Forensic Analysis and Investigation Techniques Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Forensic Analysis and Investigation Techniques flashcards as text
A CFE discovers that a controller used journal entries to inflate revenue near fiscal year-end. Which analytical procedure most effectively identifies this scheme?
Answer: Reviewing journal entries posted near period-end made by senior accounting personnel to revenue accounts
Targeting journal entries posted by senior personnel near period-end to revenue accounts directly exposes the mechanism used in financial statement manipulation schemes.
When using the indirect method to reconstruct a fraud suspect's income, which item would be included as a source of funds?
Answer: Proceeds from the sale of investments
In the indirect (net worth) method, proceeds from asset sales represent incoming funds that must be accounted for in the reconstruction of the suspect's financial activity.
A forensic examiner is tasked with recovering deleted files from a solid-state drive (SSD). What factor makes SSD forensics fundamentally different from traditional hard drive forensics?
Answer: The TRIM command causes the drive controller to zero out deleted data blocks, often making recovery impossible
The TRIM command signals the SSD controller to erase deleted data blocks in advance, which frequently destroys the content of deleted files before recovery can be attempted.
During a white-collar crime investigation, a CFE identifies a suspect who wired funds through five different countries before the money reached its final destination. This technique is best described as:
Answer: Layering
Layering is the money laundering stage in which illicit funds are moved through multiple transactions and jurisdictions to obscure their origin and ownership.
A forensic examiner recovers a deleted SQLite database from a mobile device. Some records have been deleted from a table but the database has not been vacuumed. Where is the most likely location of the deleted record data?
Answer: In the free pages within the database file itself
SQLite marks deleted records' pages as free but does not overwrite them until the database is vacuumed, leaving deleted data recoverable from free pages within the .db file.
An investigator is attempting to attribute a cyber intrusion to a specific threat actor. Which combination of indicators provides the strongest attribution?
Answer: Unique malware code features, TTPs, and infrastructure overlaps with known campaigns
Unique code characteristics, tactics, techniques, and procedures (TTPs), and infrastructure overlaps are high-confidence indicators that persist even when threat actors change IPs or domains.
A CFE is testifying as an expert witness and is challenged under the Daubert standard. Which criterion is the opposing counsel MOST likely to challenge regarding the forensic methodology used?
Answer: Whether the technique has been tested and has a known or potential error rate
Under Daubert, courts evaluate scientific testimony by assessing whether the methodology has been tested, peer-reviewed, has a known error rate, and is generally accepted in the relevant field.