Browse all practice questions for the Computer Hacking Forensic Investigator (CHFI) v11 Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Computer Hacking Forensic Investigator (CHFI) v11 Practice Test 2026 - Free CHFI Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which action is performed by the fdisk utility on a Linux system?
  • Buffer Overflow occurs when an application writes more data to a block of memory, or buffer, than the buffer is allocated to hold. Buffer overflow attacks allow an attacker to modify the __________ in order to control the process execution, crash the process and modify internal variables.
  • What file is processed at the end of a Windows XP boot to initialize the logon dialog box?
  • Which log-file naming format is used by IIS for daily rotation, as described in the source?
  • Is digital photography accepted as evidence in the court of law?
  • In a session hijacking test using Ettercap, which protocol is not inherently session-based, allowing hijacking?
  • The newer Macintosh Operating System (MacOS X) is based on which Unix lineage?
  • What will the following command accomplish? dd if=/dev/xxx of=mbr.backup bs=512 count=1
  • When an operating system marks a cluster as used but not allocated, the cluster is considered as which of the following?
  • Which security log contains logs of network and host-based security software?
  • Which hash verification algorithm is explicitly supported by Decryption Collection?
  • In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?
  • What does ICMP Type 3 Code 13 indicate?
  • A steganographic file system is a method to store the files in a way that encrypts and hides the data without the knowledge of others.
  • Interpreting the Nmap command 'nmap -sU -p445 192.168.0.0/24', which statement is correct?
  • From the following spam mail header excerpt, which host IP is the one that sent the spam?
  • In vulnerability assessment, if a second utility verifies results by exploiting the system and finds exploitable weaknesses the initial analysis said were not exploitable, what type of result is this called?
  • Where is the hidden swap file in Windows located?
  • A picture file recovered from a computer is enlarged 500% without degradation. What kind of image is this?
  • Hard disk data addressing is a method of allotting addresses to each ____ of data on a hard disk.
  • You have compromised a lower-level administrator account on an Active Directory network of a small company. While enumerating, you connect to a Domain Controller on port 389 using ldp.exe. What are you trying to accomplish here?
  • In web server logs, timestamps are typically recorded using which standard to ensure consistent correlation across servers?
  • In digital forensics, what is the primary purpose of a chain of custody form?
  • In a case where encrypted NTFS EFS files on an employee's computer were copied to removable media, which option best describes how investigators can recover the encrypted data?
  • To investigate threatening emails, which artifact should you examine to trace messages back to the sender?
  • When collecting evidence from the RAM, where do you look for data?
  • What method of copying should always be performed first before carrying out an investigation?
  • What is the primary purpose of an intrusion detection system?
  • What does the Linux command 'fdisk /dev/hda' do?
  • What type of copy is needed to obtain deleted files or fragments from a suspect's hard drive?
  • Which organization coordinates computer crime investigations across the United States?
  • Which artifact typically reveals the route an email took from sender to recipient, including servers it passed through?
  • If an attacker wants to perform a new line injection attack in a log file, what would they inject into the log?
  • In a storage partition, if the cluster size is 32 KB and the file size is 10 KB, the entire 32 KB cluster is allocated. How much slack space remains in that cluster?
  • During a DoS testing engagement, what is a primary objective?
  • Which federal statute addresses Fraud by wire, radio, or television?
  • In the web services stack, which layer is vulnerable to fault code leaks?
  • In the standard Linux Ext2 file system, a file is deleted when the inode internal link count reaches what value?
  • Netstat is a tool for collecting Information regarding network connections. It provides a simple view of TCP and UDP connections, and their state and network traffic statistics. Which of the following commands shows you the TCP and UDP network connections, listening ports, and the identifiers?
  • Which response organization tracks hoaxes as well as viruses?
  • Which of the following is an IT security focus within organizational security?
  • What is the primary purpose of a write-blocker in digital forensics?
  • Which practice best helps ensure ISO image integrity during forensic acquisition?
  • Which statement best describes a legitimate use of the MD5 utility in digital forensics?
  • Which memory type loses its contents when power is removed?
  • What is the minimum number of bit-stream copies recommended for a suspect drive?
  • What is the primary purpose of email archiving?
  • What is the primary purpose of centralized log management?
  • In forensic practice, what is the purpose of creating a forensic bit-stream image of a storage device?
  • Which principle states that every contact leaves a trace and transfer occurs between objects and people?
  • During a security test, after an external DoS attack, an FTP session from an external IP to the internal network succeeds. What happened to the firewall?
  • Which is a valid property of disk imaging when capturing evidence?
  • Which serial communication standard is used in serial data acquisition systems when the data location is at a distance?
  • During evidence collection, which device is used to prevent the system from writing data to the evidence disk?
  • Data Acquisition in digital forensics primarily involves imaging or obtaining information from a device and its peripherals.
  • During a ping sweep to identify live hosts, you receive responses from only Unix-like systems. Which statement is most accurate?
  • Which mobile operating system architecture corresponds to a system that manages communication between a mobile device and other devices such as computers, televisions, or printers?
  • In a false survey website designed to harvest credentials, what information will you be able to gather?
  • What is cold boot (hard boot)?
  • What is the best practice to ensure evidence integrity during collection?
  • Promiscuous mode on a NIC allows the device to capture what?
  • What is the formal term for the custody of evidence from collection to court?
  • Which statement best describes an expert witness?
  • Abrupt power loss results in loss of which type of memory most directly?
  • Which passwords are sent over the wire (and wireless) network, or stored on some media as it is typed without any alteration?
  • If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?
  • Which standard uses publicly disclosed cybersecurity vulnerabilities with unique identifiers?
  • Which file system would you expect on very small removable media such as old floppy disks?
  • What is the purpose of a hardware write-blocking device in digital evidence acquisition?
  • Why should you never power on a computer that you need to acquire digital evidence from?
  • Which network attack refers to sending huge volumes of email to an address in an attempt to overflow the mailbox, or overwhelm the server where the email address is hosted, to cause a denial-of-service attack?
  • Which filesystem is used by Mac OS X?
  • Which extension is commonly associated with Photoshop documents?
  • To improve SNMP security without disabling remote monitoring, which action is recommended?
  • If DNS queries in captured traffic point to non-company IPs, which attack is most likely?
  • Which command shows you the NetBIOS name table for the local machine?
  • For log files to be admissible in court, how often must they be kept?
  • In a BGP test scenario, when a router fails, what do the remaining routers communicate to maintain routing?
  • Where are files temporarily written in Unix when printing?
  • Which protocol is commonly used to synchronize time between machines?
  • What is the purpose of the Recycle Bin in Windows?
  • Which of the following is not a consideration in a forensic readiness planning checklist?
  • Determine the message length from the following hex viewer record:
  • Which tool is commonly used to perform man-in-the-middle attacks on a LAN to capture credentials?
  • Anomaly-based IDS tends to produce the most false alarms because it relies on what?
  • Digital evidence validation uses a hashing algorithm to create a fingerprint of the data. Which of the following best describes this purpose?
  • Which act aimed to protect consumers' personal financial information held by financial institutions and their service providers?
  • Which binary coding is most often used for email?
  • You have been given the task to investigate web attacks on a Windows-based server. Which of the following commands will you use to look at which sessions the machine has opened with other systems?
