Forensic Analysis Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Forensic Analysis flashcards as text
A forensic analyst is examining a Windows system and needs to determine which processes were running at the time of an incident. Which artifact best preserves this volatile data?
Answer: Hibernation file (hiberfil.sys)
The hibernation file (hiberfil.sys) captures a snapshot of RAM contents including running processes when the system hibernates.
During a memory forensics investigation, an analyst finds a process with no parent process ID and no associated executable on disk. This is MOST likely indicative of:
Answer: A kernel-mode rootkit hiding the process
A kernel-mode rootkit can manipulate process structures in memory to hide its presence, including unlinking from process lists and removing disk artifacts.
Which file system artifact on NTFS records the last 26 characters typed into the Windows Run dialog, even after a user clears the run history?
Answer: Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
The RunMRU registry key stores the most recently used commands entered in the Windows Run dialog and persists until explicitly deleted.
A forensic examiner must analyze a disk image without altering it. Which command correctly mounts the image as read-only on Linux?
Answer: mount -o ro,loop disk.img /mnt/evidence
The `-o ro,loop` flags mount the image as read-only using a loop device, preserving forensic integrity.
When analyzing network packet captures during an incident, an analyst notices large DNS TXT record responses to an unusual external domain at regular intervals. This MOST likely indicates:
Answer: DNS tunneling used for data exfiltration or C2
DNS tunneling encodes data in DNS TXT queries/responses to bypass firewalls, and regular large TXT responses to unusual domains are a strong indicator.
A forensic analyst is reviewing Windows Security event logs and sees Event ID 4624 with Logon Type 3 from an external IP. What does this indicate?
Answer: A network logon, such as accessing a shared folder
Logon Type 3 in Windows Security Event 4624 indicates a network logon, typically used for accessing shared resources over SMB.
Which hashing algorithm is MOST appropriate for generating forensic integrity checksums of evidence files today, given known weaknesses in older algorithms?
Answer: SHA-256
SHA-256 is the recommended standard for forensic hashing as MD5 and SHA-1 have known collision vulnerabilities that could undermine evidence integrity.