EC-Council CHFI (312-49) Certification Exam β Questions and Answers
Question 1: Which analysis technique examines the timing intervals between network packets to identify covert communication channels even when content is encrypted?
- Traffic timing analysis / inter-arrival time analysis (Correct answer)
- Hash-based file carving
- Banner grabbing
- Signature-based detection
Correct answer: Traffic timing analysis / inter-arrival time analysis
Traffic timing analysis examines inter-packet arrival times to detect patterns that may indicate covert channels where timing itself encodes information, bypassing content-level inspection.
Question 2: What type of data can be recovered from a Facebook account's 'Download Your Information' feature that is useful in forensic investigations?
- Only profile photos
- Only payment information
- Messages, posts, friends list, login activity, and location history (Correct answer)
- Only public posts
Correct answer: Messages, posts, friends list, login activity, and location history
Facebook's Download Your Information feature exports a comprehensive archive including private messages, post history, friend connections, IP-based login activity, and location data.
Question 3: What is 'slack space' and which two types are relevant to NTFS forensics?
- Padding in directory entries and padding in MFT records; directory slack and record slack
- Unused sectors at the disk end; types are disk slack and partition slack
- Unused space within the last cluster of a file and unused bytes in the last sector of that cluster; file slack and RAM slack (Correct answer)
- Free space in the MFT and free space in unallocated clusters; MFT slack and cluster slack
Correct answer: Unused space within the last cluster of a file and unused bytes in the last sector of that cluster; file slack and RAM slack
File slack is the unused space between the end of a file's logical data and the end of its last allocated cluster; RAM slack (within the sector) may contain remnant memory data, both can hold hidden or residual data.
Question 4: A forensic investigator needs to determine when a specific stored procedure was last modified in SQL Server. Which catalog view should they query?
- sys.partitions
- sys.objects (Correct answer)
- sys.indexes
- sys.columns
Correct answer: sys.objects
The sys.objects catalog view contains a modify_date column that records the last modification timestamp for all database objects including stored procedures.
Question 5: In a GPT-partitioned disk, where is the backup copy of the partition table stored?
- In the first partition's VBR
- In the MBR protective partition
- At the end of the disk (Correct answer)
- In the EFI System Partition
Correct answer: At the end of the disk
GPT stores a secondary (backup) copy of the partition table at the last sectors of the disk to allow recovery if the primary GPT header is damaged.
Question 6: Which of the following phases does the aforementioned duties take place in when performing the many phases of cloud forensics, one of which involves resolving functional, operational, and security issues in the cloud ecosystem?
- Lof Monitoring
- Troubleshooting (Correct answer)
- Data and system Recovery
- Investigation
Correct answer: Troubleshooting
The troubleshooting phase in cloud forensics involves identifying and resolving various issues that can arise within the complex cloud ecosystem. This includes addressing functional problems, operational inefficiencies, and security vulnerabilities that might impact the integrity of data or the forensic investigation itself. It's a proactive and reactive process to ensure the cloud environment is stable and secure for forensic activities and to overcome challenges in evidence collection.
Question 7: Which Wireshark display filter would isolate only TCP SYN packets without ACK flags?
- tcp.flags.ack == 0
- tcp.handshake == syn
- tcp.flags == 0x02
- tcp.flags.syn == 1 && tcp.flags.ack == 0 (Correct answer)
Correct answer: tcp.flags.syn == 1 && tcp.flags.ack == 0
The filter `tcp.flags.syn == 1 && tcp.flags.ack == 0` precisely isolates TCP SYN packets that initiate connections without an acknowledgment flag.
Question 8: What is the forensic significance of identifying a 'long tail' domain (very low query frequency) in DNS logs?
- It is a sign of legitimate load balancing
- It may indicate a dynamically generated domain used by malware (DGA) (Correct answer)
- It indicates a popular CDN endpoint
- It indicates a misconfigured resolver
Correct answer: It may indicate a dynamically generated domain used by malware (DGA)
Domain Generation Algorithm (DGA) malware produces rarely-seen algorithmically generated domains; these appear as 'long tail' entries with very low query counts in DNS logs.
Question 9: What is the significance of 'slack space' in forensic data acquisition?
- Slack space refers to unused RAM during acquisition that slows the process
- Slack space is the unused area in a drive's HPA
- Slack space is only present on FAT file systems and contains no useful data
- Slack space between the end of a file and the end of its last cluster may contain remnants of previously deleted data (Correct answer)
Correct answer: Slack space between the end of a file and the end of its last cluster may contain remnants of previously deleted data
File system slack (RAM slack + drive slack) occupies the space between a file's logical end and its allocated cluster boundary, which may contain overwritten fragments of old data.
Question 10: An analyst examining a compromised web server finds an `.htaccess` file modified to redirect all traffic to an external malicious site. What type of attack occurred?
- SQL injection
- DNS poisoning
- Web server configuration tampering / malicious redirect (Correct answer)
- Denial of service
Correct answer: Web server configuration tampering / malicious redirect
Modifying `.htaccess` to redirect visitors to a malicious site is a web defacement/compromise technique used after gaining write access to the server.
Question 11: An analyst captures traffic and notices that HTTP responses contain an unusually large number of Set-Cookie headers with random-looking values. This may indicate:
- HTTP/2 server push functionality
- A standard e-commerce session management system
- Cookie-based data exfiltration or C2 channel using HTTP (Correct answer)
- Normal CDN cache-control behavior
Correct answer: Cookie-based data exfiltration or C2 channel using HTTP
Malware can use HTTP cookies to smuggle data and commands between compromised hosts and C2 servers, with encoded payloads embedded in seemingly legitimate cookie values.
Question 12: What is the purpose of a write blocker in forensic disk imaging?
- To prevent any write commands from reaching the evidence drive, preserving its integrity (Correct answer)
- To encrypt the forensic image during acquisition
- To speed up the imaging process by buffering writes
- To filter out bad sectors during imaging
Correct answer: To prevent any write commands from reaching the evidence drive, preserving its integrity
A write blocker (hardware or software) intercepts and blocks write commands sent to the evidence drive, ensuring the forensic process does not modify the original evidence.
Question 13: In a FAT file system, what happens to a deleted file's directory entry?
- The first byte of the filename is replaced with 0xE5 and cluster chain is marked free in the FAT (Correct answer)
- The entry is moved to a recycle bin sector
- The file's data clusters are immediately overwritten
- The entire entry is zeroed out immediately
Correct answer: The first byte of the filename is replaced with 0xE5 and cluster chain is marked free in the FAT
When a file is deleted in FAT, the directory entry's first character is set to 0xE5 and the FAT chain entries are set to 0x00 (free), but the actual data remains until overwritten.
Question 14: Which hash algorithm is currently recommended by NIST for forensic image verification due to collision resistance concerns with MD5?
- SHA-256 (Correct answer)
- CRC-32
- SHA-1
- RIPEMD-128
Correct answer: SHA-256
NIST recommends SHA-256 (or stronger) for forensic integrity verification because MD5 and SHA-1 are vulnerable to collision attacks.
Question 15: What is the significance of the SQL Server 'default trace' in a forensic investigation?
- It monitors network bandwidth usage
- It monitors CPU usage by queries
- It captures database object changes, login failures, and DBCC events by default without configuration (Correct answer)
- It logs all SELECT queries by default
Correct answer: It captures database object changes, login failures, and DBCC events by default without configuration
SQL Server's default trace automatically captures key security and administrative events like object creation/deletion, login failures, and DBCC commands without requiring manual configuration.
Question 16: What is 'remote forensic acquisition' and what network tool is commonly used to facilitate it?
- Performing acquisition via VPN with a hardware write blocker at the remote site
- Imaging a drive over the internet using cloud storage APIs
- Acquiring evidence from a remote computer using an agent (e.g., EnCase Enterprise) deployed on the target (Correct answer)
- Using RDP to manually copy files from a remote system
Correct answer: Acquiring evidence from a remote computer using an agent (e.g., EnCase Enterprise) deployed on the target
Remote forensic acquisition uses an agent (such as EnCase Enterprise's SAFE server or F-Response) deployed on the target machine to allow an examiner to image it across the network.
Question 17: A forensic examiner uses the 'dd' command to image a drive. What is the significance of the 'bs' (block size) parameter?
- It specifies the number of bad sectors to skip
- It sets the encryption key length for the image
- It determines the amount of data read and written per operation, affecting speed and sector alignment (Correct answer)
- It defines the hash algorithm used for verification
Correct answer: It determines the amount of data read and written per operation, affecting speed and sector alignment
The block size (bs) parameter controls how many bytes dd reads and writes at once; aligning it to the disk's sector size (512 or 4096 bytes) improves accuracy and performance.
Question 18: A forensic investigator discovers volatile data on a running system. According to the order of volatility, what should be collected FIRST?
