Certified Computer Examiner (CCE) — Questions and Answers
Question 1: In HFS+ (Mac OS Extended), which structure is equivalent to the NTFS MFT and stores file metadata?
- Journal
- Allocation File
- Extents Overflow File
- Catalog File (Correct answer)
Correct answer: Catalog File
The HFS+ Catalog File is a B-tree that stores records for all files and directories on the volume, serving the same metadata role as the NTFS MFT.
Question 2: Which of the following best describes the concept of 'time stomping' in a forensic investigation?
- Deliberately modifying file timestamps to obscure activity (Correct answer)
- Synchronizing system clocks across networked devices
- Adjusting timestamps for time zone differences
- Recovering overwritten timestamps from the MFT
Correct answer: Deliberately modifying file timestamps to obscure activity
Time stomping is an anti-forensics technique where an attacker alters MAC(E) timestamps on files to disguise when they were created, modified, or accessed.
Question 3: What is a 'chain of custody' and why is it critical during incident response investigations in the US?
- A backup schedule for forensic disk images
- A network diagram showing how the attack propagated
- A list of all malware found on a system
- A documented record tracking who handled evidence, when, and what was done to it, ensuring admissibility in US courts (Correct answer)
Correct answer: A documented record tracking who handled evidence, when, and what was done to it, ensuring admissibility in US courts
Chain of custody documentation ensures evidence integrity and tracks every person who accessed the evidence, which is required for the evidence to be admissible in US legal proceedings.
Question 4: How should Certified Computer Examiner professionals handle updated procedures?
- Continue original method
- Apply only to new cases
- Wait for enforcement
- Review updates, complete training, implement revisions (Correct answer)
Correct answer: Review updates, complete training, implement revisions
Staying current with procedural updates is a professional obligation.
Question 5: During data carving, a forensic tool identifies a file header signature but cannot find a footer signature. What is the most likely outcome?
- The tool will carve a file up to a maximum size limit (Correct answer)
- The file will not be recovered at all
- The carved file will be flagged as encrypted
- The tool will skip to the next partition
Correct answer: The tool will carve a file up to a maximum size limit
When no footer is found, most carving tools recover data up to a configurable maximum file size, which may result in a larger-than-actual file or truncated output.
Question 6: Which Windows artifact stores up to the last 1,000 commands typed into the command prompt during a session?
- Prefetch files
- ConsoleHost history (Correct answer)
- LNK files
- MUI cache
Correct answer: ConsoleHost history
PowerShell/ConsoleHost_history.txt and the in-memory console command history store recently executed commands, which can provide evidence of attacker or user activity.
Question 7: Which NTFS attribute type stores the actual file content when the file is small enough to fit within the MFT record itself?
- $STANDARD_INFORMATION
- $FILE_NAME
- $DATA (resident) (Correct answer)
- $BITMAP
Correct answer: $DATA (resident)
When file data is small enough, NTFS stores it as a resident $DATA attribute directly within the MFT record, eliminating the need for separate cluster allocation.
Question 8: What types of information can be recovered from a mobile device's GPS and location-related artifacts during a forensic examination?
- Historical location trails, geotagged media metadata, and cached location data from apps (Correct answer)
- Only the current real-time GPS coordinates of the device
- Encrypted carrier-side communication metadata only
- Network credentials and saved WiFi access point passwords
Correct answer: Historical location trails, geotagged media metadata, and cached location data from apps
Mobile devices accumulate rich historical location data across multiple artifact types including GPS logs, geotagged photo EXIF data, cached map tiles, and location-aware application databases.
Question 9: What Windows file system feature can store alternate versions of a file's $DATA attribute under a different name, sometimes used to hide data?
- Alternate Data Streams (Correct answer)
- Symbolic links
- Reparse points
- Sparse files
Correct answer: Alternate Data Streams
NTFS Alternate Data Streams (ADS) allow additional data to be associated with a file under a colon-separated name (e.g., file.txt:hidden), which is invisible in standard directory listings.
Question 10: In a Windows system, the ShellBags registry key primarily records evidence of:
- Recently opened documents
- Network share connections
- Folder browsing history including deleted folders (Correct answer)
- Installed software history
Correct answer: Folder browsing history including deleted folders
ShellBags store Windows Explorer folder view settings and persist even after the folder is deleted, revealing browsing history.
Question 11: Which Windows artifact records the execution history of programs and is examined during incident response to identify malware execution?
- Event Log 4624
- Volume Shadow Copies
- Browser cookies
- Prefetch files (C:\Windows\Prefetch\) (Correct answer)
Correct answer: Prefetch files (C:\Windows\Prefetch\)
Windows Prefetch files record metadata about program execution, including the executable name, run count, and last run time, helping investigators confirm whether malware was executed.
Question 12: What is the CORRECT sequence when performing a Certified Computer Examiner technical procedure?
- Execute, then plan
- Execute immediately, document if issues arise
- Plan, prepare, execute, verify, and document (Correct answer)
- Document, execute, plan
Correct answer: Plan, prepare, execute, verify, and document
This systematic sequence ensures quality and accountability.
Question 13: What is the purpose of the $LogFile in NTFS?
