312-49V11: Computer Hacking Forensic Investigator Practice Exam
QuestionQ1
Procedures and Methodology
Save question
During an investigation into a high-profile cybercrime case, a law enforcement agency recognized a need for specialized computer forensic investigators. Its general forensic investigators were having difficulty meeting the particular demands of computer forensics. Although the agency considered hiring external forensic investigators, it rejected that option because of budget constraints. What could be a potential solution to this situation?
ATraining their current investigators in computer forensics.
BOutsourcing the investigations to a private firm.
CInvesting in advanced forensic tools to assist their current investigators.
DCollaborating with international law enforcement agencies for assistance.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Tools/Systems/Programs
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Regulations, Policies and Ethics
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Procedures and Methodology
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Procedures and Methodology
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Forensic ScienceRegulations, Policies and EthicsDigital EvidenceProcedures and MethodologyDigital Forensics ReviewLogs and Network ForensicsTools/Systems/Programs
Liam, a digital forensic investigator, is analyzing evidence from a cyberattack that targeted a Linux-based system. During his analysis, he finds that several files are missing. On further examination, he observes that a particular executable file, which was running at the time of the attack, erased its own contents, making recovery more difficult. To retrieve the lost file, Liam must identify the correct Linux command that would help recover it. Which of the following commands should Liam use to recover the lost file on the Linux system?
Acp /proc/$PID/exe /tmp/file
Bcd C:\RECYCLER\S-..User SID
CD<#>.
D$R<#>.
In exceptional circumstances, when a person considers it necessary to access original data held on a computer or storage media, that person must be competent to do so and able to explain, in court, his/her actions and their impact on the evidence. Which ACPO principle states this?
APrinciple 1
BPrinciple 2
CPrinciple 3
DPrinciple 4
Charlotte, a cloud administrator, manages the cloud infrastructure for a production environment. While reviewing logs from an Amazon EC2 instance, she detects unusual activity that may indicate a security breach. The logs reveal abnormal behavior, including multiple failed login attempts, unusual traffic patterns, and unauthorized access to sensitive data on the instance. Concerned about the attack’s possible impact on other instances in the environment, Charlotte recognizes that she must act rapidly to keep the breach from escalating. She wants to contain the incident’s spread and ensure that other resources in the environment are unaffected. In this situation, what should Charlotte do first during forensic acquisition of the EC2 instance?
AIsolate the compromised EC2 instance
BTake a snapshot of the EC2 instance
CProvision and launch a forensic workstation
DAttach the evidence volume to the forensic workstation
Sarah, a CHFI investigator, is assigned to a case involving possible child-exploitation material being distributed through a private network. A concerned citizen located the network and reported it to the authorities. Sarah’s role is to investigate and collect evidence from this network without breaching any laws or regulations. Given the sensitivity of the case and the possibility of severe penalties for those involved, Sarah must make sure the evidence she gathers will withstand scrutiny in court. What should Sarah do first in this investigation?
AObtain a search warrant based on the initial report to legally collect evidence from the network
BAccess the network covertly to gather evidence without alerting suspects
CMonitor network traffic to identify potential suspects
DLeverage social engineering tactics to infiltrate the network and identify the users involved
QuestionQ6
Logs and Network Forensics
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Forensic Science
QuestionQ8
Logs and Network Forensics
QuestionQ9
Tools/Systems/Programs
QuestionQ10
Tools/Systems/Programs
QuestionQ11
Regulations, Policies and Ethics
QuestionQ12
Regulations, Policies and Ethics
QuestionQ13
Regulations, Policies and Ethics
QuestionQ14
Regulations, Policies and Ethics
QuestionQ15
Tools/Systems/Programs
QuestionQ16
Procedures and Methodology
QuestionQ17
Regulations, Policies and Ethics
QuestionQ19
Digital Evidence
QuestionQ20
Digital Evidence
QuestionQ21
Procedures and Methodology
QuestionQ22
Procedures and Methodology
QuestionQ23
Procedures and Methodology
QuestionQ24
Procedures and Methodology
QuestionQ25
Digital Evidence
QuestionQ26
Procedures and Methodology
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A medium-sized company’s IT department observed a sudden increase in network traffic and unusual DNS requests coming from its internal servers. Suspecting a malware attack, they brought in Lisa, an experienced forensic investigator, to investigate. Lisa wants to use a tool to analyze this abnormal network activity, with particular emphasis on monitoring DNS requests. Which tool should she use?
