โ† All CCT Flashcard Decks

Digital Forensics & Malware Analysis Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensics & Malware Analysis flashcards as text
  1. Which principle ensures that digital evidence is not altered during a forensic investigation?

    Answer: Write blocking

    Write blockers are hardware or software tools that prevent any write operations to storage media, ensuring evidence integrity during acquisition.

  2. What is the correct order of volatility when collecting digital evidence, starting with the most volatile?

    Answer: CPU registers, RAM, network traffic, hard disk

    CPU registers and cache are lost instantly on power-off, followed by RAM, then active network connections, with persistent disk storage being least volatile.

  3. A forensic investigator uses the SHA-256 algorithm on a disk image immediately after acquisition and again after analysis. What is the purpose of this action?

    Answer: Verifying the image has not been tampered with

    Hashing the image before and after analysis produces a cryptographic fingerprint; matching hashes prove the image was not altered, maintaining evidence integrity.

  4. Which type of malware disguises itself as legitimate software to trick users into installing it?

    Answer: Trojan horse

    A Trojan horse masquerades as a benign or useful application while secretly performing malicious actions once executed by the user.

  5. During static malware analysis, which technique is used to identify readable strings embedded in a binary without executing it?

    Answer: Strings extraction

    The 'strings' command extracts human-readable ASCII/Unicode text from a binary, revealing URLs, registry keys, and other indicators without running the malware.

  6. What is the primary purpose of a forensic disk image (e.g., an E01 or raw DD image)?

    Answer: To create a bit-for-bit copy of storage media for analysis

    A forensic image captures every bit of the source media, including deleted files and slack space, allowing analysis without touching the original evidence.

  7. Which file system artifact is most useful for determining when files were created, modified, or accessed on an NTFS volume?

    Answer: $MFT (Master File Table)

    The NTFS $MFT stores metadata for every file including MAC (Modified, Accessed, Created) timestamps, which are critical forensic artifacts.