Incident Response and Reporting Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident Response and Reporting flashcards as text
A CFE is asked to respond to a suspected business email compromise (BEC) incident. Which evidence source should be examined FIRST to understand the scope of fraudulent activity?
Answer: Email server logs, mailbox audit logs, and email forwarding rules configured on affected accounts
BEC attackers commonly configure unauthorized email forwarding rules and access mailboxes covertly; mailbox audit logs and server logs reveal the full scope of unauthorized access.
During an incident debrief, a client asks why the forensic examiner did not make a bit-for-bit copy of a live running server. The examiner's BEST justification for using an alternative acquisition method is:
Answer: The server could not be taken offline without unacceptable business disruption, so a targeted logical acquisition was performed instead
When taking a system offline is not operationally feasible, forensic examiners may use targeted or live acquisition methods, which should be documented along with the justification.
Which of the following BEST describes 'eradication' in the context of the incident response lifecycle?
Answer: Removing malware, closing vulnerabilities, and eliminating attacker access from all affected systems
Eradication involves completely removing all components of the threat—such as malware, backdoors, and compromised accounts—from the environment before recovery begins.
A forensic examiner finds conflicting timestamps between file system metadata and server logs during an investigation. The MOST likely explanation is:
Answer: Clock skew, timezone differences, or deliberate timestamp manipulation by the attacker
Timestamp discrepancies commonly arise from misconfigured system clocks, timezone offsets, or deliberate anti-forensic timestomping techniques used by attackers to obscure their activity.
In documenting incident response findings, the term 'root cause analysis' refers to:
Answer: Determining the fundamental underlying reason the incident was able to occur
Root cause analysis goes beyond symptoms to identify the fundamental vulnerability, misconfiguration, or process failure that enabled the incident, enabling true remediation.
An examiner is preparing an incident report and must describe the attacker's method of gaining initial access. The examiner confirms a spear-phishing email delivered a malicious macro. How should this be categorized in the report?
Answer: Social engineering via phishing as the initial access technique, with macro-enabled document as the delivery mechanism
Accurately categorizing the attack vector—spear-phishing with a malicious macro—is essential for clear reporting and ensures the organization addresses the correct security controls in remediation.
Which of the following scenarios BEST illustrates the concept of 'evidence integrity' in incident response?
Answer: All acquired forensic images are hashed at collection and verified against the hash before analysis
Hashing acquired images at collection and verifying them before analysis mathematically proves that evidence has not been altered, which is fundamental to forensic integrity.