- Caches recently accessed files
- Stores user login events
- Tracks bad clusters
- Provides transaction journaling for metadata changes (Correct answer)
Correct answer: Provides transaction journaling for metadata changes
$LogFile is NTFS's transaction log that records metadata changes, allowing the file system to recover from crashes by replaying or rolling back incomplete transactions.
Question 14: Which tool is commonly used to create a verified forensic image?
- FTK Imager (Correct answer)
- Wireshark
- Disk Cleanup
- VirtualBox
Correct answer: FTK Imager
FTK Imager is a widely used and trusted software tool in digital forensics for creating verified forensic images of various storage devices. It can generate bit-for-bit copies in several formats and includes hashing capabilities to ensure the integrity and authenticity of the acquired evidence.
Question 15: In the context of ransomware incident response, what is the recommended first action upon discovering an active ransomware infection on a networked machine?
- Run antivirus software while the system remains connected to the network
- Pay the ransom immediately to prevent further encryption
- Reinstall the operating system without capturing evidence
- Isolate the infected system from the network to prevent lateral movement and further encryption (Correct answer)
Correct answer: Isolate the infected system from the network to prevent lateral movement and further encryption
Immediate network isolation (unplugging the network cable or disabling the NIC) stops ransomware from spreading to other systems while preserving the local system for forensic analysis.
Question 16: What is the maximum file size supported by the FAT32 file system?
- 4 GB minus 1 byte (Correct answer)
- 16 TB
- 8 GB
- 2 GB
Correct answer: 4 GB minus 1 byte
FAT32 uses a 32-bit file size field, which allows a maximum file size of 4,294,967,295 bytes (4 GB – 1 byte).
Question 17: When a CCE professional encounters unexpected results during a procedure, the FIRST action should be:
- Continue and address later
- Repeat immediately
- Stop, assess, and determine whether to proceed or seek guidance (Correct answer)
- Report without assessment
Correct answer: Stop, assess, and determine whether to proceed or seek guidance
Stopping to assess ensures safety before further action.
Question 18: An examiner captures HTTPS traffic in a corporate environment and cannot read the payload. What is the most forensically sound approach to decrypt this traffic?
- Ignore encrypted traffic as it is not admissible
- Capture at the physical layer instead
- Obtain the server's private key or pre-master secret log from the server's TLS configuration (Correct answer)
- Use brute force on the encryption key
Correct answer: Obtain the server's private key or pre-master secret log from the server's TLS configuration
With access to the server's private key or the pre-master secret log (e.g., from a corporate SSL inspection proxy), investigators can decrypt TLS traffic in tools like Wireshark.
Question 19: Which legislation governs unauthorized access to computer systems in the U.S.?
- Computer Fraud and Abuse Act (Correct answer)
- Privacy Act
- Digital Millennium Copyright Act
- Freedom of Information Act
Correct answer: Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act (CFAA) is a U.S. federal law that prohibits unauthorized access to protected computers. It criminalizes various computer-related activities, including accessing a computer without authorization or exceeding authorized access. This act is a cornerstone for prosecuting cybercrimes and defines the legal boundaries for computer system interactions.
Question 20: What is the PRIMARY purpose of CCE certification in Certified Computer Examiner?
- Guaranteeing employment
- Demonstrating verified competency and professional standards adherence (Correct answer)
- Bypassing education
- Personal achievement
Correct answer: Demonstrating verified competency and professional standards adherence
Certification demonstrates verified competency to employers and the public.
Question 21: What is the CORRECT sequence when performing a Certified Computer Examiner technical procedure?
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute immediately, document if issues arise
- Execute, then plan
- Document, execute, plan
Correct answer: Plan, prepare, execute, verify, and document
This systematic sequence ensures quality and accountability.
Question 22: What is the main purpose of a write blocker in digital forensics?
- To block unauthorized users
- To encrypt forensic images
- To speed up data recovery
- To prevent writing to a suspect drive (Correct answer)
Correct answer: To prevent writing to a suspect drive
A write blocker is a critical hardware or software device in digital forensics. Its main purpose is to physically or logically prevent any modifications, accidental or intentional, from being written to a suspect's storage device. This ensures the integrity and authenticity of the original evidence, making it admissible in legal proceedings.
Question 23: In a GUID Partition Table (GPT) disk, where is the primary partition table header located?
- Sector 1 (Correct answer)
- Last sector of the disk
- Sector 0
- Sector 2
Correct answer: Sector 1
In GPT, sector 0 holds a Protective MBR for legacy compatibility, and the primary GPT header is stored in sector 1 (LBA 1), with a backup at the last sector.
Question 24: What does the hash value of a forensic image ensure?
- The image will open quickly
- The image is identical to the original (Correct answer)
- The storage space is optimized
- The data can be decrypted
Correct answer: The image is identical to the original
The hash value (e.g., MD5, SHA1) of a forensic image is a unique digital fingerprint generated from its data. By comparing the hash of the original evidence with the hash of the acquired image, forensic examiners can mathematically confirm that the image is an exact, bit-for-bit duplicate and has not been altered.
Question 25: During memory forensics, which Volatility plugin would a CCE examiner use to list running processes from a memory dump?
