Sample questions
Computer Hacking Forensic Investigator CHFI practice questions
An investigator acquires an SSD from a laptop that has been turned off for 24 hours. The suspect recently deleted several incriminating files. Using a forensic imager, the investig…
Storage Forensics and File System AnalysishardSee the answer and why each option is right or wrong →In email forensics, which TWO of the following headers are most useful for identifying the true origin of an email? (Select TWO.)
A security team detects a suspicious process that writes to the Windows registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the MOST likely purpose of this act…
A forensic lab manager is setting up a new lab and must decide on the physical security measures. Which of the following is the MOST important to implement first?
Refer to the exhibit. During incident response, a first responder runs 'netstat -ano' on a compromised Windows system. Which connection is most likely to be the command-and-control…
Incident Response and First Responder SkillseasySee the answer and why each option is right or wrong →The command used to acquire a disk image resulted in an I/O error. What is the most likely cause?
In cloud forensics, one of the major challenges is that data may be stored in multiple jurisdictions with different legal requirements. This challenge is known as:
Which cloud service log is most appropriate for tracking API calls and resource changes in an AWS environment?
An investigator is analyzing cloud storage logs and finds an entry showing that a file was accessed using the root credentials from an IP address in a different geographic region.…
Which of the following is the PRIMARY purpose of using a write blocker in computer forensics?
Computer Forensics Fundamentals and ProcesseasySee the answer and why each option is right or wrong →During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API…
A forensic investigator is analyzing a compromised web server. In the Apache access logs, the investigator finds the following request: 'GET /images/../../../etc/passwd HTTP/1.1' w…
A security analyst reviewing Apache access logs finds entries like: 192.168.1.10 - - [12/Jan/2023:15:23:11 +0000] "GET /search?q=1' OR '1'='1 HTTP/1.1" 200 5324. What attack is ind…
A CHFI analyst is called to investigate a suspected data breach. The IT team has already shut down the server. Which of the following is the most appropriate order of actions to pr…
Computer Forensics Investigation ProcessmediumSee the answer and why each option is right or wrong →Which of the following BEST defines the chain of custody in digital forensics?
Computer Forensics Fundamentals and ProcesseasySee the answer and why each option is right or wrong →An email forensic investigator examines a suspicious email and notices the following header: Received: from mail.evil.com (192.168.1.100) by mail.company.com. The DKIM-Signature he…
An investigator needs to testify in court as an expert witness. Which of the following qualifications is MOST important for the court to accept their testimony?
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →What is the primary goal of computer forensics?
Computer Forensics Fundamentals and ProcesseasySee the answer and why each option is right or wrong →During a cloud forensics investigation of an AWS environment, an analyst extracts CloudTrail logs and notices many events with the error code 'AccessDenied' for a specific IAM user…
A forensic analyst is testifying as an expert witness in court. The opposing counsel challenges the analyst's testimony based on the Frye standard. What does the Frye standard requ…
Computer Forensics Fundamentals and ProcessmediumSee the answer and why each option is right or wrong →Which TWO of the following are indicators of a webshell on a web server? (Select TWO.)
Which email header field is used to verify that an email was sent by the authorized mail server for the domain and has not been tampered with, using cryptographic signatures?
During a network forensic investigation, the analyst recovers a PCAP file. What type of information can be directly extracted from this file?
Locard's exchange principle is fundamental to forensic science. How does this principle apply to computer forensics?
Computer Forensics Fundamentals and ProcesseasySee the answer and why each option is right or wrong →