โ† All CHFI Flashcard Decks

Anti-Forensics Techniques Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Anti-Forensics Techniques flashcards as text
  1. What is the primary goal of anti-forensics techniques?

    Answer: To prevent, destroy, or obfuscate digital evidence

    Anti-forensics techniques are designed to prevent, destroy, or obfuscate digital evidence to hinder forensic investigations and avoid attribution.

  2. Which technique involves overwriting storage media multiple times with random data patterns to prevent file recovery?

    Answer: Secure wiping (data sanitization)

    Secure wiping overwrites storage media multiple times with random data patterns, making the original data unrecoverable even with advanced forensic tools.

  3. What does 'timestomping' refer to in anti-forensics?

    Answer: Modifying file metadata timestamps to mislead timeline analysis

    Timestomping involves modifying a file's MAC (Modified, Accessed, Created) timestamps to mislead forensic investigators about when events occurred.

  4. Which of the following is a commonly used Windows tool for secure file deletion that supports multiple overwrite passes?

    Answer: Eraser

    Eraser is a widely used Windows tool that performs secure file deletion by overwriting files with multiple passes of random data, making recovery infeasible.

  5. What does steganography refer to in the context of anti-forensics?

    Answer: Hiding data within other seemingly innocent files such as images or audio

    Steganography involves hiding secret data within ordinary files like images, audio, or video so that the existence of the hidden data is concealed from investigators.

  6. What is the anti-forensics purpose of exploiting Alternate Data Streams (ADS) in NTFS?

    Answer: To hide data within NTFS file metadata, invisible to standard directory listings

    Alternate Data Streams (ADS) is an NTFS feature that allows data to be attached to a file's metadata stream, making it invisible to standard directory listings and many forensic tools.

  7. Which anti-forensics technique involves routing network traffic through multiple anonymizing proxies or Tor to conceal an attacker's true IP address?

    Answer: Trail obfuscation

    Trail obfuscation involves using proxies, VPNs, or Tor to hide the true origin of network activity, making it difficult for investigators to trace actions back to the attacker.