- pslist or pstree (Correct answer)
- filescan
- imageinfo
- dlllist
Correct answer: pslist or pstree
The 'pslist' and 'pstree' plugins in Volatility enumerate running processes from a memory image, revealing active and potentially malicious processes.
Question 26: During evidence collection, an examiner discovers the suspect's laptop has full disk encryption enabled and is currently powered on. What is the recommended action?
- Submit the device to the lab without any on-site action
- Perform a live acquisition before shutting down (Correct answer)
- Remove the hard drive and use a hardware decryption tool
- Immediately power off the device to prevent data destruction
Correct answer: Perform a live acquisition before shutting down
When an encrypted device is powered on and unlocked, a live acquisition should be performed to capture the decrypted data before the device is shut down and encryption re-engages.
Question 27: In mobile forensics, what is the term for physically removing and reading the memory chip directly from the circuit board?
- Chip-off extraction (Correct answer)
- JTAG extraction
- Logical extraction
- Bootloader extraction
Correct answer: Chip-off extraction
Chip-off extraction involves physically desoldering the memory chip from the device's PCB and reading it with specialized equipment, providing raw access to all stored data.
Question 28: What role does calibration play in Certified Computer Examiner technical accuracy?
- Ensures instruments produce accurate results over time (Correct answer)
- Matters only during inspections
- Optional for experienced professionals
- Only needed for new equipment
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 29: What is the PRIMARY purpose of an initial assessment in Certified Computer Examiner?
- Fulfill administrative requirements
- Establish a baseline and identify needs (Correct answer)
- Demonstrate assessor expertise
- Generate billing documentation
Correct answer: Establish a baseline and identify needs
Initial assessments establish baselines that guide all subsequent actions.
Question 30: Which SQLite forensics technique allows recovery of records that were deleted from a database but not yet overwritten?
- Freelist page parsing (Correct answer)
- Journal mode inspection
- WAL file analysis
- Index traversal
Correct answer: Freelist page parsing
SQLite stores deleted records in freelist pages until they are reused, allowing forensic recovery through freelist page parsing.
Question 31: Which file system is commonly used by Windows operating systems?
- HFS+
- NTFS (Correct answer)
- EXT4
- APFS
Correct answer: NTFS
NTFS (New Technology File System) is the default and most commonly used file system for Microsoft Windows operating systems. It offers advanced features compared to older file systems, including improved security, journaling for data integrity, support for large files and volumes, and robust data recovery capabilities.
Question 32: What is the main purpose of journaling in a file system?
- Prevents unauthorized access
- Speeds up file access
- Maintains file system integrity (Correct answer)
- Increases storage capacity
Correct answer: Maintains file system integrity
The main purpose of journaling in a file system is to maintain file system integrity, especially after unexpected system crashes or power failures. By logging changes to be made to the file system in a separate journal before committing them, the system can quickly recover to a consistent state, preventing data corruption and ensuring reliability.
Question 33: Which factor MOST affects quality of CCE technical outcomes?
- Practitioner's training, preparation, and attention to detail (Correct answer)
- Speed of completion
- Time of day
- Equipment brand
Correct answer: Practitioner's training, preparation, and attention to detail
The practitioner's competence is the most significant factor.
Question 34: What role does calibration play in Certified Computer Examiner technical accuracy?
- Only needed for new equipment
- Matters only during inspections
- Ensures instruments produce accurate results over time (Correct answer)
- Optional for experienced professionals
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 35: Which exception to the warrant requirement allows law enforcement to conduct a warrantless search to prevent imminent destruction of evidence?
- Inevitable discovery
- Consent exception
- Good faith exception
- Exigent circumstances (Correct answer)
Correct answer: Exigent circumstances
The exigent circumstances exception permits warrantless searches when evidence would likely be destroyed before a warrant could be obtained.
Question 36: In ext4 forensics, what data structure plays a role analogous to the NTFS MFT record?
- Superblock
- Journal
- Inode (Correct answer)
- Block Group Descriptor
Correct answer: Inode
An inode in ext4 stores file metadata (permissions, timestamps, size, and block pointers) for each file or directory, similar to an MFT record in NTFS.
Question 37: Which approach is MOST important for CCE professionals applying technical procedures?
- Personal shortcuts
- Fastest method regardless of standards
- Same technique without variation
- Adhering to protocols while adapting to conditions (Correct answer)
Correct answer: Adhering to protocols while adapting to conditions
Balancing protocol adherence with professional adaptation ensures quality.
Question 38: What is a 'rootkit' and how does it complicate digital forensic investigations?
- Malware that hides its presence by modifying OS structures to conceal files, processes, and network connections (Correct answer)
- A legitimate system administration tool used for root access
- A vulnerability scanner used by attackers
- A type of ransomware that encrypts the root directory
Correct answer: Malware that hides its presence by modifying OS structures to conceal files, processes, and network connections
Rootkits subvert OS functions to hide malicious activity, making standard tools return false information and requiring offline analysis or specialized tools to detect.
Question 39: What tool would a CCE examiner use to examine strings embedded in a malware binary without executing it?
