Courseiva

CCNA OS and Network Forensics Questions

17 of 167 questions · Page 3/3 · OS and Network Forensics · Answers revealed

151
MCQmedium

During a Linux forensic investigation, you find that the file /var/log/auth.log has been deleted. Which of the following artefacts would BEST help determine recent SSH login attempts?

A.Contents of /etc/shadow
B.Bash history from /root/.bash_history
C.Cron job entries in /etc/crontab
D.Output of the 'last' command
AnswerD

The 'last' command parses the binary wtmp log (/var/log/wtmp) to display session records, including user, terminal, source IP, and login/logout timestamps. This directly captures successful local and SSH logins, making it the standard artifact for identifying recent successful authentication events. Concatenating the output with the 'last' command's default format provides a timeline of who accessed the system.

Why this answer

The 'last' command reads the /var/log/wtmp binary log file, which records all login and logout events, including SSH sessions. Even if /var/log/auth.log is deleted, the wtmp file persists and provides a reliable record of recent SSH login attempts, making option D the best choice.

Exam trap

The trap here is that candidates assume auth.log is the only source for SSH login data, overlooking the wtmp file that the 'last' command queries, which is a separate and more persistent artefact.

How to eliminate wrong answers

Option A is wrong because /etc/shadow stores hashed user passwords and password aging information, not login attempt records. Option B is wrong because /root/.bash_history logs only commands executed in a bash shell, not SSH authentication events. Option C is wrong because cron job entries in /etc/crontab schedule periodic tasks and do not record login attempts.

152
MCQmedium

A forensic examiner finds a suspicious entry in the Linux file /etc/passwd: 'backdoor:x:0:0:root:/root:/bin/bash'. What is the MOST significant security issue with this entry?

A.The entry has no password hash
B.The home directory is set to /root
C.The UID is 0, granting root privileges
D.The shell is /bin/bash
AnswerC

In Linux, UID 0 is reserved for root and any process or user with UID 0 bypasses all permission checks. A passwd entry with UID 0 means that logging into that account immediately grants full root control, regardless of the username appearing in the entry. This is a well-known backdoor technique, making it the most critical indicator in the passwd file.

Why this answer

The UID (user ID) of 0 is the root user identifier in Linux. Any account with UID 0 is granted the same privileges as the root user, regardless of the account name. This entry effectively creates a backdoor account with full administrative control over the system, bypassing normal authentication and accountability measures.

Exam trap

The CHFI exam often tests the misconception that the password hash field or the shell choice is the primary security concern, when in fact the UID of 0 is the critical indicator of root-level access.

How to eliminate wrong answers

Option A is wrong because the 'x' in the password field indicates that the password hash is stored in /etc/shadow, which is standard and not a security issue by itself. Option B is wrong because setting the home directory to /root is unusual for a non-root account but does not inherently grant elevated privileges; it is a configuration choice, not a security vulnerability. Option D is wrong because /bin/bash is a standard shell and does not confer any special privileges; the shell choice does not affect the account's permission level.

153
Multi-Selecthard

Which THREE of the following are common indicators of a web shell presence on a compromised IIS web server? (Select THREE.)

Select 3 answers
A.Increased 404 errors in HTTP logs
B.Process w3wp.exe making outbound connections to an unknown IP
C.Scheduled tasks that execute cmd.exe or powershell.exe
D.Anomalous files with .asp or .aspx extensions in the wwwroot directory
E.Normal GET requests to static .html pages
AnswersB, C, D

Process w3wp.exe making outbound connections to an unknown IP is a strong indicator because w3wp.exe is the IIS worker process that normally only receives inbound HTTP requests and responds to them; it should not initiate outbound connections to arbitrary external addresses. When a web shell is uploaded and invoked, the attacker can use it to run commands, exfiltrate data, or create a reverse shell via the compromised worker process, causing the trusted w3wp.exe process to beacon to an external IP. Such unexpected outbound traffic from a known server-side process is frequently missed by simple HTTP log review, making it a high-value network-based IOC that pairs with file-based web shell detection.