  • A law enforcement officer may only search for and seize criminal evidence with ___________________, the standard that justifies a search.
  • Which vulnerability allows an attacker to execute shell commands on an IIS server by constructing SQL statements?
  • From the log excerpt, which line indicates a port scan detected from 194.222.156.169?
  • What type of flash memory card comes in Type I or Type II and consumes only five percent of the power required by small hard drives?
  • Which deposition practice is not standard?
  • Wireless discovery tools use two scanning methods: active and passive. Active scanning works by sending a specific frame and waiting for responses. Which frame is used in active scanning?
  • An image is an artifact that reproduces the likeness of some subject. These are produced by optical devices (i.e. cameras, mirrors, lenses, telescopes, and microscopes). Which property of the image shows you the number of colors available for each pixel in an image?
  • After an external IT audit, to mitigate DDoS attacks, which countermeasure would you implement?
  • Which command displays the network configuration of the NICs on the system?
  • Which wireless standard has bandwidth up to 54 Mbps and signals in a regulated frequency spectrum around 5 GHz?
  • Which federal statute specifically addresses fraud and related activity involving access devices like routers?
  • What is the purpose of a write-blocker?
  • Why is it not recommended for a small firm to conduct its own breach investigation instead of hiring professionals?
  • Which security control prevents unauthorized individuals from following an authorized person through a door?
  • Which site provides archived web pages and is commonly used to view past versions of websites?
  • File signature analysis involves collecting information from the __________ of a file to determine the type and function of the file
  • In an IIS log entry, which field identifies the target resource requested by the client?
  • If a network employs NAT and IPsec, which combination is likely to cause connectivity problems?
  • The term Master Boot Record refers to the first sector of the disk that contains bootstrapping code. Which option reflects this?
  • What is the primary purpose of a software dongle when distributing commercial software?
  • A forensics investigator searches C:\RECYCLED but finds nothing. Why might nothing be found?
  • What is the purpose of a DNS zone transfer?
  • Which operating system is associated with the Paraben Lockdown device for writing hard drive data?
  • In digital security, what is a honeypot used for?
  • Which file system is not designed for removable media and is typically associated with larger, non-removable volumes?
  • To prove that evidence has not been altered since it entered the lab, which action should you take?
  • During the confession, which technique was used to hide pictures within other pictures?
  • What operating system would respond to the command 'C:\> nmap -sW 10.10.145.65'?
  • Which step should you take first when handling a PDA found during a hacking ring investigation?
  • Which folder name is associated with the Recycle Bin on Windows file systems as used in the example?
  • In a Windows system, which statement best explains why the swap file is examined during forensics?
  • In an email header, which field is typically used to trace the path a message has traversed across multiple mail servers?
  • In legacy Windows systems, which file is responsible for reading the boot configuration and loading the kernel components?
  • Which term describes the unauthorized change of the apparent source of an email message?
  • The data acquisition process should include preserving evidence by protecting it from temperature extremes and by using controlled handling.
  • Which document is typically used to establish legal control over evidence and its admissibility in court?
  • What is the first step taken in an investigation by laboratory forensic staff members?
  • Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.
  • What is the smallest allocation unit of a hard disk?
  • On Linux/Unix based web servers, under which privilege should the daemon service be run?
  • The main role of computer forensics is to:
  • What type of analysis helps to identify the time and sequence of events in an investigation?
  • When obtaining a warrant, what is important to include?
  • True or False: Volatile information can be easily modified or lost when the system is shut down or rebooted.
  • If you are concerned about a high level of compression but not concerned about any possible data loss, what type of compression would you use?
  • Which type of firewall must you implement to ensure that incoming connections are initiated by internal computers?
  • On Linux/Unix based web servers, the daemon should run under which privilege level?
  • How many hexadecimal characters does an MD5 checksum have?
  • In professional computer forensics, how many mismanaged cases are said to ruin a practitioner’s reputation?
  • What is the Best Evidence Rule?
  • When an iPod is connected to a Windows host, which file system is used?
  • To view who is connected remotely to a Windows machine, and from which client, you would use which command?
  • In digital forensics, what is the primary advantage of using a disk imaging tool over a simple copy?
  • Which file type is typically created for Windows printer spool processing?
  • Which type of credential content is identified in HKLM\SECURITY\Policy\Secrets as being stored in plain text?
  • Which Windows process is primarily responsible for starting the user session after credentials are validated during logon?
  • Which statement about NTP Stratum Levels is true?
  • What is kept in the registry key HKLM\SECURITY\Policy\Secrets?
  • Which element should be recorded when documenting an electronic crime scene?
  • Which archive format commonly contains multiple files and directories and is used with compression to save space?
  • The Electronic Serial Number (ESN) is a unique 32-bit identifier recorded on a secure chip in a mobile device by the manufacturer.
  • What is the ISP's ability to assist in computer abuse investigations?
  • The ARP table maps IP addresses to MAC addresses on a local network. Which statement correctly describes this mapping?
  • What is the size limit for the Recycle Bin in Vista and later versions of Windows?
  • Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server's root directory?
  • A computer forensic report describes the complete investigation process.
  • Microsoft Outlook stores email messages in what type of file?
  • What is the primary advantage of sector-by-sector disk imaging in forensics?
  • Syslog is a client/server protocol standard for forwarding log messages across an IP network. Which transport protocol does Syslog use to transfer log messages in a clear text format?
  • What RestrictAnonymous value is required for complete security against anonymous null sessions?
  • In a finance fraud investigation where files on a bitmap image appear not saved, what should you examine next?
  • An ISO image of a CD contains which of the following as part of its structure?
  • What is the primary purpose of warning banners in corporate networks?
  • In Linux, seeing Zer0.tar.gz and copy.tar.gz during an investigation suggests which of the following?
  • Which practice is most consistent with a stealthy security assessment in wireless networks?
  • Which property defines the number of colors available for each pixel?
  • Digital evidence validation involves using a hashing algorithm utility to create a binary or hexadecimal number that represents the uniqueness of a data set. Which of the following hash algorithms produces a message digest that is 128 bits long?
  • Which type of attack sends spoofed UDP packets to the IP broadcast address of a large network?
  • To prove that evidence has not been altered since entering the lab, which approach is correct?
  • Which Wi-Fi chalking method refers to drawing symbols in public places to advertise open Wi-Fi networks?
  • Which marker is placed in the first byte of a FAT directory entry to indicate that a file has been deleted?
  • Which term refers to data that may remain in a cluster after the original file has been overwritten by another file?
  • Which constitutional protection prevents the police from breaking down a door and seizing equipment without a warrant?
  • Which table is used to convert huge word lists (i.e., dictionary files and brute-force lists) into password hashes?
  • Which law addresses fraud and related activity in connection with computers?
  • Which term describes evidence that supports guilt or involvement of a suspect?
  • In Windows, a Security Identifier (SID) uniquely identifies which of the following?
  • Which registry key stores the history of items entered in the Run dialog box?
  • In general, which field involves investigating data retrieved from hard disks by applying scientific methods?
  • An attack vector is a path or means by which an attacker can gain access to computer or network resources in order to deliver an attack payload or cause a malicious outcome.
  • Which Windows Registry hive contains the user's password file?
  • A suspect is accused of viewing adult websites. The search history and downloaded files have been cleared. What is the most feasible way for the investigator to prove the violation?
