Disk & Memory Forensics Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Disk & Memory Forensics flashcards as text
Which file system artifact stores metadata about deleted files in Windows NTFS volumes?
Answer: $Recycle.Bin
$Recycle.Bin retains metadata (original path, deletion time) about deleted files until they are permanently purged.
An investigator finds a memory dump where the EPROCESS list appears intact but scanning with a pool-tag tool reveals hidden processes. Which technique was most likely used?
Answer: DKOM (Direct Kernel Object Manipulation)
DKOM unlinks EPROCESS entries from the doubly-linked list, hiding processes from list-based tools while pool allocations remain.
When imaging a hard drive using dd, which flag ensures that read errors do not halt the acquisition?
Answer: conv=noerror
conv=noerror instructs dd to continue past read errors, typically paired with conv=sync to pad bad blocks.
Which Windows registry hive contains the most recently accessed files and applications for a specific user?
Answer: HKCU\NTUSER.DAT
NTUSER.DAT is the per-user hive loaded into HKCU; it contains RecentDocs, UserAssist, and other user-activity artifacts.
A forensic analyst needs to recover timestamps that were altered by anti-forensic timestomping. Which NTFS artifact is most useful for comparison?
Answer: $MFT File Name attribute
The $FILE_NAME attribute timestamps are harder to modify via user-mode tools and often differ from the $STANDARD_INFORMATION timestamps after timestomping.
In a Windows memory image, which Volatility plugin is best for detecting injected code in a process that has no corresponding file on disk?
Answer: malfind
malfind scans process VAD entries for executable memory regions that lack a mapped file on disk, a strong indicator of code injection.
Which hash algorithm is preferred over MD5 for forensic evidence integrity verification in modern investigations?
Answer: SHA-256
SHA-256 is collision-resistant and cryptographically stronger than MD5 or SHA-1, making it the current standard for evidence hashing.