โ† All CCP Flashcard Decks

Disk & Memory Forensics Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Disk & Memory Forensics flashcards as text
  1. Which type of memory contains the page file (pagefile.sys) that may hold remnants of previously running processes?

    Answer: Virtual memory

    Virtual memory uses pagefile.sys on disk to extend RAM; it can retain process memory artifacts long after a process terminates.

  2. During live forensics, an analyst runs 'netstat -an' and sees an established connection to an external IP on port 4444. What should be the immediate next step?

    Answer: Capture a full memory dump before any changes

    Capturing memory preserves volatile evidence including process handles, network connections, and encryption keys before they are lost.

  3. Which Windows artifact tracks program execution times, run counts, and is stored in C:\Windows\Prefetch?

    Answer: Prefetch files (.pf)

    Prefetch files record execution metadata for applications; each .pf file contains the executable name, run count, and last eight execution times.

  4. An examiner images a suspect SSD using a write blocker. After imaging, hash verification fails. What is the most likely explanation specific to SSDs?

    Answer: Background garbage collection or wear leveling altered data

    SSDs perform background operations like garbage collection and wear leveling that can modify data even when protected by a hardware write blocker.

  5. Which memory forensics artifact would reveal the password of an encrypted TrueCrypt volume if the volume was mounted at the time of acquisition?

    Answer: Encryption keys stored in RAM

    When an encrypted volume is mounted, the decryption keys reside in RAM and can be extracted from a memory image using tools like Volatility.

  6. Which Sleuth Kit (TSK) tool is used to list files and directories in an image file, including deleted ones?

    Answer: fls

    fls lists file and directory names from a file system image, flagging deleted entries with a '*' or '-' prefix.

  7. A suspect's hard drive shows a file carved from unallocated space with no corresponding MFT entry. What forensic technique was used?

    Answer: File carving

    File carving recovers files from raw disk data using file header and footer signatures, without relying on file system metadata.