Computer Forensics Tools & Techniques Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Computer Forensics Tools & Techniques flashcards as text
Which SQLite forensics technique allows recovery of records that were deleted from a database but not yet overwritten?
Answer: Freelist page parsing
SQLite stores deleted records in freelist pages until they are reused, allowing forensic recovery through freelist page parsing.
What is the forensic significance of the Windows.edb file found in %ProgramData%\Microsoft\Search?
Answer: It contains the Windows Search index including content previews
Windows.edb is the Windows Search index database that may contain indexed content, metadata, and previews of files even after deletion.
Which artifact would best establish a timeline of USB device connections on a Windows 10 system?
Answer: SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR registry key records device class identifiers, serial numbers, and first/last connection times for USB storage devices.
In email forensics, which header field is MOST reliable for determining the true origin of a message?
Answer: The earliest Received: header
The earliest (innermost) Received header is added by the originating mail server and is hardest to forge compared to other headers.
Which technique does the tool Xways Forensics use to identify files in unallocated space that span multiple non-contiguous clusters?
Answer: Fragmented file carving with block reassembly
Fragmented file carving attempts to reassemble files spread across non-contiguous disk sectors using header/footer matching and content validation.
A forensic examiner finds a .lnk file pointing to a removable drive that is no longer present. What forensic value does this provide?
Answer: It reveals the volume serial number and original file path of the accessed file
Windows .lnk (shortcut) files store metadata including the target volume serial number, MAC times, and original file path of the accessed resource.
Which tool is the industry standard for performing RAM acquisition on a live Windows system while minimizing forensic footprint?
Answer: DumpIt (Magnet RAM Capture)
DumpIt/Magnet RAM Capture is widely used for live Windows memory acquisition due to its minimal footprint and single-executable deployment.