Digital Forensics & Malware Analysis Flashcards
7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital Forensics & Malware Analysis flashcards as text
What is the purpose of YARA rules in malware analysis?
Answer: Scanning files and memory for patterns that identify malware families
YARA rules define string and byte patterns that, when matched in a file or process, identify malware samples belonging to a specific family or campaign.
A forensic examiner recovers a deleted file from an NTFS partition. Which condition must be true for full recovery to be possible?
Answer: The file's data clusters have not been overwritten by new data
When a file is deleted, NTFS marks its clusters as available but does not erase them; if those clusters haven't been reallocated, the file content remains recoverable.
Which anti-forensics technique involves an attacker deliberately changing MAC timestamps on files to mislead investigators?
Answer: Timestomping
Timestomping modifies a file's Modified, Accessed, and Created timestamps to obscure the true timeline of attacker activity.
During a forensic investigation, an examiner finds a file with a .jpg extension but the magic bytes read '50 4B 03 04'. What does this indicate?
Answer: The file is actually a ZIP archive with a renamed extension
Magic bytes 50 4B 03 04 are the signature for ZIP archives (PK header); the .jpg extension is a disguise used to evade file-type filters.
What is the primary use of steganography in a cybersecurity attack?
Answer: Hiding data or commands inside innocent-looking carrier files like images
Steganography conceals data within ordinary files (images, audio, video) so that exfiltrated data or C2 commands appear as legitimate media traffic.
Which log source on a Windows system records successful and failed logon attempts and is critical for intrusion investigations?
Answer: Security event log
The Windows Security event log (Event IDs 4624/4625) records authentication events, making it the primary source for detecting unauthorized access attempts.
A rootkit hides malicious processes by intercepting system calls before they reach the OS kernel. What type of rootkit is this?
Answer: Kernel-mode rootkit
Kernel-mode rootkits operate at ring 0 and hook or patch system call tables to filter OS responses, making malicious processes and files invisible to user-space tools.