  • If you discover a criminal act while investigating a corporate policy abuse, it becomes a public-sector investigation and should be referred to law enforcement?
  • In a wireless security investigation, determining the gateway IP helps identify which device?
  • An investigator is searching through firewall logs and notices ICMP packets larger than 65,536 bytes. What type of activity is this?
  • What type of attack sends SYN requests to a target system with spoofed IP addresses?
  • In handling computer-related incidents, which IT role is typically responsible for recovery, containment, and prevention to constituents?
  • In NTFS, which structure contains detailed metadata for files and directories used by forensic tools to locate and recover data?
  • Which security objective is most directly concerned with protecting data confidentiality?
  • Which term describes an attack performed by a computer program rather than manual steps?
  • Accessing a router's configuration via an HTTP URL demonstrates which vulnerability?
  • Which protocol is used to describe the connection points of Web services?
  • Which deposition scenario is considered a standard practice?
  • Which DNS operation transfers a complete zone data from master to slave?
  • Two common methods used by password cracking software?
  • In incident response, what is the primary purpose of synchronizing time across multiple hosts?
  • Under the Daubert standard, which factor is commonly considered to validate forensic tools?
  • In evidence collection, why should you note all cable connections for a seized computer?
  • You can interact with the Registry through intermediate programs. Graphical user interface (GUI) Registry editors such as Regedit.exe or Regedt32.exe are commonly used as intermediate programs in Windows 7. Which of the following is a root folder of the registry editor?
  • In raw data acquisition, the initial data set is typically stored as what type of file?
  • In Linux forensic imaging, what would the command dcfldd if=/dev/zero of=/dev/hda bs=4096 conv=noerror, sync accomplishes?
  • What best defines a bit-for-bit copy?
  • Profiling is a forensic technique for analyzing evidence. After a system is compromised, which factor would be most important in forming a profile of the incident?
  • In password cracking, what is the second step after creating a wordlist?
  • To check for POP3 traffic using Ethereal, which port should you filter by?
  • Diskcopy is which of the following?
  • Which technique hides data inside an image by manipulating the least significant bits?
  • Which IDS capability analyzes events in real time to detect anomalies as they occur?
  • Which Operating System logs contain information about operational actions performed by OS components?
  • Which attribute of a forensics report can render it inadmissible in a court of law?
  • Which method will allow you to trace all ever-established user accounts on a Windows 2000 server over its lifetime?
  • What determines the source, nature, and time of an attack on a compromised system?
  • Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
  • Which statement best describes local archives in email forensics?
  • Which registry key stores the values typed into the Run dialog box in the Start menu?
  • Which measure confirms the integrity of forensic copies?
  • Which technique involves manually typing different user IDs into logging tools, suggesting tampering?
  • Corporate investigations are typically easier than public investigations because:
  • What is the primary purpose of creating a forensic image using a write blocker?
  • P0P3 (Post Office Protocol 3) is a standard protocol for receiving email. By default, to fetch emails, the client connects to the POP3 server on which port?
  • While looking through the IIS log file of a web server, you find the following entries: What is evident from this log file?
  • Which steganography technique uses transform domain methods?
  • What term describes the practice of locating wireless networks by moving around with a wireless device, often to map networks and collect data?
  • A rogue access point is defined as one that is not authorized for operation.
  • When should an MD5 hash check be performed during processing of evidence?
  • In social engineering training, which principle was demonstrated when an attacker leverages a superior's name to obtain credentials?
  • Graphics Interchange Format (GIF) is a ______ RGB bitmap Image format for images with up to 256 distinct colors per frame.
  • What is a common method to bypass a BIOS password?
  • During Windows forensics, which device helps prevent contamination to the evidence drive during acquisition?
  • In Windows 7, where are Microsoft Security IDs (SIDs) located within the Registry?
  • Which statement best describes a bit-for-bit copy?
  • During a legal search with a valid warrant, officers observe an item of evidence in plain view that was not included in the warrant. What doctrine allows this evidence to be admissible?
  • Which file extension is used by Microsoft Outlook to store its data?
  • In a credential harvesting exercise, which scenario would most clearly indicate an attacker collecting credentials through a fake login page?
  • In a court case, a lay witness is asked to testify. In terms of expertise, in what field would a lay witness be considered an expert?
  • Which statement is NOT part of disk imaging tool requirements?
  • Which document must be obtained before an on-site digital investigation?
  • What is the name of the service used to synchronize time among multiple computers?
  • You are testing a dynamic website for vulnerabilities and input a test string that triggers a pop-up saying 'This is a test.' What vulnerability does this indicate?
  • All Blackberry email is eventually sent and received through what proprietary mechanism operated by RIM?
  • In a vulnerable login scenario, a query containing DROP TABLE demonstrates what kind of vulnerability?
  • Which statement best explains why Linux/Unix-based computers are preferred for idle scanning in the given scenario?
  • Attack using dot-dot-slash sequences is known as what?
  • Data files from original evidence should be used for forensics analysis.
  • Which integrity check is used by EnCase to ensure forensic evidence remains unchanged?
  • Network forensics allows investigators to inspect network traffic and logs to identify and locate the attack system. Which statement best describes a typical outcome?
  • In forensic reporting, what type of evidence supports a suspect's guilt?
  • In Windows XP, what is a security risk associated with the repair installation?
  • A web bug is commonly used to track a user's activity on a website. Which option best describes this?
  • Which file in Novel GroupWise stores information about user accounts?
  • After three failed PIN attempts, which option allows access to SIM data?
  • Which of the following would indicate an external network scanning activity in firewall logs?
  • What does the superblock in Linux define?
  • Setting APs on different channels primarily reduces which type of interference?
  • In a forensic examination of hard drives, which type of user would have the most file slack to analyze?
  • What feature of Decryption Collection allows an investigator to crack a password as quickly as possible?
  • Which of the following is a common source within a system that can retain data before it is swapped in memory?
  • What is the first step that needs to be carried out to investigate wireless attacks?
  • Which memory card type comes in Type I or II and consumes only five percent of the power?
  • Data Acquisition is the process of imaging or otherwise obtaining information from a digital device and its peripheral equipment and media. Which statement is true?
  • What is the maximum number of computers over which Decryption Collection can distribute processing?
  • What is the first step to crack the password?
  • In a breach scenario, which term describes the attack on a PBX system used to store music files?
  • Which mobile operating system is free and open source?
  • In a backbone router flood scenario, what will the other routers communicate to each other to maintain services?
  • In a Linux forensic write operation, using /dev/zero as the input device to /dev/hda results in what?
  • In the dd command shown, which parameter specifies the input device or file?
  • Which steganography type is described as hiding the secret message in a pattern on the document that is unclear to the average reader?
  • What step could help secure SNMP on a network after a SAS 70 audit?
  • Which Task List command provides information about listed processes, including the image name, PID, name, and the session number?
  • Event correlation is the process of
  • In hexadecimal notation, what does the prefix 0x indicate?
  • Which standard is based on a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?
  • _______________ is simply the application of Computer Investigation and analysis techniques in the interests of determining potential legal evidence.
  • What is a primary reason for performing a penetration test from inside an organization?
  • Sniffers that place network interface cards in promiscuous mode operate at which layer of the OSI model?