- The 'strings' utility or BinText (Correct answer)
- Volatility
- Wireshark
- Autopsy
Correct answer: The 'strings' utility or BinText
The 'strings' command-line utility or tools like BinText extract printable character sequences from a binary, often revealing URLs, registry keys, and function names.
Question 40: In Wireshark, which display filter would isolate only DNS query traffic?
- udp.port == 53
- ip.proto == 17
- tcp.port == 53
- dns.flags.response == 0 (Correct answer)
Correct answer: dns.flags.response == 0
The filter dns.flags.response == 0 specifically isolates DNS query packets, excluding responses.
Question 41: What is 'slack space' at the volume level (also called 'volume slack' or 'partition slack')?
- The unused space within the last cluster of a file
- Space reserved by the OS for system files
- The space allocated to the MFT zone
- Unused space between the end of the file system and the end of the partition (Correct answer)
Correct answer: Unused space between the end of the file system and the end of the partition
Volume slack is the space between the last sector used by the file system and the last sector defined by the partition entry, which may contain residual data from prior use.
Question 42: What is the primary forensic purpose of storing a mobile device in a Faraday bag during transport and storage?
- To isolate the device from all electromagnetic signals including cellular, WiFi, and Bluetooth (Correct answer)
- To protect the device from physical shock and impact
- To maintain proper chain of custody documentation
- To prevent battery drain during long-term storage
Correct answer: To isolate the device from all electromagnetic signals including cellular, WiFi, and Bluetooth
A Faraday bag blocks all electromagnetic signals, preventing remote access, location tracking, remote wipe commands, or unauthorized data synchronization while the device is in evidence custody.
Question 43: When a CCE professional encounters unexpected results during a procedure, the FIRST action should be:
- Repeat immediately
- Report without assessment
- Stop, assess, and determine whether to proceed or seek guidance (Correct answer)
- Continue and address later
Correct answer: Stop, assess, and determine whether to proceed or seek guidance
Stopping to assess ensures safety before further action.
Question 44: What is the default cluster size for an NTFS volume formatted on a partition larger than 2 GB?
- 8,192 bytes
- 1,024 bytes
- 4,096 bytes (Correct answer)
- 512 bytes
Correct answer: 4,096 bytes
Windows defaults to 4,096-byte (4 KB) clusters for NTFS volumes larger than 2 GB, balancing storage efficiency and performance.
Question 45: During malware analysis, what is the significance of an executable importing 'VirtualAlloc' and 'WriteProcessMemory' from the Windows API?
- These functions are required for all GUI applications
- These functions indicate the software is digitally signed
- These functions indicate the software performs legitimate database operations
- These functions are commonly used for process injection and shellcode execution in malicious software (Correct answer)
Correct answer: These functions are commonly used for process injection and shellcode execution in malicious software
VirtualAlloc allocates memory and WriteProcessMemory writes data into another process's memory space; together they are hallmarks of code injection techniques used by malware.
Question 46: During an incident response investigation, an examiner finds a PowerShell script with base64-encoded content. What is the most appropriate first step?
- Delete the script immediately as it is definitely malicious
- Restart the affected system to clear the script from memory
- Ignore it as PowerShell encoding is always legitimate
- Decode the base64 content in an isolated environment to determine its purpose (Correct answer)
Correct answer: Decode the base64 content in an isolated environment to determine its purpose
Base64 encoding in PowerShell is a common obfuscation technique; decoding it in an isolated environment reveals the actual commands being executed without risk.
Question 47: Which factor MOST affects quality of CCE technical outcomes?
- Time of day
- Speed of completion
- Practitioner's training, preparation, and attention to detail (Correct answer)
- Equipment brand
Correct answer: Practitioner's training, preparation, and attention to detail
The practitioner's competence is the most significant factor.
Question 48: Which of the following file carving signatures correctly identifies the start of a JPEG file?
- 50 4B 03 04
- FF D8 FF (Correct answer)
- 25 50 44 46
- 89 50 4E 47
Correct answer: FF D8 FF
JPEG files begin with the magic bytes FF D8 FF, which represent the Start of Image (SOI) marker used to identify JPEG/JFIF data.
Question 49: Which technique is best suited to recover deleted files from a FAT file system?
- Registry cleaning
- Password cracking
- File carving (Correct answer)
- Disk defragmentation
Correct answer: File carving
File carving is a technique used to recover deleted or fragmented files from raw disk images, especially effective when file system metadata is damaged or missing. It works by searching for known file headers and footers (signatures) within the raw data. This method is particularly useful for recovering files from simpler file systems like FAT where metadata might be less robustly preserved after deletion.
Question 50: In incident response triage, what does the order of volatility principle dictate about evidence collection?
- Collect disk images after interviewing witnesses
- Collect network logs before examining endpoints
- Collect the most volatile data (RAM, running processes) first before it is lost (Correct answer)
- Collect physical hard drives first as they contain the most data
Correct answer: Collect the most volatile data (RAM, running processes) first before it is lost
The order of volatility requires collecting the most transient data first—RAM, running processes, network connections—before powering down a system, as this data is lost on shutdown.
Question 51: In a forensic investigation involving an SSD, why is traditional file recovery often less successful than with HDDs?
