Virtual Facilitation & Technology Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Virtual Facilitation & Technology flashcards as text
An examiner is facilitating a virtual fraud debrief and needs to share a forensic report with remote participants securely. Which method BEST protects the document from unauthorized redistribution?
Answer: Sharing via a password-protected link with view-only permissions and access logging
A password-protected link with view-only access and access logging controls distribution and creates an audit trail of who accessed the report.
During a virtual facilitation of a fraud awareness training session, a participant claims that IP addresses alone are sufficient to identify a fraudster. How should the CFE respond?
Answer: Explain that IP addresses identify network connections, not individuals, and must be corroborated with other evidence
IP addresses identify network endpoints shared by multiple users (NAT, VPNs, proxies), requiring corroborating evidence to attribute activity to a specific person.
A forensic examiner is analyzing log files from a cloud-based accounting system to identify unauthorized access. Which log entry field is MOST critical for reconstructing the attacker's actions?
Answer: Session activity timestamps paired with resource access events
Timestamps paired with resource access events create a chronological action trail that shows what the attacker accessed and when.
When presenting digital forensic findings virtually to a non-technical jury or client, which communication strategy is MOST effective?
Answer: Using visual timelines and analogies to translate technical findings into understandable narratives
Visual timelines and plain-language analogies help non-technical audiences understand complex digital evidence without losing evidentiary accuracy.
A CFE suspects that a remote employee falsified timekeeping records using a virtual desktop infrastructure (VDI) session. Which VDI artifact is MOST probative of the actual hours the employee was active?
Answer: VDI broker authentication logs showing session start/end times and idle periods
VDI broker logs capture exact session start, end, and idle times independently of the user, providing an objective activity record.
A company falls victim to a business email compromise (BEC) scheme facilitated via a cloned virtual meeting invitation. Which technical indicator would MOST strongly suggest the meeting link was malicious?
Answer: The meeting URL uses a domain that visually resembles but differs from the legitimate vendor's domain (homograph attack)
Homograph attacks use visually similar characters (e.g., Cyrillic letters) in domains to trick recipients into clicking fraudulent links.
An examiner is tasked with preserving evidence from a suspect's cloud storage account under a litigation hold. What is the MOST important first action?
Answer: Notify the cloud provider of the litigation hold to prevent automated deletion or purging
Notifying the provider and issuing a litigation hold prevents automatic data deletion policies from destroying potentially relevant evidence.