Anti-Forensics Techniques Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Anti-Forensics Techniques flashcards as text
Which US Department of Defense standard specifies a data sanitization method using multiple overwrite passes with specific data patterns?
Answer: DoD 5220.22-M
The DoD 5220.22-M standard specifies a data sanitization method with multiple overwrite passes using defined patterns, widely implemented in secure wiping tools.
What is the forensic significance of 'slack space' that makes it relevant to anti-forensics investigations?
Answer: It is the unused space between the end of a file and the end of its allocated cluster that may contain remnant data
Slack space is the unused portion between the end of a file and the end of its allocated storage cluster, which may retain remnant data from previously stored files.
Which anti-forensics technique involves modifying or deleting system log files to erase evidence of an attacker's activities?
Answer: Log tampering (log sanitization)
Log tampering involves modifying or deleting system, application, or security log files to erase records of an attacker's actions and prevent forensic reconstruction of events.
What is a rootkit in the context of anti-forensics?
Answer: Malware that hides its presence and other malicious activity from the OS and forensic tools
A rootkit is malicious software designed to hide its own presence and the presence of other malware from the operating system, security software, and forensic investigation tools.
Which open-source full disk encryption tool is considered a major challenge for digital forensic investigators due to its strong encryption?
Answer: VeraCrypt
VeraCrypt provides strong full-disk or volume encryption that makes encrypted data completely inaccessible without the correct passphrase or key, presenting a significant obstacle to forensic access.
Which anti-forensics technique involves an attacker deliberately planting false digital evidence to mislead forensic investigators?
Answer: Evidence fabrication (anti-forensic deception)
Evidence fabrication involves planting false or misleading digital artifacts to confuse investigators, waste forensic resources, or frame innocent parties for the crime.
Which Windows artifact records information about recently executed programs including execution count and last run time, even after the program is deleted?
Answer: Prefetch files
Windows Prefetch files record details about recently executed programs including execution count and timestamps, providing evidence of program execution even after the program has been deleted.