Why this answer

Option B is correct because w3wp.exe is the IIS worker process that normally serves web content and should not initiate outbound network connections; seeing it connect to an unknown external IP is a strong indicator that a web shell is being used for command-and-control or data exfiltration. Option C is correct because attackers commonly establish persistence alongside a web shell by creating scheduled tasks that invoke cmd.exe or powershell.exe, which is abnormal for a standard IIS server. Option D is correct because web shells are typically dropped as .asp or .aspx files in the wwwroot directory so they can be executed by IIS, and unexpected files with those extensions in that location are a classic compromise artifact.

Option A is not a reliable indicator because increased 404 errors simply reflect missing resources or scanning noise and do not by themselves indicate a web shell. Option E is not an indicator because normal GET requests for static .html pages are ordinary benign web traffic.

Exam trap

A common misconception is that HTTP error codes like 404 are direct signs of compromise, when in reality they are more indicative of reconnaissance or misconfiguration, not the active presence of a web shell.

154
Multi-Selectmedium

Which TWO Windows Event IDs are associated with successful logon or explicit credential usage? (Choose TWO.)

Select 2 answers
A.4648
B.4720
C.4624
D.4625
E.7045
AnswersA, C

Event ID 4648 records a logon attempt using explicit credentials, such as when a user runs a process with `runas` or supplies alternate domain credentials for a network connection. This satisfies the stem’s constraint of “explicit credential usage” because the event logs the target account and the source process, distinguishing it from interactive logon events like 4624.

Why this answer

Event ID 4624 [CORRECT] is logged in the Windows Security log when a logon attempt succeeds, recording details such as logon type, account name, and authentication package, so it directly matches the 'successful logon' part of the question. Event ID 4648 [CORRECT] is generated when a process attempts an explicit logon using credentials other than those of the current logged-on user (for example, RunAs or passing alternate credentials), which matches the 'explicit credential usage' part. By contrast, 4720 is logged when a new user account is created, 4625 records a failed logon attempt, and 7045 is a System log event indicating a new service was installed — none of these represent a successful logon or explicit credential use.

Exam trap

The trap here is that candidates often confuse Event ID 4625 (failed logon) with 4624 (successful logon), or mistakenly associate 4720 (account creation) with logon activity, while overlooking the specific purpose of 4648 for explicit credential usage.

155
Multi-Selectmedium

In a Mac forensic investigation, which TWO artifacts are valuable for determining the timeline of file access? (Select two.)

Select 2 answers
A.ShellBags
B.Prefetch files
C.Unified logging
D.NTUSER.DAT
E.FSEvents
AnswersC, E

Unified logging is a macOS subsystem that captures structured, timestamped diagnostic messages from the kernel, processes, and user applications into binary .tracev3 stores under /var/db/diagnostics and /var/db/uuidtext. Investigators query it with log show or log stream to reconstruct file access, process execution, network activity, and system errors. It is a core native artifact on modern Macs and one of the two valid items in this question.

Why this answer

Unified logging (C) is correct because macOS's unified logging system (introduced in 10.12) stores system and application activity in .tracev3 files under /var/db/diagnostics, and its timestamps can establish when processes ran or files were touched, supporting timeline reconstruction. FSEvents (E) is correct because the FSEvents database (.fseventsd) records directory-level filesystem change events with timestamps, which is a core artifact for building a macOS file-access timeline. ShellBags (A) and NTUSER.DAT (D) are Windows artifacts (registry-based folder view settings and per-user registry hive, respectively) and do not exist on macOS.

Prefetch files (B) are also a Windows artifact (C:\Windows\Prefetch) used for program execution analysis, not macOS file-access timelines.

Exam trap

CHFI often tests the distinction between Windows-specific artifacts (ShellBags, Prefetch, NTUSER.DAT) and macOS-specific artifacts (Unified logging, FSEvents), so the trap here is assuming all forensic artifacts are cross-platform or that registry-based artifacts apply to macOS.

156
MCQmedium

A Windows system is suspected of having malware that maintains persistence by starting every time a user logs in. Which registry key should be examined FIRST for this persistence mechanism?

