← All CCT Flashcard Decks

Digital Forensics & Malware Analysis Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Forensics & Malware Analysis flashcards as text
  1. What is the purpose of YARA rules in malware analysis?

    Answer: Scanning files and memory for patterns that identify malware families

    YARA rules define string and byte patterns that, when matched in a file or process, identify malware samples belonging to a specific family or campaign.

  2. A forensic examiner recovers a deleted file from an NTFS partition. Which condition must be true for full recovery to be possible?

    Answer: The file's data clusters have not been overwritten by new data

    When a file is deleted, NTFS marks its clusters as available but does not erase them; if those clusters haven't been reallocated, the file content remains recoverable.

  3. Which anti-forensics technique involves an attacker deliberately changing MAC timestamps on files to mislead investigators?

    Answer: Timestomping

    Timestomping modifies a file's Modified, Accessed, and Created timestamps to obscure the true timeline of attacker activity.

  4. During a forensic investigation, an examiner finds a file with a .jpg extension but the magic bytes read '50 4B 03 04'. What does this indicate?

    Answer: The file is actually a ZIP archive with a renamed extension

    Magic bytes 50 4B 03 04 are the signature for ZIP archives (PK header); the .jpg extension is a disguise used to evade file-type filters.

  5. What is the primary use of steganography in a cybersecurity attack?

    Answer: Hiding data or commands inside innocent-looking carrier files like images

    Steganography conceals data within ordinary files (images, audio, video) so that exfiltrated data or C2 commands appear as legitimate media traffic.

  6. Which log source on a Windows system records successful and failed logon attempts and is critical for intrusion investigations?

    Answer: Security event log

    The Windows Security event log (Event IDs 4624/4625) records authentication events, making it the primary source for detecting unauthorized access attempts.

  7. A rootkit hides malicious processes by intercepting system calls before they reach the OS kernel. What type of rootkit is this?

    Answer: Kernel-mode rootkit

    Kernel-mode rootkits operate at ring 0 and hook or patch system call tables to filter OS responses, making malicious processes and files invisible to user-space tools.