Courseiva

CCNA Computer Forensics Investigation Process Questions

5 questions · Computer Forensics Investigation Process · All types, answers revealed

1
MCQeasy

During a forensic investigation, an analyst discovers that the suspect's hard drive was encrypted using BitLocker. The analyst has obtained the recovery key. Which of the following is the best next step to ensure data integrity?

A.Decrypt the drive using the recovery key and then create a forensic image.
B.Run a live analysis tool to extract encryption keys from memory.
C.Create a forensic image of the encrypted drive, then decrypt the image.
D.Boot the suspect computer and copy files to an external drive.
AnswerC

Creating a bit-for-bit forensic image of the encrypted drive before any decryption preserves the original evidence in its native state, capturing the full encrypted volume, partition table, free space, and deleted data remnants. The analyst can then decrypt that image on a write-protected or isolated forensic workstation using the known recovery key or extracted keys, leaving the original exhibit untouched and maintaining chain of custody. This workflow is the accepted standard for full-disk-encrypted evidence because it separates acquisition from decryption and permits multiple independent analyses.

Why this answer

Creating a forensic image of the encrypted drive before decryption preserves the original evidence in its pristine, unaltered state. Decrypting the image later using the recovery key ensures that the original encrypted data remains intact and verifiable, maintaining data integrity throughout the investigation.

Exam trap

EC-Council often tests the principle that forensic imaging must occur before any decryption or analysis to preserve evidence integrity, and candidates mistakenly believe decryption first is acceptable because they have the key.

How to eliminate wrong answers

Option A is wrong because decrypting the drive directly on the original hardware modifies the data and metadata, breaking the chain of custody and potentially altering evidence. Option B is wrong because running a live analysis tool to extract encryption keys from memory is unnecessary when the recovery key is already obtained, and live acquisition risks modifying the system state and compromising integrity. Option D is wrong because booting the suspect computer and copying files to an external drive alters the original media and does not create a bit-for-bit forensic image, violating forensic best practices.

2
MCQmedium

A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?

A.Immediately power on the server to check for running processes.
B.Copy all files from the server to an external USB drive.
C.Run antivirus scan to ensure no malware is present before imaging.
D.Secure the scene, photograph the setup, document connections, remove hard drives, and create forensic images using a write-blocker.
AnswerD

This is the correct forensic process: first secure the scene to prevent interference, then photograph and document the physical setup and all connections to preserve the context. Identify and collect volatile data if applicable, then remove the hard drives using proper anti-static procedures. Using a write-blocker when creating a forensic image prevents any write operations to the original drive, and hashing the image ensures the preservation of a verifiable, bit-for-bit copy for analysis and chain-of-custody.

Why this answer

It follows the established forensic investigation process: secure the scene to prevent contamination, document the state of the server (photographs and connection diagrams), then physically remove the hard drives and create forensic images using a write-blocker to preserve the original data without alteration. This ensures evidence integrity and admissibility in legal proceedings.

Exam trap

EC-Council often tests the misconception that immediate data collection (like powering on or scanning) is acceptable, when in fact the first priority is to preserve the scene and prevent any modification to the evidence.

How to eliminate wrong answers

Option A is wrong because powering on a server that has been shut down can alter volatile data (e.g., memory contents, temporary files, system logs) and may trigger anti-forensic mechanisms, destroying evidence. Option B is wrong because copying files directly to an external USB drive modifies file metadata (e.g., last access timestamps) and does not capture deleted data or unallocated space, violating forensic best practices. Option C is wrong because running an antivirus scan on a live or powered-off system can modify files (e.g., quarantine, deletion, or repair) and alter the evidence, compromising its integrity.

3
MCQeasy

A CHFI analyst is called to investigate a suspected insider threat. The suspect's laptop is turned on and logged in. The analyst needs to capture volatile data before shutting it down. Which of the following should the analyst capture first?

A.The contents of the RAM
B.The contents of the hard drive
C.The web browser cache
D.The system event logs
AnswerA

RAM contains volatile data such as running processes, network connections, and encryption keys, which are lost when the system is powered off. Capturing RAM first preserves this critical evidence. It is the most volatile and should be prioritized. Tools like FTK Imager or Volatility can be used for memory capture.