A.ShellBags
B.NTUSER.DAT
C.Run keys
D.HKLM\SAM
AnswerC

The Run registry keys, specifically HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, define programs that Windows automatically executes each time a user logs on. Each value name is arbitrary, but the value data is a command line (e.g., C:\Windows\Temp\payload.exe). Malware frequently uses these keys for persistence because they are easy to write, require no elevated privilege for HKCU, and survive a reboot; they are also a primary focus of Autoruns/Windows Defender detections.

Why this answer

The Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) are the most common and straightforward persistence mechanism for malware that executes on user login. These registry keys specify programs that automatically run when a user logs into their account, making them the first place to check for such persistence.

Exam trap

In CHFI, the trap is that candidates might confuse persistence mechanisms like ShellBags (view settings) or SAM (credentials) with startup entries, leading them to pick a wrong answer. The Run keys (HKCU and HKLM) are the standard locations for user logon persistence.

How to eliminate wrong answers

Option A is wrong because ShellBags store folder view settings (size, position, icon layout) for Explorer windows, not executable startup entries. Option B is wrong because NTUSER.DAT is a registry hive file that contains per-user settings, including Run keys, but it is not a specific registry key to examine directly; the question asks for a registry key, not a file. Option D is wrong because HKLM\SAM stores local user account credentials and security account manager data, not startup programs.

157
MCQeasy

A security analyst is reviewing Windows Security Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this MOST likely indicate?

A.Brute-force password guessing attack
B.Service installation
C.Account lockout policy change
D.Successful account logon
AnswerA

Event ID 4625 is the Windows Security log event for a failed logon attempt. When dozens or hundreds of these events occur from the same source IP or user account within a short window, it strongly indicates a brute-force password guessing attack. Analysts should correlate Sub Status codes (e.g., 0xC000006A for bad password) and Logon Type (e.g., 2 interactive, 3 network) to confirm automated guessing. The rapid repetition of failures with varying passwords is the classic signature of this attack.

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple failures in a short time suggest a brute-force attack against the user account.

158
Multi-Selectmedium

During a Linux forensic investigation, an analyst examines the file /var/log/auth.log and finds repeated entries with 'Failed password for root from 192.168.1.200 port 22 ssh2'. Which TWO conclusions can the analyst draw from this evidence?

Select 2 answers
A.The source IP 192.168.1.200 belongs to a local subnet
B.The system is experiencing a brute-force attack on SSH
C.The SSH service is enabled and listening on port 22
D.The attacker attempted to exploit a vulnerability in the SSH version
E.An unauthorized user successfully logged in as root
AnswersB, C

The log pattern shows multiple 'Failed password' events for SSH from the same source IP within a short window, which is the classic indicator of an automated brute-force attack. Attackers cycle through username/password combinations hoping for a match, generating a high volume of authentication failures. This does not require any vulnerability in SSH itself; it merely targets weak credentials.

Why this answer

Option B is correct because repeated 'Failed password for root' entries in /var/log/auth.log indicate multiple unsuccessful SSH authentication attempts against the root account, which is the classic signature of an SSH brute-force attack. Option C is correct because the log entries show connections to port 22 with the ssh2 protocol, meaning the SSH daemon (sshd) is running and accepting connections on TCP port 22. Option A is not supported: 192.168.1.200 is a private RFC 1918 address, but that alone does not prove it is on the same local subnet as the examined host.

Option D is wrong because failed password entries reflect authentication failures, not exploitation of an SSH software vulnerability. Option E is wrong because 'Failed password' explicitly indicates the login attempts did not succeed.

Exam trap

EC-Council CHFI often tests the distinction between failed authentication attempts (indicating a brute-force attack) and successful logins or vulnerability exploitation, leading candidates to incorrectly assume a successful breach or a software exploit from mere failure logs.

159
MCQeasy

Which Linux log file is the PRIMARY source for authentication-related events such as user logins, sudo usage, and failed authentication attempts?