- Network configuration files on disk
- Hard disk contents
- Optical media
- CPU registers and cache (Correct answer)
Correct answer: CPU registers and cache
CPU registers and cache are the most volatile data and must be collected first as they are lost immediately upon power-off.
Question 19: In a PostgreSQL forensic investigation, which directory contains the server log files by default?
- $PGDATA/pg_stat
- $PGDATA/log (Correct answer)
- $PGDATA/global
- $PGDATA/pg_wal
Correct answer: $PGDATA/log
PostgreSQL writes server log files to the $PGDATA/log directory by default, recording connections, errors, and optionally all SQL statements.
Question 20: What is the primary purpose of using 'segment files' (e.g., E01.E01, E01.E02...) during forensic acquisition?
- To accommodate file system size limits and enable splitting across multiple storage media (Correct answer)
- To allow different examiners to work on separate segments simultaneously
- To encrypt each segment with a different key for security
- To allow parallel hashing of each segment separately
Correct answer: To accommodate file system size limits and enable splitting across multiple storage media
Forensic image segmentation splits large images into manageable chunks to work within file system limitations (e.g., FAT32's 4GB limit) or to span multiple storage devices.
Question 21: Which hashing algorithm is recommended by NIST for generating forensic integrity hashes of email evidence files such as PST archives?
- SHA-256 or SHA-3 (Correct answer)
- Base64 encoding
- MD5 alone
- CRC32
Correct answer: SHA-256 or SHA-3
NIST recommends SHA-256 or stronger algorithms for forensic evidence integrity verification, as MD5 and SHA-1 are considered cryptographically weak and vulnerable to collision attacks.
Question 22: A mobile malware sample on Android requests the READ_SMS and SEND_SMS permissions. From a forensic perspective, which threat category does this MOST indicate?
- Ransomware seeking contact exfiltration
- Adware generating click fraud revenue
- Spyware recording microphone audio
- Banking trojan intercepting OTP SMS codes (Correct answer)
Correct answer: Banking trojan intercepting OTP SMS codes
Banking trojans commonly abuse SMS permissions to intercept one-time passwords sent by banks for two-factor authentication, forwarding them to the attacker.
Question 23: Which Windows forensic artifact stores evidence of files that were deleted via the Windows GUI (dragged to Recycle Bin) including original file path and deletion time?
- C:\Windows\System32\recycler.dat
- $Recycle.Bin\$R files on the volume root
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket
- $Recycle.Bin\$I files on the volume root (Correct answer)
Correct answer: $Recycle.Bin\$I files on the volume root
$I files in $Recycle.Bin store the original file path, file size, and deletion timestamp for each deleted item, while $R files hold the actual deleted content.
Question 24: During mobile forensics, an examiner discovers a file named 'mmssms.db' on an Android device. What does this file contain?
- Mobile payment records
- Installed application list
- Multimedia gallery metadata
- SMS and MMS message history (Correct answer)
Correct answer: SMS and MMS message history
The mmssms.db SQLite database stores SMS and MMS messages on Android devices.
Question 25: An investigator finds a deleted SMS on an Android device by examining raw NAND flash blocks. What technique is being used?
- JTAG extraction
- Logical acquisition
- Manual extraction
- Chip-off forensics (Correct answer)
Correct answer: Chip-off forensics
Chip-off forensics involves physically removing the NAND flash chip and reading its raw contents, allowing recovery of deleted data.
Question 26: What term describes the area between the last partition and the end of the disk that is not allocated to any partition?
- Disk slack
- Unpartitioned space (Correct answer)
- Slack space
- Host protected area
Correct answer: Unpartitioned space
Unpartitioned space (also called unallocated space at the disk level) exists between the last partition boundary and the physical end of the disk.
Question 27: During malware analysis, you find that a sample uses atom bombing β writing shellcode to the global atom table and using callback functions to execute it. Which Windows mechanism does this abuse?
- AppInit_DLLs loading through atom table entries
- Kernel callback table manipulation using atoms
- COM object hijacking via the global atom table
- NtQueueApcThread with GlobalAddAtom for code injection without WriteProcessMemory (Correct answer)
Correct answer: NtQueueApcThread with GlobalAddAtom for code injection without WriteProcessMemory
Atom bombing injects code by writing shellcode into the global atom table and using NtQueueApcThread to queue an APC that copies and executes the atom data in the target process without calling WriteProcessMemory.
Question 28: A malware sample is found to create a service with a binary path pointing to a UNC path (\\server\share\evil.exe). What persistence mechanism does this represent?
- DLL hijacking via UNC path
- Pass-the-hash persistence
- Remote service execution for lateral movement (Correct answer)
- Token impersonation persistence
Correct answer: Remote service execution for lateral movement
Malware can create Windows services with UNC paths so that the payload is loaded from an attacker-controlled network share, enabling both persistence and lateral movement.
Question 29: A web application firewall (WAF) log shows a block event for a request containing `SLEEP(5)` in a parameter. What attack technique was attempted?
- Remote file inclusion
- HTTP response splitting
- Time-based blind SQL injection (Correct answer)
- Reflected XSS
Correct answer: Time-based blind SQL injection
Time-based blind SQL injection uses functions like `SLEEP()` to cause database delays, inferring information based on response time when no data is returned directly.
Question 30: What does the term 'inode' refer to in Linux/ext4 file systems?
- The directory entry linking a filename to data
- A data structure containing file metadata such as permissions, timestamps, and block pointers (Correct answer)
- The journal entry for a file transaction
- The physical block where file data is stored
Correct answer: A data structure containing file metadata such as permissions, timestamps, and block pointers
An inode is a data structure in ext file systems that stores all metadata about a file except its name, including ownership, permissions, and pointers to data blocks.
Question 31: What is the primary purpose of NetFlow data in network forensics?
- Decrypting SSL/TLS sessions
- Providing summarized metadata about network traffic flows (Correct answer)
- Mapping physical network topology
- Capturing full packet payloads for deep inspection
Correct answer: Providing summarized metadata about network traffic flows
NetFlow records summarize traffic flow metadata (source/destination IPs, ports, byte counts, timestamps) without capturing full payloads, enabling efficient large-scale traffic analysis.
Question 32: A forensic investigator discovers shellbags in the Windows registry. What specific user activity do shellbags record?
- Application installation history including install date and version
- Files downloaded from the internet through web browsers
- Folder view preferences and evidence that a user opened specific folders, including on removed external drives (Correct answer)
- Shell command history from PowerShell and CMD sessions
Correct answer: Folder view preferences and evidence that a user opened specific folders, including on removed external drives
Shellbags store folder view settings and prove a user opened specific directories, even revealing folder names from devices no longer connected to the system.
Question 33: In investigating a Twitter/X account for evidence, which API does law enforcement reference for legal data requests to the platform?
- Twitter Developer API v2 public endpoints
- Google Safe Browsing API
- WHOIS API
- Twitter's Legal Request Submission portal under the Stored Communications Act (Correct answer)
Correct answer: Twitter's Legal Request Submission portal under the Stored Communications Act
Law enforcement submits legal requests for Twitter/X user data through Twitter's official legal request portal, following the Stored Communications Act framework for subpoenas and warrants.
Question 34: Which dcfldd command option generates a hash of the acquired image simultaneously during the imaging process?
- bs=hashmode
- conv=hash
- hashlog= (Correct answer)
- --verify
Correct answer: hashlog=
dcfldd's 'hashlog=' option writes a running hash (MD5 or SHA-1) to a specified log file as the image is being created, enabling simultaneous acquisition and verification.
Question 35: Which HTTP response code in web server logs most strongly indicates a successful directory traversal attack?
- 500 Internal Server Error
- 403 Forbidden
- 200 OK with unexpected file content (Correct answer)
- 404 Not Found
Correct answer: 200 OK with unexpected file content
A 200 OK response to a traversal-style request (e.g., `../../etc/passwd`) confirms the server served a file outside the web root.
Question 36: Which acquisition method captures only the allocated, in-use clusters on a drive rather than every sector?
- Logical acquisition (Correct answer)
- Sparse acquisition
- Live acquisition
- Targeted acquisition
Correct answer: Logical acquisition
Logical acquisition copies only the active file system contents (allocated clusters), not unallocated space or slack space.
Question 37: A Windows system was shut down abruptly. Which file can help a forensic investigator recover the contents of RAM at the time of shutdown?
- bootmgr
- pagefile.sys
- swapfile.sys
- hiberfil.sys (Correct answer)
Correct answer: hiberfil.sys
hiberfil.sys stores a compressed image of RAM when the system hibernates, allowing recovery of memory contents including running processes and open files.
Question 38: A forensic investigator is documenting the scene before touching any evidence. Which documentation method provides the most comprehensive scene record?
- A verbal description recorded on audio
- A single photograph of the workstation
- Handwritten notes only
- Photographs, video, sketches, and written notes combined (Correct answer)
Correct answer: Photographs, video, sketches, and written notes combined
Combining photographs, video, sketches, and written notes provides the most thorough and legally defensible documentation of the original crime scene.
