โ† All CHFI Flashcard Decks

General MCQ Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 General MCQ flashcards as text
  1. Which artifact on a Windows system records the first and last execution time of applications along with a run count?

    Answer: Registry UserAssist key

    The UserAssist registry key in HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist records application execution counts and timestamps in ROT13-encoded format.

  2. What is the role of the 'slack space' in a forensic disk investigation?

    Answer: Space between end of a file and end of its last cluster

    File slack space is the area between the logical end of a file and the end of the last cluster allocated to it, which may contain remnant data.

  3. A CHFI investigator discovers an encrypted TrueCrypt/VeraCrypt container. Which approach is legally and forensically sound?

    Answer: Image the container and attempt password attacks in a lab environment

    The correct approach is to image the encrypted container and perform password/brute-force attacks against the copy in a controlled lab to avoid altering the original.

  4. Which Windows artifact is a binary file created by the OS to speed up application launches and can reveal execution history?

    Answer: Prefetch files (.pf)

    Prefetch files (.pf) are created by Windows to speed up application loading and contain metadata about the last run times and file paths accessed.

  5. During cloud forensics, which type of data is most difficult to acquire due to multi-tenancy and shared infrastructure?

    Answer: RAM and live memory of running cloud instances

    Live memory of cloud instances is extremely difficult to acquire forensically due to shared physical hardware, hypervisor isolation, and lack of investigator access to the host.

  6. What does the 'first responder' rule state regarding digital evidence at a crime scene?

    Answer: The first responder should document the scene before touching any device

    The first responder must photograph, sketch, and document the scene and device states before any evidence is collected or altered.

  7. Which anti-forensic technique involves overwriting free disk space with random data to prevent recovery of deleted files?

    Answer: Disk wiping / secure erase

    Disk wiping overwrites free space with random or zero data patterns to prevent forensic recovery of previously deleted files.