A./var/log/kern.log
B./var/log/syslog
C./var/log/boot.log
D./var/log/auth.log
AnswerD

/var/log/auth.log records PAM and sudo authentication events on Debian-based systems, capturing successful logins, failed password attempts, and privilege escalation via sudo. This directly satisfies the stem's requirement for a primary authentication source covering logins, sudo usage, and failures, unlike general system or kernel logs.

Why this answer

/var/log/auth.log is the primary log file on Linux systems (especially Debian/Ubuntu) that records authentication-related events, including user logins (via sshd, login, su), sudo command executions, and failed authentication attempts. This log is generated by the authpriv facility in syslog and is specifically designed to capture security and authentication messages, making it the go-to source for forensic analysis of user access and privilege escalation.

Exam trap

In EC-CHFI, candidates often confuse /var/log/syslog with /var/log/auth.log, thinking syslog captures all system events. However, authentication events are specifically routed to a separate file (auth.log or secure) for security isolation and forensic analysis of user access.

How to eliminate wrong answers

Option A is wrong because /var/log/kern.log contains kernel messages (e.g., driver errors, hardware events) and does not log user authentication or sudo usage. Option B is wrong because /var/log/syslog captures general system messages (e.g., daemon logs, cron jobs) but not the authpriv facility by default; authentication events are typically excluded from syslog to separate security-relevant data. Option C is wrong because /var/log/boot.log records boot-time messages from the init system (e.g., systemd or SysV) and has no relation to runtime authentication events like logins or sudo.

160
Multi-Selecthard

An analyst is reviewing a Linux system for signs of a rootkit. Which THREE of the following are common indicators of a rootkit infection? (Select THREE.)

Select 3 answers
A.Incorrect file permissions on /etc/passwd
B.Anomalies in the /proc filesystem
C.Large number of failed SSH login attempts
D.Suspicious loadable kernel modules
E.Modified system binaries like ls and ps
AnswersB, D, E

Anomalies in the /proc filesystem are a strong rootkit indicator because /proc is a virtual filesystem that reflects kernel data structures, including the live process list and network sockets. Kernel-level rootkits often hook the /proc handler routines or hide their own PIDs and associated entries, so comparing output of ps and netstat against /proc directly can reveal hidden processes or mismatched connection tables. For example, a rootkit may unlink its process from the task list while left visible in /proc's pid directory, or vice versa, and an examiner should inspect /proc/<pid>/cmdline and /proc/net/tcp for subtle inconsistencies.

Why this answer

Option B is correct because a rootkit often hooks or hides processes, files, and network sockets by tampering with the kernel's virtual /proc filesystem, so discrepancies between /proc entries and tools like ps or ls, or missing PIDs, are a classic anomaly. Option D is correct because rootkits frequently install malicious loadable kernel modules (LKMs) to intercept syscalls and conceal their presence, so unexpected or unsigned modules in lsmod//proc/modules are a strong indicator. Option E is correct because rootkits commonly replace or trojanize core system binaries such as ls, ps, netstat, and top so they omit the attacker's processes and files, which can be detected via package verification (rpm -V, debsums) or checksum comparison.

Option A is not a typical rootkit indicator, since incorrect permissions on /etc/passwd usually reflect misconfiguration or a separate privilege/account issue rather than kernel-level concealment. Option C is also not specific to rootkits, as a high volume of failed SSH logins indicates brute-force or credential-stuffing attempts, not the stealth mechanisms a rootkit employs.

Exam trap

EC-Council often tests the distinction between network-based attack indicators (like failed SSH logins) and host-based rootkit artifacts (like /proc anomalies or modified binaries), leading candidates to confuse brute-force activity with kernel-level compromise.

161
Multi-Selecthard

A security team is analyzing a compromised Linux server. Indicators suggest the attacker used a web shell. Which THREE of the following are common persistence mechanisms that may be found on the system? (Select THREE.)

Select 3 answers
A.Adding an SSH public key to /root/.ssh/authorized_keys
B.Cron jobs added to /etc/crontab
C.Modification of the NTUSER.DAT registry hive
D.Prefetch file creation
E.A systemd service in /etc/systemd/system/
AnswersA, B, E

An attacker who gains root access can append a public key to /root/.ssh/authorized_keys, enabling passwordless SSH logins as root indefinitely. This is a low-effort, high-impact persistence mechanism because the legitimate key file already exists and may not trigger immediate alarms. Even if the web shell is patched, the SSH key provides a clean, encrypted backdoor that bypasses normal authentication. Removing it requires auditing the authorized_keys file for unexpected entries.

Why this answer

Option A is correct because appending an attacker-controlled public key to /root/.ssh/authorized_keys grants passwordless SSH access as root, a classic Linux persistence technique. Option B is correct because entries added to /etc/crontab (or /etc/cron.d, user crontabs) cause malicious commands or reverse shells to execute on a schedule, surviving reboots. Option E is correct because a malicious unit file placed in /etc/systemd/system/ and enabled with systemctl enable will start the attacker's payload automatically at boot.

Option C is incorrect because NTUSER.DAT is a Windows registry hive and does not exist on Linux. Option D is incorrect because Prefetch files are a Windows artifact created by the OS for performance, not a Linux persistence mechanism.

Exam trap

EC-Council often tests cross-platform knowledge by including Windows-specific artifacts (like NTUSER.DAT or Prefetch) in Linux-focused questions, hoping candidates overlook the operating system context and select them out of familiarity.

162
MCQeasy

Which tool is commonly used in timeline analysis for digital forensics to parse various artifacts and create a super timeline?

A.Volatility
B.Wireshark
C.Sleuth Kit
D.log2timeline / Plaso
AnswerD

log2timeline (now evolved into Plaso) is the definitive open-source tool for digital forensics timeline analysis. It recursively parses a disk image or collection of files, using numerous parsers to extract timestamps from file system metadata, operating system logs, application traces, browser history, registry keys, and many other artifact types. All parsed timestamps are normalized into a unified SQLite database, enabling the investigator to generate a 'super timeline' that correlates events across multiple sources for temporal reconstruction. This comprehensive multi-source approach is exactly what timeline analysis demands, making it the correct answer.

Why this answer

log2timeline (now part of the Plaso framework) is specifically designed to parse a wide variety of digital forensic artifacts—such as Windows Event Logs, Prefetch files, registry hives, and browser history—and aggregate them into a single, unified super timeline. This super timeline allows investigators to correlate events across different data sources and identify sequences of activity with precise timestamps, which is essential for timeline analysis in OS and network forensics.

Exam trap

EC-Council often tests the distinction between low-level filesystem tools (like Sleuth Kit) and high-level artifact parsing tools (like log2timeline/Plaso), leading candidates to mistakenly choose Sleuth Kit because they associate 'timeline analysis' with file timestamps (MAC times) rather than the comprehensive super timeline that aggregates multiple artifact types.

How to eliminate wrong answers

Option A is wrong because Volatility is a memory forensics framework used for analyzing RAM dumps (e.g., processes, network connections, registry hives in memory), not for parsing filesystem artifacts to build a super timeline. Option B is wrong because Wireshark is a network packet analyzer that captures and inspects live or recorded network traffic (e.g., TCP/IP packets), not a tool for parsing local OS artifacts or generating timelines. Option C is wrong because Sleuth Kit (TSK) provides low-level filesystem analysis tools (e.g., fls, icat, mmls) and can extract file metadata and recover deleted files, but it does not natively parse high-level application artifacts or produce a unified super timeline; that requires additional scripting or integration with tools like log2timeline.

163
MCQmedium

A security analyst detects a sudden spike in failed logon events with Event ID 4625 on a Windows domain controller. The source IP addresses are random and from various external subnets. Which type of attack is MOST likely occurring?

A.Pass‑the‑hash attack
B.Kerberos ticket forgery (Golden Ticket)
C.Insider threat with compromised credentials
D.Brute‑force attack
AnswerD

Each 4625 event explicitly records an authentication failure with logon type, source IP, and username, so a sudden spike from many different source addresses targeting the same accounts is the hallmark of a distributed password-guessing attack. The attacker submits candidate passwords over RDP, SMB, or VPN until one succeeds, which is exactly why the failed-logon count spikes before eventual access. The varied external IPs and volume distinguish this from credential misuse or ticket-forging attacks.

