← All CCE Flashcard Decks

Mixed Deck — All CCE Topics Flashcards

100 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CCE Topics flashcards as text
  1. Which mobile device extraction method provides the most comprehensive forensic data, including deleted files and unallocated space?

    Answer: Physical extraction

    Physical extraction creates a bit-by-bit copy of the entire device storage, including deleted data and unallocated space, making it the most comprehensive method.

  2. What does JTAG stand for in the context of mobile device forensics?

    Answer: Joint Test Action Group

    JTAG stands for Joint Test Action Group, an industry standard hardware interface originally for circuit testing that forensic examiners use to access device memory directly through test ports.

  3. A first responder arrives at a scene where a desktop computer is running. Network cables are connected. What should be done regarding the network connection?

    Answer: Document the connection state before deciding whether to disconnect

    The examiner should document the current state of network connections before taking any action, as the decision to disconnect depends on case specifics and may need to be justified later.

  4. What is 'chip-off' forensics and when is it typically employed?

    Answer: Physically removing flash memory chips from a device to read them directly with specialized equipment

    Chip-off forensics involves physically desoldering and removing flash memory chips (NAND/NOR) from a device to read their raw contents when software-based acquisition methods fail.

  5. Which layer of the OSI model do MAC addresses belong to, and why is this relevant to network forensics?

    Answer: Layer 2 – Data Link

    MAC addresses operate at Layer 2 (Data Link) and can help investigators identify specific network interface cards involved in an incident.

  6. When examining the $UsnJrnl ($J) file in NTFS, what type of evidence does a forensic examiner primarily find?

    Answer: A chronological log of file system changes including creates, deletes, and renames

    The NTFS Update Sequence Number Journal ($UsnJrnl) records change reasons and timestamps for file and directory operations, providing a timeline of file system activity.

  7. The 'plain view' doctrine in digital forensics allows examiners to:

    Answer: Seize evidence found in plain sight during a lawful search

    The plain view doctrine permits seizure of evidence that is immediately apparent and observed during a lawful search.

  8. Which file system is commonly used by Windows operating systems?

    Answer: NTFS

    NTFS (New Technology File System) is the default and most commonly used file system for Microsoft Windows operating systems. It offers advanced features compared to older file systems, including improved security, journaling for data integrity, support for large files and volumes, and robust data recovery capabilities.

  9. During evidence packaging, what should be used to package hard drives to protect against electrostatic discharge?

    Answer: Anti-static bags and foam padding

    Hard drives must be packaged in anti-static bags to prevent electrostatic discharge damage, combined with foam padding for physical shock protection during transport.

  10. In the context of digital forensics, 'spoliation' refers to:

    Answer: The intentional or negligent destruction or alteration of evidence

    Spoliation is the destruction or material alteration of evidence, which can result in adverse inference instructions against the responsible party.

  11. What is the primary purpose of the $MFT file in NTFS forensics?

    Answer: Track all file and directory metadata on the volume

    The Master File Table ($MFT) contains metadata records for every file and directory on an NTFS volume.

  12. What is the role of the Volume Boot Record (VBR) in a FAT or NTFS volume?

    Answer: Contains the BPB and bootstrap code needed to mount the volume

    The Volume Boot Record contains the BIOS Parameter Block (BPB), which describes volume geometry and layout, and bootstrap code that initiates the OS loading process.

  13. What is the main purpose of journaling in a file system?

    Answer: Maintains file system integrity

    The main purpose of journaling in a file system is to maintain file system integrity, especially after unexpected system crashes or power failures. By logging changes to be made to the file system in a separate journal before committing them, the system can quickly recover to a consistent state, preventing data corruption and ensuring reliability.

  14. What types of information can be recovered from a mobile device's GPS and location-related artifacts during a forensic examination?

    Answer: Historical location trails, geotagged media metadata, and cached location data from apps

    Mobile devices accumulate rich historical location data across multiple artifact types including GPS logs, geotagged photo EXIF data, cached map tiles, and location-aware application databases.

  15. Which mobile data acquisition method uses the device's own operating system APIs to access and export user data?

    Answer: Logical extraction

    Logical extraction leverages the device's built-in operating system APIs and backup interfaces to access and export data, retrieving only what the OS exposes as accessible.

  16. What does ADB stand for, and what is its primary use in Android forensics?

    Answer: Android Debug Bridge — for communication between a computer and an Android device

    Android Debug Bridge (ADB) is a command-line tool that allows forensic examiners to communicate with, issue shell commands to, and extract data from Android devices.

  17. A forensic examiner finds a file with a logical size of 1 byte but a physical size of 4,096 bytes on an NTFS volume. What best explains this difference?

    Answer: Cluster slack space

    Cluster slack (file slack) is the unused space between the logical end of file data and the end of the last allocated cluster, which may contain remnants of previously stored data.

  18. The 'fruit of the poisonous tree' doctrine means that:

    Answer: Evidence obtained through an unlawful search may be inadmissible along with subsequent evidence it led to

    This doctrine excludes evidence discovered as a result of an illegal search, as it is tainted by the original constitutional violation.

  19. An investigator finds a file with MAC times all identical and very recent. This most likely indicates:

    Answer: Timestomping was used to obscure the file's true age

    Timestomping is an anti-forensic technique that modifies file timestamps; all-identical recent times often indicate deliberate manipulation.

  20. Which factor MOST affects quality of CCE technical outcomes?

    Answer: Practitioner's training, preparation, and attention to detail

    The practitioner's competence is the most significant factor.