer

UPX (Ultimate Packer for Executables) is a common packer that compresses Windows executables. The PEiD output 'UPX 0.89.6 - 1.02 / 1.05 - 1.24' confirms the file is packed with UPX. Running `upx -d` (decompress) reverses the packing, restoring the original executable code for static analysis.

This is the standard next step before attempting disassembly or dynamic analysis.

Exam trap

The CHFI exam often tests the distinction between detection (YARA), dynamic analysis (sandbox), and direct disassembly (IDA) versus the correct unpacking step, trapping candidates who think any analysis tool can handle packed files without prior decompression.

How to eliminate wrong answers

Option B is wrong because searching for YARA rules matching UPX would only confirm the packer's presence, not extract the original code; it's a detection step, not a decompression technique. Option C is wrong because running the executable in Cuckoo Sandbox is dynamic analysis, which risks executing potentially malicious code and does not directly extract the original packed code for static analysis. Option D is wrong because loading a UPX-packed executable directly into IDA Pro results in disassembly of the UPX stub, not the original program code; the stub must be decompressed first.

61
Multi-Selecthard

A security team is investigating a suspected Advanced Persistent Threat (APT) intrusion. They have identified several IoCs. Which THREE of the following are considered standard types of Indicators of Compromise?

Select 3 answers
A.Employee badge number
B.IP address of a command and control server
C.MD5 hash of a malicious executable
D.Registry key path used for persistence
E.Email subject line from a phishing campaign
AnswersB, C, D

An IP address for a command and control (C2) server is a standard network-based IoC because it identifies the remote host a compromised endpoint contacts to receive instructions or exfiltrate data. Analysts frequently cross-reference such addresses with threat intelligence feeds that map them to known malware families, botnets, or ongoing campaigns, then create firewall rules, IDS alerts, or sinkhole entries. However, a single IP may be rotated quickly or sit behind a CDN, so robust detection typically correlates it with domains, certificates, or JA3 hashes.

Why this answer

Option B is correct because the IP address of a command and control (C2) server is a classic network-based IoC that defenders use to detect beaconing or outbound connections to attacker infrastructure. Option C is correct because an MD5 hash of a malicious executable is a file-based (hash) IoC that uniquely identifies known malware samples and enables blocklisting or scanning. Option D is correct because a registry key path used for persistence is a host-based IoC, since attackers commonly abuse Run keys, Services, or similar registry locations to survive reboots.

Option A is not a standard IoC type because employee badge numbers are identity/HR data, not technical artifacts of compromise. Option E is not a standard IoC type because an email subject line is contextual phishing content, not a reliable technical indicator such as a hash, IP, domain, URL, or registry artifact.

Exam trap

EC-Council often tests the distinction between technical IoCs (like IP addresses, hashes, registry keys) and non-technical or variable indicators (like employee IDs or email subject lines), trapping candidates who confuse phishing campaign metadata with standard forensic IoCs.

62
MCQeasy

A forensic investigator needs to analyze the keychain data from an iOS device backup. Which tool is specifically designed to decrypt and display iOS keychain contents?

A.Elcomsoft Phone Breaker
B.Cellebrite UFED
C.Oxygen Forensic Detective
D.Magnet AXIOM
AnswerA

Elcomsoft Phone Breaker is purpose-built for accessing iOS keychain contents, using a combination of iTunes/ramdisk backup decryption, keybag extraction, and GPU-accelerated brute-force or dictionary attacks against the backup password. It directly targets the cryptographic constructs (e.g., the device or backup keybag classes) to recover stored passwords, certificates, and tokens from keychain databases such as keychain-2.db. This is the only tool listed whose primary workflow is keychain decryption rather than general mobile data extraction.

Why this answer

Elcomsoft Phone Breaker is specifically designed to decrypt and display iOS keychain contents from backups, including passwords, tokens, and cryptographic keys. It leverages techniques such as brute-force, dictionary attacks, and GPU acceleration to recover the backup password, then extracts and decrypts the keychain data using its own implementation of the keychain decryption process, deriving the necessary encryption keys from the recovered backup password.

Exam trap

The CHFI exam often tests the misconception that general-purpose forensic tools like Cellebrite UFED or Magnet AXIOM can decrypt iOS keychain natively, when in fact only specialized tools like Elcomsoft Phone Breaker are designed for that specific task.

