Forensic Analysis and Investigation Techniques Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Forensic Analysis and Investigation Techniques flashcards as text
A CFE is investigating a Ponzi scheme where the operator commingled investor funds with personal accounts. Which forensic accounting method is most appropriate to determine each victim's net loss?
Answer: Net winner/net loser analysis using a tracing-of-funds approach
Net winner/net loser analysis traces each investor's deposits and withdrawals to determine whether they received more or less than they contributed, establishing individual losses.
A forensic examiner is analyzing a .pcap file and observes a large number of TCP SYN packets sent to sequential ports on a target host with no corresponding SYN-ACK responses. What activity does this most likely indicate?
Answer: A TCP SYN port scan
Sequential TCP SYN packets to multiple ports with no SYN-ACK replies indicate a TCP SYN scan used to discover open ports on the target system.
When examining a suspect's social media accounts under a preservation request, which action by the forensic examiner would COMPROMISE the integrity of the evidence?
Answer: Logging into the suspect's account using obtained credentials to browse private messages
Logging into the suspect's account without authorization may constitute unauthorized access under the Computer Fraud and Abuse Act and taints the evidence.
A financial institution suspects an employee of creating fictitious vendor payments. Which analytical procedure is most effective for identifying payments to fictitious vendors?
Answer: Matching vendor names and addresses against employee personnel records
Matching vendor master file data (addresses, tax IDs, bank accounts) against employee records is a classic test for fictitious vendor schemes where employees control both sides of the transaction.
A forensic examiner is analyzing steganography in image files suspected of containing hidden communications. Which tool output most directly confirms that data is hidden within an image?
Answer: Detection of known steganographic signatures or statistical anomalies in LSB distribution
Steganalysis tools detect statistical anomalies in least significant bit (LSB) distributions or match known steganographic tool signatures to confirm hidden data.
During a fraud investigation, the CFE discovers the suspect used prepaid debit cards purchased with cash. Which investigative step would provide the most actionable intelligence about how the cards were used?
Answer: Subpoenaing transaction records from the card issuer or processor
Prepaid card issuers and processors maintain transaction logs showing where, when, and for what amount each card was used, even without cardholder registration.
An examiner is reviewing Windows Prefetch files as part of a fraud investigation. What does the presence of a Prefetch file for an application MOST reliably indicate?
Answer: The application was executed at least once on that system
Windows Prefetch files are created when an application is executed, serving as execution artifacts that prove the program ran on that system.