  • At a crime scene, if a computer is powered off, should you turn it on?
  • In a FAT32 system using 512-byte sectors, a 123 KB file occupies how many sectors?
  • Which statement best defines forensic computing?
  • At which OSI layer are you primarily observing when monitoring traffic on a router for investigative purposes?
  • In Windows IIS Web Server logs, how often is a new log file created?
  • A grant of a property right for a new machine, process, utile composition of matter or manufacture is called what?
  • In the Nmap command shown, what does data_length 66000 test?
  • In web server logs, the resource not found message corresponds to which HTTP status code?
  • Hash injection attack allows attackers to inject a compromised hash into a local session and use the hash to validate network resources.
  • Which statement is true about the physical security of a forensics lab?
  • How many possible sequence number combinations are there in TCP/IP protocol?
  • Which type of memory is volatile and loses its contents when power is lost?
  • After running rdisk /s to grab the backup SAM file, where should you navigate on the system to find the file?
  • Which Google search string would locate the Microsoft Outlook Web Access Default Portal?
  • During a Daubert challenge in court, which argument could weaken the case for a forensic tool that hasn't been peer-reviewed?
  • Kimberly wants to learn a networking protocol language that routers utilize; which is the appropriate choice?
  • Which element is most useful for tracing the source of a threatening email?
  • To sniff FTP credentials between the Swiss bank and its London subsidiary, which tool would you use?
  • If a company has not published a policy on inspecting computing assets, what privacy risk does this create for employees?
  • Information posted in a job listing that reveals internal technology details is considered what?
  • What does IDS stand for in security?
  • During a network investigation, DNS packets traveling across the network belonged to a non-company configured IP. Which attack can be inferred?
  • Recovery of the deleted partition is the process by which the investigator evaluates and extracts the deleted partitions.
  • System software password cracking is defined as cracking the operating system and all other utilities that enable a computer to function.
  • In the context of mitigating DDoS, which option would help reduce broadcast-based amplification?
  • What is the outcome of executing a vulnerable login query that ends with DROP TABLE members;--' in the same batch as a SELECT query?
  • After a file is deleted on a FAT file system, what is the status of its data blocks?
  • Refusing a law enforcement request to place a network sniffer on your network is appropriate because doing so would:
  • Which term describes the unwanted or uncontrolled growth of a project’s scope?
  • Network forensics data collection typically includes which components?
  • Using DNS DIG with AXFR/IXFR, what is the attacker attempting to do?
  • Identify the attack from the following sequence of actions? Step 1: A user logs in to a trusted site and creates a new session Step 2: The trusted site stores a session identifier for the session in a cookie in the web browser Step 3: The user is tricked to visit a malicious site Step 4: the malicious site sends a request from the user's browser using his session cookie
  • Injection flaws are web application vulnerabilities that allow untrusted data to be interpreted and executed as part of a command or query. Which injection flaw involves injecting malicious code through a web application?
  • Given the drive dimensions 22,164 cylinders per disk, 80 heads per cylinder, and 63 sectors per track, what is the approximate capacity?
  • Which federal statute is associated with Fraud and related activity in connection with computers?
  • What does the acronym POST mean as it relates to a PC?
  • What is a chain of custody?
  • TCP and UDP utilize which layer of the OSI model?
  • Which is a Linux journaling file system?
  • Which security control best prevents tailgating into a restricted area?
  • Which program is the boot loader when Windows XP starts up?
  • An ISO image of optical media stored in a CDFS format is being analyzed. What type of evidence does this ISO image represent?
  • Which statement about a sheepdip computer is true?
  • In a honeypot log, which event line indicates a port scan from an external IP?
  • Which statute governs preservation of user emails by an ISP in response to a legal request, specifically the f subsection?
  • In a wireless local area network (WLAN), which device determines the next network point to which a packet should be forwarded toward its destination?
  • A method used to maintain state in HTTP communications across requests is the use of cookies.
  • From the screenshot of the network device in a maintenance audit, which change should the client company make?
  • LBA (Logical Block Address) addresses data by allotting a ___________to each sector of the hard disk.
  • Which technique involves impersonating another device by altering the MAC address to bypass access controls?
  • In the sample honeypot log, which event indicates an FTP password retrieval attempt?
  • The ARP table of a router is used to map IP addresses to MAC addresses. Which command in Windows 7 displays this mapping?
  • Routers operate at which layer of the OSI model?
  • In digital forensics, which artifact is used to verify a forensic image has not been altered?
  • Which statement is not part of securing and evaluating electronic crime scene checklist?
  • In GSM devices, the first eight digits of an IMEI identify the model and country of origin. What does TAC stand for?
  • Which action best maintains evidence integrity when collecting data?
  • When examining a hard disk without a write-blocker, you should not start Windows because Windows will write data to the:
  • NFS is designed to provide access to a network file system over which protocol?
  • Which IDS capability is required to satisfy a time-based induction machine mandate and supports detecting anomalies in real time?
  • Which file system metadata marks a deleted file in Windows 7?
  • Steven designing a computer forensics lab; how many exits should he include?
  • Why were passwords set to 14 characters cracked quickly in the password audit?
  • What port do you send an email to on the company SMTP server?
  • Technical Steganography is defined as steganography that uses which method to hide the existence of a message?
  • Which virus type mutates its decryption routine with every infection, altering its signature but not necessarily rewriting the entire code?
  • Volatile Memory capture: which is most appropriate to overcome capturing volatile memory?
  • Which of the following statements is incorrect when preserving digital evidence?
  • In a compromised Active Directory environment, which port and tool combination is typically used to interrogate LDAP on a Domain Controller?
  • Which HTTP status code indicates the requested resource could not be located?
  • How do the evidence handling procedures differ between criminal and civil cases?
  • Damaged portions of a disk on which no read/Write operation can be performed is known as __________.
  • The SIM file system resides in which type of memory?
  • Raw data acquisition format creates ____________ of a data set or suspect drive.
  • What is the purpose of creating a forensic image?
  • Which file structure database, commonly used on floppy disks, contains information about files stored on the drive?
  • Which Windows artifact is best for reconstructing user logon sequences on a host?
  • The MD5 checksum on evidence is used to:
  • In the aa/ddmmyy/nnnn/zz format of evidence labeling, what does the nnn denote?
  • Which protocol commonly uses port 445 for Windows file sharing?
  • What does CDFS stand for in the context of optical media and ISO images?
  • Technical Steganography is defined as steganography that uses which method to hide a message?
  • MD5 checksums serve what purpose in digital forensics?
  • Which practice is recommended regarding antivirus scanning on a forensic workstation?
  • Which statement about logon warning banners is correct?
  • Which factor is most important to a CHFI professional's reputation?
  • In a 20-digit ICCID, which digits denote the issuer identifier number?
  • During a DoS test, sending ICMP ECHO requests to the broadcast address corresponds to which type of attack?
  • Event correlation type used when an organization operates across different operating systems and hardware platforms.
  • A honeypot is set up as a DMZ with no direct access to production networks. Why might pursuing legal action against the intruder be problematic?
  • From a 20-digit ICCID, identify the issuer identifier number.
  • Which forensic investigation concept traces the entire sequence of an incident from its initiation to the impact on the victim?
  • The attack that corrupts DNS cache causing users to be directed to the wrong site is called what?