How to eliminate wrong answers

Option B (Cellebrite UFED) is wrong because it is a physical extraction and analysis tool for mobile devices, not specialized in decrypting iOS keychain data; it focuses on file system and logical extractions. Option C (Oxygen Forensic Detective) is wrong because it is a comprehensive forensic platform for mobile and cloud data, but it does not have native keychain decryption capabilities; it relies on third-party tools or manual extraction. Option D (Magnet AXIOM) is wrong because it is a digital forensic platform that processes artifacts from multiple sources, but it does not include a dedicated iOS keychain decryptor; it may import keychain data but cannot decrypt it natively.

63
MCQhard

During an iOS forensic examination of an iCloud backup, an analyst finds that the SQLite database files for the Health app are encrypted. Which component is MOST likely responsible for encrypting this data, and what is required to decrypt it?

A.The data is encrypted with the device's hardware UID; decryption is impossible without Apple's assistance.
B.The data is encrypted using Apple's FileVault; decryption requires the user's iCloud password.
C.The data is encrypted using SQLCipher; decryption requires a 256-bit key stored in the Keychain.
D.The data is protected by iOS Data Protection using a key derived from the device passcode; decryption requires the passcode or a forensic bypass tool.
AnswerD

This is correct: iOS Health data is stored in HealthKit and protected by iOS Data Protection using a per-file key wrapped by a class key that depends on the device's UID and the user's passcode. The passcode is the critical user-supplied secret; without it, decryption typically requires a forensic bypass tool that can brute-force or otherwise recover the passcode, or leverage a trusted pairing/escrow keybag when available. Apple cannot simply decrypt the data because the passcode is not known to them.

Why this answer

IOS Health app data is protected by iOS Data Protection, which uses a class key derived from the user's device passcode. This key encrypts the SQLite database files in iCloud backups, and decryption requires either the passcode or a forensic bypass tool that can extract the key from the device's Secure Enclave.

Exam trap

EC-Council often tests the distinction between device-level encryption (hardware UID) and iCloud backup encryption (passcode-derived keys), and the trap here is confusing SQLCipher (a third-party tool) with Apple's proprietary iOS Data Protection framework.

How to eliminate wrong answers

Option A is wrong because the hardware UID is used for device-level encryption of files on the local device, not for iCloud backup encryption; iCloud backups use a different key hierarchy involving the user's iCloud account and passcode. Option B is wrong because FileVault is a macOS full-disk encryption technology, not used on iOS or for iCloud backup encryption. Option C is wrong because SQLCipher is a third-party encryption library that apps can use, but Apple's Health app uses iOS Data Protection (Apple's built-in encryption framework), not SQLCipher; the key is derived from the passcode and stored in the Secure Enclave, not in the Keychain as a 256-bit key.

64
MCQmedium

A security analyst is reviewing output from a Cuckoo Sandbox analysis of a suspicious executable. The report shows that the process created a mutex named 'Global\GLOBAL_MUTEX_123' and modified the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\. Which behavioral indicator is MOST evident?

A.Command and control communication
B.Persistence mechanism
C.Anti-debugging technique
D.Privilege escalation
AnswerB

The Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a well-known autorun persistence location that executes a designated binary every time the targeted user logs on. By adding a value here, malware ensures it survives reboots and is relaunched automatically, a behavior that directly maps to the MITRE ATT&CK technique T1547.001 (Registry Run Keys / Startup Folder). In a sandbox report, seeing this registry modification is strong evidence the sample is establishing persistence, making this the correct classification.

Why this answer

The modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism. This key is automatically processed by Windows Explorer at user logon, causing any executable listed there to run. Combined with the mutex creation (which prevents multiple instances), the behavioral indicator is clearly an attempt to establish persistence on the host.

Exam trap

EC-Council often tests the distinction between user-level persistence (HKCU Run) and system-level persistence (HKLM Run or services), and candidates may confuse the registry modification with privilege escalation or C2 activity because they see 'Run' and assume it implies higher privileges or network communication.

