โ† All CCP Flashcard Decks

Disk & Memory Forensics Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Disk & Memory Forensics flashcards as text
  1. Which Windows Event Log ID records successful user logon events and is critical for authentication timeline analysis?

    Answer: 4624

    Event ID 4624 is generated on successful account logon and contains logon type, username, source IP, and session ID.

  2. In memory forensics, what does a 'VAD' (Virtual Address Descriptor) tree represent?

    Answer: Memory regions mapped within a process's virtual address space

    The VAD tree is a kernel structure describing each memory region in a process, including permissions, type (heap/stack/mapped file), and backing file.

  3. Which anti-forensic technique involves overwriting file data with zeros or random data before deletion to prevent recovery?

    Answer: Secure deletion / file wiping

    Secure deletion tools overwrite file content before unlinking it, preventing file carving or slack space recovery.

  4. An analyst examines a Linux system and finds cron jobs in /var/spool/cron/crontabs for root running a script every 5 minutes. This is relevant to forensics because it indicates:

    Answer: A potential persistence mechanism

    Scheduled tasks in cron are a common persistence mechanism for malware to survive reboots and maintain access.

  5. Which Windows artifact records USB device connection history including vendor ID, product ID, and first/last connection times?

    Answer: HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

    USBSTOR registry key records metadata for every USB storage device ever connected, including serial numbers and timestamps.

  6. During memory analysis, which structure helps identify the parent-child relationship between processes to detect suspicious spawning?

    Answer: EPROCESS.InheritedFromUniqueProcessId

    The InheritedFromUniqueProcessId field in EPROCESS stores the parent PID, allowing detection of anomalies like cmd.exe spawned by a browser.

  7. What is 'slack space' in disk forensics?

    Answer: Space between the end of a file and the end of its allocated cluster

    Slack space is the unused area between a file's logical end and its last allocated cluster boundary, which can contain remnants of previously stored data.