Digital Forensics & Cybercrime Flashcards
7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Forensics & Cybercrime flashcards as text
Which file system artifact is most useful for identifying files that were deleted but previously accessed on an NTFS volume?
Answer: $Recycle Bin INFO2 or $I files
The $Recycle Bin contains $I files (Windows Vista+) or INFO2 records that store the original path, deletion timestamp, and file size of deleted items.
A forensic examiner discovers a 'slack space' artifact. What does this term specifically refer to?
Answer: The space between the end of a file's logical size and the end of its last allocated cluster
File slack (also called RAM slack + drive slack) is the unused space between the logical end of a file and the physical end of the last cluster allocated to it.
Under the Computer Fraud and Abuse Act (CFAA), which element is NOT required to establish criminal liability for unauthorized computer access?
Answer: Proof the defendant received financial gain
Financial gain is not required for all CFAA offenses; some subsections only require unauthorized access with intent to defraud or to obtain information.
When analyzing a Windows registry hive for forensic evidence, which hive contains user-specific settings such as recently accessed files and installed software per user?
Answer: NTUSER.DAT
NTUSER.DAT is the per-user registry hive located in each user's profile folder and stores personalized settings, MRU lists, and user-specific software keys.
In network forensics, what is the primary purpose of capturing pcap (packet capture) files at the time of an incident?
Answer: To preserve full packet-level evidence of network communications for later analysis
Pcap files capture raw network traffic including headers and payloads, providing a complete record of communications that can be replayed and analyzed forensically.
Which volatile data source should be collected FIRST during live forensic acquisition of a compromised system, before any other action?
Answer: Running process list and network connections
Running processes and active network connections are the most volatile data and will be lost immediately upon shutdown, making them the highest priority in live acquisition.
A forensic analyst is examining mobile device data. Which extraction method provides the deepest level of access, including deleted data and unallocated space, but requires specialized hardware?
Answer: Physical extraction (JTAG/chip-off)
Physical extraction methods such as JTAG and chip-off bypass the operating system to read raw NAND flash memory, enabling recovery of deleted data and unallocated space.