How to eliminate wrong answers

Option A is wrong because command and control communication typically involves network indicators such as DNS queries, HTTP/S connections to external IPs, or beaconing patterns, not registry modifications or mutex creation. Option C is wrong because anti-debugging techniques usually involve checking for the presence of a debugger via API calls like IsDebuggerPresent, NtQueryInformationProcess, or timing checks, not creating a mutex or writing to Run keys. Option D is wrong because privilege escalation involves gaining higher-level access rights, often via token manipulation, service exploitation, or UAC bypass; modifying the current user's Run key does not elevate privileges—it only runs code at the existing user's privilege level.

65
MCQmedium

A forensic examiner uses Oxygen Forensic Detective to acquire data from an Android device. The tool reports that it performed a 'full file system' extraction. Which of the following is a prerequisite for this type of extraction?

A.The bootloader must be unlocked
B.The device must be rooted
C.The device must be in recovery mode
D.USB debugging must be enabled
AnswerB

Root access is the decisive prerequisite because Android's kernel sandbox prevents the unprivileged adbd shell user from reading package-private app data, protected system directories, or raw block devices. With root, Oxygen Forensic Detective can execute su or other elevated commands to access /data, application databases, caches, and system partitions, enabling a true file-system extraction. Without root, the tool may still perform a logical extraction of contacts, call logs, and media via public APIs, but the deep application artifacts and deleted-record areas hidden in the file system remain out of reach.

Why this answer

A full file system extraction in Oxygen Forensic Detective requires root access on the Android device because the tool must bypass the Linux kernel's permission model to read protected partitions (e.g., /data, /cache). Without root privileges, the extraction is limited to the logical or file-based scope, as the Android security model restricts user-space processes from accessing raw block devices or system files owned by root.

Exam trap

EC-Council often tests the misconception that USB debugging alone enables full file system extraction, but in reality, USB debugging only provides ADB shell access with limited (shell) user privileges, not the root-level access required for raw partition imaging.

How to eliminate wrong answers

Option A is wrong because an unlocked bootloader is a prerequisite for flashing custom recovery or rooting, but it is not directly required for a full file system extraction; the extraction itself can be performed on a device with a locked bootloader if root access is already obtained. Option C is wrong because recovery mode is used for flashing firmware or performing factory resets, not for forensic extraction; Oxygen Forensic Detective typically requires the device to be booted into Android with USB debugging enabled and root access granted. Option D is wrong because USB debugging is necessary for ADB communication and logical extractions, but it alone does not grant the elevated privileges needed to read the full file system; root access is the critical prerequisite.

66
MCQmedium

An investigator extracts the SMS.db file from an iOS backup. Which table within this database would contain the actual message content for sent and received messages?

A.message
B.attachment
C.handle
D.chat
AnswerA

The `message` table is the core content store in iOS's `sms.db`; each row represents a single SMS or iMessage and includes the `text` column, which holds the actual message body, along with metadata such as `ROWID`, `guid`, `date`, `is_from_me`, and `handle_id`. An investigator extracting the SMS database from an iOS backup must query this table to recover the textual content of messages. The `text` field can be `NULL` for attachment-only messages, but the conversational text lives here.

Why this answer

The `message` table in iOS's SMS.db database stores the actual text content of each SMS and iMessage in its `text` column. This is the primary table queried to retrieve the body of sent and received messages, as it contains one row per message with fields like `is_from_me`, `date`, and `text`.

Exam trap

EC-Council often tests the distinction between where message content is stored versus where metadata (like attachment info or participant handles) resides, leading candidates to confuse the `chat` or `handle` tables as containing the message body.

How to eliminate wrong answers

Option B is wrong because the `attachment` table stores metadata about file attachments (e.g., file names, MIME types, transfer state), not the message text itself. Option C is wrong because the `handle` table maps phone numbers or email addresses to a unique identifier used for addressing, but does not contain message content. Option D is wrong because the `chat` table defines chat sessions (group chats, participants) and links to messages via the `chat_message_join` table, but does not hold the message body.

67
MCQeasy

A forensic analyst is examining a Windows malware sample using static analysis. Which tool is BEST suited for viewing the PE header structure, including sections, imports, and exports?