Question 39: Which Windows registry hive is stored in the file %SystemRoot%\System32\config\SAM and what forensic information does it contain?
- HKLM\SOFTWARE β stores installed application settings and license keys
- HKCU β stores the current user's personal preferences and recent documents
- HKLM\SECURITY β stores local security policies and cached credentials
- HKLM\SAM β stores local user account names and password hashes (Correct answer)
Correct answer: HKLM\SAM β stores local user account names and password hashes
The SAM hive stores local user accounts and their NTLM/LM password hashes, which can be extracted and cracked offline by investigators or attackers.
Question 40: An investigator recovers a Windows system where the attacker cleared the Security event log. Which artifact may still contain evidence of the log clearing action?
- The Setup event log β event ID 2
- Both the System log (1074) and Application log (1000)
- The System event log β event ID 104 (Correct answer)
- The Application event log β event ID 1102
Correct answer: The System event log β event ID 104
Event ID 104 in the System log records when the Security log was cleared, and event ID 1102 in the Security log records the same action if any entries remain.
Question 41: A forensic investigator notices repeated POST requests to `/wp-login.php` with hundreds of different passwords. What attack type is this?
- Credential stuffing
- Password spraying
- Brute-force attack (Correct answer)
- Dictionary attack
Correct answer: Brute-force attack
Repeated login attempts against a single account with many passwords characterizes a brute-force attack.
Question 42: Which protocol is primarily analyzed when investigating DNS-based data exfiltration attacks?
- HTTPS
- FTP
- DNS (Correct answer)
- SMTP
Correct answer: DNS
DNS tunneling encodes data within DNS query/response payloads to exfiltrate data, making DNS traffic the primary focus of such investigations.
Question 43: A forensic examiner needs to acquire a 4TB drive but only has 2TB of available storage. Which approach is MOST appropriate?
- Perform a logical acquisition of only allocated files
- Skip acquisition and examine the original drive in-place
- Partition the image across multiple 1TB raw files using dd split
- Use compressed forensic imaging (e.g., E01 with compression) (Correct answer)
Correct answer: Use compressed forensic imaging (e.g., E01 with compression)
Compressed forensic image formats like E01 can significantly reduce storage requirements while maintaining forensic integrity and embedded hash verification.
Question 44: Cloud forensics are divided into nine main groups, according to NIST.
- False (Correct answer)
- True
Correct answer: False
This statement is false. NIST (National Institute of Standards and Technology) has published extensive guidelines and frameworks for cloud computing and forensics, but they do not categorize cloud forensics into a specific number like 'nine main groups.' NIST documents typically define cloud deployment models, service models, and outline challenges and principles for cloud forensics, rather than a fixed number of groups.
Question 45: Which forensic artifact is MOST useful for identifying the geographic origin of a web attack?
- TLS session tickets
- HTTP response headers
- Source IP address in access logs correlated with GeoIP databases (Correct answer)
- Cookie values
Correct answer: Source IP address in access logs correlated with GeoIP databases
The source IP address recorded in access logs can be queried against GeoIP databases to approximate the attacker's geographic location.
Question 46: What is the Host Protected Area (HPA) and why is it forensically significant?
- A partition reserved for RAID metadata
- A hardware encryption zone that stores BitLocker keys
- A manufacturer's diagnostic log stored in NVRAM
- A hidden drive region invisible to the OS that may contain concealed data (Correct answer)
Correct answer: A hidden drive region invisible to the OS that may contain concealed data
The HPA is a reserved area at the end of a drive that the OS cannot see; suspects may hide data there, and standard imaging tools miss it unless configured to access it.
Question 47: Which forensic concept describes the practice of ensuring that the investigation process itself does not alter or contaminate the evidence?
- Admissibility standard
- Forensic soundness (Correct answer)
- Contemporaneous recording
- Evidence spoliation
Correct answer: Forensic soundness
Forensic soundness means that acquisition and analysis methods do not modify the original evidence and can be validated by hash verification.
Question 48: Which Windows artifact can reveal evidence of a program execution even if the executable has since been deleted, by tracking compatibility telemetry data?
- Windows Error Reporting (WER) files in C:\ProgramData\Microsoft\Windows\WER
- Driver store at C:\Windows\System32\DriverStore
- Application Compatibility Cache (Shimcache) in the registry (Correct answer)
- Windows Installer logs in C:\Windows\Temp
Correct answer: Application Compatibility Cache (Shimcache) in the registry
The Shimcache (AppCompatCache) registry key tracks executables that the Windows Application Compatibility engine has processed, persisting evidence of execution even after deletion.
Question 49: A wiper malware overwrites the first 512 bytes of every connected drive. What critical structure is it targeting?
- NTFS $Boot file
- GUID Partition Table (GPT) header
- Master Boot Record (MBR) (Correct answer)
- Volume Boot Record (VBR)
Correct answer: Master Boot Record (MBR)
The Master Boot Record occupies the first 512 bytes of a disk and contains the bootloader code and partition table; overwriting it renders the system unbootable.
Question 50: What is 'chain of custody' documentation required to include for a forensic image to be admissible in court?
- A signed affidavit from the forensic tool vendor confirming software accuracy
- Identity of each person who handled the evidence, dates/times of transfer, and condition of evidence at each transfer (Correct answer)
- Only the hash value of the image is legally required
- The suspect's signature acknowledging the acquisition occurred
Correct answer: Identity of each person who handled the evidence, dates/times of transfer, and condition of evidence at each transfer
Chain of custody records must document every person who handled the evidence, when transfers occurred, and the evidence's condition, establishing an unbroken accountability trail from collection to court.
Question 51: What network forensics technique involves correlating traffic across multiple capture points to trace the path of an attacker through the network?
- Deep packet inspection
- Packet carving
- Protocol decoding
- Traffic path reconstruction (Correct answer)
Correct answer: Traffic path reconstruction
Traffic path reconstruction correlates timestamps and connection metadata from multiple network taps or logs to trace how an attacker moved laterally through network segments.
Question 52: An attacker sends the payload `<img src=x onerror=alert(1)>` in a comment field that is rendered on a public page. This is an example of which XSS variant?
- DOM-based XSS
- Reflected XSS
- Blind XSS
- Stored XSS (Correct answer)
Correct answer: Stored XSS
Stored (persistent) XSS occurs when malicious script is saved to the server (e.g., a database) and later rendered to other users.
Question 53: What is 'write blocking' and which layer does a software write blocker operate at?
- Encrypts all writes to prevent data modification
- Intercepts write commands via OS driver or API interception before they reach the drive (Correct answer)
- Physically disconnects the write pin; operates at the SATA controller layer
- Monitors SMART data to detect write operations
Correct answer: Intercepts write commands via OS driver or API interception before they reach the drive
Software write blockers intercept OS-level write commands (via drivers or system call hooks) before they reach the storage device, preventing data modification during examination.
Question 54: A forensic analyst discovers a Windows process with no parent process ID and an unusual network connection to a foreign IP. Which technique best describes what the malware is likely using?
- Orphan process injection
- DLL side-loading
- Process hollowing (Correct answer)
- DKOM rootkit hiding
Correct answer: Process hollowing
Process hollowing replaces a legitimate process's code with malicious code, often resulting in a process that appears legitimate but has anomalous network behavior and no normal parent.
Question 55: Which protocol is used to retrieve email from a mail server and keeps messages stored server-side, making it critical for cloud-based email forensics?
- POP3
- IMAP (Correct answer)
- FTP
- SMTP
Correct answer: IMAP
IMAP (Internet Message Access Protocol) keeps emails stored on the server, meaning evidence may be preserved in the cloud even after local deletion.
Question 56: What is the primary purpose of maintaining a strict Chain of Custody for digital evidence?
- To prove the integrity and authenticity of the evidence and show it has not been tampered with. (Correct answer)
- To speed up the analysis phase by pre-categorizing the evidence.
- To track the cost of the investigation and the tools used.
- To ensure the investigator understands the technical details of the evidence.
Correct answer: To prove the integrity and authenticity of the evidence and show it has not been tampered with.
The Chain of Custody is a chronological paper trail that documents the seizure, custody, control, transfer, analysis, and disposition of evidence. Its main purpose is to ensure the integrity of the evidence, proving that it has not been altered or tampered with, which is critical for its admissibility in court.
Question 57: A suspect's drive shows a partition type code of 0x07 in the MBR partition table. What file system does this typically indicate?
- Linux ext4
- NTFS or exFAT (Correct answer)
- FAT32
- Linux swap
Correct answer: NTFS or exFAT
Partition type code 0x07 is assigned to NTFS (and exFAT) partitions in the MBR partition table scheme.
Question 58: A forensic analyst finds that an attacker sent an HTTP request with the header `X-Forwarded-For: 127.0.0.1`. What was the attacker trying to achieve?
