Disk & Memory Forensics Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Disk & Memory Forensics flashcards as text
Which Windows Event Log ID records successful user logon events and is critical for authentication timeline analysis?
Answer: 4624
Event ID 4624 is generated on successful account logon and contains logon type, username, source IP, and session ID.
In memory forensics, what does a 'VAD' (Virtual Address Descriptor) tree represent?
Answer: Memory regions mapped within a process's virtual address space
The VAD tree is a kernel structure describing each memory region in a process, including permissions, type (heap/stack/mapped file), and backing file.
Which anti-forensic technique involves overwriting file data with zeros or random data before deletion to prevent recovery?
Answer: Secure deletion / file wiping
Secure deletion tools overwrite file content before unlinking it, preventing file carving or slack space recovery.
An analyst examines a Linux system and finds cron jobs in /var/spool/cron/crontabs for root running a script every 5 minutes. This is relevant to forensics because it indicates:
Answer: A potential persistence mechanism
Scheduled tasks in cron are a common persistence mechanism for malware to survive reboots and maintain access.
Which Windows artifact records USB device connection history including vendor ID, product ID, and first/last connection times?
Answer: HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
USBSTOR registry key records metadata for every USB storage device ever connected, including serial numbers and timestamps.
During memory analysis, which structure helps identify the parent-child relationship between processes to detect suspicious spawning?
Answer: EPROCESS.InheritedFromUniqueProcessId
The InheritedFromUniqueProcessId field in EPROCESS stores the parent PID, allowing detection of anomalies like cmd.exe spawned by a browser.
What is 'slack space' in disk forensics?
Answer: Space between the end of a file and the end of its allocated cluster
Slack space is the unused area between a file's logical end and its last allocated cluster boundary, which can contain remnants of previously stored data.