Why this answer

Event ID 4625 indicates a failed logon attempt. A sudden spike from random, external source IPs is characteristic of a brute-force attack, where an attacker systematically tries many username/password combinations against the domain controller. This pattern does not match the stealthier or more targeted nature of the other attack types.

Exam trap

EC-Council often tests the distinction between a brute-force attack (many failed logons from varied IPs) and a pass-the-hash attack (which uses a valid hash and does not generate failed logon events), leading candidates to confuse the two when they see Event ID 4625.

How to eliminate wrong answers

Option A is wrong because a pass-the-hash attack uses captured NTLM hashes to authenticate without needing the plaintext password, and it typically originates from a compromised internal host, not from random external IPs. Option B is wrong because Kerberos ticket forgery (Golden Ticket) involves forging a Kerberos TGT using the KRBTGT hash, which does not generate a spike in failed logon events (Event ID 4625) from external sources. Option C is wrong because an insider threat with compromised credentials would likely show successful logons or a targeted pattern, not a high volume of failed attempts from many random external subnets.

164
MCQmedium

A security analyst reviews Windows Security event logs and finds Event ID 4625 with Logon Type 10. What does this indicate?

A.Failed remote interactive logon (e.g., RDP)
B.Failed service logon attempt
C.Successful network logon
D.Successful local logon
AnswerA

Event ID 4625 is the Windows security event for failed authentication, and Logon Type 10 (RemoteInteractive) is assigned specifically when the attempt occurs via a remote interactive protocol such as RDP. A 4625 event with Logon Type 10 therefore precisely indicates a failed remote interactive logon, commonly seen in RDP brute-force attacks. The combination of the failure code (4625) and the remote interactive logon type (10) leaves no ambiguity about the attempt's outcome and origin.

Why this answer

Event ID 4625 with Logon Type 10 specifically indicates a failed Remote Interactive logon attempt, which is characteristic of Remote Desktop Protocol (RDP) connections. Logon Type 10 is defined in Windows security auditing as 'RemoteInteractive' and is triggered when an authentication attempt fails over a remote desktop session, typically using RDP (port 3389). This event is critical for detecting brute-force or unauthorized RDP access attempts.

Exam trap

The trap here is that candidates often confuse Logon Type 10 with Logon Type 2 (interactive) or Logon Type 3 (network), failing to recognize that Type 10 is specifically for remote interactive (RDP) logons, and that Event ID 4625 always indicates failure, not success.

How to eliminate wrong answers

Option B is wrong because a failed service logon attempt is represented by Logon Type 5, not Logon Type 10, and involves scheduled tasks or services running under a specific account. Option C is wrong because Event ID 4625 is explicitly a failure event (the '5' in 4625 denotes failure), whereas successful network logons are logged as Event ID 4624 with Logon Type 3 (network logon). Option D is wrong because a successful local logon is Event ID 4624 with Logon Type 2 (interactive), not a failure event, and Logon Type 10 is specifically for remote interactive sessions, not local console logons.

165
MCQhard

During a Mac forensic investigation, you examine the unified log for process execution around the time of an incident. Which command-line tool is used to query the macOS unified log?

A.log
B.journalctl
C.dmesg
D.syslog
AnswerA

The unified log is queried with the log command (e.g., log show --last 1h --predicate 'process == "Finder"' --info --debug). It reads the structured, privacy-redacted binary store under /var/db/diagnostics, applying predicates to return timestamps, process metadata, and persistence flags. In forensic triage you typically run log collect to aggregate entries while preserving causality and before volatile data is lost.

Why this answer

The `log` command is the native macOS tool for querying the unified log system, which consolidates kernel, driver, and application logs into a single, high-performance data store. It supports filtering by process, time range, and subsystem, making it essential for forensic timeline reconstruction on macOS. Unlike traditional syslog, the unified log uses a binary format that only `log` can efficiently parse.

Exam trap

EC-Council often tests the distinction between Linux and macOS logging tools, expecting candidates to know that `journalctl` is Linux-specific and that macOS uses its own `log` command, not legacy syslog utilities.

How to eliminate wrong answers

Option B (journalctl) is wrong because it is the query tool for systemd's journal on Linux, not for macOS's unified log. Option C (dmesg) is wrong because it prints kernel ring buffer messages, which is a legacy Linux/Unix utility and does not access the macOS unified log store. Option D (syslog) is wrong because it refers to the legacy syslog protocol and daemon (e.g., syslogd), which macOS replaced with the unified log system in OS X Yosemite (10.10); the `syslog` command is deprecated and cannot query the modern binary log store.

166
MCQhard

An analyst reviews proxy logs and sees repeated requests to a known malicious domain from multiple internal hosts, each using a different User-Agent string. The requests are all GET requests for /images/icon.png. What technique is most likely being used to evade detection?

A.User-Agent randomization
B.HTTPS tunneling
C.IP spoofing
D.Domain generation algorithm (DGA)
AnswerA

Repeated requests containing randomized User-Agent strings strongly indicate the client is deliberately changing that header on every request. User-Agent randomization is a standard anti-detection technique because unmodified command-line tools with absent or malformed User-Agents are easily filtered by security appliances, while frequent switching between browser-like values makes traffic appear to come from diverse legitimate clients. In proxy logs, varied User-Agents from the same source IP defeat naive signature matching, but the high rotation rate itself remains a suspicious behavioral pattern.

Why this answer

The repeated GET requests for the same resource (/images/icon.png) from multiple internal hosts, each with a different User-Agent string, is a classic indicator of User-Agent randomization. This technique is used by malware to evade signature-based detection that relies on static User-Agent values, making the traffic appear to originate from diverse browsers or devices.

Exam trap

EC-Council often tests the distinction between techniques that modify request headers (User-Agent randomization) versus those that change the destination (DGA) or transport (HTTPS tunneling), so candidates may confuse User-Agent randomization with DGA because both are used for evasion.

How to eliminate wrong answers

Option B (HTTPS tunneling) is wrong because the logs show plain HTTP GET requests, not encrypted tunnel traffic; HTTPS tunneling would obscure the request content, not randomize User-Agent headers. Option C (IP spoofing) is wrong because IP spoofing would forge source IP addresses, but the logs show requests from multiple internal hosts (real IPs), and spoofed IPs would not receive responses for TCP-based HTTP. Option D (Domain generation algorithm (DGA)) is wrong because DGA is used to generate new domain names to evade domain blocklists, not to randomize User-Agent strings; the requests here target a single known malicious domain.

167
MCQmedium

In Mac forensics, which artifact stores system-wide and per-user application preferences, often used to determine configured settings and recently accessed files?

A.Unified logging
B..plist files
C.Sqlite databases
D.FSEvents
AnswerB

Property list files encode application preferences as key-value pairs, storing both system-wide settings in /Library/Preferences and per-user settings in ~/Library/Preferences. This satisfies the stem's requirement to determine configured settings and recently accessed files, since plists also record recent items, window states and document history.

Why this answer

In macOS, application and system preferences are stored in property list (.plist) files. These XML or binary files contain key-value pairs that define configured settings, default values, and recently accessed files (e.g., NSRecentDocuments). Forensic examiners parse .plist files to recover user behavior, application usage, and system configuration.

Exam trap

EC-Council often tests the distinction between preference storage (.plist) and logging (Unified logging) or file system change tracking (FSEvents), leading candidates to confuse operational logs with persistent configuration artifacts.

How to eliminate wrong answers

Option A is wrong because Unified logging (os_log) captures system and application log messages, not persistent preference settings or recently accessed file lists. Option C is wrong because SQLite databases store structured data like contacts, messages, or browser history, but they are not the primary artifact for system-wide or per-user application preferences; .plist files serve that role. Option D is wrong because FSEvents records file system changes (creation, modification, deletion) for Time Machine and Spotlight, not application preferences or configured settings.

← PreviousPage 3 of 3 · 167 questions total

Ready to test yourself?

Try a timed practice session using only OS and Network Forensics questions.