- Spoof the source IP to appear as localhost and bypass IP-based access controls (Correct answer)
- Exploit an open redirect vulnerability
- Inject JavaScript into the response
- Escalate HTTP to HTTPS
Correct answer: Spoof the source IP to appear as localhost and bypass IP-based access controls
By forging the `X-Forwarded-For` header to `127.0.0.1`, attackers attempt to trick applications into treating the request as coming from localhost, bypassing IP allowlists.
Question 59: If a crime is committed in a cloud environment, identify the specific offense that was committed there.
- Cloud as a subject (Correct answer)
- Cloud as an object
- Cloud as a tool
Correct answer: Cloud as a subject
When a crime is committed *in* a cloud environment, meaning the cloud itself is the target or location of the criminal activity (e.g., data theft from a cloud server, unauthorized access to cloud resources), it is categorized as 'Cloud as a Subject.' This distinguishes it from using the cloud as a tool to commit a crime elsewhere or the cloud being the object of a crime (e.g., the cloud provider itself being attacked).
Question 60: During a network forensics investigation, an analyst notices many short-duration flows to a single external IP. This pattern is most consistent with:
- Normal web browsing
- VoIP communications
- File transfer protocol activity
- Beaconing malware behavior (Correct answer)
Correct answer: Beaconing malware behavior
Regular short-duration connections to a single external IP at consistent intervals are a hallmark of malware beaconing for command-and-control communication.
Question 61: What are the following? cloud computing services that deliver hardware, operating systems, and virtual machines. Which a service API may be used to govern.
- Platform-as-a-Service (PaaS)
- Platform-as-a-Service (PaaS)
- Infrastructure-as-a-Service (IaaS) (Correct answer)
Correct answer: Infrastructure-as-a-Service (IaaS)
Infrastructure-as-a-Service (IaaS) provides virtualized computing resources over the internet, including virtual machines, storage, networks, and operating systems. Users have control over the operating systems, applications, and middleware, while the cloud provider manages the underlying infrastructure. This model allows for significant flexibility and scalability, often managed through APIs for programmatic control.
Question 62: What is the purpose of the $MFT file in NTFS forensics?
- It contains the Windows boot sector and partition layout
- It is the Master File Table containing metadata for every file and directory on the volume (Correct answer)
- It logs all file access timestamps in real time
- It stores encrypted file system keys
Correct answer: It is the Master File Table containing metadata for every file and directory on the volume
The $MFT (Master File Table) is the core NTFS structure storing file name, size, timestamps, and data location for every file.
Question 63: What is the Device Configuration Overlay (DCO) and how does it differ from the HPA?
- DCO is configured by the manufacturer or OEM to limit drive capacity; HPA is user-configurable (Correct answer)
- DCO and HPA are different names for the same feature
- DCO stores partition tables; HPA stores firmware
- DCO is set by the user; HPA is set by the manufacturer at the factory
Correct answer: DCO is configured by the manufacturer or OEM to limit drive capacity; HPA is user-configurable
The DCO is typically set by manufacturers to standardize drive capacity across product lines, while the HPA can be set by the user or OS to hide data; both are invisible to the OS.
Question 64: When an investigator testifies in court about forensic findings, what role does the investigator serve?
- Character witness
- Expert witness (Correct answer)
- Fact witness
- Hearsay witness
Correct answer: Expert witness
A forensic investigator testifies as an expert witness, allowed to provide opinions and interpretations based on specialized knowledge.
Question 65: What tool can a CHFI investigator use to read and analyze MySQL binary logs during a database forensic investigation?
- mysqlbinlog (Correct answer)
- mysqldump
- mysqlcheck
- mysql_upgrade
Correct answer: mysqlbinlog
The mysqlbinlog utility reads MySQL binary log files, allowing investigators to reconstruct all SQL statements executed on the server.
Question 66: What is the Device Configuration Overlay (DCO) on ATA hard drives?
- A hidden area similar to HPA that restricts features and capacity visible to the OS and BIOS (Correct answer)
- The error correction code area on each track
- A diagnostic partition created by the manufacturer
- A firmware update mechanism for hard drives
Correct answer: A hidden area similar to HPA that restricts features and capacity visible to the OS and BIOS
DCO is an ATA feature that allows manufacturers or users to permanently hide disk capacity and features; like HPA, it requires special ATA commands to detect.
Question 67: What forensic technique involves comparing database schema versions to identify unauthorized structural changes?
- Query profiling
- Index fragmentation analysis
- Schema diffing (Correct answer)
- Log tailing
Correct answer: Schema diffing
Schema diffing compares two versions of a database schema to detect unauthorized additions, modifications, or deletions of tables, columns, or stored procedures.
Question 68: Which forensic technique involves reviewing the `Last-Modified` and `ETag` HTTP response headers to establish a timeline of web content changes?
- Fuzzing
- Passive fingerprinting
- Deep packet inspection
- Cache-based temporal analysis (Correct answer)
Correct answer: Cache-based temporal analysis
Cache-related headers like `Last-Modified` and `ETag` reflect when server-side content was last changed, helping investigators establish a timeline of modifications.
Question 69: A malware analyst is performing static analysis on a suspicious executable. The analyst notes that the file has a very small import address table (IAT) but a section with unusually high entropy. What is the most likely reason for these characteristics?
- The file is a script-based malware, such as a PowerShell script.
- The executable is corrupted and missing its header information.
- The file is a benign utility with minimal dependencies.
- The malware is packed or encrypted to obfuscate its true code. (Correct answer)
Correct answer: The malware is packed or encrypted to obfuscate its true code.
Packers compress or encrypt a malware's original code. The resulting binary has a small unpacking 'stub' with few imports, which is responsible for decompressing/decrypting the real malicious code in memory. The packed section itself appears random, leading to high entropy, which is a classic indicator of this obfuscation technique.
Question 70: What is the primary forensic challenge posed by Apple's 'Secure Enclave Processor' (SEP) in modern iPhones?
- It encrypts iCloud backups differently than device backups
- It requires specialized JTAG probes to access
- It wipes data after 10 failed passcode attempts at the hardware level
- It stores encryption keys that cannot be extracted even by Apple (Correct answer)
Correct answer: It stores encryption keys that cannot be extracted even by Apple
The SEP stores cryptographic keys in hardware that are never exposed to the main OS, making brute-force attacks the only viable method.
Question 71: Which tool is built into Windows and can be used to view the detailed security permissions and audit settings on registry keys?
- eventvwr.msc
- regedit.exe with 'Permissions' dialog (Correct answer)
- msconfig.exe
- gpedit.msc
Correct answer: regedit.exe with 'Permissions' dialog
Regedit's right-click Permissions dialog exposes ACLs and audit settings on registry keys, revealing who can read or write each key.
Question 72: Which email header field is most important for tracing the originating IP address of an email message?
- Reply-To
- Message-ID
- From
- Received (Correct answer)
Correct answer: Received
The 'Received' headers form a chain of mail server hops and the earliest 'Received' header contains the originating IP address of the sender.
Question 73: What is the primary purpose of the 'chain of custody' document in digital forensics?
- Track evidence handling to preserve admissibility (Correct answer)
- Document the network topology of the crime scene
- Record all software used during analysis
- List all suspects involved in the case
Correct answer: Track evidence handling to preserve admissibility
Chain of custody tracks who handled evidence, when, and how to ensure it remains unaltered and legally admissible.
Question 74: A Windows forensic investigation reveals the presence of a file named 'NTUSER.DAT.LOG1'. What is the forensic significance of this file?
- It is a backup copy of the user hive created by Windows Backup
- It records the history of user login timestamps for the past 30 days
- It is a transaction log for the NTUSER.DAT registry hive that may contain uncommitted registry changes (Correct answer)
- It is an encrypted duplicate of NTUSER.DAT used for BitLocker recovery
Correct answer: It is a transaction log for the NTUSER.DAT registry hive that may contain uncommitted registry changes
NTUSER.DAT.LOG1 and .LOG2 are registry transaction logs that buffer pending writes; they may contain registry data not yet flushed to the main hive file.
Question 75: What does the 'conversation' view in Wireshark primarily help an investigator accomplish?
- Filter packets by protocol type
- Identify all unique bidirectional communication pairs in a capture (Correct answer)
- Reassemble fragmented IP datagrams
- Decode encrypted traffic
Correct answer: Identify all unique bidirectional communication pairs in a capture
Wireshark's Conversations window displays all unique endpoint pairs communicating in the capture, showing statistics like packet counts and bytes exchanged per conversation.
Question 76: A suspect's laptop uses full-disk BitLocker encryption and is found powered ON. What is the BEST immediate action to preserve decrypted data?
