Virtual Facilitation & Technology Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Virtual Facilitation & Technology flashcards as text
A forensic examiner is tasked with recovering deleted messages from a cloud-based collaboration platform like Microsoft Teams. Which artifact location is most likely to contain recoverable message data on a Windows endpoint?
Answer: IndexedDB files in the application's local cache directory
Microsoft Teams stores message data locally in IndexedDB files within the app's local cache, making it a primary recovery target.
When conducting a forensic investigation of a Zoom meeting recording stored in the cloud, which chain of custody step is most critical before downloading the file?
Answer: Capture a cryptographic hash of the file before downloading
Capturing a hash before download establishes the original file's integrity and protects against claims of tampering.
A suspect allegedly exfiltrated confidential data via a virtual private network (VPN). What is the MOST reliable forensic artifact on the suspect's machine to confirm VPN usage?
Answer: VPN connection logs and configuration files stored locally
VPN configuration files and connection logs provide direct evidence of VPN use, including connection timestamps and server endpoints.
During a virtual fraud investigation, an examiner needs to establish the timeline of a suspect's online activity. Which artifact provides the MOST precise timestamping across different time zones?
Answer: Server-side logs with UTC timestamps
Server-side logs use UTC timestamps, eliminating time zone ambiguity and providing a consistent, authoritative timeline.
An investigator analyzing a video-conferencing tool on a corporate laptop discovers ephemeral (end-to-end encrypted) chat messages that were deleted. Which approach offers the BEST chance of recovery?
Answer: Acquire a forensic image of the device and analyze unallocated space
Deleted data may persist in unallocated disk space; a forensic image allows file carving and recovery before overwriting occurs.
Which metadata field in a Zoom cloud recording is most useful for proving a specific participant was actively speaking at a given moment?
Answer: Active speaker timeline embedded in the recording metadata
Zoom's active speaker timeline metadata logs which participant was speaking at each timestamp, providing strong attribution evidence.
A forensic examiner is analyzing Slack workspace data exported by a corporate administrator. Which limitation must be disclosed when presenting this evidence?
Answer: Administrator-exported data may exclude direct messages in free workspaces
Slack's free-tier export does not include direct messages, meaning key communications may be absent from the evidence set.