ASnort
BWireshark
CNmap
DNessus
A system administrator configures a new storage array for a critical application and chooses a RAID level that uses data striping with dedicated parity. The RAID configuration requires at least three disks and stripes data at the byte level across multiple drives, with one drive reserved for parity information to provide fault tolerance. After setting up the RAID system, the administrator tests tolerance for a single-drive failure and confirms that the system can continue operating without data loss. Which RAID level is the system administrator using?
ARAID 10
BRAID 1
CRAID 3
DRAID 0
A suspect is accused of violating the acceptable-use policy for computing resources because he visited adult websites and downloaded images. The investigator wants to show that the suspect did visit those sites. However, the suspect has cleared the search history, emptied the cookie cache, and removed any images he may have downloaded. What can the investigator do to prove the violation?
AImage the disk and try to recover deleted files
BSeek the help of co-workers who are eye-witnesses
CCheck the Windows registry for connection data (you may or may not recover)
DApproach the website's administrator for evidence
While collecting Active Transaction Logs in SQL Server Management Studio, the query Select * from ::fn_dblog(NULL, NULL) displays the active part of the transaction log file. In this context, what does assigning NULL values imply?
AStart and end points for log sequence numbers are specified
BStart and end points for log files are not specified
CStart and end points for log files are specified
DStart and end points for log sequence numbers are not specified
Robert is a regional manager at a reputed organization. One day, he suspects a malware attack after unwanted programs begin popping up when he logs in to his computer. The network administrator is called to trace any intrusion on the computer and finds that suspicious activity has occurred within Autostart locations. In this situation, which of the following tools does the network administrator use to detect an intrusion on a system?
AHex Editor
BInternet Evidence Finder
CProcess Monitor
DReport Viewer
An expert witness is a __________________ who is usually appointed by a party to help formulate and prepare that party’s claim or defense.
AExpert in criminal investigation
BSubject matter specialist
CWitness present at the crime scene
DExpert law graduate appointed by attorney
Identify the term for individuals who, because of their knowledge and expertise, give an independent opinion on a case-related matter using the information provided.
AExpert Witness
BEvidence Examiner
CForensic Examiner
DDefense Witness
A regional bank operating in several cities recently found account-balance discrepancies during routine audits. The issues appeared across multiple branches, leading to an internal investigation. Further analysis revealed that an individual with prior authorization had changed financial records. The investigation determined that a former employee, whose credentials were not deactivated after departing the company, retained full control of critical systems. This lapse enabled the person to alter transactional data, resulting in inaccurate financial reports and possible damage to the bank’s reputation. The former employee’s changes were deliberate and affected customer accounts. Although the individual was no longer employed, the failure to revoke their permissions allowed these changes to happen without barriers. Which cybercrime classification best fits this incident?
AAn abuse of role-based access from within the network.
BAn authentication flaw due to expired password policies.
CAn impersonation attempt using credential stuffing techniques.
DA breach caused by external actors bypassing firewalls.
In a corporate setting, a senior executive’s Android smartphone is secured for an internal forensic review after signs of unauthorized data access. The inquiry is administrative, and the executive remains available to help with the investigation. A passcode protects the device, preventing immediate access to possible evidence. Investigators must gain access without modifying existing data or using escalated technical measures. To proceed lawfully while preserving evidential integrity, which approach is most appropriate?
AUtilize Android-specific forensic software for a compliant brute-force passcode attack, systematically guessing combinations to access data while adhering to legal and ethical standards.
BRequest management approval for physical device acquisition using specialized tools, ensuring data access without compromising evidence integrity.
CUse remote MDM software to reset device passcode, enabling data access while maintaining evidence integrity.
DSeek employee’s cooperation for voluntary passcode disclosure, ensuring lawful data access without compromising investigation integrity.
You are a forensic analyst investigating a possible cyberattack on a bank’s network. You have been given an image of the suspected machine for examination. To ensure a thorough investigation, you chose Autopsy for file-system analysis. However, the image is huge, and manually sifting through the data could take weeks. Which Autopsy feature can be used to speed up the analysis process?
AFile carving
BKeyword search
CTimeline analysis
DImage mounting
Liam, a forensic investigator, was investigating an unusual internet-banking transaction that occurred on a financial manager’s system. The manager confirmed that no unauthorized person had physically accessed the device, causing Liam to suspect remote-access involvement. To identify the perpetrator, Liam captured network traffic to analyze the network activities related to the transaction. Which phase of a wireless network forensic investigation is Liam performing?
AIdentify active connections
BDetect rogue/malicious access points
CDiscover wireless access points
DSniff and analyze packets
This refers to a statement, other than one made by the declarant while testifying at the trial or hearing, that is offered in evidence to establish the truth of the matter asserted. Which of the following is appropriate for the statement above?
ARule 1001
BTestimony by the accused
CHearsay rule
DLimited admissibility
A call detail record (CDR) supplies metadata about calls made through a phone service. Which of the following data fields is not included in a CDR?
AA unique sequence number identifying the record
BThe call duration
CPhone number receiving the call
DThe language of the call
An organization is investigating a series of cyberattacks that appear to originate from a prominent hacker collective. The attacks seem highly coordinated and employ advanced malware, with command-and-control infrastructure resembling that of an organization pursuing a specific geopolitical agenda. However, investigators suspect the attackers may be using tools to imitate the collective’s established tactics and conceal their real identity. Which attribution challenge is the organization most likely encountering?
AThe attackers using false-flag methods to impersonate those of a known group.
BThe inability to access technical indicators such as malware signatures or command-and-control infrastructure.
CThe lack of cooperation from the attacker’s country, making it difficult to investigate cross-border activities.
DThe difficulty in identifying geopolitical motivations behind the attacks.
Which phase of the Computer Forensics Investigation Process includes planning and budgeting for a forensics lab?
APost-investigation Phase
BReporting Phase
CPre-investigation Phase
DInvestigation Phase
You are conducting a forensic investigation of a suspected data-exfiltration incident at a multinational corporation. During the investigation, you encounter several seemingly unrelated incidents across multiple systems in different regions of the world. To understand these incidents and determine whether they may be connected, which approach should you use?
AConducting a separate investigation for each incident
BRedoing the entire investigation from scratch
CPerforming a deep dive analysis of the most severe incident
DUsing event correlation to find a link between the incidents
An investigator is performing a forensic analysis of a suspect’s Microsoft Outlook account. The investigator determines that the suspect’s emails are kept in both .pst (Personal Storage Table) and .ost (Offline Storage Table) files. Because the .ost file is mainly used for offline email access in IMAP, Exchange, or Outlook.com accounts, the investigator must determine the suitable method for acquiring and analyzing the data in these files. The investigator is especially focused on examining the .ost file for email evidence.
Which of the following actions should the investigator take to properly acquire the email data from the .ost file?
AConvert the .ost file to a .pst file using Kernel for OST to PST or similar tools.
BOpen the .ost file with a text editor to view the raw data.
COnly analyze the .pst file, as the .ost file is not used for email storage.
DDirectly extract the email messages from the .ost file using SysTools MailPro+.
Sophia, a forensic investigator, is working on a major corporate data-theft case. The suspect, an IT employee, allegedly downloaded hundreds of confidential files to his laptop before abruptly resigning. Sophia obtained a search-and-seizure warrant and, while executing it, found the suspect’s laptop, a desktop computer, and several storage devices.
To maintain the chain of custody and comply with the ACPO principles of digital evidence, what should she do next?
AShe should immediately begin analyzing the digital devices on-site.
BShe should ask the suspect for the passwords to the devices to expedite the investigation.
CShe should only seize the personal laptop as per the information on the warrant.
DShe should seize all the devices and send them to a forensic lab for analysis.
Following a recent security incident at a popular online retail store, an incident response team is investigating. They determined that an attacker made thousands of purchase attempts using varying combinations of credit card information in only a few minutes. The team also found that the same IP address was responsible for every transaction. As a computer hacking forensic investigator, which attack type is most likely involved?
ACookie Poisoning attack.
BBrute Force attack.
CParameter Tampering attack.
DXML External Entity (XXE) attack.
A security research team is building a dedicated malware-analysis testbed. The team makes sure the testing environment is isolated from the functional network, so malware cannot affect business operations. The testbed contains virtual machines, victim machines with varying configurations (patched and unpatched), and required tools such as imaging tools, file-analysis tools, and network-capture tools.
What is the primary advantage of using a sandbox environment in the malware-analysis lab?
AThe sandbox isolates malware from the external network but does not impact malware execution.
BThe sandbox ensures all virtual machines are updated with the latest security patches before testing.
CThe sandbox allows malware to execute in a controlled setting without risking network-wide infection.
DThe sandbox enables malware to access the functional network for testing propagation.
Community Discussion