โ† All CCP Flashcard Decks

Disk & Memory Forensics Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Disk & Memory Forensics flashcards as text
  1. Which file system artifact stores metadata about deleted files in Windows NTFS volumes?

    Answer: $Recycle.Bin

    $Recycle.Bin retains metadata (original path, deletion time) about deleted files until they are permanently purged.

  2. An investigator finds a memory dump where the EPROCESS list appears intact but scanning with a pool-tag tool reveals hidden processes. Which technique was most likely used?

    Answer: DKOM (Direct Kernel Object Manipulation)

    DKOM unlinks EPROCESS entries from the doubly-linked list, hiding processes from list-based tools while pool allocations remain.

  3. When imaging a hard drive using dd, which flag ensures that read errors do not halt the acquisition?

    Answer: conv=noerror

    conv=noerror instructs dd to continue past read errors, typically paired with conv=sync to pad bad blocks.

  4. Which Windows registry hive contains the most recently accessed files and applications for a specific user?

    Answer: HKCU\NTUSER.DAT

    NTUSER.DAT is the per-user hive loaded into HKCU; it contains RecentDocs, UserAssist, and other user-activity artifacts.

  5. A forensic analyst needs to recover timestamps that were altered by anti-forensic timestomping. Which NTFS artifact is most useful for comparison?

    Answer: $MFT File Name attribute

    The $FILE_NAME attribute timestamps are harder to modify via user-mode tools and often differ from the $STANDARD_INFORMATION timestamps after timestomping.

  6. In a Windows memory image, which Volatility plugin is best for detecting injected code in a process that has no corresponding file on disk?

    Answer: malfind

    malfind scans process VAD entries for executable memory regions that lack a mapped file on disk, a strong indicator of code injection.

  7. Which hash algorithm is preferred over MD5 for forensic evidence integrity verification in modern investigations?

    Answer: SHA-256

    SHA-256 is collision-resistant and cryptographically stronger than MD5 or SHA-1, making it the current standard for evidence hashing.