Certified Computer Examiner (CCE) — Questions and Answers
Question 1: How frequently should ongoing assessments be conducted in Certified Computer Examiner?
- Only when audited
- At regular intervals and when conditions change (Correct answer)
- Once annually
- Only when problems are reported
Correct answer: At regular intervals and when conditions change
Both scheduled intervals and situational triggers ensure continuous monitoring.
Question 2: During evidence collection at a business, the examiner discovers the primary suspect's workstation is connected to a RAID array. How should the RAID array be handled?
- Power off the RAID array immediately and seize only the drives without documentation
- Leave the RAID array in place and only image the suspect's workstation
- Document the RAID configuration and controller settings before disassembly, then image individually (Correct answer)
- Image each individual drive separately without documenting the RAID configuration
Correct answer: Document the RAID configuration and controller settings before disassembly, then image individually
RAID configuration details (type, stripe size, drive order) must be documented before disassembly because this information is needed to reconstruct the logical volume from individual drive images.
Question 3: What does the acronym 'MACB' refer to in NTFS timestamp analysis?
- Modified, Archived, Created, Backed-up
- Modified, Accessed, Changed, Born (Correct answer)
- Master, Attributed, Cached, Backed-up
- Metadata, Allocation, Checksum, Backup
Correct answer: Modified, Accessed, Changed, Born
MACB stands for Modified, Accessed, Changed (MFT entry changed), and Born (created), representing the four timestamps stored in NTFS MFT entries for each file.
Question 4: In a forensic investigation involving an SSD, why is traditional file recovery often less successful than with HDDs?
- SSDs compress all data before writing
- SSDs use proprietary encryption by default
- The TRIM command allows the OS to zero out deleted data blocks proactively (Correct answer)
- SSD sectors are too small for standard carving tools
Correct answer: The TRIM command allows the OS to zero out deleted data blocks proactively
The TRIM command notifies the SSD controller that deleted blocks can be wiped immediately, causing the underlying data to be erased before forensic recovery is attempted.
Question 5: How should Certified Computer Examiner professionals handle updated procedures?
- Apply only to new cases
- Review updates, complete training, implement revisions (Correct answer)
- Continue original method
- Wait for enforcement
Correct answer: Review updates, complete training, implement revisions
Staying current with procedural updates is a professional obligation.
Question 6: Which factor MOST affects quality of CCE technical outcomes?
- Time of day
- Speed of completion
- Practitioner's training, preparation, and attention to detail (Correct answer)
- Equipment brand
Correct answer: Practitioner's training, preparation, and attention to detail
The practitioner's competence is the most significant factor.
Question 7: An investigator observes a large volume of outbound DNS queries to randomly generated domain names. This pattern most likely indicates:
- A misconfigured DHCP server
- Normal recursive DNS resolution
- Domain Generation Algorithm (DGA) malware activity (Correct answer)
- An NTP amplification attack
Correct answer: Domain Generation Algorithm (DGA) malware activity
Domain Generation Algorithms (DGAs) are used by malware to generate pseudo-random domain names to contact command-and-control servers while evading blacklists.
Question 8: In mobile forensics, what does a 'logical extraction' of an Android device typically capture?
- SIM card raw data
- Files accessible through the Android backup protocol or ADB (Correct answer)
- Baseband processor firmware
- Raw NAND flash chip data
Correct answer: Files accessible through the Android backup protocol or ADB
Logical extraction uses Android Debug Bridge (ADB) or backup protocols to copy accessible files and databases without raw flash access.
Question 9: What is the maximum file size supported by the FAT32 file system?
- 16 TB
- 2 GB
- 4 GB minus 1 byte (Correct answer)
- 8 GB
Correct answer: 4 GB minus 1 byte
FAT32 uses a 32-bit file size field, which allows a maximum file size of 4,294,967,295 bytes (4 GB – 1 byte).
Question 10: Which of the following file carving signatures correctly identifies the start of a JPEG file?
- 25 50 44 46
- FF D8 FF (Correct answer)
- 50 4B 03 04
- 89 50 4E 47
Correct answer: FF D8 FF
JPEG files begin with the magic bytes FF D8 FF, which represent the Start of Image (SOI) marker used to identify JPEG/JFIF data.
Question 11: When using FTK Imager to acquire a live system, which artifact is most critical to capture before shutting down the machine?
- Browser cache
- Hibernation file
- Windows registry hives
- Volatile RAM contents (Correct answer)
Correct answer: Volatile RAM contents
Volatile RAM contains active processes, network connections, encryption keys, and running malware that are lost upon shutdown.
Question 12: Which action could compromise the admissibility of digital evidence in court?
- Creating an exact forensic image
- Documenting every step
- Failing to use a write blocker (Correct answer)
- Using a certified forensic tool
Correct answer: Failing to use a write blocker
Failing to use a write blocker is a critical error that can compromise the integrity of digital evidence. Without a write blocker, the forensic examiner's actions could inadvertently alter the suspect drive's contents, such as updating access times or creating temporary files. This alteration could lead to the evidence being deemed inadmissible in court, as its authenticity cannot be guaranteed.
Question 13: What tool would a CCE examiner use to examine strings embedded in a malware binary without executing it?
- The 'strings' utility or BinText (Correct answer)
- Volatility
- Autopsy
- Wireshark
Correct answer: The 'strings' utility or BinText
The 'strings' command-line utility or tools like BinText extract printable character sequences from a binary, often revealing URLs, registry keys, and function names.
Question 14: In ext4 forensics, what data structure plays a role analogous to the NTFS MFT record?
- Journal
- Block Group Descriptor
- Inode (Correct answer)
- Superblock
Correct answer: Inode
An inode in ext4 stores file metadata (permissions, timestamps, size, and block pointers) for each file or directory, similar to an MFT record in NTFS.
Question 15: Which file system is commonly used by Windows operating systems?
- NTFS (Correct answer)
- HFS+
- EXT4
- APFS
Correct answer: NTFS
NTFS (New Technology File System) is the default and most commonly used file system for Microsoft Windows operating systems. It offers advanced features compared to older file systems, including improved security, journaling for data integrity, support for large files and volumes, and robust data recovery capabilities.
Question 16: During evidence collection, an examiner discovers the suspect's laptop has full disk encryption enabled and is currently powered on. What is the recommended action?
- Immediately power off the device to prevent data destruction
- Submit the device to the lab without any on-site action
- Remove the hard drive and use a hardware decryption tool
- Perform a live acquisition before shutting down (Correct answer)
Correct answer: Perform a live acquisition before shutting down
When an encrypted device is powered on and unlocked, a live acquisition should be performed to capture the decrypted data before the device is shut down and encryption re-engages.
Question 17: What Windows file system feature can store alternate versions of a file's $DATA attribute under a different name, sometimes used to hide data?
- Sparse files
- Symbolic links
- Reparse points
- Alternate Data Streams (Correct answer)
Correct answer: Alternate Data Streams
NTFS Alternate Data Streams (ADS) allow additional data to be associated with a file under a colon-separated name (e.g., file.txt:hidden), which is invisible in standard directory listings.
Question 18: A forensic examiner is analyzing a disk and finds that the first sector of a partition contains 'EB 52 90 4E 54 46 53'. What does this indicate?
- The partition uses FAT32
- The partition uses NTFS (Correct answer)
- The partition is unformatted
- The sector is a GPT header
Correct answer: The partition uses NTFS
'EB 52 90' is the x86 jump instruction prefix and '4E 54 46 53' is the ASCII string 'NTFS', which are the first bytes of an NTFS Volume Boot Record.
Question 19: Which of the following best describes the concept of 'time stomping' in a forensic investigation?
- Synchronizing system clocks across networked devices
- Recovering overwritten timestamps from the MFT
- Deliberately modifying file timestamps to obscure activity (Correct answer)
- Adjusting timestamps for time zone differences
Correct answer: Deliberately modifying file timestamps to obscure activity
Time stomping is an anti-forensics technique where an attacker alters MAC(E) timestamps on files to disguise when they were created, modified, or accessed.
Question 20: When documenting CCE assessment findings, which approach is MOST appropriate?
- Include only positive findings
- Record objective findings and observations factually (Correct answer)
- Use expert-only jargon
- Summarize verbally only
Correct answer: Record objective findings and observations factually
Objective, factual documentation supports decision-making and scrutiny.
Question 21: What is the forensic significance of the Windows.edb file found in %ProgramData%\Microsoft\Search?
- It stores Windows Update history
- It contains the Windows Search index including content previews (Correct answer)
- It logs failed login attempts
- It maintains the Windows firewall ruleset
Correct answer: It contains the Windows Search index including content previews
Windows.edb is the Windows Search index database that may contain indexed content, metadata, and previews of files even after deletion.
Question 22: What is process hollowing, and why is it significant in malware analysis?
- Injecting malicious code into a legitimate process's memory space by replacing its contents; used to evade detection (Correct answer)
- Terminating system processes to cause a denial of service; significant for availability analysis
- Duplicating a process in memory; significant for load balancing
- Creating a new legitimate process; significant for system performance analysis
Correct answer: Injecting malicious code into a legitimate process's memory space by replacing its contents; used to evade detection
Process hollowing involves starting a legitimate process, unmapping its code from memory, and replacing it with malicious code to evade security tools that whitelist trusted processes.
Question 23: Which approach is MOST important for CCE professionals applying technical procedures?
- Fastest method regardless of standards
- Adhering to protocols while adapting to conditions (Correct answer)
- Same technique without variation
- Personal shortcuts
Correct answer: Adhering to protocols while adapting to conditions
Balancing protocol adherence with professional adaptation ensures quality.
Question 24: The Health Insurance Portability and Accountability Act (HIPAA) impacts digital forensics investigations primarily by:
- Requiring hospitals to allow warrantless searches
- Restricting disclosure of protected health information found during an investigation (Correct answer)
- Requiring all forensic examiners to obtain HIPAA certification
- Mandating that medical devices be excluded from forensic scope
Correct answer: Restricting disclosure of protected health information found during an investigation
HIPAA's Privacy and Security Rules restrict how protected health information (PHI) may be accessed, used, and disclosed, even during investigations.
Question 25: In HFS+ (Mac OS Extended), which structure is equivalent to the NTFS MFT and stores file metadata?
- Journal
- Catalog File (Correct answer)
- Extents Overflow File
- Allocation File
Correct answer: Catalog File
The HFS+ Catalog File is a B-tree that stores records for all files and directories on the volume, serving the same metadata role as the NTFS MFT.
Question 26: What is the CORRECT sequence when performing a Certified Computer Examiner technical procedure?
- Document, execute, plan
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute, then plan
- Execute immediately, document if issues arise
Correct answer: Plan, prepare, execute, verify, and document
This systematic sequence ensures quality and accountability.
Question 27: When analyzing a JPEG image for metadata, which tool and metadata type would reveal the GPS coordinates where a photo was taken?
- Foremost, file header signatures
- Strings tool, ASCII text extraction
- Binwalk, embedded file analysis
- ExifTool, EXIF GPS metadata (Correct answer)
Correct answer: ExifTool, EXIF GPS metadata
ExifTool parses EXIF metadata embedded in JPEG files, including GPS latitude/longitude coordinates recorded by camera-enabled devices.
Question 28: Which approach is MOST important for CCE professionals applying technical procedures?
- Same technique without variation
- Personal shortcuts
- Fastest method regardless of standards
- Adhering to protocols while adapting to conditions (Correct answer)
Correct answer: Adhering to protocols while adapting to conditions
Balancing protocol adherence with professional adaptation ensures quality.
Question 29: Which NTFS attribute type stores the actual file content when the file is small enough to fit within the MFT record itself?
- $DATA (resident) (Correct answer)
- $FILE_NAME
- $STANDARD_INFORMATION
- $BITMAP
Correct answer: $DATA (resident)
When file data is small enough, NTFS stores it as a resident $DATA attribute directly within the MFT record, eliminating the need for separate cluster allocation.
Question 30: What is a 'sandbox' in the context of malware analysis?
- A network segment used for testing patches
- A forensic write blocker
- An isolated virtual environment used to execute and observe malware behavior safely (Correct answer)
- A secure offline backup system
Correct answer: An isolated virtual environment used to execute and observe malware behavior safely
A sandbox is an isolated environment (typically a VM) where malware can be executed and monitored without risk of infecting production systems.
Question 31: Which Windows artifact records the execution history of programs and is examined during incident response to identify malware execution?
- Prefetch files (C:\Windows\Prefetch\) (Correct answer)
- Browser cookies
- Event Log 4624
- Volume Shadow Copies
Correct answer: Prefetch files (C:\Windows\Prefetch\)
Windows Prefetch files record metadata about program execution, including the executable name, run count, and last run time, helping investigators confirm whether malware was executed.
Question 32: What is the primary forensic purpose of storing a mobile device in a Faraday bag during transport and storage?
- To isolate the device from all electromagnetic signals including cellular, WiFi, and Bluetooth (Correct answer)
- To maintain proper chain of custody documentation
- To prevent battery drain during long-term storage
- To protect the device from physical shock and impact
Correct answer: To isolate the device from all electromagnetic signals including cellular, WiFi, and Bluetooth
A Faraday bag blocks all electromagnetic signals, preventing remote access, location tracking, remote wipe commands, or unauthorized data synchronization while the device is in evidence custody.
Question 33: When a CCE professional encounters unexpected results during a procedure, the FIRST action should be:
- Stop, assess, and determine whether to proceed or seek guidance (Correct answer)
- Continue and address later
- Report without assessment
- Repeat immediately
Correct answer: Stop, assess, and determine whether to proceed or seek guidance
Stopping to assess ensures safety before further action.
Question 34: Which of the following best describes the concept of 'write blocking' in digital forensics?
- Encrypting the evidence drive before imaging
- Preventing any data from being written to the evidence drive during acquisition (Correct answer)
- Compressing data on the evidence drive to save space
- Blocking network access to the evidence drive
Correct answer: Preventing any data from being written to the evidence drive during acquisition
Write blockers prevent any write operations to the source evidence drive, ensuring the original data remains unaltered during forensic acquisition.
Question 35: When a CCE professional encounters unexpected results during a procedure, the FIRST action should be:
- Stop, assess, and determine whether to proceed or seek guidance (Correct answer)
- Continue and address later
- Report without assessment
- Repeat immediately
Correct answer: Stop, assess, and determine whether to proceed or seek guidance
Stopping to assess ensures safety before further action.
Question 36: In a Windows system, the ShellBags registry key primarily records evidence of:
- Network share connections
- Folder browsing history including deleted folders (Correct answer)
- Recently opened documents
- Installed software history
Correct answer: Folder browsing history including deleted folders
ShellBags store Windows Explorer folder view settings and persist even after the folder is deleted, revealing browsing history.
Question 37: When a forensic examiner testifies as an expert witness, they are permitted to do something fact witnesses are not, which is:
- Offer opinions and draw conclusions based on specialized knowledge (Correct answer)
- Introduce physical evidence into the record
- Waive privilege on behalf of the client
- Refuse to answer cross-examination questions
Correct answer: Offer opinions and draw conclusions based on specialized knowledge
Under FRE 702, expert witnesses may offer opinion testimony based on their specialized knowledge, skill, experience, training, or education.
Question 38: Which method is most commonly used to recover deleted files?
- Formatting
- File carving (Correct answer)
- Disk defragmentation
- Data masking
Correct answer: File carving
File carving is a powerful data recovery technique used to extract files from raw disk images or unallocated space without relying on the file system's metadata. It works by searching for known file headers and footers (signatures) to reconstruct files, making it highly effective for recovering deleted, corrupted, or fragmented data.
Question 39: During malware analysis, what is the difference between static and dynamic analysis?
- Static analysis runs the malware; dynamic analysis reads the binary without executing it
- Static analysis uses network traffic; dynamic analysis uses memory dumps
- Static analysis is faster than dynamic analysis in all cases
- Static analysis examines the malware without executing it; dynamic analysis runs the malware in a controlled environment (Correct answer)
Correct answer: Static analysis examines the malware without executing it; dynamic analysis runs the malware in a controlled environment
Static analysis inspects malware code, strings, and structure without execution, while dynamic analysis runs the malware in a sandbox to observe its behavior.
Question 40: What database format is most commonly used by Android applications to store structured local data?
- MongoDB
- SQLite (Correct answer)
- PostgreSQL
- MySQL
Correct answer: SQLite
Android applications predominantly use SQLite databases to store structured data, stored as .db files in the application's /data/data directory and accessible via standard SQL queries.
Question 41: How should Certified Computer Examiner professionals handle updated procedures?
- Continue original method
- Wait for enforcement
- Review updates, complete training, implement revisions (Correct answer)
- Apply only to new cases
Correct answer: Review updates, complete training, implement revisions
Staying current with procedural updates is a professional obligation.
Question 42: What is the maximum volume size supported by FAT32?
- 4 GB
- 2 GB
- 8 TB
- 2 TB (Correct answer)
Correct answer: 2 TB
FAT32 supports volumes up to 2 TB when using 512-byte sectors, though Windows format tools artificially limit it to 32 GB.
Question 43: How should Certified Computer Examiner professionals handle updated procedures?
- Apply only to new cases
- Review updates, complete training, implement revisions (Correct answer)
- Continue original method
- Wait for enforcement
Correct answer: Review updates, complete training, implement revisions
Staying current with procedural updates is a professional obligation.
Question 44: Which anti-forensic technique involves writing random data to all unallocated space on a drive to prevent file carving?
- Metadata stripping
- Secure deletion
- Disk wiping/slack space sanitization (Correct answer)
- Encryption
Correct answer: Disk wiping/slack space sanitization
Wiping unallocated space overwrites sectors not currently used by active files, destroying carved data that would otherwise be recoverable.
Question 45: The 'fruit of the poisonous tree' doctrine means that:
- Evidence obtained through an unlawful search may be inadmissible along with subsequent evidence it led to (Correct answer)
- Metadata derived from documents is inadmissible hearsay
- Evidence collected without expert testimony is excluded
- Digital evidence stored on encrypted drives is inadmissible
Correct answer: Evidence obtained through an unlawful search may be inadmissible along with subsequent evidence it led to
This doctrine excludes evidence discovered as a result of an illegal search, as it is tainted by the original constitutional violation.
Question 46: Which factor MOST affects quality of CCE technical outcomes?
- Equipment brand
- Practitioner's training, preparation, and attention to detail (Correct answer)
- Speed of completion
- Time of day
Correct answer: Practitioner's training, preparation, and attention to detail
The practitioner's competence is the most significant factor.
Question 47: What is the primary purpose of a YARA rule in malware analysis and incident response?
- Encrypting forensic disk images
- Automating patch deployment on infected systems
- Pattern matching to identify and classify malware based on textual or binary patterns (Correct answer)
- Monitoring network traffic in real time
Correct answer: Pattern matching to identify and classify malware based on textual or binary patterns
YARA rules define patterns (strings, byte sequences, conditions) used to scan files and memory to identify and classify malware families across large datasets.
Question 48: An examiner receives a storage device that has been exposed to water. What is the recommended immediate action?
- Allow the device to air dry completely before any analysis attempt
- Immediately power on the device to check if it still works
- Place the device in a freezer to slow down corrosion
- Submerge the device in distilled water to prevent oxidation until a specialist can examine it (Correct answer)
Correct answer: Submerge the device in distilled water to prevent oxidation until a specialist can examine it
Keeping a water-damaged storage device submerged in distilled water prevents oxidation and corrosion while it awaits specialist recovery, as air exposure causes rust that can destroy the device.
Question 49: What is the primary purpose of obtaining written consent before conducting a forensic examination of a personally-owned device?
- To allow the device owner to monitor the examination
- To satisfy vendor licensing requirements
- To protect the examiner legally and establish a valid legal basis for the search (Correct answer)
- To create a billable documentation record
Correct answer: To protect the examiner legally and establish a valid legal basis for the search
Written consent provides a legal basis for the search without a warrant and protects the examiner from claims of unauthorized access.
Question 50: Which legislation governs unauthorized access to computer systems in the U.S.?
- Privacy Act
- Freedom of Information Act
- Digital Millennium Copyright Act
- Computer Fraud and Abuse Act (Correct answer)
Correct answer: Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act (CFAA) is a U.S. federal law that prohibits unauthorized access to protected computers. It criminalizes various computer-related activities, including accessing a computer without authorization or exceeding authorized access. This act is a cornerstone for prosecuting cybercrimes and defines the legal boundaries for computer system interactions.
Question 51: Which foundational principle is MOST important for Certified Computer Examiner success?
- Minimum certification requirements
- Maximizing financial returns
- Continuous learning, ethical practice, and quality outcomes (Correct answer)
- Narrow specialization only
Correct answer: Continuous learning, ethical practice, and quality outcomes
Success requires learning, ethics, and quality focus.
Question 52: In incident response triage, what does the order of volatility principle dictate about evidence collection?
- Collect the most volatile data (RAM, running processes) first before it is lost (Correct answer)
- Collect network logs before examining endpoints
- Collect physical hard drives first as they contain the most data
- Collect disk images after interviewing witnesses
Correct answer: Collect the most volatile data (RAM, running processes) first before it is lost
The order of volatility requires collecting the most transient data first—RAM, running processes, network connections—before powering down a system, as this data is lost on shutdown.
Question 53: Under the Fourth Amendment, which standard must law enforcement meet to obtain a warrant for digital evidence?
- Clear and convincing evidence
- Reasonable suspicion
- Preponderance of evidence
- Probable cause (Correct answer)
Correct answer: Probable cause
The Fourth Amendment requires probable cause supported by oath or affirmation before a warrant can be issued.
Question 54: What distinguishes iCloud forensics from traditional mobile device forensics?
- iCloud forensics requires the physical device to be present during acquisition
- iCloud only retains photos and does not contain forensically relevant communication data
- iCloud data cannot be acquired through any legal process
- iCloud forensics acquires data remotely using credentials or legal process without needing the physical device (Correct answer)
Correct answer: iCloud forensics acquires data remotely using credentials or legal process without needing the physical device
iCloud forensics involves remotely acquiring data stored in Apple's cloud infrastructure using the account credentials or a legal process (warrant/court order), without requiring physical possession of the device.
Question 55: During an incident response investigation, an examiner finds a PowerShell script with base64-encoded content. What is the most appropriate first step?
- Delete the script immediately as it is definitely malicious
- Ignore it as PowerShell encoding is always legitimate
- Decode the base64 content in an isolated environment to determine its purpose (Correct answer)
- Restart the affected system to clear the script from memory
Correct answer: Decode the base64 content in an isolated environment to determine its purpose
Base64 encoding in PowerShell is a common obfuscation technique; decoding it in an isolated environment reveals the actual commands being executed without risk.
Question 56: Which FAT32 structure contains a 4-byte value indicating whether a cluster is in use, free, or the end of a chain?
- Boot Sector
- Directory Entry
- File Allocation Table (Correct answer)
- Root Directory
Correct answer: File Allocation Table
The File Allocation Table itself holds a 28-bit entry (in a 32-bit field) per cluster that indicates its status: free (0x00000000), end-of-chain (0x0FFFFFFF), or the next cluster in the chain.
Question 57: Which approach is MOST important for CCE professionals applying technical procedures?
- Personal shortcuts
- Adhering to protocols while adapting to conditions (Correct answer)
- Same technique without variation
- Fastest method regardless of standards
Correct answer: Adhering to protocols while adapting to conditions
Balancing protocol adherence with professional adaptation ensures quality.
Question 58: What is the significance of ACPO (Association of Chief Police Officers) guidelines in digital forensics?
- They govern cross-border evidence sharing between countries
- They establish minimum hardware requirements for forensic workstations
- They provide principles for handling digital evidence including non-alteration and documentation (Correct answer)
- They define encryption standards for evidence storage
Correct answer: They provide principles for handling digital evidence including non-alteration and documentation
ACPO guidelines establish four key principles for digital evidence handling, most notably that original data must not be altered and all actions must be documented and auditable.
Question 59: What is 'chip-off' forensics and when is it typically employed?
- Disassembling a hard drive to read platters with an electron microscope
- Removing the CPU to read cached memory from the processor registers
- Physically removing flash memory chips from a device to read them directly with specialized equipment (Correct answer)
- Extracting SIM card data without the device's PIN
Correct answer: Physically removing flash memory chips from a device to read them directly with specialized equipment
Chip-off forensics involves physically desoldering and removing flash memory chips (NAND/NOR) from a device to read their raw contents when software-based acquisition methods fail.
Question 60: According to NIST SP 800-61, what are the four phases of the incident response lifecycle?
- Identify, Protect, Detect, Respond
- Triage, Investigation, Remediation, Closure
- Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity (Correct answer)
- Planning, Execution, Review, Reporting
Correct answer: Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity
NIST SP 800-61 defines the incident response lifecycle as Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
Question 61: A forensic examiner needs to collect volatile data from a live Windows system. What should be collected FIRST?
- Windows registry hives
- Running processes and network connections
- Contents of the paging file
- Contents of the RAM (Correct answer)
Correct answer: Contents of the RAM
RAM contents are the most volatile and will be lost immediately upon shutdown, so they must be captured before any other volatile data collection.
Question 62: In a GUID Partition Table (GPT) disk, where is the primary partition table header located?
- Sector 2
- Sector 1 (Correct answer)
- Last sector of the disk
- Sector 0
Correct answer: Sector 1
In GPT, sector 0 holds a Protective MBR for legacy compatibility, and the primary GPT header is stored in sector 1 (LBA 1), with a backup at the last sector.
Question 63: In the context of ransomware incident response, what is the recommended first action upon discovering an active ransomware infection on a networked machine?
- Pay the ransom immediately to prevent further encryption
- Run antivirus software while the system remains connected to the network
- Isolate the infected system from the network to prevent lateral movement and further encryption (Correct answer)
- Reinstall the operating system without capturing evidence
Correct answer: Isolate the infected system from the network to prevent lateral movement and further encryption
Immediate network isolation (unplugging the network cable or disabling the NIC) stops ransomware from spreading to other systems while preserving the local system for forensic analysis.
Question 64: During a corporate investigation, an examiner must collect email evidence from a cloud-based Exchange server. What legal instrument is typically required?
- A forensic preservation order only
- Written consent from the company's IT department
- A subpoena or court order directed at the cloud service provider (Correct answer)
- A letter rogatory from a foreign court
Correct answer: A subpoena or court order directed at the cloud service provider
To compel a third-party cloud provider to produce data, law enforcement typically requires a subpoena or court order under the Stored Communications Act or similar legislation.
Question 65: In NTFS, what structure stores the metadata for every file and directory on the volume?
- Volume Boot Record
- Partition Table
- File Allocation Table
- Master File Table (Correct answer)
Correct answer: Master File Table
The Master File Table (MFT) in NTFS contains at least one record for every file and directory, storing metadata such as timestamps, permissions, and data locations.
Question 66: What is 'slack space' at the volume level (also called 'volume slack' or 'partition slack')?
- Unused space between the end of the file system and the end of the partition (Correct answer)
- Space reserved by the OS for system files
- The space allocated to the MFT zone
- The unused space within the last cluster of a file
Correct answer: Unused space between the end of the file system and the end of the partition
Volume slack is the space between the last sector used by the file system and the last sector defined by the partition entry, which may contain residual data from prior use.
Question 67: When a file is deleted on an NTFS volume, what typically happens to the MFT record?
- It is immediately overwritten with zeros
- The MFT record is encrypted
- The file is moved to a quarantine zone
- The record is marked as available but the data remains (Correct answer)
Correct answer: The record is marked as available but the data remains
Deleting a file in NTFS marks the MFT record as unallocated, but the actual file data and the record itself persist until the space is reused.
Question 68: What is 'indicators of compromise' (IOCs) and how are they used in incident response?
- Observable artifacts (IP addresses, file hashes, registry keys) that indicate a system may be compromised (Correct answer)
- Documented software vulnerabilities used to patch systems
- Network performance benchmarks
- Legal court orders for seizing digital evidence
Correct answer: Observable artifacts (IP addresses, file hashes, registry keys) that indicate a system may be compromised
IOCs are forensic artifacts such as malicious IP addresses, file hashes, registry entries, or domain names used to identify compromised systems and detect similar attacks.
Question 69: What is the CORRECT sequence when performing a Certified Computer Examiner technical procedure?
- Execute, then plan
- Execute immediately, document if issues arise
- Document, execute, plan
- Plan, prepare, execute, verify, and document (Correct answer)
Correct answer: Plan, prepare, execute, verify, and document
This systematic sequence ensures quality and accountability.
Question 70: Which Windows registry hive contains autorun entries most commonly abused by malware for persistence?
- HKEY_LOCAL_MACHINE\SAM\SAM\Domains
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run (Correct answer)
- HKEY_CLASSES_ROOT\CLSID
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Correct answer: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
The 'Run' and 'RunOnce' keys under HKCU and HKLM \Software\Microsoft\Windows\CurrentVersion are the most common registry locations malware uses to establish persistence.
Question 71: During memory forensics, which Volatility plugin would a CCE examiner use to list running processes from a memory dump?
- pslist or pstree (Correct answer)
- imageinfo
- dlllist
- filescan
Correct answer: pslist or pstree
The 'pslist' and 'pstree' plugins in Volatility enumerate running processes from a memory image, revealing active and potentially malicious processes.
Question 72: A forensic examiner finds evidence of a crime unrelated to the original investigation scope while executing a valid warrant. This is best described as:
- A plain view discovery requiring further legal authority before seizure (Correct answer)
- Automatically within scope if found on the same device
- Exigent circumstances allowing immediate arrest
- An illegal expansion of the warrant
Correct answer: A plain view discovery requiring further legal authority before seizure
Evidence found in plain view during a lawful search may be noted but typically requires additional legal authority (e.g., an expanded warrant) before it can be seized and used.
Question 73: Which assessment method provides the MOST reliable data for CCE professionals?
- Single-source stakeholder data
- Informal verbal feedback
- Social media reviews
- Standardized tools combined with professional observation (Correct answer)
Correct answer: Standardized tools combined with professional observation
Combining standardized tools with observation provides comprehensive data.
Question 74: A forensic examiner is retained by a defense attorney. The examiner discovers evidence that strongly incriminates the defendant. The examiner must:
- Destroy the evidence to protect the client
- Conceal the findings from the prosecution
- Report directly to the court without telling the attorney
- Report findings accurately and fully to the retaining attorney (Correct answer)
Correct answer: Report findings accurately and fully to the retaining attorney
The examiner must report findings fully and accurately to the retaining attorney; the attorney then bears responsibility for legal and ethical disclosure obligations.
Question 75: The ethical principle of 'objectivity' in forensic examination means the examiner should:
- Report all findings accurately regardless of how they affect the case (Correct answer)
- Focus only on inculpatory evidence
- Withhold exculpatory evidence to strengthen the prosecution
- Always support the findings requested by the hiring party
Correct answer: Report all findings accurately regardless of how they affect the case
Objectivity requires reporting all findings truthfully, including exculpatory evidence, without bias toward any party.
Question 76: When recovering data from a RAID 5 array with one failed drive, what is the minimum number of remaining drives needed to reconstruct the missing data?
- All remaining drives (Correct answer)
- Any one drive
- Any two drives
- The parity drive only
Correct answer: All remaining drives
RAID 5 stores parity distributed across all drives, so ALL remaining drives (n-1) must be operational to reconstruct the data from the failed drive using XOR parity.
Question 77: What is the function of the Master File Table (MFT) in NTFS?
- Logs system crashes
- Stores user profiles
- Manages boot processes
- Contains file system metadata (Correct answer)
Correct answer: Contains file system metadata
The Master File Table (MFT) is a core component of the NTFS file system, acting as a database that stores critical metadata about every file and directory on the volume. This metadata includes file names, sizes, timestamps, security attributes, and the physical location of the data on the disk, making it essential for file system organization.
Question 78: When a CCE professional encounters unexpected results during a procedure, the FIRST action should be:
- Report without assessment
- Stop, assess, and determine whether to proceed or seek guidance (Correct answer)
- Continue and address later
- Repeat immediately
Correct answer: Stop, assess, and determine whether to proceed or seek guidance
Stopping to assess ensures safety before further action.
Question 79: What is the main purpose of journaling in a file system?
- Speeds up file access
- Increases storage capacity
- Prevents unauthorized access
- Maintains file system integrity (Correct answer)
Correct answer: Maintains file system integrity
The main purpose of journaling in a file system is to maintain file system integrity, especially after unexpected system crashes or power failures. By logging changes to be made to the file system in a separate journal before committing them, the system can quickly recover to a consistent state, preventing data corruption and ensuring reliability.
Question 80: What role does calibration play in Certified Computer Examiner technical accuracy?
- Optional for experienced professionals
- Only needed for new equipment
- Matters only during inspections
- Ensures instruments produce accurate results over time (Correct answer)
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 81: Which file system supports journaling and is used on macOS?
- FAT32
- EXT2
- NTFS
- APFS (Correct answer)
Correct answer: APFS
APFS (Apple File System) is the modern, default file system for macOS, iOS, and other Apple operating systems, designed specifically for flash and solid-state drives. It supports advanced features like strong encryption, space sharing, snapshots, and journaling, which significantly enhance data integrity and overall system reliability.
Question 82: In incident response, what does the term 'containment' refer to?
- Reporting the incident to law enforcement
- Limiting the spread and impact of an incident while preserving forensic evidence (Correct answer)
- Deleting all evidence of the incident
- Restoring systems to their pre-incident state
Correct answer: Limiting the spread and impact of an incident while preserving forensic evidence
Containment involves taking steps to stop the incident from spreading further while carefully preserving evidence for forensic analysis.
Question 83: What is a 'chain of custody' and why is it critical during incident response investigations in the US?
- A network diagram showing how the attack propagated
- A list of all malware found on a system
- A documented record tracking who handled evidence, when, and what was done to it, ensuring admissibility in US courts (Correct answer)
- A backup schedule for forensic disk images
Correct answer: A documented record tracking who handled evidence, when, and what was done to it, ensuring admissibility in US courts
Chain of custody documentation ensures evidence integrity and tracks every person who accessed the evidence, which is required for the evidence to be admissible in US legal proceedings.
Question 84: What role does calibration play in Certified Computer Examiner technical accuracy?
- Ensures instruments produce accurate results over time (Correct answer)
- Only needed for new equipment
- Optional for experienced professionals
- Matters only during inspections
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 85: What role does calibration play in Certified Computer Examiner technical accuracy?
- Optional for experienced professionals
- Only needed for new equipment
- Ensures instruments produce accurate results over time (Correct answer)
- Matters only during inspections
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 86: Which of the following is NOT typically considered volatile data during a live system investigation?
- Currently logged-in users
- ARP cache entries
- Files in the Recycle Bin (Correct answer)
- Open network sockets
Correct answer: Files in the Recycle Bin
Files in the Recycle Bin are stored on disk and persist after shutdown, making them non-volatile data unlike ARP cache, logged-in users, and open network sockets.
Question 87: Which Windows artifact stores up to the last 1,000 commands typed into the command prompt during a session?
- MUI cache
- Prefetch files
- ConsoleHost history (Correct answer)
- LNK files
Correct answer: ConsoleHost history
PowerShell/ConsoleHost_history.txt and the in-memory console command history store recently executed commands, which can provide evidence of attacker or user activity.
Question 88: What is the primary forensic reason for placing a mobile device in Airplane Mode during evidence acquisition?
- To save battery life during long acquisitions
- To prevent remote wiping or unauthorized data modification (Correct answer)
- To increase USB data transfer speeds
- To enable USB debugging mode automatically
Correct answer: To prevent remote wiping or unauthorized data modification
Airplane Mode disables all wireless communications, preventing remote wipe commands or data synchronization that could alter or destroy evidence on the device.
Question 89: Where are call logs most commonly stored on Android devices?
- In plaintext files in the /system/calls directory
- In a SQLite database managed by the contacts/call log content provider (Correct answer)
- In encrypted binary logs stored in /proc/telephony
- Exclusively on the SIM card memory
Correct answer: In a SQLite database managed by the contacts/call log content provider
Android call logs are maintained in a SQLite database accessed through the contacts/call log content provider, typically stored under /data/data/com.android.providers.contacts/.
Question 90: In email forensics, which header field is MOST reliable for determining the true origin of a message?
- X-Originating-IP:
- Reply-To:
- From:
- The earliest Received: header (Correct answer)
Correct answer: The earliest Received: header
The earliest (innermost) Received header is added by the originating mail server and is hardest to forge compared to other headers.
Question 91: During malware analysis, what is the significance of an executable importing 'VirtualAlloc' and 'WriteProcessMemory' from the Windows API?
- These functions are commonly used for process injection and shellcode execution in malicious software (Correct answer)
- These functions indicate the software performs legitimate database operations
- These functions indicate the software is digitally signed
- These functions are required for all GUI applications
Correct answer: These functions are commonly used for process injection and shellcode execution in malicious software
VirtualAlloc allocates memory and WriteProcessMemory writes data into another process's memory space; together they are hallmarks of code injection techniques used by malware.
Question 92: What is lateral movement in the context of an incident response investigation?
- Techniques used by attackers to progressively move through a network after initial compromise to reach target systems (Correct answer)
- Migrating virtual machines between hypervisor hosts
- Transferring data between two forensic workstations
- Moving forensic evidence from one location to another
Correct answer: Techniques used by attackers to progressively move through a network after initial compromise to reach target systems
Lateral movement refers to attacker techniques such as pass-the-hash, RDP exploitation, or credential theft used to pivot from an initially compromised system to other valuable targets on the same network.
Question 93: What does 'rooting' an Android device enable a forensic examiner to accomplish during an investigation?
- Gain superuser (root) access to extract data from protected system and data partitions (Correct answer)
- Encrypt the device to secure it as evidence
- Connect the device directly to law enforcement databases remotely
- Reinstall the Android operating system to a known-good state
Correct answer: Gain superuser (root) access to extract data from protected system and data partitions
Rooting grants superuser privileges, allowing forensic examiners to access protected areas such as the /data partition where application databases, call logs, and messages reside.
Question 94: In exFAT (used on large flash media), what replaces the traditional File Allocation Table for tracking cluster usage?
- Inode Table
- B-tree Index
- Allocation Bitmap (Correct answer)
- Cluster Map File
Correct answer: Allocation Bitmap
exFAT uses an Allocation Bitmap to track which clusters are in use rather than a linked-list FAT structure, improving performance for large volumes.
Question 95: How should Certified Computer Examiner professionals handle updated procedures?
- Review updates, complete training, implement revisions (Correct answer)
- Continue original method
- Apply only to new cases
- Wait for enforcement
Correct answer: Review updates, complete training, implement revisions
Staying current with procedural updates is a professional obligation.
Question 96: Which artifact would best establish a timeline of USB device connections on a Windows 10 system?
- SYSTEM\CurrentControlSet\Enum\USBSTOR (Correct answer)
- NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
- NTUSER.DAT\Software\Microsoft\Internet Explorer\TypedURLs
- SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Correct answer: SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR registry key records device class identifiers, serial numbers, and first/last connection times for USB storage devices.
Question 97: What role does calibration play in Certified Computer Examiner technical accuracy?
- Matters only during inspections
- Only needed for new equipment
- Ensures instruments produce accurate results over time (Correct answer)
- Optional for experienced professionals
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 98: What is 'slack space' in the context of digital forensics?
- Free space available for new file storage
- The space between the end of a file's actual data and the end of its allocated cluster (Correct answer)
- Unused storage capacity on an unpartitioned drive
- Space reserved by the OS for system files
Correct answer: The space between the end of a file's actual data and the end of its allocated cluster
Slack space is the remnant data that can exist between the logical end of a file and the physical end of the last cluster allocated to it, and may contain previously deleted data fragments.
Question 99: Which SQLite forensics technique allows recovery of records that were deleted from a database but not yet overwritten?
- WAL file analysis
- Journal mode inspection
- Index traversal
- Freelist page parsing (Correct answer)
Correct answer: Freelist page parsing
SQLite stores deleted records in freelist pages until they are reused, allowing forensic recovery through freelist page parsing.
Question 100: What is a 'rootkit' and how does it complicate digital forensic investigations?
- A legitimate system administration tool used for root access
- A vulnerability scanner used by attackers
- Malware that hides its presence by modifying OS structures to conceal files, processes, and network connections (Correct answer)
- A type of ransomware that encrypts the root directory
Correct answer: Malware that hides its presence by modifying OS structures to conceal files, processes, and network connections
Rootkits subvert OS functions to hide malicious activity, making standard tools return false information and requiring offline analysis or specialized tools to detect.
Question 101: What is 'chain of custody' documentation primarily designed to ensure?
- That evidence integrity and handling history are verifiable in court (Correct answer)
- That evidence is collected quickly
- That backups are created before analysis
- That suspects are notified of seizure
Correct answer: That evidence integrity and handling history are verifiable in court
Chain of custody documents every person who handled evidence and all actions taken, ensuring its integrity is defensible in court.
Certified Computer Examiner (CCE)
The CCE, offered by the International Society of Forensic Computer Examiners (ISFCE), validates expertise in digital forensics including evidence acquisition, file system analysis, network investigations, incident response, and forensic reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds