โ† All CHFI Flashcard Decks

General Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 General flashcards as text
  1. Which hashing algorithm is commonly used in CHFI to verify the integrity of forensic disk images?

    Answer: MD5 or SHA-1

    MD5 and SHA-1 (or SHA-256) hashes are computed before and after acquisition to confirm the image is an exact copy of the original media.

  2. What type of investigation focuses on analyzing employee misconduct, policy violations, or internal fraud within an organization?

    Answer: Corporate/internal forensics

    Corporate or internal forensics deals with workplace investigations such as data theft, insider threats, and HR policy violations.

  3. Which law in the US specifically addresses unauthorized access to computer systems and is frequently cited in cybercrime investigations?

    Answer: Computer Fraud and Abuse Act (CFAA)

    The CFAA criminalizes unauthorized access to protected computers and is the primary federal statute used in computer crime prosecutions.

  4. What is a 'dead box' forensic examination?

    Answer: Forensic analysis of a powered-off system using an external boot device

    Dead box forensics involves examining a system that has been powered off, typically by booting from forensic media to access the drive.

  5. Which tool is widely used by CHFI investigators for comprehensive disk imaging and forensic analysis on Windows systems?

    Answer: FTK (Forensic Toolkit)

    FTK by AccessData is a comprehensive forensic platform supporting disk imaging, file analysis, password cracking, and evidence management.

  6. What is the role of a 'first responder' at a digital crime scene?

    Answer: To secure the scene, document initial state, and preserve volatile data

    The first responder must secure the scene, prevent evidence tampering, document the environment, and capture volatile data before shutdown.

  7. In mobile device forensics, what does 'logical acquisition' refer to?

    Answer: Extracting data through the device's OS via standard interfaces like USB or Bluetooth

    Logical acquisition extracts data accessible via the operating system's APIs, yielding files and databases but potentially missing deleted data.