โ† All CHFI Flashcard Decks

General Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 General flashcards as text
  1. Which Windows registry hive stores user-specific settings and is critical for forensic investigations of user activity?

    Answer: HKEY_CURRENT_USER

    HKEY_CURRENT_USER (backed by the NTUSER.DAT hive) stores settings and activity data specific to the logged-in user.

  2. In network forensics, what does the term 'full packet capture' refer to?

    Answer: Recording complete network packet content including payloads

    Full packet capture records entire network packets, including headers and payload data, enabling comprehensive traffic reconstruction.

  3. What is the significance of the MFT (Master File Table) in NTFS forensics?

    Answer: It contains metadata for every file and directory on the volume

    The MFT is the core database of an NTFS volume, containing attributes including timestamps, file size, and data location for every object.

  4. Which anti-forensic technique involves hiding data within ordinary-looking files such as images or audio?

    Answer: Steganography

    Steganography conceals secret data within innocuous carrier files, making detection challenging without specialized tools.

  5. What is the purpose of the 'dd' command in Unix-based forensic investigations?

    Answer: To create a bit-for-bit image of a storage device

    The dd command copies data at the bit level, enabling forensic duplication of drives while preserving every byte including deleted data.

  6. Which artifact found on Windows systems records recently accessed files and application launch history?

    Answer: Prefetch files

    Windows Prefetch files cache application launch data to speed startup and record execution timestamps and file access patterns.

  7. In the context of CHFI investigations, what does the term 'volatile data' refer to?

    Answer: Data that exists only while a system is powered on and is lost at shutdown

    Volatile data resides in RAM, CPU registers, and running processes, and is immediately lost when the system is powered off.