โ† All CCE Flashcard Decks

Computer Forensics Tools & Techniques Flashcards

7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Computer Forensics Tools & Techniques flashcards as text
  1. Which Autopsy feature allows investigators to identify files that have been deliberately hidden by renaming their extensions?

    Answer: File signature analysis

    File signature analysis compares a file's magic bytes against its extension to detect mismatches indicating hidden content.

  2. When using FTK Imager to acquire a live system, which artifact is most critical to capture before shutting down the machine?

    Answer: Volatile RAM contents

    Volatile RAM contains active processes, network connections, encryption keys, and running malware that are lost upon shutdown.

  3. In Wireshark, which display filter would isolate only DNS query traffic?

    Answer: dns.flags.response == 0

    The filter dns.flags.response == 0 specifically isolates DNS query packets, excluding responses.

  4. What is the primary purpose of the $MFT file in NTFS forensics?

    Answer: Track all file and directory metadata on the volume

    The Master File Table ($MFT) contains metadata records for every file and directory on an NTFS volume.

  5. A suspect used CCleaner before seizure. Which forensic artifact is MOST likely to survive CCleaner's default cleaning?

    Answer: VSS shadow copies

    Volume Shadow Copy Service (VSS) snapshots are typically not touched by CCleaner's default cleaning routines.

  6. Which steganography detection technique analyzes statistical anomalies in the least significant bits of image pixels?

    Answer: RS (Regular-Singular) analysis

    RS analysis detects LSB steganography by measuring statistical regularities that become disturbed when data is hidden in pixel values.

  7. When examining a suspect's iPhone using Cellebrite UFED, which extraction method provides the most complete data including deleted records?

    Answer: Physical extraction

    Physical extraction acquires a bit-for-bit image of the device's flash memory, enabling recovery of deleted data and unallocated space.