- Shut it down immediately to prevent data changes
- Wait for BitLocker to time out and re-encrypt
- Perform a live RAM acquisition before powering off (Correct answer)
- Remove the drive and image it in a write blocker
Correct answer: Perform a live RAM acquisition before powering off
Performing a live RAM acquisition captures the BitLocker encryption keys stored in volatile memory before the machine is powered off.
Question 77: Which NTFS timestamp is NOT updated when a file is simply read (accessed) on a default Windows 10/11 system?
- Only $MFT record change time updates
- $FILENAME last access time
- All timestamps are always updated on access
- $STANDARD_INFORMATION last access time (Correct answer)
Correct answer: $STANDARD_INFORMATION last access time
By default, Windows disables updating of the $SI last access time (NtfsDisableLastAccessUpdate=1) to improve performance, so reading a file does not update it.
Question 78: What forensic information can be extracted from Windows Jump Lists located in AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations?
- Browser history and cookie data for all installed web browsers
- Scheduled task definitions and their last execution timestamps
- Cached passwords for recently used network shares and web sites
- Recently and frequently accessed files per application, including files on removed media (Correct answer)
Correct answer: Recently and frequently accessed files per application, including files on removed media
Jump Lists store per-application MRU entries (AppIDs) linking recently opened files, revealing what an application accessed even after files are deleted.
Question 79: In web attack forensics, what does the presence of `%2e%2e%2f` in a URL request indicate?
- Base64-encoded command injection
- URL-encoded directory traversal (`../`) (Correct answer)
- XML entity injection
- LDAP injection attempt
Correct answer: URL-encoded directory traversal (`../`)
`%2e%2e%2f` is the URL-encoded form of `../`, used in directory traversal attacks to escape the web root.
Question 80: What is the primary forensic value of the SQL Server msdb database?
- Stores model database templates
- Holds temporary objects
- Stores user data tables
- Contains SQL Agent job history and backup/restore history (Correct answer)
Correct answer: Contains SQL Agent job history and backup/restore history
The msdb database stores SQL Server Agent job history, backup and restore history, and Database Mail data, providing a timeline of automated activities.
Question 81: What is the purpose of performing a 'disk-to-disk' clone versus a 'disk-to-image' acquisition?
- Disk-to-disk clones are always preferred because they produce exact forensic images
- Disk-to-image copies only partition tables, not data
- Disk-to-disk is faster but does not preserve deleted files
- Disk-to-disk creates a bootable working copy while disk-to-image creates an investigative archive (Correct answer)
Correct answer: Disk-to-disk creates a bootable working copy while disk-to-image creates an investigative archive
Disk-to-disk cloning produces a bootable duplicate that can replace the original for examination, while disk-to-image creates a compressed archive used for analysis and preservation.
Question 82: Which sector on a standard 512-byte sector MBR disk contains the partition table?
- Sector 1 (the second sector)
- Sector 0 (the first sector of the disk) (Correct answer)
- The last sector of the first track
- Sector 63 (the first usable sector)
Correct answer: Sector 0 (the first sector of the disk)
On an MBR disk, sector 0 contains the 446-byte bootstrap code, the 64-byte partition table (4 entries of 16 bytes each), and the 2-byte signature 0x55AA.
Question 83: Which RFC defines the syslog protocol commonly used to collect network device logs for forensic analysis?
- RFC 1918
- RFC 2616
- RFC 791
- RFC 5424 (Correct answer)
Correct answer: RFC 5424
RFC 5424 defines the current syslog protocol standard, specifying the format for system log messages used by network devices, servers, and security appliances.
Question 84: Which Oracle database view provides information about all currently connected sessions and can help identify unauthorized access?
- DBA_TABLES
- V$SESSION (Correct answer)
- V$DATAFILE
- ALL_OBJECTS
Correct answer: V$SESSION
V$SESSION is a dynamic performance view in Oracle that displays information about all current database sessions including username, logon time, and program.
Question 85: What does the NTFS $LogFile record, and why is it forensically valuable?
- Content of recently opened documents
- Transactional metadata changes to the file system, allowing reconstruction of recent file operations (Correct answer)
- User login events and failed authentication attempts
- Network connections associated with file transfers
Correct answer: Transactional metadata changes to the file system, allowing reconstruction of recent file operations
The NTFS $LogFile is a circular transaction log that records metadata changes; forensic tools can parse it to reconstruct file creation, deletion, and renaming events even after file system operations.
Question 86: Which tool is commonly used by CHFI investigators to analyze email headers and trace email origins?
- Nmap
- Wireshark
- Metasploit
- MXToolbox Email Header Analyzer (Correct answer)
Correct answer: MXToolbox Email Header Analyzer
MXToolbox Email Header Analyzer parses raw email headers to display the routing path, timestamps, and originating IP addresses in an investigator-friendly format.
Question 87: What distinguishes a 'selective' acquisition from a 'full physical' acquisition?
- Selective acquisition uses hardware write blockers exclusively
- Selective acquisition copies every bit of the drive including HPA
- Selective acquisition targets specific files or folders based on relevance criteria (Correct answer)
- Selective acquisition always produces a compressed output
Correct answer: Selective acquisition targets specific files or folders based on relevance criteria
Selective acquisition collects only specific, forensically relevant files or directories rather than imaging the entire drive.
Question 88: Which artifact on a Windows system stores evidence of web-based email access (e.g., Gmail via browser) useful in email forensics?
- Browser cache, history, and cookies (Correct answer)
- Windows Event Logs only
- Prefetch files only
- Registry hives only
Correct answer: Browser cache, history, and cookies
Browser cache files may contain cached email content and attachments, browser history shows Gmail/webmail access timestamps, and cookies can reveal authenticated sessions.
Question 89: Which email authentication mechanism adds a digital signature to outgoing emails that can be verified to confirm the sender's domain integrity?
- DKIM (Correct answer)
- SPF
- DMARC
- MX record
Correct answer: DKIM
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to the email header that allows receivers to verify the email was not altered and originated from the claimed domain.
Question 90: A forensic analyst discovers that malware is using DNS TXT records to receive commands. This is an example of which C2 technique?
- DNS tunneling for command-and-control (Correct answer)
- Domain generation algorithm (DGA)
- Fast-flux DNS evasion
- DNS cache poisoning
Correct answer: DNS tunneling for command-and-control
DNS tunneling encodes C2 commands and data within DNS query/response fields such as TXT records, allowing covert communication that often bypasses firewall rules permitting DNS traffic.
Question 91: In a web attack investigation, what is the purpose of correlating web server logs with database query logs?
- To measure page load performance
- To identify legitimate user session cookies
- To match malicious HTTP requests with the actual database queries they generated (Correct answer)
- To verify SSL certificate validity
Correct answer: To match malicious HTTP requests with the actual database queries they generated
Correlating web and database logs links specific HTTP requests to the database queries they triggered, confirming whether an injection attack reached and affected the database.
Question 92: In a corporate investigation, HR asks a forensic investigator to monitor an employee's email without a warrant. This is legally permissible primarily because:
- The company owns the email system and employees have notice of monitoring policies (Correct answer)
- Email evidence never requires a warrant in any jurisdiction
- Investigators have implied authority over all network traffic
- Corporate emails are public records
Correct answer: The company owns the email system and employees have notice of monitoring policies
Employers can monitor company-owned systems when employees have been notified through acceptable-use policies, making a warrant unnecessary.
Question 93: Which tool is specifically designed for acquiring volatile memory (RAM) on a live Windows system?
- WinPmem (Correct answer)
- FTK Imager Lite (disk only mode)
- dcfldd
- Autopsy
Correct answer: WinPmem
WinPmem is an open-source Windows memory acquisition tool that dumps physical RAM to a file for forensic analysis of volatile data.
Question 94: During a web forensics investigation, an analyst discovers requests to `/admin/../../../etc/shadow`. What evasion technique is the attacker using?
- Path traversal with null byte injection
- Path traversal disguised within a valid-looking path (Correct answer)
- HTTP verb tampering
- Parameter pollution
Correct answer: Path traversal disguised within a valid-looking path
The attacker embeds `../` sequences within an apparently legitimate path to evade simple blacklist filters that only check the beginning of the URL.
Question 95: What information is stored in the Windows Prefetch files located in C:\Windows\Prefetch?
- Executable run count, last run time, and files/directories referenced during execution (Correct answer)
- Cached DNS query results used to speed up network connections
- Pre-fetched web page content stored by Internet Explorer
- Application crash dumps collected before system shutdown
Correct answer: Executable run count, last run time, and files/directories referenced during execution
Prefetch (.pf) files record execution count, last eight run timestamps, and all files and directories loaded during an application's startup, aiding timeline reconstruction.
Question 96: Which SQL Server feature, when enabled, records all login attempts including failed ones, and is critical for forensic investigations?
- Database Mirroring
- Change Data Capture
- Replication
- SQL Server Audit (Correct answer)
Correct answer: SQL Server Audit
SQL Server Audit tracks and logs SQL Server and database-level events including successful and failed login attempts, providing a forensic audit trail.
