โ† All CCE Flashcard Decks

Computer Forensics Tools & Techniques Flashcards

7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Computer Forensics Tools & Techniques flashcards as text
  1. Which tool is specifically designed to parse and analyze Windows Registry hives for forensic evidence?

    Answer: RegRipper

    RegRipper automates the extraction of forensically relevant data from Windows Registry hives using plugin-based analysis.

  2. In a Windows system, the ShellBags registry key primarily records evidence of:

    Answer: Folder browsing history including deleted folders

    ShellBags store Windows Explorer folder view settings and persist even after the folder is deleted, revealing browsing history.

  3. What does the Volatility framework's 'pslist' plugin enumerate during memory forensics?

    Answer: Active processes from the EPROCESS doubly linked list

    The pslist plugin walks the EPROCESS doubly linked list in memory to enumerate active processes at the time of the memory capture.

  4. Which file carving technique reconstructs files based on header and footer signatures rather than file system metadata?

    Answer: Signature-based carving

    Signature-based carving identifies file boundaries using known magic bytes (headers) and terminators (footers) to reconstruct files from raw disk data.

  5. An investigator finds a file with MAC times all identical and very recent. This most likely indicates:

    Answer: Timestomping was used to obscure the file's true age

    Timestomping is an anti-forensic technique that modifies file timestamps; all-identical recent times often indicate deliberate manipulation.

  6. Which Bulk Extractor scanner would be most useful for finding credit card numbers in a disk image?

    Answer: ccn scanner

    Bulk Extractor's ccn (credit card number) scanner uses Luhn algorithm validation to identify potential credit card numbers across the image.

  7. During network forensics, which protocol analysis would reveal encrypted C2 (command-and-control) communication by analyzing traffic patterns rather than content?

    Answer: Behavioral/traffic flow analysis

    Behavioral traffic flow analysis examines packet timing, size, and frequency patterns to identify C2 beaconing even when content is encrypted.