Why this answer

RAM is the most volatile data and is lost when the system is powered off. Capturing it first preserves running processes, network connections, and potentially encryption keys. Hard drive contents, event logs, and browser cache are non-volatile and can be acquired later.

Following the order of volatility is a key principle in forensic investigations.

Exam trap

The trap here is assuming that hard drive data is more important because it is larger, ignoring that RAM is irreplaceable once lost.

4
MCQmedium

An analyst executed the commands shown in the exhibit on a Windows system to prepare a forensic image for analysis. What is the most likely reason for the error message from e2fsck?

A.The analyst failed to properly dismount the source volume before imaging, leading to filesystem inconsistencies.
B.The forensic image was not acquired with a write-blocker, causing data corruption.
C.The image file contains an NTFS filesystem, but e2fsck is designed for ext filesystems.
D.The e2fsck command syntax is incorrect; it should be 'e2fsck -f -n' instead.
AnswerA

The sequence shows `fsutil dismount` being run on C:, but a forensic image taken afterward—especially after Windows remounts the volume or during a live acquisition—will capture the volume in an inconsistent state. When Windows later performs recovery on the dirty volume, metadata updates begin immediately, so e2fsck in the analyst's analysis environment will legitimately report superblock, group descriptor, or inode inconsistencies that were never present in the source. This is the classic 'dirty volume' imaging error, not a problem with the image tool.

Why this answer

The error message from e2fsck indicates that the filesystem has inconsistencies, which typically occur when a volume is imaged while it is still mounted and actively being written to. The analyst likely did not dismount the source volume before acquiring the forensic image, resulting in a snapshot that reflects an inconsistent state (e.g., dirty journal, unflushed writes). This is a common chain-of-custody and acquisition procedure error in forensic imaging.

Exam trap

EC-Council often tests the misconception that a write-blocker alone guarantees a forensically sound image, but the trap here is that even with a write-blocker, imaging a mounted volume can produce an inconsistent filesystem because the OS may have pending writes in cache.

How to eliminate wrong answers

Option B is wrong because a write-blocker prevents writes to the source drive during acquisition, but it does not affect the consistency of the filesystem on the source volume if the volume was mounted and active; the error is about filesystem state, not write-blocker usage. Option C is wrong because the exhibit shows the analyst used 'dd' to create a raw image, and e2fsck is designed for ext2/3/4 filesystems; if the image contained NTFS, e2fsck would produce a different error (e.g., 'bad magic number') rather than a filesystem inconsistency error. Option D is wrong because the syntax 'e2fsck -f -n' is valid (force check and non-interactive), but the error message shown is about filesystem inconsistencies, not a command syntax error; the command executed correctly and detected the issue.

5
MCQmedium

A CHFI analyst is preparing a forensic workstation to image a suspect's USB flash drive. The analyst needs to ensure that the write-blocker is functioning correctly before connecting the drive. Which of the following is the most appropriate method to verify that the write-blocker is preventing write operations?

A.Connect the suspect's USB drive directly to the forensic workstation and attempt to write a test file; if the write succeeds, the write-blocker is not needed.
B.Connect the write-blocker to the forensic workstation, then use a known clean USB drive and attempt to write a file to it; if the write fails, the write-blocker is working.
C.Use a software write-blocker on the forensic workstation instead of a hardware write-blocker, as software blockers are more reliable and do not require validation.
D.Check the write-blocker's LED indicators; if the power light is on and the read/write switch is set to read-only, the write-blocker is functioning correctly.
AnswerB

This method directly tests the write-blocker's function by attempting a write operation to a known clean drive. If the write is blocked, it confirms the write-blocker is operational. It is safe because the drive is not evidence, and the test does not alter the original evidence. This is a standard validation procedure recommended in forensics.

Why this answer

The correct method is to test the write-blocker with a known clean drive by attempting a write operation. If the write is blocked, the write-blocker is functioning. This ensures the suspect's drive remains unaltered.

Other methods either rely on indicators, which are insufficient, or risk contaminating evidence. Proper validation is a key step in the forensic process.

Exam trap

The trap here is assuming that LED indicators or software write-blockers provide sufficient assurance without functional testing.

Ready to test yourself?

Try a timed practice session using only Computer Forensics Investigation Process questions.

CCNA Computer Forensics Investigation Process Questions | Courseiva