  • Larry plans on shutting down the city’s network using BGP devices and zombies. What type of Penetration Testing is this?',
  • What element is unique to ISO 9660 images compared to typical hard drive file systems?
  • Before starting a search in EnCase, which item should be prepared to guide the search?
  • A rogue/unauthorized access point is one that is not authorized for operation by a particular firm or network.
  • During a hacking ring investigation, you recover a PDA attached to several peripherals. What is the first step to preserve the integrity of the evidence?
  • Which data source is most reliable for reconstructing the creation events of user accounts on a Windows server?
  • In the logon event ID table, which event ID represents a successful logging on to a computer?
  • In a TCP header, how many bits is the Source Port Number?
  • Digital evidence is not fragile in nature.
  • Data is striped at a byte level across multiple drives and parity information is distributed among all member drives. Which RAID level is represented here?
  • When a vulnerability scan is interrupted because the IDS cuts off your connection, what type of IDS is being used?
  • In mobile device forensics, if the display is on and you want to preserve evidence, you should:
  • Which attack uses a trusted site's cookie to forge a request from the victim's browser?
  • What should you do when approached by a reporter about a case you are investigating?
  • During the seizure of digital evidence, is the suspect allowed to touch the computer system?
  • Shortcuts with extension .Ink are created and accessed by users. They provide information about:
  • To recover the IMEI number from a Nokia device, which key combination should you use?
  • In preparing an investigative report, which electronic format should be used for the primary electronic copy?
  • Which of the following is not correct when documenting an electronic crime scene?
  • DNS poisoning primarily results in wrong responses from which component?
  • What is the primary purpose of an electronic crime scene checklist?
  • What security measure is essential in a computer forensics lab to protect evidence and limit access?
  • Which term describes the smallest addressable unit on a disk in common terminology?
  • Why do PDF passwords not provide maximum protection when sending PDFs via email?
  • Which type of scan uses ICMP ECHO Requests to detect live hosts?
  • What must an investigator do before disconnecting an iPod from any type of computer?
  • If a file of 2600 bytes on a hard disk uses 512-byte sectors, how many sectors are normally allocated to the file?
  • Who is responsible for securing the scene and maintaining it in a secure state until the forensic team advises, and for making notes for the forensic team?
  • Where is the default location for Apache access logs on a Linux computer?
  • What does LBA stand for in disk addressing?
  • Which command shows the username and IP address used to access the system via a remote login session and the Type of client from which they are accessing the system?
  • Data compression maintains data integrity?
  • In an investigation of a potential email crime, what is often the first step?
  • Where could the investigator search to find the message tracking log file on the Exchange server?
  • Which action best supports maintaining objectivity when evidence suggests innocence?
  • Harold wants to allow FTP-PUT; which firewall would be most appropriate?
  • Which action is NOT recommended when preserving evidence?
  • Which registry hive stores system-wide configuration and hardware information?
  • Which encryption type would have prevented stolen corporate information from laptops if properly applied?
  • When the operating system marks cluster as used, but does not allocate them to any file, these clusters are known as __________.
  • Which protocol is primarily responsible for routing email messages between mail servers?
  • Which registry hive contains hardware and software configuration information?
  • If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system during an investigation, what can you conclude?
  • Which action is least appropriate during documentation of chain of custody?
  • In the Ping of Death exploit, which header field is manipulated?
  • To preserve digital evidence, an investigator should make two copies of each evidence item using different imaging tools.
  • How many times can data be written to a DVD+R disk?
  • In the computer forensics investigation methodology, in which step would you run an MD5 checksum on the evidence?
  • What advantage does a forensic disk image have over a simple backup copy in investigations?
  • At what layer does a cross site scripting attack occur on?
  • Which network protocol analyzer is commonly used for real-time packet capture in forensic investigations?
  • An employee attempts to wipe data from CDs and DVDs with a magnet. CDs and DVDs are ________ media and are not affected by the magnet.
  • Which methodology is associated with ECSA-style security testing?
  • Office documents include a code that tracks the MAC address of the machine that created the document. What is this code called?
  • In an email header, which entity represents the email's first origin?
  • In Windows 7 auditing, the event ID for changes to audit policy is:
  • To prevent an attacker from enumerating Cisco router model, OS version, and capabilities, which feature should be disabled?
  • Which Outlook file type is typically used to store archived emails offline?
  • Which disk area is most commonly examined to recover remnants of deleted data in forensic analysis?
  • Which type of device most commonly responds to ICMP ping requests in a typical network?
  • Why might Firewalk traffic not appear in a sniffer placed deeper in the network when testing a Cisco PIX firewall?
  • What is static executable file analysis?
  • Which device interference could cause intermittent wireless dropouts in a home network with no encryption?
  • In the given C program, which vulnerability arises when argv[1] is copied into a fixed-size buffer?
  • The efforts to obtain information before a trial by demanding documents, depositions, and examination of the scene is described as what legal term?
  • Which intrusion detection system audits events on a specific host?
  • Why would a scanner like Nessus not be recommended for stealthy wireless network testing?
  • When the INF02 entry is deleted, it is recreated after which action?
  • In email logs, which item uniquely identifies a single message across systems?
  • The doctrine of handing over the results of private investigations to authorities due to indications of criminal activity is known as which doctrine?
  • Which of the following is not an example of a cyber-crime?
  • In the Recycle Bin rename Dxy.ext, the segment 'ext' stands for which of the following?
  • Application and Web server logs are most useful in detecting which of the following?
  • If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system during an investigation, what can you conclude?
  • A packet is sent to a router that does not have the destination address in its route table. What mechanism allows it to be forwarded toward the proper destination?
  • What is the maximum drive size supported by FAT32?
  • During evidence transport, which practice helps preserve integrity?
  • Which stage of incident handling involves reporting events?
  • What advantage does the tool Evidor have over the built-in Windows search?
  • Using Lophtcrack in sniffing mode, what information can be gathered about a target's account?
  • Which platform’s tooling is commonly used to mount an ISO image?
  • Using Linux to carry out a forensics investigation, what would the following command accomplish? dd if=/usr/home/partition.image of=/dev/sdb2 bs=4096 conv=notrunc,noerror
  • What step verifies that digital evidence has not been altered since collection?
  • When collecting electronic evidence at a crime scene, the data collection should proceed from most volatile to least volatile. Which statement best describes this principle?
  • Regarding handling evidence, you should always work with original evidence.
  • In NTP terminology, a Stratum-1 time server is linked to UTC sources such as GPS via what medium?
  • Which statement is NOT correct while preparing for testimony?
  • Which two methods are commonly used by password cracking tools?
  • An expert witness is someone whose education, profession, or experience gives them specialized knowledge beyond the average person.
  • First sector of a hard disk is known as:
  • How should custody forms be stored for 15 hard drives to preserve chain of custody?
  • What will this search produce?
  • Under US federal rules, what is the most appropriate reason for denying the eligibility of a computer forensic expert as an expert witness?
  • During security testing, you use virus code that rewrites itself entirely and changes the signatures with each infection but preserves functionality. What type of virus is this?
  • What is the role of a Data Recovery Agent in Windows Encrypting File System (EFS)?
  • Paraben Lockdown device uses which operating system to write hard drive data?
  • The newer Macintosh Operating System (MacOS X) is based on which of the following?