- SSDs use proprietary encryption by default
- SSDs compress all data before writing
- SSD sectors are too small for standard carving tools
- The TRIM command allows the OS to zero out deleted data blocks proactively (Correct answer)
Correct answer: The TRIM command allows the OS to zero out deleted data blocks proactively
The TRIM command notifies the SSD controller that deleted blocks can be wiped immediately, causing the underlying data to be erased before forensic recovery is attempted.
Question 52: What does the term 'chain of custody' refer to in digital forensics?
- The hierarchy of approvals needed to access evidence
- The order in which evidence items are processed in the lab
- The sequence of hashing algorithms applied to evidence
- The documented chronological history of who handled, collected, and transferred evidence (Correct answer)
Correct answer: The documented chronological history of who handled, collected, and transferred evidence
Chain of custody is the chronological documentation showing the seizure, custody, control, transfer, and analysis of evidence, ensuring its integrity and admissibility.
Question 53: When a CCE professional encounters unexpected results during a procedure, the FIRST action should be:
- Repeat immediately
- Continue and address later
- Report without assessment
- Stop, assess, and determine whether to proceed or seek guidance (Correct answer)
Correct answer: Stop, assess, and determine whether to proceed or seek guidance
Stopping to assess ensures safety before further action.
Question 54: What is the CORRECT sequence when performing a Certified Computer Examiner technical procedure?
- Document, execute, plan
- Execute immediately, document if issues arise
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute, then plan
Correct answer: Plan, prepare, execute, verify, and document
This systematic sequence ensures quality and accountability.
Question 55: In incident response, what does the term 'containment' refer to?
- Deleting all evidence of the incident
- Reporting the incident to law enforcement
- Limiting the spread and impact of an incident while preserving forensic evidence (Correct answer)
- Restoring systems to their pre-incident state
Correct answer: Limiting the spread and impact of an incident while preserving forensic evidence
Containment involves taking steps to stop the incident from spreading further while carefully preserving evidence for forensic analysis.
Question 56: A suspect used CCleaner before seizure. Which forensic artifact is MOST likely to survive CCleaner's default cleaning?
- Windows prefetch files
- Browser cookies
- Temporary internet files
- VSS shadow copies (Correct answer)
Correct answer: VSS shadow copies
Volume Shadow Copy Service (VSS) snapshots are typically not touched by CCleaner's default cleaning routines.
Question 57: What term describes the area on a hard disk between the end of one partition and the start of the next, which may contain hidden or deleted data?
- Bad sector pool
- Unpartitioned space (Correct answer)
- Volume shadow
- Slack space
Correct answer: Unpartitioned space
Unpartitioned space (also called inter-partition space) is the area on a disk not assigned to any partition and can be used to hide data or may contain remnants of old partitions.
Question 58: What is the primary first step a forensic examiner should take when acquiring a mobile device as evidence?
- Install forensic software on the device
- Power off the device to preserve battery life
- Connect it immediately to a forensic workstation
- Document and photograph the device in its current state (Correct answer)
Correct answer: Document and photograph the device in its current state
Documenting and photographing the device in its current state establishes the chain of custody and preserves the initial evidence condition before any acquisition steps.
Question 59: In NTFS, what structure stores the metadata for every file and directory on the volume?
- Master File Table (Correct answer)
- Volume Boot Record
- Partition Table
- File Allocation Table
Correct answer: Master File Table
The Master File Table (MFT) in NTFS contains at least one record for every file and directory, storing metadata such as timestamps, permissions, and data locations.
Question 60: Which FAT32 structure contains a 4-byte value indicating whether a cluster is in use, free, or the end of a chain?
- File Allocation Table (Correct answer)
- Root Directory
- Directory Entry
- Boot Sector
Correct answer: File Allocation Table
The File Allocation Table itself holds a 28-bit entry (in a 32-bit field) per cluster that indicates its status: free (0x00000000), end-of-chain (0x0FFFFFFF), or the next cluster in the chain.
Question 61: A private employer wants to monitor employee emails on company systems. Which statement is MOST accurate legally?
- Employee consent is never needed for monitoring
- Employers can never monitor employee communications
- Employers generally may monitor company systems if employees have been notified (Correct answer)
- A warrant is required before any employer monitoring
Correct answer: Employers generally may monitor company systems if employees have been notified
Employers generally have the right to monitor company-owned systems, especially when employees are notified through acceptable use policies.
Question 62: How does the CCE body of knowledge relate to daily practice?
- Only for exams
- Only for research
- Theoretical only
- Provides the framework guiding decisions and standard practices (Correct answer)
Correct answer: Provides the framework guiding decisions and standard practices
The body of knowledge guides daily decision-making.
Question 63: Which factor MOST affects quality of CCE technical outcomes?
- Time of day
- Speed of completion
- Equipment brand
- Practitioner's training, preparation, and attention to detail (Correct answer)
Correct answer: Practitioner's training, preparation, and attention to detail
The practitioner's competence is the most significant factor.
Question 64: What distinguishes a Certified Computer Examiner certified professional from non-certified practitioners?
- No meaningful difference
- Validated competency through standardized assessment (Correct answer)
- More experience always
- Only works in large organizations
Correct answer: Validated competency through standardized assessment
Certification provides objective validation through standardized assessment.
Question 65: What is 'indicators of compromise' (IOCs) and how are they used in incident response?
- Documented software vulnerabilities used to patch systems
- Network performance benchmarks
- Observable artifacts (IP addresses, file hashes, registry keys) that indicate a system may be compromised (Correct answer)
- Legal court orders for seizing digital evidence
Correct answer: Observable artifacts (IP addresses, file hashes, registry keys) that indicate a system may be compromised
IOCs are forensic artifacts such as malicious IP addresses, file hashes, registry entries, or domain names used to identify compromised systems and detect similar attacks.
Question 66: Which act criminalizes unauthorized access to computer systems and is most commonly applied in computer crime prosecutions in the US?
- Digital Millennium Copyright Act
- Computer Fraud and Abuse Act (CFAA) (Correct answer)
- Cybersecurity Information Sharing Act
- Electronic Espionage Act
Correct answer: Computer Fraud and Abuse Act (CFAA)
The CFAA (18 U.S.C. § 1030) is the primary federal statute criminalizing unauthorized access to protected computers.
Question 67: Which hashing algorithm is currently recommended by NIST for verifying the integrity of forensic images?
- CRC-32
- SHA-1
- MD5
- SHA-256 (Correct answer)
Correct answer: SHA-256
SHA-256 is the current NIST-recommended hashing algorithm as MD5 and SHA-1 have known collision vulnerabilities that could undermine evidence integrity verification.
Question 68: What is the primary purpose of a YARA rule in malware analysis and incident response?
- Pattern matching to identify and classify malware based on textual or binary patterns (Correct answer)
- Encrypting forensic disk images
- Automating patch deployment on infected systems
- Monitoring network traffic in real time
Correct answer: Pattern matching to identify and classify malware based on textual or binary patterns
YARA rules define patterns (strings, byte sequences, conditions) used to scan files and memory to identify and classify malware families across large datasets.
Question 69: How does the CCE body of knowledge relate to daily practice?
- Only for research
- Theoretical only
- Provides the framework guiding decisions and standard practices (Correct answer)
- Only for exams
Correct answer: Provides the framework guiding decisions and standard practices
The body of knowledge guides daily decision-making.
Question 70: A first responder arrives at a scene where a desktop computer is running. Network cables are connected. What should be done regarding the network connection?
- Leave the network connected to monitor traffic
- Disconnect the network cable immediately to prevent remote data destruction
- Document the connection state before deciding whether to disconnect (Correct answer)
- Take a screenshot of network activity then disconnect
Correct answer: Document the connection state before deciding whether to disconnect
The examiner should document the current state of network connections before taking any action, as the decision to disconnect depends on case specifics and may need to be justified later.
Question 71: What is process hollowing, and why is it significant in malware analysis?
- Injecting malicious code into a legitimate process's memory space by replacing its contents; used to evade detection (Correct answer)
- Duplicating a process in memory; significant for load balancing
- Terminating system processes to cause a denial of service; significant for availability analysis
- Creating a new legitimate process; significant for system performance analysis
Correct answer: Injecting malicious code into a legitimate process's memory space by replacing its contents; used to evade detection
Process hollowing involves starting a legitimate process, unmapping its code from memory, and replacing it with malicious code to evade security tools that whitelist trusted processes.
Question 72: What is the forensic significance of the Windows.edb file found in %ProgramData%\Microsoft\Search?
- It stores Windows Update history
- It logs failed login attempts
- It maintains the Windows firewall ruleset
- It contains the Windows Search index including content previews (Correct answer)
Correct answer: It contains the Windows Search index including content previews
Windows.edb is the Windows Search index database that may contain indexed content, metadata, and previews of files even after deletion.
Question 73: Which factor MOST affects quality of CCE technical outcomes?
- Time of day
- Equipment brand
- Speed of completion
- Practitioner's training, preparation, and attention to detail (Correct answer)
Correct answer: Practitioner's training, preparation, and attention to detail
The practitioner's competence is the most significant factor.
Question 74: Which approach is MOST important for CCE professionals applying technical procedures?
- Fastest method regardless of standards
- Adhering to protocols while adapting to conditions (Correct answer)
- Same technique without variation
- Personal shortcuts
Correct answer: Adhering to protocols while adapting to conditions
Balancing protocol adherence with professional adaptation ensures quality.
Question 75: During a corporate investigation, an examiner must collect email evidence from a cloud-based Exchange server. What legal instrument is typically required?
- A subpoena or court order directed at the cloud service provider (Correct answer)
- Written consent from the company's IT department
- A letter rogatory from a foreign court
- A forensic preservation order only
Correct answer: A subpoena or court order directed at the cloud service provider
To compel a third-party cloud provider to produce data, law enforcement typically requires a subpoena or court order under the Stored Communications Act or similar legislation.
Question 76: Which Android directory typically stores private data for user-installed applications, including databases and preferences?
- /sdcard/Android
- /data/data (Correct answer)
- /proc/data
- /system/app
Correct answer: /data/data
The /data/data directory on Android stores each application's private data, including SQLite databases, shared preferences, and cache files, making it a primary forensic target.
Question 77: What does the term 'orphaned file' mean in the context of file system forensics?
- A file stored in slack space
- A file whose directory entry exists but has no parent directory reference (Correct answer)
- A file with no read permissions
- A file that has been wiped with DoD-standard overwriting
Correct answer: A file whose directory entry exists but has no parent directory reference
An orphaned file is one whose inode or MFT record still exists but has been disconnected from its parent directory, often due to corruption or anti-forensics techniques.
Question 78: Which type of legal process generally requires the LEAST judicial oversight when obtaining digital records from a third-party provider?
- Search warrant
- Court order under 18 U.S.C. § 2703(d)
- Emergency disclosure request
- Grand jury subpoena (Correct answer)
Correct answer: Grand jury subpoena
A grand jury subpoena requires no judicial approval before issuance, making it the process with the least pre-issuance oversight.
Question 79: Which Volatility plugin would an examiner use to detect process injection by finding executable memory not backed by a file on disk?
- malfind (Correct answer)
- dlllist
- cmdline
- pslist
Correct answer: malfind
The malfind plugin identifies memory regions marked executable/writable that lack a corresponding file on disk, a common indicator of code injection.
Question 80: What is lateral movement in the context of an incident response investigation?
- Moving forensic evidence from one location to another
- Migrating virtual machines between hypervisor hosts
- Transferring data between two forensic workstations
- Techniques used by attackers to progressively move through a network after initial compromise to reach target systems (Correct answer)
Correct answer: Techniques used by attackers to progressively move through a network after initial compromise to reach target systems
Lateral movement refers to attacker techniques such as pass-the-hash, RDP exploitation, or credential theft used to pivot from an initially compromised system to other valuable targets on the same network.
Question 81: When Certified Computer Examiner assessment results are inconclusive, the BEST practice is to:
- Delay until favorable
- Conduct additional assessment using alternative methods (Correct answer)
- Report as definitive
- Discard and start over
Correct answer: Conduct additional assessment using alternative methods
Alternative methods help triangulate and clarify findings.
Question 82: What role does calibration play in Certified Computer Examiner technical accuracy?
- Ensures instruments produce accurate results over time (Correct answer)
- Only needed for new equipment
- Optional for experienced professionals
- Matters only during inspections
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 83: How should Certified Computer Examiner professionals handle updated procedures?
- Review updates, complete training, implement revisions (Correct answer)
- Wait for enforcement
- Apply only to new cases
- Continue original method
Correct answer: Review updates, complete training, implement revisions
Staying current with procedural updates is a professional obligation.
Question 84: When a file is deleted on an NTFS volume, what typically happens to the MFT record?
- The record is marked as available but the data remains (Correct answer)
- The file is moved to a quarantine zone
- It is immediately overwritten with zeros
- The MFT record is encrypted
Correct answer: The record is marked as available but the data remains
Deleting a file in NTFS marks the MFT record as unallocated, but the actual file data and the record itself persist until the space is reused.
Question 85: When a forensic examiner testifies as an expert witness, they are permitted to do something fact witnesses are not, which is:
- Refuse to answer cross-examination questions
- Waive privilege on behalf of the client
- Introduce physical evidence into the record
- Offer opinions and draw conclusions based on specialized knowledge (Correct answer)
Correct answer: Offer opinions and draw conclusions based on specialized knowledge
Under FRE 702, expert witnesses may offer opinion testimony based on their specialized knowledge, skill, experience, training, or education.
Question 86: What is a 'sandbox' in the context of malware analysis?
- A forensic write blocker
- A network segment used for testing patches
- A secure offline backup system
- An isolated virtual environment used to execute and observe malware behavior safely (Correct answer)
Correct answer: An isolated virtual environment used to execute and observe malware behavior safely
A sandbox is an isolated environment (typically a VM) where malware can be executed and monitored without risk of infecting production systems.
Question 87: Which tool is the industry standard for performing RAM acquisition on a live Windows system while minimizing forensic footprint?
- Volatility
- DumpIt (Magnet RAM Capture) (Correct answer)
- Wireshark
- Autopsy
Correct answer: DumpIt (Magnet RAM Capture)
DumpIt/Magnet RAM Capture is widely used for live Windows memory acquisition due to its minimal footprint and single-executable deployment.
Question 88: Which tool is specifically designed to parse and analyze Windows Registry hives for forensic evidence?
- Bulk Extractor
- RegRipper (Correct answer)
- NetworkMiner
- Volatility
Correct answer: RegRipper
RegRipper automates the extraction of forensically relevant data from Windows Registry hives using plugin-based analysis.
Question 89: What is slack space in data recovery?
- Encrypted partition
- Unwritten disk buffer
- Allocated sector
- Unused space that may hold deleted data (Correct answer)
Correct answer: Unused space that may hold deleted data
Slack space refers to the unused portion of the last allocated cluster on a disk that a file occupies. This space, though not part of the active file, can often contain remnants of previously deleted files or other data, making it a valuable source for forensic recovery and uncovering hidden information.
Question 90: A forensic examiner needs to collect volatile data from a live Windows system. What should be collected FIRST?
- Windows registry hives
- Running processes and network connections
- Contents of the RAM (Correct answer)
- Contents of the paging file
Correct answer: Contents of the RAM
RAM contents are the most volatile and will be lost immediately upon shutdown, so they must be captured before any other volatile data collection.
Question 91: A forensic examiner finds a file with a logical size of 1 byte but a physical size of 4,096 bytes on an NTFS volume. What best explains this difference?
- Cluster slack space (Correct answer)
- The file is compressed
- The file is encrypted
- The MFT record is corrupt
Correct answer: Cluster slack space
Cluster slack (file slack) is the unused space between the logical end of file data and the end of the last allocated cluster, which may contain remnants of previously stored data.
Question 92: Which assessment method provides the MOST reliable data for CCE professionals?
- Social media reviews
- Single-source stakeholder data
- Informal verbal feedback
- Standardized tools combined with professional observation (Correct answer)
Correct answer: Standardized tools combined with professional observation
Combining standardized tools with observation provides comprehensive data.
Question 93: Which Bulk Extractor scanner would be most useful for finding credit card numbers in a disk image?
- ccn scanner (Correct answer)
- email scanner
- domain scanner
- url scanner
Correct answer: ccn scanner
Bulk Extractor's ccn (credit card number) scanner uses Luhn algorithm validation to identify potential credit card numbers across the image.
Question 94: Which Windows registry hive contains autorun entries most commonly abused by malware for persistence?
- HKEY_CLASSES_ROOT\CLSID
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run (Correct answer)
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
- HKEY_LOCAL_MACHINE\SAM\SAM\Domains
Correct answer: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
The 'Run' and 'RunOnce' keys under HKCU and HKLM \Software\Microsoft\Windows\CurrentVersion are the most common registry locations malware uses to establish persistence.
Question 95: What does 'rooting' an Android device enable a forensic examiner to accomplish during an investigation?
- Connect the device directly to law enforcement databases remotely
- Reinstall the Android operating system to a known-good state
- Encrypt the device to secure it as evidence
- Gain superuser (root) access to extract data from protected system and data partitions (Correct answer)
Correct answer: Gain superuser (root) access to extract data from protected system and data partitions
Rooting grants superuser privileges, allowing forensic examiners to access protected areas such as the /data partition where application databases, call logs, and messages reside.
Question 96: What is the CORRECT sequence when performing a Certified Computer Examiner technical procedure?
- Execute, then plan
- Document, execute, plan
- Execute immediately, document if issues arise
- Plan, prepare, execute, verify, and document (Correct answer)
Correct answer: Plan, prepare, execute, verify, and document
This systematic sequence ensures quality and accountability.
Question 97: What is a 'hash set' and how is it used in digital evidence collection?
- A database of known file hash values used to identify known good or known bad files (Correct answer)
- A set of hardware tools used to compute hash values in the field
- A collection of hash algorithms applied simultaneously for stronger verification
- A security container for storing cryptographic keys used in evidence encryption
Correct answer: A database of known file hash values used to identify known good or known bad files
A hash set is a database of pre-computed hash values (such as NSRL for known good files or CAID for child exploitation material) used to quickly identify or exclude files during forensic examination.
Question 98: According to NIST SP 800-61, what are the four phases of the incident response lifecycle?
- Triage, Investigation, Remediation, Closure
- Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity (Correct answer)
- Identify, Protect, Detect, Respond
- Planning, Execution, Review, Reporting
Correct answer: Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity
NIST SP 800-61 defines the incident response lifecycle as Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
Question 99: During malware analysis, what is the difference between static and dynamic analysis?
- Static analysis examines the malware without executing it; dynamic analysis runs the malware in a controlled environment (Correct answer)
- Static analysis is faster than dynamic analysis in all cases
- Static analysis runs the malware; dynamic analysis reads the binary without executing it
- Static analysis uses network traffic; dynamic analysis uses memory dumps
Correct answer: Static analysis examines the malware without executing it; dynamic analysis runs the malware in a controlled environment
Static analysis inspects malware code, strings, and structure without execution, while dynamic analysis runs the malware in a sandbox to observe its behavior.
Question 100: What role does calibration play in Certified Computer Examiner technical accuracy?
- Ensures instruments produce accurate results over time (Correct answer)
- Optional for experienced professionals
- Matters only during inspections
- Only needed for new equipment
Correct answer: Ensures instruments produce accurate results over time
Regular calibration prevents measurement drift and ensures reliability.
Question 101: When analyzing a JPEG image for metadata, which tool and metadata type would reveal the GPS coordinates where a photo was taken?
- Binwalk, embedded file analysis
- ExifTool, EXIF GPS metadata (Correct answer)
- Strings tool, ASCII text extraction
- Foremost, file header signatures
Correct answer: ExifTool, EXIF GPS metadata
ExifTool parses EXIF metadata embedded in JPEG files, including GPS latitude/longitude coordinates recorded by camera-enabled devices.
Certified Computer Examiner (CCE)
The CCE, offered by the International Society of Forensic Computer Examiners (ISFCE), validates expertise in digital forensics including evidence acquisition, file system analysis, network investigations, incident response, and forensic reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds