CHFI Forensic Investigation Process 3 — Questions and Answers
Question 1: During a post-incident forensic review, investigators find that logs were overwritten before collection. Which process failure does this represent?
- Improper chain of custody
- Failure to preserve volatile evidence in time
- Inadequate evidence identification (Correct answer)
- Lack of legal authorization
Correct answer: Inadequate evidence identification
Overwritten logs indicate a failure in the identification phase — critical evidence sources were not identified quickly enough for preservation.
Question 2: What distinguishes a 'bit-stream image' from a simple file backup in digital forensics?
- A bit-stream image compresses data to save space
- A bit-stream image captures every bit including deleted files and slack space (Correct answer)
- A bit-stream image only copies active files
- A bit-stream image encrypts the copied data automatically
Correct answer: A bit-stream image captures every bit including deleted files and slack space
A bit-stream (forensic) image captures an exact sector-by-sector copy including deleted files, slack space, and unallocated regions.
Question 3: An investigator needs to analyze a suspect's smartphone without triggering remote wipe commands. What is the best immediate action?
- Remove the SIM card and place the phone in a Faraday bag (Correct answer)
- Power off the device immediately
- Connect it to a charger and begin extraction
- Update the device firmware for compatibility
Correct answer: Remove the SIM card and place the phone in a Faraday bag
Placing the device in a Faraday bag isolates it from all wireless signals, preventing remote wipe commands while preserving its powered state.
Question 4: In a corporate investigation, HR asks a forensic investigator to monitor an employee's email without a warrant. This is legally permissible primarily because:
- Corporate emails are public records
- The company owns the email system and employees have notice of monitoring policies (Correct answer)
- Investigators have implied authority over all network traffic
- Email evidence never requires a warrant in any jurisdiction
Correct answer: The company owns the email system and employees have notice of monitoring policies
Employers can monitor company-owned systems when employees have been notified through acceptable-use policies, making a warrant unnecessary.
Question 5: Which type of forensic investigation scope specifically covers crimes involving networked systems across multiple geographic locations?
- Physical forensics
- Mobile forensics
- Network forensics (Correct answer)
- Memory forensics
Correct answer: Network forensics
Network forensics focuses on capturing and analyzing network traffic and logs to investigate crimes spanning multiple systems or locations.
Question 6: When an investigator testifies in court about forensic findings, what role does the investigator serve?
- Fact witness
- Expert witness (Correct answer)
- Character witness
- Hearsay witness
Correct answer: Expert witness
A forensic investigator testifies as an expert witness, allowed to provide opinions and interpretations based on specialized knowledge.
Question 7: What is the purpose of the 'Locard's Exchange Principle' in digital forensics?
- Every crime scene contains exactly one type of digital artifact
- Every contact leaves a trace, meaning attackers always leave digital evidence (Correct answer)
- Digital evidence must be exchanged between jurisdictions
- Evidence must be verified through a third-party exchange process
Correct answer: Every contact leaves a trace, meaning attackers always leave digital evidence
Locard's Exchange Principle states that every contact leaves a trace, meaning attackers leave behind digital footprints such as logs, files, or registry entries.
During a post-incident forensic review, investigators find that logs were overwritten before collection.
Which process failure does this represent?