  • What is the role of metadata in a forensic investigation?
  • Which IDS approach typically yields the most false alarms due to unpredictable user and network behavior?
  • When a monitor is powered on but the display is blank at a crime scene, what is the recommended action?
  • Which attack floods a network by sending ICMP echo requests to a broadcast address?
  • If a user closes a browser on a public computer without logging out, and an attacker later reuses the same browser session to impersonate the user, which vulnerability type best describes this exploitation?
  • In legacy Windows boot processes, which file is responsible for reading the boot configuration and loading the kernel components?
  • During the cataloging of digital evidence, what is the primary objective?
  • What type of steganography did the suspects use?
  • Log management includes all processes and techniques used to collect, aggregate, and analyze computer-generated log messages. True or False?
  • What type of attack occurs when a router is flooded with many open connections so that all hosts behind it are effectively disabled?
  • A law enforcement request to monitor all network traffic could potentially make you what if complied with?
  • In digital forensics, what maintains hash signatures for known software to help identify components in a system?
  • Dumpster diving refers to:
  • What rule prevents sharing the status of an investigation with the CEO in a law-firm setting?
  • What is the essential tool to prevent alteration of evidence when imaging a drive?
  • The disk in the disk drive rotates at high speed, and heads in the disk drive are used only to read data.
  • In the context of file deletion process, which statement holds true?
  • What can an investigator examine to verify that a file has the correct extension?
  • Mobile phone forensics is the science of recovering digital evidence from a mobile phone under forensically sound conditions.
  • Which of the following is NOT a part of the environmental conditions of a forensics lab?
  • Which organization serves as the certifying body for forensic laboratories?
  • Under what circumstances would you conduct searches without a warrant?
  • When is computer forensics appropriate?
  • During a security audit, a tester disguised as a technician follows employees into restricted areas, enabling access to the server room. What attack type is this?
  • What information can be obtained from DHCP logs?
  • Which tool is commonly used to search for a string within a file on a disk image during a forensic investigation?
  • In digital forensics, what is the primary purpose of hashing the evidence container?
  • Which tool is commonly used to burn ISO images to optical media?
  • In Windows XP repair installation, which option could grant administrative rights during setup?
  • Hard disk sectors typically contain how many bytes?
  • Which of the following attacks allows attacker to acquire access to the communication channels between the victim and server to extract the information?
  • JPEG compression uses a lossy algorithm that divides the image into blocks of pixels. These blocks are of what size?
  • In Windows Security Event Log, event ID 531 indicates what?
  • Which of the following network attacks refers to a process in which an attacker changes his or her IP address so that he or she appears to be someone else?
  • In Linux, what is the smallest possible shellcode?
  • Which practice ensures data integrity of digital evidence during transfer?
  • Which statement about copyright duration is correct?
  • Which organization is the certifying body of forensics labs?
  • In netstat output, what do 0.0.0.0 IP addresses indicate about the connections?
  • An 'idle' system is also referred to as what?
  • What information will the virtual memory scan reveal when inspecting a system potentially used as a botnet server?
  • In an XMAS scan where most ports do not respond, in what state are these ports?
  • Which statement does not support the case assessment?
  • Which tool is recommended for passive footprinting of a target web presence?
  • Which field in the log contains the date and time of the request?
  • To avoid contaminating the suspect’s hard drive when starting up the computer, which hardware setting should be consulted?
  • Which option represents a recommended method for permanently erasing a hard drive so it can be reused?
  • To verify the integrity of evidence during processing, which practice is recommended?
  • Which component of WPA uses a rekeying mechanism to provide fresh encryption and integrity keys?
  • Which of the following is not a part of the technical specification of the laboratory-based imaging system?
  • In Windows NTLM authentication, the passwords stored on domain controllers are in which database?
  • Which of the following is NOT a graphics file?
  • Which action is not a responsibility of the first responder at a computer crime scene?
  • Which term describes luring a suspect to commit a crime by presenting a fake vulnerability in a controlled environment?
  • A buffer overflow attack can be used to modify the target process's address space to control the process execution.
  • What happens when a file is deleted in Windows 7?
  • On a FAT-based file system, what happens when a file is deleted?
  • Which statement best describes the action of a Network Intrusion Prevention System (NIPS)?
  • What is the smallest physical storage unit on a hard drive?
  • What is the primary purpose of a software firewall?
  • Quality of a raster image is determined by the __________ and the amount of information in each pixel.
  • What is considered the most common type of white-collar crime in corporate America forensics investigators focus on?
  • During first responder procedure you should follow all laws while collecting the evidence, and contact a computer forensic examiner as soon as possible.
  • In the physical storage format used by the Recycle Bin, files are renamed as Dxy.ext. What does the placeholder X represent?
  • Centralized logging is defined as gathering logs in a central location for monitoring and detecting security incidents. Which statement is true?
  • Which encryption algorithm is used by Blackberry devices for Password Keeper?
  • To determine whether an observed vulnerability is new, which database or organization should you submit the information to?
  • Which wireless access control attack allows the attacker to set up a rogue access point outside the corporate perimeter and lure employees to connect to it?
  • Which hashing method is used to password protect Blackberry devices?
  • George, recently fired as an IT analyst, wants to break into the company network by cracking service accounts. Which password cracking technique should he use in this situation?
  • Which file system is typically used on floppy disks?
  • What is a drawback of pulling the power plug to shut down a system abruptly?
  • Daryl's data acquisition scenario asks how many data acquisition tools should be used when copying evidence. How many are recommended?
  • A data acquisition system is described as a combination of tools or processes used to gather, analyze and record information about a phenomenon. Which option best represents this definition?
  • What does the Windows SAM file store?
  • In the example command 'firewalk -F 80 10.10.10.1', which IP is the target host used for the scan?
  • Which type of report is delivered under oath to a board of directors/managers/panel of jury?
  • In forensic reporting, which statement best describes an ISO image captured from optical media?
  • JPEG compression is commonly described as lossy. Which statement correctly reflects this property?
  • Which encryption option would have best prevented theft of data from laptops?
  • Which encryption algorithm does WPA2 use for enterprise and Wi-Fi security?
  • Which category of forensic analysis involves examining data transmitted over networks to detect anomalies?
  • What does CHS stand for in disk geometry?
  • An ISO image is best described as which type of forensic evidence?
  • In the IIS log sample, which value represents the service status code?
  • Which tool is commonly used to generate a hash for verifying data integrity?
  • For acquiring digital evidence from four 30 TB storage area networks, which method is most efficient?
  • In a forensic ISO image, which artifact is most likely to indicate the source medium type?
  • In a DHCP-enabled network, which log is most reliable for associating a specific IP with a MAC address at a moment in time?
  • Which statement is incorrect related to acquiring electronic evidence at a crime scene?
  • TCP/IP is a communication protocol used to connect different hosts in the Internet. It contains four layers, namely the network interface layer, Internet layer, transport layer, and application layer. Which of the following protocols works under the transport layer of TCP/IP?
  • What type of equipment would a forensics investigator store in a StrongHold bag?
  • During a forensic examination, which procedure is performed with the hard drive removed?
  • Which organization maintains a database of hash signatures for known software used in digital forensics?
  • Which TCP/IP header field is involved in the Ping of Death exploit?
