Courseiva
← Back to Computer Hacking Forensic Investigator CHFI questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Computer Hacking Forensic Investigator CHFI practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CHFI
exam code
EC-Council
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CHFI topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

In email forensics, which TWO of the following headers are most useful for identifying the true origin of an email? (Select TWO.)

Question 2mediummulti select
Full question →

Which TWO of the following are indicators of a webshell on a web server? (Select TWO.)

Question 3mediummulti select
Full question →

Which TWO artifacts are commonly used to identify USB device insertion history on a Windows system? (Select TWO.)

Question 4hardmulti select
Full question →

Which THREE of the following are challenges specific to container forensics? (Select THREE.)

Question 5hardmulti select
Full question →

A cloud forensic investigator is analyzing a GCP audit log entry for a Compute Engine instance. Which THREE fields are essential for identifying the user and operation performed?

Question 6mediummulti select
Full question →

Which TWO of the following are requirements for evidence to be admissible in court? (Select two.)

Question 7easymulti select
Full question →

Which TWO of the following are valid email header fields that can be used to detect email spoofing? (Select 2)

Question 8mediummulti select
Full question →

Which TWO of the following are appropriate techniques for identifying a webshell on a compromised web server?

Question 9easymulti select
Full question →

A forensic analyst reviews a Windows system for signs of malware persistence. Which TWO registry locations are commonly used to achieve persistence via auto-start programs?

Question 10mediummulti select
Full question →

A forensic analyst is examining a Google Cloud Platform (GCP) environment after a security incident. Which TWO GCP services should the analyst use to audit API activity and resource changes? (Select TWO.)

Question 11mediummulti select
Full question →

During a mobile forensic investigation, an examiner wants to recover deleted WhatsApp messages from an Android device. Which of the following artefacts should the examiner examine? (Select TWO.)

Question 12easymulti select
Full question →

Which TWO of the following are common hashing algorithms used to verify the integrity of forensic images? (Select two.)

Question 13mediummulti select
Full question →

Which TWO of the following are essential steps that a first responder should take when arriving at a digital crime scene? (Select TWO)

Question 14mediummulti select
Full question →

Which TWO tools are specifically designed for file carving (recovering files based on signatures) and are commonly used in digital forensics?

Question 15easymulti select
Full question →

Which TWO of the following are primary purposes of using the GrayKey tool in iOS forensics?

Question 16mediummulti select
Full question →

A forensic analyst is examining an Android device using ADB extraction. Which TWO statements about ADB extraction are true?

Question 17easymulti select
Full question →

An Android forensic examiner performs a physical acquisition on a device. Which TWO of the following are typical artefacts that can be recovered from the /data/data/ directory on a non-rooted device if the acquisition method allows full file system access?

Question 18hardmulti select
Full question →

During dynamic analysis of a malware sample in a sandbox, an analyst observes the following behaviours: (1) A file is created at C:\Windows\System32\drivers\etc\hosts, (2) A registry key is set at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateSvc, (3) Outbound TCP connections to 198.51.100.10 on port 8080. Which THREE of the following IoCs are MOST relevant to share with the threat intelligence team?

Question 19hardmulti select
Full question →

A security analyst observes a process making repeated network connections to an IP address 192.168.1.100 on TCP port 4444, and the process writes a DLL file to C:\Users\Public\. Which THREE actions should the analyst take immediately as part of dynamic analysis?

Question 20mediummulti select
Full question →

A forensic examiner is analyzing an Android device that was factory reset. Which TWO artefacts or methods could the examiner use to potentially recover or identify data from before the reset?

These CHFI practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style CHFI questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.