A.Strings
B.Ghidra
C.IDA Pro
D.PEiD
AnswerD

PEiD (Portable Executable Identifier) is a specialized forensic and reverse-engineering tool that statically parses PE files to identify the compiler, linker, and—most importantly—the packer or protector used. It extracts and displays PE header details such as the entry point, the section table with names and sizes, and optional header fields, then cross-references them against a signature database of known packers (e.g., UPX, ASPack, Themida) using byte patterns and section heuristics. For a malware analyst performing triage, PEiD instantly reveals whether a binary is packed and which tool packed it, making it the correct choice for PE header and packer analysis.

Why this answer

PEiD is specifically designed to analyze PE (Portable Executable) headers, making it ideal for quickly viewing section tables, import/export tables, and detecting packers or compilers. It parses the IMAGE_NT_HEADERS structure directly, providing a concise summary of the PE layout without requiring disassembly or decompilation.

Exam trap

EC-Council often tests the distinction between a specialized PE header analysis tool (PEiD) and general-purpose reverse-engineering tools (Ghidra, IDA Pro), leading candidates to choose a more complex tool when a simpler, purpose-built one is correct.

How to eliminate wrong answers

Option A is wrong because Strings is a command-line tool that extracts readable ASCII/Unicode strings from a binary, not a PE header parser. Option B is wrong because Ghidra is a full reverse-engineering framework focused on disassembly and decompilation, not a lightweight PE header viewer. Option C is wrong because IDA Pro is a disassembler/debugger that can show PE headers but is overkill for this specific task and not the best tool for a quick header inspection.

68
MCQeasy

In Android forensics, which of the following acquisition methods provides the most complete and forensically sound image of the device's internal storage?

A.Manual extraction through the user interface
B.Logical extraction via ADB
C.File system extraction
D.Physical extraction using a JTAG or chip-off technique
AnswerD

Physical extraction using a JTAG or chip-off technique is the most comprehensive acquisition method because it reads the raw flash memory chips directly, bypassing the Android operating system and its file system driver. JTAG (Joint Test Action Group) connects to the device's test access port to command the CPU to dump the flash contents, while chip-off involves physically desoldering the NAND/eMMC chip and reading it with a dedicated programmer; both yield a complete bit-for-bit image of the entire flash memory, including deleted files, unallocated space, hidden partitions, and data remnants that software-based methods cannot access. This approach is particularly valuable when the device is damaged, locked, or otherwise unresponsive, though it is invasive, may require breaking the device, and demands deep knowledge of the specific chip datasheet and interface protocols.

Why this answer

Physical extraction using a JTAG or chip-off technique provides the most complete and forensically sound image because it accesses the raw NAND flash memory at the hardware level, bypassing the operating system and any software-based restrictions. This method captures deleted data, unallocated space, and the entire file system structure, including areas not accessible via logical or file system extractions, ensuring a bit-for-bit copy of the internal storage.

Exam trap

EC-Council often tests the misconception that logical extraction via ADB is sufficient for a complete forensic image, but candidates must recognize that only physical methods (JTAG/chip-off) capture the entire raw storage, including deleted and hidden data.

How to eliminate wrong answers

Option A is wrong because manual extraction through the user interface only captures data visible to the user through the device's screen and does not access underlying file systems, deleted data, or unallocated space, making it highly incomplete and not forensically sound. Option B is wrong because logical extraction via ADB (Android Debug Bridge) uses the Android operating system's APIs to retrieve only active files and directories, missing deleted data, slack space, and low-level system partitions. Option C is wrong because file system extraction, while more thorough than logical extraction, still relies on the device's kernel to parse the file system and cannot recover data from unallocated blocks or areas outside the mounted file system, unlike physical extraction.

69
MCQmedium

A malware analyst uses Cuckoo Sandbox to analyze a sample. The report shows that the sample sends HTTP POST requests to 'http://malicious.example.com/gate.php' with encrypted data. Which type of indicator of compromise (IoC) is this?

A.Host-based IoC
B.Memory-based IoC
C.Hash-based IoC
D.Network-based IoC
AnswerD

The URL and domain are classic network-based IoCs because they represent communication channels between the infected host and the attacker's command-and-control (C2) infrastructure. In Cuckoo's analysis, these are extracted from captured DNS queries, HTTP requests, or IRC/HTTPS sessions, making them directly associated with network traffic rather than host state or file content.

Why this answer

The HTTP POST request to a remote URL with encrypted data is a classic network-based indicator because it involves communication over a network protocol (HTTP) to an external server. Cuckoo Sandbox captures this as a network artifact, making it a network-based IoC (Option D). Host-based IoCs focus on file system or registry changes, memory-based on in-RAM artifacts, and hash-based on file fingerprints.

Exam trap

EC-Council often tests the distinction between host-based and network-based IoCs by presenting a network artifact (like an HTTP request) and expecting candidates to recognize it as network-based, not host-based, even though the malware runs on the host.

How to eliminate wrong answers

Option A is wrong because host-based IoCs refer to artifacts on the local system (e.g., files created, registry keys modified, processes spawned), not outbound network traffic. Option B is wrong because memory-based IoCs involve artifacts found in RAM (e.g., injected code, API hooks, process memory dumps), not network packets. Option C is wrong because hash-based IoCs are cryptographic hashes (e.g., MD5, SHA-1, SHA-256) of files, used to identify known malware samples, not behavioral network patterns.

70
MCQeasy

During a mobile forensics investigation, an examiner needs to acquire data from an iPhone running iOS 14. Which of the following acquisition methods provides the MOST complete data extraction?

A.File system acquisition via jailbreak
B.Manual acquisition by browsing the device
C.Physical acquisition via JTAG or chip-off
D.Logical acquisition via iTunes backup
AnswerC

Physical acquisition via JTAG or chip-off is the gold standard for mobile forensic imaging because it accesses the raw NAND/eMMC storage controller directly, independent of the device's operating system. JTAG exploits the Joint Test Action Group debug port to force the CPU to dump memory, while chip-off removes the memory chip and reads it with a programmer; both produce a complete bit-for-bit forensic image, including deleted data, unallocated clusters, and partially overwritten file remnants that would be unavailable through any logical method. This approach preserves the entire chip's contents and allows advanced data recovery, though it requires skill, may destroy the device during chip removal, and must be performed with proper anti-static and bitstream-level hashing procedures.

Why this answer

Physical acquisition via JTAG or chip-off provides the most complete data extraction because it captures a bit-for-bit copy of the raw NAND flash memory, including deleted files, unallocated space, and system partitions that are otherwise inaccessible. On iOS 14, Apple's security features (e.g., full-disk encryption, SEP) limit logical and file system methods, but physical techniques bypass the operating system to retrieve the entire storage image, albeit with decryption challenges.

Exam trap

EC-Council often tests the misconception that jailbreak-based file system acquisition is the most complete method, but physical acquisition (JTAG/chip-off) is technically superior because it captures the entire raw storage, including areas the OS hides or encrypts.

How to eliminate wrong answers

Option A is wrong because jailbreaking iOS 14 is often not possible or reliable due to Apple's hardened security (e.g., KTRR, PAC), and even if achieved, file system acquisition still cannot access the raw physical memory or unallocated space, leaving gaps in data recovery. Option B is wrong because manual acquisition only captures visible data through the user interface, missing hidden files, metadata, and deleted content, making it the least complete method. Option D is wrong because logical acquisition via iTunes backup only retrieves files that iOS chooses to include in the backup (e.g., app data, settings), excluding system files, deleted data, and unallocated space, and it relies on the backup encryption state.

71
MCQeasy

In Android forensics, which command is used to extract a full physical image of a device's flash memory over USB using the Android Debug Bridge (ADB)?

A.adb pull /data data.img
B.adb shell dd if=/dev/block/mmcblk0 of=/sdcard/physical.img
C.adb backup -f backup.ab
D.adb install physical.img
AnswerB

adb shell dd if=/dev/block/mmcblk0 of=/sdcard/physical.img invokes the dd utility on the device to read the raw block device /dev/block/mmcblk0, which typically represents the entire internal storage or eMMC chip. This creates a bit-for-bit physical image that includes all data, including deleted files and unallocated sectors, making it ideal for forensic analysis; in practice, you would often redirect output via adb exec-out to a host rather than write to /sdcard to avoid altering evidence.

Why this answer

The `adb shell dd if=/dev/block/mmcblk0 of=/sdcard/physical.img` command uses the `dd` utility to perform a bit-for-bit copy of the raw block device representing the internal flash memory (mmcblk0) to a file on the device's SD card, which can then be pulled via ADB. This method captures a full physical image, including deleted data and unallocated space, which is essential for deep forensic analysis.

Exam trap

The CHFI exam often tests the distinction between logical acquisition (adb pull) and physical acquisition (adb shell dd), so the trap here is that candidates confuse the simple file copy command (adb pull) with the raw block-level imaging command (adb shell dd), assuming any command with 'pull' or 'backup' can produce a forensic image.

How to eliminate wrong answers

Option A is wrong because `adb pull /data data.img` only copies the logical contents of the /data partition, not a raw block-level image, and thus misses deleted files, unallocated space, and metadata from other partitions. Option C is wrong because `adb backup -f backup.ab` creates a logical backup of app data and system settings, not a physical image of flash memory; it does not capture the raw block device or unallocated space. Option D is wrong because `adb install physical.img` is used to install an APK file, not to extract an image; attempting to install a raw image file would fail or corrupt the device.

72
MCQhard

During a forensic examination of a Windows system infected with ransomware, the analyst finds that the file timestamps (creation, modification, access) for several critical system files have been altered to match legitimate Windows files. Which anti-forensic technique is MOST likely being used?

A.Data hiding via ADS
B.Steganography
C.Log wiping
D.Timestomping
AnswerD

Timestomping is an anti-forensic technique that deliberately alters a file's timestamps—such as creation, modification, and access times—typically on NTFS by modifying $STANDARD_INFORMATION or $FILE_NAME attributes. Attackers use it to make malicious files appear old, legitimate, or to match expected system activity, thereby evading investigative timelines. Detection often relies on inconsistencies between MFT attributes, USN journal entries, or comparing timestamps against volume shadow copies and prefetch data.

Why this answer

Timestomping is the deliberate alteration of file timestamps (creation, modification, access) to mislead forensic investigators. In this scenario, the ransomware modified critical system file timestamps to match legitimate Windows files, which is the hallmark of timestomping. This technique is commonly used to evade timeline analysis and hide the true sequence of malicious activity.

Exam trap

EC-Council often tests the distinction between timestomping (altering file timestamps) and log wiping (removing event logs), so the trap here is that candidates may confuse 'log wiping' with any timestamp-related manipulation, but log wiping specifically targets event logs, not file metadata.

How to eliminate wrong answers

Option A is wrong because data hiding via Alternate Data Streams (ADS) conceals data within NTFS file streams without altering timestamps, not by modifying them to match legitimate files. Option B is wrong because steganography hides data within other files (e.g., images or audio) and does not involve changing file timestamps. Option C is wrong because log wiping targets system or application logs to remove evidence, not file metadata timestamps on the filesystem.

73
MCQhard

A forensic examiner is analyzing an Android device that has been factory reset. Which of the following artefacts is MOST likely to still be recoverable from the device's flash memory after a factory reset, assuming no overwrite has occurred?

A.The GUID Partition Table (GPT)
B.The device's encryption keys
C.The Android OS system files
D.User data such as photos and contacts
AnswerD

A factory reset in Android formats the userdata partition by deleting its ext4 or f2fs metadata and marking blocks as free, but it does not necessarily overwrite the underlying sectors on the flash storage. Forensic examiners can therefore carve files from unallocated space using techniques like file signature carving, and if the device's encryption was disabled or the cryptographic keys can be derived/reset, data like photos and contacts may be reconstructed. This is precisely why the examiner should focus on residual user data in unallocated space after a reset.

Why this answer

After a factory reset on an Android device, the operating system typically performs a 'fastboot format' or 'wipe data/factory reset' which only unmounts the userdata partition and marks its blocks as free in the ext4 or F2FS filesystem metadata. The actual user data (photos, contacts, etc.) remains physically stored in the NAND flash memory until those blocks are overwritten by new data. Because no overwrite has occurred in this scenario, the raw data is still recoverable using forensic tools that bypass the filesystem and read the flash memory directly.

Exam trap

EC-Council often tests the misconception that a factory reset securely erases all data, when in fact it only removes filesystem pointers, leaving the underlying data recoverable until overwritten.

How to eliminate wrong answers

Option A is wrong because the GUID Partition Table (GPT) is stored in the boot partition area (LBA 1–34) and is not erased or affected by a factory reset; it remains intact and is not a user-data artifact. Option B is wrong because encryption keys are stored in the device's dedicated hardware-backed keystore (e.g., Trusted Execution Environment or StrongBox) and are securely wiped or invalidated during a factory reset, making them unrecoverable. Option C is wrong because Android OS system files reside in the system partition, which is read-only and not modified by a factory reset; they are not user data and are not the target of recovery in this context.

74
MCQhard

A forensic investigator is analyzing a malware sample that appears to be packed. Using PEiD, the analyst detects an entropy value of 7.8 and the entry point section is named 'UPX0'. Which of the following tools should the analyst use NEXT to unpack the malware for static analysis?

A.UPX -d
B.Ghidra
C.Process Monitor
D.IDA Pro
AnswerA

UPX -d is the correct command-line invocation because the -d flag tells the UPX utility to decompress (unpack) an executable that was previously packed with UPX. This restores the original program code and data so a malware analyst can statically inspect the actual malicious logic rather than the small decompression stub. It is the most direct, automated method available in the standard toolset for this exact purpose.

Why this answer

The presence of 'UPX0' as the entry point section name and an entropy value of 7.8 (very high, indicating compression or encryption) strongly suggests the malware is packed with UPX (Ultimate Packer for eXecutables). The correct next step is to use UPX with the -d (decompress) switch to unpack the binary, restoring the original executable for static analysis. This is a standard, reversible unpacking method that does not require dynamic analysis or disassembly of the packed stub.

Exam trap

EC-Council often tests the distinction between tools for unpacking versus tools for analysis, expecting candidates to recognize that UPX -d is the direct unpacking utility, while Ghidra and IDA Pro are analysis tools that require an already-unpacked binary for effective static analysis.

How to eliminate wrong answers

Option B (Ghidra) is wrong because Ghidra is a reverse-engineering framework for disassembly and decompilation, not a dedicated unpacking tool; attempting to analyze a packed binary in Ghidra without first unpacking it would yield obfuscated or compressed code, making static analysis ineffective. Option C (Process Monitor) is wrong because Process Monitor is a dynamic analysis tool for capturing real-time system activity (registry, file system, process/thread activity), not for unpacking or static analysis of a binary. Option D (IDA Pro) is wrong because IDA Pro is an interactive disassembler and debugger; while it can be used to analyze packed binaries with plugins, the immediate next step after detecting UPX packing is to use the UPX tool itself to decompress the file, as IDA Pro is not a dedicated unpacker and would still require unpacking first for effective static analysis.

75
MCQmedium

During a malware investigation, you find that a process named `svchost.exe` is making outbound connections to an IP address known to be malicious. What tool would be BEST to capture the network traffic for further analysis?

A.PEiD
B.Process Explorer
C.Regshot
D.Wireshark
AnswerD

Wireshark is the correct tool because it is a network protocol analyzer that captures live packets and decodes hundreds of protocols, allowing you to inspect individual frames, follow TCP streams, and filter traffic by IP, port, or protocol. In a malware investigation, it reveals command-and-control activity, malicious payloads, and data exfiltration patterns associated with the suspicious process's network communications.

Why this answer

Wireshark is the best tool for capturing and analyzing network traffic because it can intercept packets at the network interface level, allowing you to inspect the full payload and headers of outbound connections from `svchost.exe` to the malicious IP. This enables deep analysis of protocols, data exfiltration attempts, and command-and-control communication patterns, which is essential in malware forensics.

Exam trap

EC-Council often tests the distinction between process analysis tools (like Process Explorer) and network analysis tools (like Wireshark), leading candidates to mistakenly choose Process Explorer because it can show network connections in its lower pane, but it cannot capture or inspect packet contents.

How to eliminate wrong answers

Option A is wrong because PEiD is a tool for detecting packers, cryptors, and compilers in executable files, not for capturing network traffic. Option B is wrong because Process Explorer is a process management and analysis tool that shows process details, handles, and DLLs, but it does not capture or analyze network packets. Option C is wrong because Regshot is a registry comparison tool used to detect changes made to the Windows registry, not for network traffic capture.

Page 1 of 2 · 119 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Mobile and Malware Forensics questions.