  • During evidence handling, which practice supports integrity and chain of custody?
  • Area density on storage media refers to the amount of data per which metric?
  • Which of the following commands shows all network services currently running on Windows-based servers?
  • Which is a standard procedure to perform during all computer forensics investigations?
  • Web applications provide an Interface between end users and web servers through a set of web pages that are generated at the server-end or contain script code to be executed dynamically within the client Web browser.
  • In a FAT32 file system with 512-byte sectors, how many sectors are needed to store a 125 KB file?
  • At the time of evidence transfer, both sender and receiver need to give the information about date and time of transfer in the chain of custody record.
  • In a forensics investigation, restoration of information should be attempted only by qualified computer forensics personnel.
  • Which of the following email headers specifies an address for mailer-generated errors, like "no such user" bounce messages, to go to (instead of the sender's address)?
  • In a setup with Microsoft Exchange and Blackberry Enterprise Server, where would you search to find emails sent from a Blackberry device?
  • What time standard is used by IIS 6.0 in its logs?
  • Which hashing method is used to password protect Blackberry devices?
  • Which artifact is most likely to retain remnants of deleted data on a bitmap image?
  • Temporal Key Integrity Protocol (TKIP) enhances WEP by adding a rekeying mechanism to provide fresh encryption and integrity keys. Temporal keys are changed for every __________.
  • Router log files provide detailed Information about the network traffic on the Internet. It gives information about the attacks to and from the networks. The router stores log files in the____________.
  • What is the goal of forensic science?
  • In a TCP header, which field is 16 bits long and represents the source port?
  • Where does Encase search to recover NTFS files and folders?
  • In chain of custody, what does a link refer to?
  • In a partition with an 8 GB size and a 4 KB cluster size, a 1 KB file is stored. How much slack space is wasted?
  • As a CHFI professional, which of the following is the most important to your professional reputation?
  • Web applications provide an interface between end users and web servers through pages generated on the server or via client-side scripts.
  • Windows identifies which application to open a file with by examining which of the following?
  • Firewalk aims to map which layer's firewall rules by sending packets with specific TTL values?
  • BMP (Bitmap) is a standard file format for Windows. Which element specifies the dimensions, compression type, and color format for the bitmap?
  • When examining a file with a hex editor, which part of the file contains the header?
  • Which item is least likely to be stored in standard email server logs?
  • Which standard emphasizes testing, peer review, error rates, and general acceptance in admissibility of scientific evidence?
  • Which statement is true about the combination of EFS, HFS+, EXT2, and NFS?
  • What is the term used for Jacob's testimony regarding the accuracy and integrity of technical log files gathered in an investigation?
  • Which statement best describes Slack space in a file system?
  • Which statement is not correct when dealing with a powered-on computer at a crime scene?
  • In a network packet capture, what do the Sequence (Seq) and Acknowledgment (Ack) fields primarily indicate?
  • The type of attack that floods a service to render it unavailable is called?
  • Which Windows system file stores the contents of RAM when the system hibernates?
  • Which file should be used to restore archived email messages for someone using Microsoft Outlook?
  • A forensics investigator needs to copy data around 42 GB to removable media for analysis at another location. Which type of media would be suitable?
  • In the CIDR example shown, which prefix length is indicated?
  • During the seizure process, which practice is incorrect?
  • During a test, when an external firewall unexpectedly allows an internal connection after a DoS event, what is the most likely explanation?
  • If a web application responds with an error after entering a stray quotation mark in a user input field, what can you infer?
  • What will the following Linux command accomplish? dd if=/dev/mem of=/home/sam/mem.bin bs=1024
  • From the given sample log entries, which line is an Apache error log entry?
  • Why is it important to consider health and safety factors in forensic work at all stages?
  • With regard to using an antivirus scanner during a computer forensics investigation, you should:
  • Which OSI layer is primarily responsible for end-to-end communication and error recovery?
  • If exculpatory evidence is found and is not released to the defense, what should you do?
  • In Microsoft file structures, sectors are grouped together to form which of the following?
  • What would be the next sequence of events after securing the incident scene and labeling cables?
  • Before testifying as an expert witness, what must an attorney do first?
  • What is the first step required when preparing a computer for forensics investigation?
  • An on-site incident response team is called to investigate an alleged case of computer tampering within their company. The CEO classifies the incident as low level. How long will the team have to respond?
  • ISO 9660 is primarily used with which type of physical media?
  • What does GLBA stand for?
  • On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?
  • In DriveSpy, which format correctly specifies a copy of 150 sectors starting at sector 1709 on the primary hard drive?
  • Which tool is used to scan for open ports on a target host?
  • The role of the forensic investigator includes which of the following?
  • Why should you not delete a partition on a dynamic disk during a forensic investigation?
  • What term describes embedding information into something else for the sole purpose of hiding that information from the casual observer?
  • What information do you need to recover when searching a victim computer for a crime committed with a specific e-mail message?
  • Forensic computing: Which description best captures the goal?
  • In the provided C code snippet, the vulnerability arises when copying argv[1] into a fixed-size buffer?
  • Which term best describes network-enabled corporate spying?
  • Which statement about a steganographic file system is accurate?
  • Which port is used to receive SNMP traps?
  • SMTP (Simple Mail Transfer protocol) receives outgoing mail from clients and validates source and destination addresses, and also sends and receives emails to and from other SMTP servers.
  • In echo data hiding, the secret message is embedded into which element as an echo?
  • Can an employer file a criminal complaint if investigating within the workplace?
  • Which protocol uses port 25 by default for email transfer?
  • In a DHCP-enabled network, which logs should you examine to determine which system (MAC address) held a specific IP address at a given time?
  • Which stage of incident handling would you perform immediately after containment to restore normal operations?
  • In the Master File Table of an NTFS disk, what type of file is represented by a colon followed by a name?
  • To determine source, nature, and time of an attack from Application and Web server logs, you should:
  • Steganography is a technique of hiding a secret message within an ordinary message and extracting it at the destination to maintain the confidentiality of data.
  • Which Windows feature is associated with alternate data streams?
  • Which statute protects critical infrastructure by prohibiting willful damage to power or communications lines?
  • Where is the Windows Security Accounts Manager (SAM) file typically located?
  • Julia used which principle of social engineering when she posed as an IT technician and obtained credentials?
  • Cyber-crime is defined as any Illegal act involving a gun, ammunition, or its applications.
  • In wireless discovery, which action characterizes active scanning?
  • Which site can be used to view archived web pages of defunct sites?
  • Which approach checks and compares all the fields systematically and intentionally for correlation with each other across one or multiple fields?
  • What does ADS stand for in Windows forensic terminology?
  • In Windows security, a SID is best described as what?
  • What technique is used by JPEGs for compression?
  • Which step is essential before presenting evidence in court?
  • During ISO image creation, which aspect is most likely preserved to maintain evidence integrity?
  • Which method would be most efficient for acquiring evidence from large storage arrays in a network, minimizing time and space?
  • When carving a disk image, recovering the original image primarily depends on which factor?
  • What is SCSI (Small Computer System Interface)?
  • When investigating a computer, you find many files whose first letter has been replaced by the hex code 5h. What does this indicate?
  • If an attacker's IPID of 31400 to a zombie on an open port in IDLE scanning, what will be the response?
  • In the Nmap command shown, which flag increases the verbosity of the output?
  • Which statute authorizes an investigator to request preservation of all emails for a user account, compelling the ISP to preserve records?
  • For preliminary investigations in a sexual harassment case, how many investigators are recommended?
  • Tracks numbering ends at which value on a typical hard disk?
  • Which statement about a forensic tool's capability is true?
  • Identify the Apache error log from the Linux logs: which option represents an error log entry?
  • Email spoofing refers to:
  • Which artifact did Heather find that suggested covert communication among the suspects?
  • Which statement reflects the policy on attempting to restore or recover information from a system containing electronic data during a forensic investigation?
  • A clothing designer uses the same graphic symbol as their employer with different wording; which area of law is implicated?
  • Which file contains records that correspond to each deleted file in the Recycle Bin?
  • Which statement best describes CDFS in Windows?
  • George wants to monitor only SFTP traffic in Ethereal. Which filter should he apply?
  • If you come across a sheepdip computer at a client site, what would you infer?
  • Encrypting File System (EFS) is a feature of which Windows file system?
  • On a Linux system, which device name identifies the slave disk on the secondary IDE controller?
  • In NTFS Master File Table, a data stream file corresponds to which descriptor?
  • When should an MD5 hash check be performed during evidence processing?
  • Which memory artifact is most likely to indicate covert processes running in the system when investigating potential botnet activity?
  • Why can files emptied from the Recycle Bin sometimes be recovered on Windows?
  • What practice helps verify the integrity of a forensic image?
  • In a scenario involving seizure of equipment, which US Amendment is implicated in protecting against unreasonable searches?
  • During data acquisition, you should typically work on a duplicated copy rather than the original to preserve evidence.
  • MAC filtering uses a network card's address of which bit length?
  • In routers, which memory area contains the startup configuration?
  • Which statement reflects the guideline about attempting to restore or recover information from a system holding electronic information?
  • While reviewing HTML code in a web page, you discover a tiny element that loads a resource from a remote server to report when the page is viewed. What is this element most commonly called?
  • In the Davidson Trucking harassment case, whom should the prosecuting attorney call upon for not upholding company policy?
  • Netstat: Which netstat option lists all active TCP and UDP connections along with their process IDs and listening ports?
  • Which of the following is not a role of the first responder at a computer crime scene?
  • Which statement about a Fraggle attack is correct?
  • In incident response, which log would contain entries about security software alerts and policy violations on endpoints?
  • In CHS disk geometry, which term represents the factor multiplied by 512 bytes per sector to compute disk size?
  • DBX files recovered during forensic investigation can be analyzed by which email client?
  • A vulnerability scan that identifies a vulnerability that is actually exploitable is called what?
  • When NTFS is formatted, the initial sectors are allocated to boot sectors and bootstrap code. How many of the first sectors are reserved?
  • During a security assessment, why is it recommended to remove extraneous identifying information from service banners?
  • When bypassing a switch by sending an IP packet with the ACK bit and spoofed source address, what is the attacker attempting?
  • What is the primary purpose of an Outlook PST file?
  • Email archiving: Local archives: Which statement is correct while dealing with local archives?
  • Which TCP/UDP port is associated with the netstat toolkit as described in some practice materials?
  • In a 1,000,000-population city, how many law enforcement computer investigators should staff the forensics lab?
  • RAID 5 provides fault tolerance by distributing parity across disks.
  • John should specify which type of shredder in guidelines to destroy outdated documents?
  • Which action could compromise forensic integrity if not prevented during ISO imaging?
  • Warning banners are used to address employees' concerns about privacy when connecting to the company intranet, network, or VPN. They primarily address which right?
  • Which organization provides tools and procedures for testing and validating computer forensics software?
  • What is the primary function of a SIM card in mobile networks?
  • Which of the following should a computer forensics lab used for investigations have?
  • In expert witness criteria, which option expresses the requirement that opinions rely on specialized knowledge?
  • Which CIDR prefix length corresponds to a subnet mask of 255.255.255.0?
  • From a honeypot log excerpt, which IP address is shown as performing a port scan?
  • During evidence collection, what action represented evidence tampering?
  • Software firewalls operate at which layer of the OSI model?
  • Which command shows the currently running processes on a Windows system?
  • When searching file headers for JPEG formats in hex, which sequence indicates a JPEG header?
  • Where is the startup configuration located on a router?
  • Which of the following is not a part of data acquisition forensics Investigation?
  • Which command shows you the names of all open shared files on a server and the number of file locks on each file?
  • Which component is NOT part of ISO 9660 and is used to extend compatibility, including longer file names in images?
  • What is a primary objective when securing relevant media at a crime scene?
  • Where is a honeypot best placed on a network according to recommended practice?
  • Which password cracking technique works like a dictionary attack but adds some numbers and symbols to words from the dictionary?
  • In intrusion detection systems, which approach uses statistical models to establish a baseline of normal activity?
  • Which command would you use to view active network connections on a Windows machine?
  • Which disk structure is typically found on fixed disks and contains boot information?
  • From the log excerpt, which line indicates a DNS version query?
  • In an investigation of corporate policy abuse, discovering an act that constitutes a crime should be referred to law enforcement authorities?
  • Which protocol operates in the transport layer of TCP/IP and provides connectionless communication?
  • What is the purpose of the Exchange message tracking log?
  • Which HTTP request method is shown in the sample log line?
  • Which NTFS component stores metadata about files?
  • What Linux command is commonly used to create bit-stream images?
  • What type of testimony is presented by someone who performed the actual fieldwork and does not offer a view in court?
  • Which nbtstat switch lists NetBIOS sessions?
  • Which risk is associated with performing evidence collection without proper safeguards?
  • Which steganography type hides the secret message in a pattern on the document that is unclear to the average reader?
  • Which term describes an attack that exhausts network bandwidth by flooding traffic?
  • A computer forensics investigator analyzing firewall logs observes unusual traffic patterns. What can be inferred?
  • Why is it important to set each wireless access point on a different channel when deploying multiple APs?
  • What technique used by Encase makes it virtually impossible to tamper with evidence once acquired?
  • When a router receives a routing table update, how does the metric for that path typically change?
  • Which steganography technique is used to create cover for secret communication?
  • Which tool is commonly used to obtain password hashes when sniffing mode is used by an attacker?
  • One way to identify the presence of hidden partitions on a suspect's hard drive is to...
  • If a suspect computer location may involve toxic chemicals, what is the proper response?
  • Which steganography technique is described as creating a cover for secret communication?
  • Which tool is used to perform an XMAS scan in the described scenario?
  • In a forensic investigative report, consistency of information is considered more important than adhering to a strict formatting style.
  • In computer forensic analysis, which practice helps prevent the work from expanding beyond the original scope?
  • Which log injection attack uses white space padding to create unusual log entries?
  • In incident response, who is responsible for collecting, preserving, and packaging electronic evidence?
  • Which term describes a vulnerability assessment result where the test reports no issues, but exploitable vulnerabilities exist?
  • Which option describes formatting the drive with a low-level disk utility to wipe data?
  • Which document is typically used to formally document the chain of custody for digital evidence?
  • In an unpatched IIS web server, a path traversal exploit to cmd.exe could result in which outcome?
  • Which statement correctly describes the duration of copyright protection for a published work?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy