Disk & Memory Forensics Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Disk & Memory Forensics flashcards as text
Which Volatility command lists network connections from a Windows 7 memory image, including closed/terminated connections?
Answer: connscan
connscan uses pool scanning to find TCP connection objects including terminated ones, unlike connections which only shows active sockets.
A forensic investigator discovers that a RAID 5 array needs to be imaged. Which approach is correct?
Answer: Image all member drives individually, then reconstruct the logical volume
Each RAID member drive must be individually imaged, and the logical volume is then reconstructed using the RAID parameters to analyze the full dataset.
Which Windows artifact stores evidence of files accessed via Windows Explorer, including network shares, even after the files are deleted?
Answer: LNK (shortcut) files
LNK files created by Windows Explorer record the original file path, MAC times, volume serial number, and network share details of accessed files.
What is the primary purpose of Write Blockers in digital forensics?
Answer: Prevent any data from being written to the evidence drive during acquisition
Write blockers intercept write commands to the evidence device, ensuring forensic integrity by preventing modification of original evidence.
A memory dump shows an smss.exe process with a parent PID pointing to a non-standard process instead of the System process. This most likely indicates:
Answer: Process masquerading or malware impersonation
Legitimate smss.exe is always spawned by System (PID 4); a different parent PID strongly suggests a malicious process impersonating smss.exe.
Which file system feature in NTFS can hide data from forensic tools that only parse allocated file entries?
Answer: Alternate Data Streams (ADS)
ADS allows additional data streams to be appended to a file using the filename:streamname syntax, invisible to standard directory listings.
When analyzing a memory image for lateral movement artifacts, which structure reveals recently resolved DNS hostnames?
Answer: DNS resolver cache in memory (dnsapi.dll heap)
The DNS client resolver cache is maintained in memory by dnsapi.dll and can be extracted from a memory image to reveal recent hostname resolutions.