← All CHFI Flashcard Decks

General MCQ Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 General MCQ flashcards as text
  1. In the context of email forensics, which header field reveals the originating IP address of the sender's mail client?

    Answer: Received:

    The 'Received:' header chain in an email message traces the path of the message and typically includes the originating IP address of the sending client.

  2. Which forensic framework provides a Python-based API for analyzing memory dumps, including support for Windows, Linux, and macOS profiles?

    Answer: Volatility

    Volatility is an open-source memory forensics framework with a plugin-based architecture for analyzing RAM dumps across multiple operating systems.

  3. An investigator needs to prove that a forensic image is an exact copy of the original drive. Which two hash values are typically computed and compared?

    Answer: MD5 and SHA-1

    MD5 and SHA-1 are the two hash algorithms most commonly used together in forensic tools like FTK Imager to verify image integrity.

  4. What is a 'dead-box' forensic examination?

    Answer: Forensic analysis of a powered-off device using an acquired image

    Dead-box forensics refers to examining a device that has been powered off, typically through analysis of a forensic disk image.

  5. Which artifact in Windows records recently opened files and folders and is used by the system to populate the 'Recent Items' list?

    Answer: LNK (shortcut) files

    LNK (shortcut) files are automatically created in the Recent Items folder and record metadata about files recently opened, including original file path and timestamps.

  6. During a network intrusion investigation, a forensic analyst captures packets and finds large amounts of DNS TXT record queries with encoded payloads. What attack technique does this suggest?

    Answer: DNS tunneling

    DNS tunneling encodes data within DNS query and response records (often TXT records) to covertly exfiltrate data or establish C2 communication.

  7. Under the US Federal Rules of Evidence, for digital evidence to be admissible it must meet which foundational requirement?

    Answer: It must be authenticated — shown to be what it is claimed to be

    Under FRE Rule 901, digital evidence must be authenticated, meaning the proponent must produce evidence sufficient to support a finding that the item is what it is claimed to be.