Question 97: What does the MFT entry attribute $DATA contain in NTFS?
- The actual file content or data runs pointing to the file's data clusters (Correct answer)
- The file's security descriptor and ACL
- The parent directory reference
- The file's MAC timestamps
Correct answer: The actual file content or data runs pointing to the file's data clusters
The $DATA attribute in an MFT entry either contains the file's data directly (resident) or data runs that map to the clusters holding the file's content (non-resident).
Question 98: Which law in the US specifically addresses unauthorized access to computer systems and is frequently cited in cybercrime investigations?
- Electronic Communications Privacy Act (ECPA)
- Digital Millennium Copyright Act (DMCA)
- Gramm-Leach-Bliley Act (GLBA)
- Computer Fraud and Abuse Act (CFAA) (Correct answer)
Correct answer: Computer Fraud and Abuse Act (CFAA)
The CFAA criminalizes unauthorized access to protected computers and is the primary federal statute used in computer crime prosecutions.
Question 99: When a hacker utilizes one compromised cloud to attack additional accounts, they are using the cloud as a tool.
- False
- True (Correct answer)
Correct answer: True
This statement is true. When a hacker leverages a compromised cloud environment (e.g., using a compromised virtual machine or cloud account) to launch attacks against other targets, the cloud infrastructure is serving as an instrument or means to facilitate the crime. In this scenario, the cloud is not the victim or the location of the crime, but rather the 'tool' used by the perpetrator to achieve their malicious goals.
Question 100: During investigation, logs show the attacker's session cookie was identical across 20 different IP addresses. What attack scenario does this MOST likely indicate?
- Distributed brute-force attack
- Cross-site request forgery
- Cookie poisoning by a rogue CDN node
- Session hijacking β the attacker stole and reused a victim's session token (Correct answer)
Correct answer: Session hijacking β the attacker stole and reused a victim's session token
A single session cookie appearing from multiple IPs indicates the attacker stole a legitimate session token and used it from different hosts or proxies.
Question 101: A CHFI is conducting dynamic analysis of a suspected ransomware sample in an isolated, sandboxed environment. Which of the following actions would be the primary focus of the analyst's monitoring to confirm the malware's classification and behavior?
- Checking for an increase in CPU usage and memory consumption by the suspicious process.
- Observing rapid and widespread file read/write/rename operations, especially with a new file extension being added. (Correct answer)
- Analyzing the PE header of the file to determine the compile time and linked libraries.
- Extracting all embedded strings from the binary to look for keywords like 'encrypt'.
Correct answer: Observing rapid and widespread file read/write/rename operations, especially with a new file extension being added.
Dynamic analysis focuses on observing the malware's behavior at runtime. The defining characteristic of ransomware is its encryption of user files. Therefore, monitoring for high-volume file system I/O, particularly operations that involve reading original files and writing newly encrypted versions (often with a specific extension), is the most direct way to observe and confirm its malicious intent.
Question 102: Which SQL Server system database stores metadata about all other databases on the SQL Server instance?
- master (Correct answer)
- model
- msdb
- tempdb
Correct answer: master
The master database stores all instance-level metadata including login accounts, endpoints, linked servers, and configuration settings.
Question 103: Which forensic evidence would confirm that a VPN tunnel was established between two hosts, even if the tunneled content is encrypted?
- Presence of encapsulating protocols such as GRE, ESP, or OpenVPN's UDP traffic on known VPN ports (Correct answer)
- TCP RST packets between the hosts
- ICMP echo-reply messages
- HTTP GET requests in cleartext
Correct answer: Presence of encapsulating protocols such as GRE, ESP, or OpenVPN's UDP traffic on known VPN ports
VPN protocols leave identifiable traces such as ESP (IPsec), GRE encapsulation headers, or UDP traffic on well-known VPN ports (e.g., 1194 for OpenVPN, 500/4500 for IKE) even when payload is encrypted.
Question 104: The Inspect Pane can be used to view the file content of evidence files. To display file content, the View pane offers a number of tabs.Β Which of these tabs offers native views of the formats that Oracle supports outside of its own technology?
- Text tab
- Hex tab
- Doc tab (Correct answer)
- Picture tab
Correct answer: Doc tab
The Doc tab in forensic tools like EnCase is designed to provide native views of various document formats, including those created by applications like Microsoft Office, Adobe PDF, and other common business software. It allows investigators to view these files as they would appear in their original applications, without needing the applications themselves. This functionality is crucial for examining a broad range of document types, including those that might be supported by or interact with Oracle technologies, but are not exclusively Oracle's proprietary format.
Question 105: Which tool is widely used by CHFI investigators for comprehensive disk imaging and forensic analysis on Windows systems?
- Nmap
- FTK (Forensic Toolkit) (Correct answer)
- Wireshark
- Metasploit
Correct answer: FTK (Forensic Toolkit)
FTK by AccessData is a comprehensive forensic platform supporting disk imaging, file analysis, password cracking, and evidence management.
Question 106: Which artifact from a Windows system BEST helps determine what files were recently accessed by malware running under a specific user account?
- Amcache.hve entries
- NTUSER.DAT RecentDocs and OpenSave MRU keys (Correct answer)
- Event Log ID 4688 entries
- Prefetch file execution counts
Correct answer: NTUSER.DAT RecentDocs and OpenSave MRU keys
The RecentDocs and OpenSave MRU registry keys in NTUSER.DAT record files recently opened or saved by the user account, revealing malware file access patterns.
Question 107: What is the forensic significance of the Windows Volume Shadow Copy Service (VSS)?
- It maintains a duplicate copy of the MFT in a hidden shadow partition
- It monitors network traffic and logs packet captures to a shadow volume
- It encrypts files at rest to prevent unauthorized access during forensic acquisition
- It creates point-in-time snapshots of volumes that may contain previous versions of deleted or modified files (Correct answer)
Correct answer: It creates point-in-time snapshots of volumes that may contain previous versions of deleted or modified files
VSS shadow copies can contain previous versions of files, registry hives, and even deleted artifacts, providing investigators access to historical system states.
Question 108: A forensic image of a compromised host shows that the malware modified the hosts file to redirect antivirus update domains to 127.0.0.1. What is the forensic artifact path for the Windows hosts file?
- C:\ProgramData\Microsoft\Windows\hosts
- C:\Windows\System32\etc\hosts
- C:\Windows\System32\drivers\etc\hosts (Correct answer)
- C:\Windows\SysWOW64\drivers\hosts
Correct answer: C:\Windows\System32\drivers\etc\hosts
The Windows hosts file is located at C:\Windows\System32\drivers\etc\hosts and is a common target for malware to block security tool updates by overriding DNS resolution.
Question 109: Which CHFI-relevant tool is specifically designed to recover and analyze SQLite database files commonly found on mobile devices and applications?
- Volatility
- Wireshark
- DB Browser for SQLite (Correct answer)
- FTK Imager
Correct answer: DB Browser for SQLite
DB Browser for SQLite allows forensic investigators to open, view, and recover data from SQLite database files, which are widely used in mobile apps and desktop applications.
Question 110: When a cloud acts like an object, it is committing the crime of cloud as object.
- False (Correct answer)
- True
Correct answer: False
This statement is false. When a cloud acts as an object, it means the cloud itself is the victim of the crime, such as a denial-of-service attack against a cloud provider's infrastructure or data being stolen from cloud storage. The cloud is not 'committing' the crime; rather, it is the entity being acted upon by the criminal, suffering the impact of the malicious activity.
Question 111: An investigator is analyzing a botnet C2 protocol and finds that the malware generates domain names using the current date as a seed for a pseudo-random algorithm. This is BEST described as:
- Domain generation algorithm (DGA) (Correct answer)
- Bullet-proof hosting
- DNS sinkholeability evasion
- Fast-flux DNS
Correct answer: Domain generation algorithm (DGA)
A Domain Generation Algorithm (DGA) uses a seed value such as the current date to algorithmically produce large numbers of potential C2 domain names, making takedowns difficult.
Question 112: Which Windows registry key stores the time zone setting of the system, which is critical for accurate timeline normalization during forensic analysis?
- HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation (Correct answer)
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
- HKCU\Control Panel\International\TimeZone
- HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
Correct answer: HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation
The TimeZoneInformation key stores the active time zone bias values used by Windows, essential for converting system timestamps to UTC for accurate correlation.
Question 113: A forensic investigator is tasked with creating a bit-for-bit copy of a suspect's hard drive. To ensure the integrity of the original evidence, which of the following tools is essential to use during the acquisition process?
- A network sniffer
- A file carving tool
- A write-blocker (Correct answer)
- A hashing utility
Correct answer: A write-blocker
A write-blocker is a device or software that prevents any write operations to a storage device, ensuring that the original evidence is not altered during the forensic imaging process. This preserves the integrity of the data, which is a fundamental principle in digital forensics. Hashing is used for verification after the image is created, file carving is for data recovery, and a network sniffer captures network traffic.
Question 114: A forensic investigator captures a packet with TTL value of 1. What does this most likely indicate?
- The packet originated from a local subnet
- The packet is encrypted
- The packet was crafted to expire after one hop (Correct answer)
- The packet uses IPv6
Correct answer: The packet was crafted to expire after one hop
A TTL of 1 means the packet will be dropped after crossing one router, often seen in traceroute probes or deliberately crafted reconnaissance packets.
Question 115: Which Windows registry hive stores user-specific settings and is loaded from the user's profile directory?
- HKEY_LOCAL_MACHINE
- HKEY_CURRENT_USER (NTUSER.DAT) (Correct answer)
- HKEY_CLASSES_ROOT
- HKEY_LOCAL_MACHINE\SYSTEM
Correct answer: HKEY_CURRENT_USER (NTUSER.DAT)
HKEY_CURRENT_USER maps to NTUSER.DAT in the user's profile folder and stores user-specific configuration.
Question 116: What does a high number of RST packets from a single source typically indicate during forensic analysis?
- Successful SSL handshakes
- A port scan where the scanner receives RST responses from closed ports (Correct answer)
- Normal TCP session termination
- A busy web server handling many requests
Correct answer: A port scan where the scanner receives RST responses from closed ports
TCP RST packets in response to connection attempts indicate closed ports; many RSTs from one target in response to one scanner suggest a port scanning probe.
Question 117: What does the 'Date' field in an email header represent, and why must investigators treat it with caution?
- The date the email was received by the destination server, which is always accurate
- The date set by the sender's email client, which can be manipulated by the sender (Correct answer)
- The date the email was scanned by antivirus
- The date the email was backed up
Correct answer: The date set by the sender's email client, which can be manipulated by the sender
The Date header is set by the sender's mail client and can be manually altered, so investigators should corroborate it against 'Received' header timestamps from mail servers.
Question 118: What is the forensic significance of the MIME (Multipurpose Internet Mail Extensions) structure in email investigation?
- It encrypts email body content
- It authenticates sender domains
- It defines email routing rules
- It encodes attachments and multi-part content that may contain embedded malware or evidence (Correct answer)
Correct answer: It encodes attachments and multi-part content that may contain embedded malware or evidence
MIME encoding allows emails to carry attachments and multi-part content; forensic investigators must decode MIME parts to extract and examine potentially malicious or evidential attachments.
Question 119: During a forensic investigation, an analyst discovers that SQL Server error log entries have been deleted. Where else might evidence of malicious database activity be found?
- Only in network packet captures
- Only in the application tier
- Windows Event Logs and SQL Server transaction logs (Correct answer)
- Only in firewall logs
Correct answer: Windows Event Logs and SQL Server transaction logs
Windows Event Logs record SQL Server service events and security events, while transaction logs record all data modifications, providing corroborating evidence even when error logs are deleted.
Question 120: A forensic examiner finds evidence of a malware using named pipes for inter-process communication. Which Windows Sysinternals tool would BEST enumerate active named pipes?
- TCPView
- PipeList (Correct answer)
- Process Monitor
- Autoruns
Correct answer: PipeList
PipeList from Sysinternals enumerates all named pipes on a Windows system, making it ideal for identifying malicious IPC channels used by malware.
Question 121: In the context of CHFI investigations, what does the term 'volatile data' refer to?
- Data overwritten by file system operations
- Data that exists only while a system is powered on and is lost at shutdown (Correct answer)
- Data hidden in slack space
- Data stored in encrypted containers
Correct answer: Data that exists only while a system is powered on and is lost at shutdown
Volatile data resides in RAM, CPU registers, and running processes, and is immediately lost when the system is powered off.
Question 122: Which of the following is a legal concern when collecting evidence from a cloud storage provider?
- Cloud evidence is always admissible without authentication
- Cloud providers are required to hand over data without any legal process
- Jurisdiction and the need for legal process such as subpoenas or mutual legal assistance treaties (Correct answer)
- Cloud data cannot be used as forensic evidence
Correct answer: Jurisdiction and the need for legal process such as subpoenas or mutual legal assistance treaties
Cloud data may reside in foreign jurisdictions, requiring subpoenas, court orders, or mutual legal assistance treaties (MLATs) to obtain legally.
Question 123: A forensic investigator finds that attacker requests used chunked transfer encoding with abnormal chunk sizes. What might this indicate?
- A legitimate compression technique
- Normal CDN behavior
- An HTTP/2 protocol upgrade
- An attempt to evade WAF/IDS signature detection by obfuscating the payload (Correct answer)
Correct answer: An attempt to evade WAF/IDS signature detection by obfuscating the payload
Attackers sometimes use chunked transfer encoding to split malicious payloads across chunks, evading WAF and IDS signatures that inspect full request bodies.
Question 124: What type of attack involves inserting malicious SQL code into a query to extract or manipulate database data, and is commonly investigated in CHFI database forensics?
- SQL injection (Correct answer)
- ARP poisoning
- Buffer overflow
- Cross-site scripting
Correct answer: SQL injection
SQL injection attacks insert malicious SQL statements into input fields to manipulate database queries, often leaving traces in web server logs and database logs.
Question 125: An investigator needs to analyze a suspect's smartphone without triggering remote wipe commands. What is the best immediate action?
- Power off the device immediately
- Remove the SIM card and place the phone in a Faraday bag (Correct answer)
- Connect it to a charger and begin extraction
- Update the device firmware for compatibility
Correct answer: Remove the SIM card and place the phone in a Faraday bag
Placing the device in a Faraday bag isolates it from all wireless signals, preventing remote wipe commands while preserving its powered state.
Question 126: During malware triage, an analyst finds a PE file whose .text section has an entropy value of 7.8 out of 8. This MOST likely indicates:
- The executable uses heavy compiler optimizations
- The code section is packed or encrypted (Correct answer)
- The file is a legitimate compiled binary
- The binary is a debug build with symbol tables
Correct answer: The code section is packed or encrypted
Entropy near 8.0 in a PE code section indicates highly randomized data, which is characteristic of packing, encryption, or compression applied to hide the true payload.
Question 127: During a Windows forensic investigation, an examiner identifies event ID 7045 in the System log. What does this event signify?
- A removable disk was safely removed from the system
- Windows Defender detected and quarantined malware
- A new service was installed on the system (Correct answer)
- A user account was locked out after repeated failed logon attempts
Correct answer: A new service was installed on the system
Event ID 7045 ('A new service was installed in the system') is a key indicator of malware or attacker persistence via malicious service installation.
Question 128: What is the purpose of the Volume Boot Record (VBR) in a disk partition?
- Holds the file allocation table
- Contains the bootstrap code to load the operating system for that partition (Correct answer)
- Stores the partition table for the disk
- Maps bad sectors on the disk
Correct answer: Contains the bootstrap code to load the operating system for that partition
The VBR resides at the first sector of each partition and contains bootstrap code that the MBR passes control to during boot.
Question 129: Which Windows artifact records information about recently executed programs including execution count and last run time, even after the program is deleted?
- Start menu entries
- Desktop shortcut .lnk files
- Recycle Bin metadata
- Prefetch files (Correct answer)
Correct answer: Prefetch files
Windows Prefetch files record details about recently executed programs including execution count and timestamps, providing evidence of program execution even after the program has been deleted.
Question 130: What is 'passive OS fingerprinting' in network forensics?
- Identifying operating systems by analyzing characteristics of traffic they generate without sending probes (Correct answer)
- Sending probe packets to determine a remote system's OS
- Scanning open ports to match known OS signatures
- Examining installed patches on a target system
Correct answer: Identifying operating systems by analyzing characteristics of traffic they generate without sending probes
Passive OS fingerprinting identifies remote operating systems by analyzing observable TCP/IP stack characteristics (TTL values, TCP window sizes, flag combinations) in captured traffic without generating any probe traffic.
Question 131: During an email forensics investigation, what does a missing or broken DMARC alignment indicate?
- The email was encrypted end-to-end
- The email may be a phishing attempt or spoofed to impersonate a legitimate domain (Correct answer)
- The email was sent via a mobile device
- The email server is overloaded
Correct answer: The email may be a phishing attempt or spoofed to impersonate a legitimate domain
Failed DMARC alignment indicates that SPF and/or DKIM checks failed, suggesting the email may be spoofed or sent by an unauthorized server impersonating the domain.
Question 132: Which RFC defines the format and structure of email messages and is important for email forensics?
- RFC 1918
- RFC 2616
- RFC 2822 (Correct answer)
- RFC 5321
Correct answer: RFC 2822
RFC 2822 defines the Internet Message Format, specifying how email headers and body content are structured.
Question 133: Which technique allows a forensic investigator to recover deleted rows from a SQL Server database without a backup?
- Schema comparison
- Log file analysis using transaction log parser (Correct answer)
- Index scan
- Full-text search
Correct answer: Log file analysis using transaction log parser
Deleted rows remain in the transaction log until the log is truncated, allowing forensic tools like ApexSQL Log to reconstruct and recover deleted data.
Question 134: What is the purpose of analyzing the 'Bcc' (Blind Carbon Copy) field in email forensics investigations?
- Bcc encrypts the email content
- Bcc is always visible in email headers and easy to read
- Bcc recipients are hidden from other recipients but may appear in server logs or sender's sent folder, revealing hidden communication parties (Correct answer)
- Bcc prevents the email from being forwarded
Correct answer: Bcc recipients are hidden from other recipients but may appear in server logs or sender's sent folder, revealing hidden communication parties
While Bcc recipients are invisible to To/Cc recipients, mail server logs, the sender's sent items, and mail server transaction logs may reveal who received Bcc copies.
Question 135: A ransomware sample generates a unique key per victim and sends it to a C2 server before encrypting files. If the C2 is taken down before the key is transmitted, what is the most likely forensic implication?
- Backup shadow copies will remain intact
- The encryption key is permanently lost
- The ransomware will fail to encrypt any files
- Decryption may be possible from memory artifacts (Correct answer)
Correct answer: Decryption may be possible from memory artifacts
If the key was generated in memory before transmission, forensic memory analysis may recover it from RAM dumps or hibernation files before it is overwritten.
Question 136: Which OWASP tool is specifically designed for intercepting and modifying HTTP/HTTPS traffic during web application security testing and forensic analysis?
- Metasploit
- OWASP ZAP (Zed Attack Proxy) (Correct answer)
- Maltego
- OpenVAS
Correct answer: OWASP ZAP (Zed Attack Proxy)
OWASP ZAP is an open-source web proxy tool used to intercept, inspect, and modify HTTP/HTTPS traffic for security testing and forensic purposes.
Question 137: Which of the following best describes the cloud deployment paradigm used for shared infrastructure between multiple enterprises with common concerns (security, compliance, jurisdiction, etc.)?
- Community Cloud (Correct answer)
- Hybrid Cloud
- Public Cloud
- Private Cloud
Correct answer: Community Cloud
A community cloud deployment model is designed for a specific community of organizations that share common concerns, such as security requirements, compliance regulations, or jurisdiction. It can be managed internally or by a third party and hosted either internally or externally. This model allows for shared infrastructure and resources while addressing the unique needs of the participating entities, offering a balance between public and private cloud benefits.
Question 138: During a post-incident forensic review, investigators find that logs were overwritten before collection. Which process failure does this represent?
- Failure to preserve volatile evidence in time
- Inadequate evidence identification (Correct answer)
- Lack of legal authorization
- Improper chain of custody
Correct answer: Inadequate evidence identification
Overwritten logs indicate a failure in the identification phase β critical evidence sources were not identified quickly enough for preservation.
Question 139: In email forensics, what does the 'X-Originating-IP' header reveal?
- The destination mail server IP
- The IP address of the client that originally submitted the email (Correct answer)
- The DNS server IP used for delivery
- The antivirus scanner IP
Correct answer: The IP address of the client that originally submitted the email
The X-Originating-IP header, added by some mail providers, records the IP address of the device that originally sent the email, which can identify the sender's location.
Question 140: An investigator is analyzing a Windows 10 system to determine which external storage devices have been previously connected. Which Registry hive and key would provide the most direct evidence of USB devices, including vendor and product IDs?
- HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\TypedURLs
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR (Correct answer)
- HKEY_LOCAL_MACHINE\SAM\Domains\Account\Users
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Correct answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR
The `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR` registry key is specifically designed to enumerate USB Mass Storage Devices that have been connected to the system. It contains subkeys for each unique device, which in turn store details like the device's vendor ID, product ID, and unique serial number.
Question 141: In database forensics, what information can be extracted from the MySQL ibdata1 file?
- Only index data
- InnoDB tablespace data including deleted records not yet purged (Correct answer)
- Only table schemas
- Only stored procedures
Correct answer: InnoDB tablespace data including deleted records not yet purged
The ibdata1 file is the InnoDB shared tablespace and contains table data, indexes, and potentially deleted records that have not yet been purged by InnoDB's background purge process.
Question 142: In CHFI investigations of web attacks, what is the PRIMARY purpose of hashing web server log files upon collection?
- To encrypt the logs from unauthorized access
- To compress the logs for storage efficiency
- To index the logs for faster searching
- To ensure the integrity of log evidence and detect any post-collection tampering (Correct answer)
Correct answer: To ensure the integrity of log evidence and detect any post-collection tampering
Hashing log files (e.g., with SHA-256) at the time of collection creates a verifiable integrity record, proving the evidence has not been altered since acquisition.
Question 143: During a database forensics investigation, an investigator finds rows in a SQL Server table with no matching audit records. What should be checked first?
- The transaction log for direct inserts (Correct answer)
- DNS logs
- Firewall logs
- Application event logs
Correct answer: The transaction log for direct inserts
Direct inserts bypassing the application layer appear in the transaction log even if application-level audit triggers did not fire.
Question 144: During memory forensics with Volatility, which plugin would BEST detect a userland rootkit that has unlinked a process from the EPROCESS doubly linked list?
- cmdline
- pslist
- dlllist
- psscan (Correct answer)
Correct answer: psscan
psscan scans raw memory pools for EPROCESS structures rather than walking the linked list, so it finds processes hidden by DKOM that have been unlinked from the list.
Question 145: Which network forensics artifact would best help an investigator determine the exact time a specific external IP address first communicated with an internal host?
- ARP cache entries
- SNMP trap logs
- Routing table entries
- Firewall log timestamps for the first allowed session (Correct answer)
Correct answer: Firewall log timestamps for the first allowed session
Firewall logs record timestamped allow/deny decisions for every connection attempt, providing the most reliable record of when external communication with an internal host first occurred.
Question 146: Which database format stores the majority of application data, call logs, and messages on both iOS and Android devices?
- SQLite (Correct answer)
- XML
- JSON
- LevelDB
Correct answer: SQLite
SQLite is the primary relational database engine used by mobile operating systems to store structured application data.
Question 147: Which of the following best describes the primary goal of performing reverse engineering on a malware sample during a forensic investigation?
- To understand the malware's precise functionality, algorithms, and capabilities by analyzing its disassembled code. (Correct answer)
- To determine the date and time the malware was compiled by the author.
- To safely execute the malware in a sandbox to observe its network traffic.
- To create a valid cryptographic hash of the malicious file for an IOC database.
Correct answer: To understand the malware's precise functionality, algorithms, and capabilities by analyzing its disassembled code.
Reverse engineering involves disassembling or decompiling a binary to analyze its assembly code. The ultimate goal is to understand exactly what the program does, how its algorithms work (e.g., encryption routines, C2 communication protocols), and what its full capabilities are. This provides a much deeper understanding than static or dynamic analysis alone.
Question 148: Which Windows artifact stores the last 10 commands typed into the Run dialog box and is found in the registry?
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU (Correct answer)
- HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
- HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit
Correct answer: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
The RunMRU key stores the most recently used commands typed into the Run dialog, useful for tracking attacker activity.
Question 149: Which Volatility 3 plugin would an investigator use to extract network connections (including those in CLOSE_WAIT and TIME_WAIT states) from a Windows memory image?
- windows.netstat
- windows.connections
- windows.netscan (Correct answer)
- windows.sockets
Correct answer: windows.netscan
windows.netscan scans memory pools for network structures and recovers connections in various TCP states including those that windows.netstat would miss.
Question 150: When performing a forensic hash verification of a disk image, which combination of algorithms is considered best practice to minimize collision risk?
- CRC32 and Adler-32
- MD5 and SHA-256 together (Correct answer)
- Base64 encoding of MD5
- SHA-1 only
Correct answer: MD5 and SHA-256 together
Using both MD5 (for legacy compatibility) and SHA-256 (for cryptographic strength) together minimizes the risk of an undetected collision or tampering in forensic evidence.
Question 151: When analyzing a suspect's network traffic, an investigator observes large ICMP packets with payloads containing structured data. This suggests:
- ICMP tunneling for covert data exfiltration (Correct answer)
- Fragmentation reassembly issues
- IPv6 transition mechanism
- Normal network diagnostics
Correct answer: ICMP tunneling for covert data exfiltration
ICMP tunneling embeds data inside ICMP echo request/reply payloads, exploiting protocols often allowed through firewalls to create a covert communication channel.
EC-Council CHFI (312-49) Certification Exam
The EC-Council Computer Hacking Forensic Investigator (CHFI) v11 certification validates professionals in detecting cyberattacks, extracting digital evidence, and reporting cybercrime findings for legal proceedings.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds