← All CDFI Flashcard Decks

Memory Forensics & Volatile Data Analysis Flashcards

7 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Memory Forensics & Volatile Data Analysis flashcards as text
  1. In Linux memory forensics, which special file provides access to the system's physical memory for acquisition purposes?

    Answer: /dev/mem

    /dev/mem is the character device file in Linux that represents physical memory and is used as a source for live memory acquisition on Linux systems.

  2. What forensic value do Windows crash dump files (BSOD memory dumps) provide to a digital forensics investigator?

    Answer: They capture a snapshot of kernel memory at the moment of the crash, preserving process and network artifacts

    Windows crash dumps preserve kernel memory state including running processes, loaded modules, and network connections at the time of the crash, providing valuable forensic evidence.

  3. Which Volatility plugin should be used for Windows 7 and later systems to identify both active and recently closed network connections from a memory image?

    Answer: netscan

    The `netscan` plugin supports Windows Vista/7 and later, scanning memory for network structures to identify active and recently terminated TCP/UDP connections.

  4. What is the forensic significance of finding a process in memory whose executable image path differs from its expected on-disk location?

    Answer: It may indicate process masquerading or a code injection technique used by malware

    A mismatch between the in-memory image path and the expected on-disk location is a strong indicator of process name spoofing or malware injecting into a legitimate process.

  5. Which memory forensics technique compares a potentially compromised memory image against a known-good baseline to identify anomalies?

    Answer: Differential analysis (memory diffing)

    Differential analysis (memory diffing) compares a suspicious memory image against a clean baseline to quickly surface unauthorized processes, modules, or memory modifications.

  6. How does analyzing MFT timestamp data cached in memory help establish a forensic timeline during an investigation?

    Answer: It allows correlation of file creation or modification times with the suspected time of compromise

    MFT timestamps cached in memory can be correlated with a suspected attack window to identify newly created or modified malicious executables and establish an event timeline.

  7. What is the correct first action when a suspect system is discovered powered on and potentially holding evidence in volatile memory?

    Answer: Perform live memory acquisition first before any other action, following the Order of Volatility

    Live memory acquisition must be performed before shutdown because volatile RAM data is permanently lost when power is removed, in accordance with the Order of Volatility.