Certified Digital Forensic Investigator (CDFI) — Questions and Answers
Question 1: Which legal principle requires evidence to be collected and preserved properly?
- Habeas corpus.
- Exclusionary rule.
- Due process (Correct answer)
- Double jeopardy.
Correct answer: Due process
Due process is a fundamental legal principle that ensures fair treatment through the normal judicial system, including the proper collection and preservation of evidence. It dictates that evidence must be handled according to established procedures to protect the rights of individuals and ensure the integrity and admissibility of evidence in legal proceedings.
Question 2: What is the significance of 'EXIF metadata' embedded in photos from a mobile device in a forensic investigation?
- It stores the device's encryption keys
- It holds the user's cloud account credentials
- It contains GPS coordinates, timestamps, and device information that corroborate or contradict a suspect's alibi (Correct answer)
- It logs every app installation
Correct answer: It contains GPS coordinates, timestamps, and device information that corroborate or contradict a suspect's alibi
EXIF metadata in photos records GPS location, date/time, camera model, and settings, providing investigators with powerful corroborating or contradicting evidence for a suspect's location and timeline.
Question 3: Which technique helps identify hidden or deleted files?
- Network scanning.
- Data encryption.
- File carving (Correct answer)
- Data compression.
Correct answer: File carving
File carving is a powerful technique in digital forensics used to recover files or fragments of files from raw data, even when file system metadata has been deleted or corrupted. It works by searching for known file headers and footers, enabling investigators to reconstruct and retrieve hidden or deleted data that could be crucial evidence.
Question 4: Which tool is commonly used to acquire a live memory image from a Windows system during a forensic investigation?
- Autopsy Browser
- Magnet RAM Capture (formerly DumpIt) (Correct answer)
- Wireshark Packet Analyzer
- WinHex Sector Editor
Correct answer: Magnet RAM Capture (formerly DumpIt)
Magnet RAM Capture (formerly DumpIt) is a purpose-built tool for capturing a full physical memory image from live Windows systems.
Question 5: Which artifact on an Android device stores SMS and MMS messages that a forensic investigator should examine?
- accounts.db
- mmssms.db (Correct answer)
- calendar.db
- contacts2.db
Correct answer: mmssms.db
The mmssms.db SQLite database on Android devices stores all SMS and MMS messages, making it a primary target for communication evidence in mobile forensics.
Question 6: Which technique allows a forensic investigator to reassemble fragmented IP packets for analysis?
- ARP spoofing
- NAT traversal
- Deep packet inspection filtering
- Packet defragmentation (Correct answer)
Correct answer: Packet defragmentation
Packet defragmentation reassembles split IP datagrams in the correct order so investigators can examine the complete payload of transmitted data.
Question 7: What tool is widely used by CDFI investigators to capture and analyze live network traffic packets?
- EnCase
- Wireshark (Correct answer)
- FTK Imager
- Autopsy
Correct answer: Wireshark
Wireshark is the industry-standard open-source packet analyzer used to capture and inspect live and recorded network traffic during forensic investigations.
Question 8: What type of data is typically found in an iOS device's 'iTunes backup' that is valuable for forensic analysis?
- Bootloader firmware exclusively
- Contacts, messages, app data, photos, and call history (Correct answer)
- Kernel crash dumps only
- CPU performance counters
Correct answer: Contacts, messages, app data, photos, and call history
An iTunes/Finder backup contains contacts, SMS/iMessages, photos, call history, app data, and device settings, making it a rich forensic artifact even without physical access.
Question 9: What is 'faraday shielding' used for when handling a suspect's mobile device at the scene?
- Unlocking the device's bootloader
- Charging the device battery safely
- Blocking wireless signals to prevent remote wipe or data alteration (Correct answer)
- Encrypting the device's storage
Correct answer: Blocking wireless signals to prevent remote wipe or data alteration
A Faraday bag or cage blocks cellular, Wi-Fi, and Bluetooth signals, preventing the device from receiving remote wipe commands or new data that could alter evidence.
Question 10: Which factor MOST impacts the usefulness of documentation & best practices outputs in Certified Digital Forensics Investigator?
- Complexity of the analysis
- Format and visual presentation only
- Volume of data collected
- Timeliness, accuracy, and relevance to the intended audience (Correct answer)
Correct answer: Timeliness, accuracy, and relevance to the intended audience
Information is most useful when it is timely, accurate, and relevant to the needs of the people who will use it.
Question 11: Which characteristic BEST describes a successful performance monitoring & optimization culture in Certified Digital Forensics Investigator?
- Focus on compliance over genuine improvement
- Continuous learning where all team members actively seek improvement (Correct answer)
- Top-down directives without employee input
- Periodic campaigns without sustained effort
Correct answer: Continuous learning where all team members actively seek improvement
A culture where all team members actively seek improvement opportunities creates sustainable quality enhancement across the organization.
Question 12: In Certified Digital Forensics Investigator, which system architecture & design practice BEST ensures system reliability?
- Relying on a single point of contact for all technical issues
- Running systems until failure occurs
- Implementing redundancy, regular testing, and documented recovery procedures (Correct answer)
- Updating systems only when vendors release patches
Correct answer: Implementing redundancy, regular testing, and documented recovery procedures
Redundancy, regular testing, and documented recovery procedures create a robust environment that minimizes downtime and data loss.
Question 13: What forensic value do Windows crash dump files (BSOD memory dumps) provide to a digital forensics investigator?
- They are used solely for hardware diagnostics by Microsoft support personnel
- They capture a snapshot of kernel memory at the moment of the crash, preserving process and network artifacts (Correct answer)
- They exclusively contain Windows Event Viewer log entries at crash time
- They store encrypted copies of user account credentials for recovery
Correct answer: They capture a snapshot of kernel memory at the moment of the crash, preserving process and network artifacts
Windows crash dumps preserve kernel memory state including running processes, loaded modules, and network connections at the time of the crash, providing valuable forensic evidence.
Question 14: What is the primary purpose of acquiring volatile memory (RAM) during a digital forensics investigation?
- To preserve encryption keys, passwords, and running process data that would be lost on shutdown (Correct answer)
- To create a forensic backup of the hard drive contents
- To recover deleted files from unallocated filesystem clusters
- To analyze stored network traffic logs from the past 30 days
Correct answer: To preserve encryption keys, passwords, and running process data that would be lost on shutdown
RAM contains volatile data—including encryption keys, active process details, and credentials—that is permanently lost when the system powers off.
Question 15: In network forensics, what is the significance of a 'golden ticket' attack in Kerberos traffic logs?
- It marks normal load-balancer behavior
- It means an attacker forged a Kerberos TGT for persistent unauthorized access (Correct answer)
- It identifies a DNS misconfiguration
- It indicates a successful patch update
Correct answer: It means an attacker forged a Kerberos TGT for persistent unauthorized access
A golden ticket attack involves forging a Kerberos Ticket Granting Ticket using a stolen KRBTGT hash, granting attackers long-term, stealthy domain access.
Question 16: What is a key characteristic of an effective incident response team?
- Limited communication.
- Unclear roles.
- Slow decision-making.
- Trained and coordinated team (Correct answer)
Correct answer: Trained and coordinated team
A key characteristic of an effective incident response team is that it is well-trained and highly coordinated. Team members must possess the necessary technical skills, clearly understand their roles and responsibilities, and be able to communicate and collaborate seamlessly under pressure. This preparedness ensures a swift, efficient, and effective response to security incidents, minimizing their impact.
Question 17: What is 'flow analysis' in the context of network forensics?
- Reviewing summarized metadata about network conversations without full packet contents (Correct answer)
- Examining physical cable connections
- Analyzing application source code
- Recovering corrupted network logs
Correct answer: Reviewing summarized metadata about network conversations without full packet contents
Flow analysis examines NetFlow/IPFIX metadata (source, destination, ports, bytes, duration) to detect anomalies without needing full packet payloads.
Question 18: Which forensic tool is widely recognized for mobile device acquisition and analysis in the US law enforcement community?
- Autopsy
- Volatility
- Cellebrite UFED (Correct answer)
- FTK Imager
Correct answer: Cellebrite UFED
Cellebrite UFED (Universal Forensic Extraction Device) is the industry-leading tool used by US law enforcement for mobile device data extraction and analysis.
Question 19: In memory forensics, what does the malware technique known as 'process hollowing' involve?
- Compressing idle process memory to free up available RAM
- Injecting malicious code into a suspended process after unmapping its original memory (Correct answer)
- A legitimate Windows process consuming excessive RAM resources
- Encrypting process memory to prevent forensic extraction
Correct answer: Injecting malicious code into a suspended process after unmapping its original memory
Process hollowing is a code injection technique where a legitimate process is started in suspended state, its memory is unmapped, and replaced with malicious code to evade detection.
Question 20: Which factor BEST indicates mastery of troubleshooting & problem resolution in Certified Digital Forensics Investigator?
- The ability to adapt knowledge and skills to varying contexts while maintaining standards (Correct answer)
- Number of certifications held
- Speed of task completion
- Years of experience in a single setting
Correct answer: The ability to adapt knowledge and skills to varying contexts while maintaining standards
True mastery is demonstrated by the ability to apply knowledge flexibly across different contexts while consistently maintaining quality standards.
Question 21: What is the forensic significance of finding a process in memory whose executable image path differs from its expected on-disk location?
- It indicates the executable is loading from a mapped network drive
- It may indicate process masquerading or a code injection technique used by malware (Correct answer)
- It indicates the executable was recently updated through Windows Update
- It is entirely normal behavior for all Windows system service processes
Correct answer: It may indicate process masquerading or a code injection technique used by malware
A mismatch between the in-memory image path and the expected on-disk location is a strong indicator of process name spoofing or malware injecting into a legitimate process.
Question 22: What should be avoided during evidence handling?
- Using write blockers.
- Avoiding evidence contamination (Correct answer)
- Detailed documentation.
- Proper labeling.
Correct answer: Avoiding evidence contamination
During evidence handling, avoiding contamination is paramount to preserve the integrity and admissibility of digital evidence. Contamination can introduce foreign data, alter existing data, or compromise the chain of custody, rendering the evidence unreliable or inadmissible in court. Strict protocols, such as using write blockers and maintaining a sterile environment, are followed to prevent any alteration.
Question 23: What does analyzing a mobile device's 'location history' (e.g., from Google Maps or iOS Significant Locations) provide in a forensic investigation?
- Details of Wi-Fi passwords stored on the device
- The user's app purchase history
- The device's manufacturing date
- A timeline of physical locations visited by the device and its user (Correct answer)
Correct answer: A timeline of physical locations visited by the device and its user
Location history logs store timestamped GPS coordinates of places the device visited, enabling investigators to build a precise physical movement timeline for a suspect.
Question 24: When facing an unfamiliar challenge in troubleshooting & problem resolution within Certified Digital Forensics Investigator, what is the BEST approach?
- Avoid the challenge if possible
- Attempt to resolve it independently without consultation
- Research established best practices, consult colleagues, and document the approach (Correct answer)
- Apply the most familiar technique regardless of suitability
Correct answer: Research established best practices, consult colleagues, and document the approach
Researching best practices and consulting colleagues combines established knowledge with practical experience, while documentation supports future reference.
Question 25: How should system architecture & design upgrades be managed in a Certified Digital Forensics Investigator environment?
- By upgrading all systems simultaneously without staging
- By implementing changes immediately without testing
- Only during business hours for maximum visibility
- Through a structured change management process with testing and rollback plans (Correct answer)
Correct answer: Through a structured change management process with testing and rollback plans
A structured change management process with testing and rollback plans minimizes risk and ensures upgrades do not disrupt operations.
Question 26: Which forensic artifact from a firewall is most valuable for reconstructing an attacker's lateral movement through a network?
- SSL certificate expiration dates
- DHCP lease duration settings
- DNS TTL cache entries
- Firewall connection logs showing accepted/denied traffic between internal hosts (Correct answer)
Correct answer: Firewall connection logs showing accepted/denied traffic between internal hosts
Firewall connection logs record accepted and denied traffic between hosts, allowing investigators to trace an attacker's path as they moved laterally across the network.
Question 27: Why is consent important before collecting digital evidence?
- To confuse suspects.
- To ensure lawful evidence collection (Correct answer)
- To speed up data deletion.
- To ignore privacy laws.
Correct answer: To ensure lawful evidence collection
Consent is paramount before collecting digital evidence to ensure the entire process is lawful and respects privacy rights. Without explicit consent from the owner or a legal warrant, any collected data may be deemed inadmissible in court, undermining the investigation's validity. This step upholds legal and ethical standards, protecting both the evidence and the rights of individuals.
Question 28: In cloud forensics, what is a 'legal hold' and why is it critical to issue one quickly?
- A court order to shut down a cloud service
- A tool for encrypting cloud evidence
- A software lock preventing cloud account login
- A formal notification to a cloud provider to preserve data and suspend normal deletion processes (Correct answer)
Correct answer: A formal notification to a cloud provider to preserve data and suspend normal deletion processes
A legal hold instructs the cloud provider to suspend routine data deletion and preserve relevant evidence; delayed issuance risks evidence being permanently destroyed by automatic retention policies.
Question 29: During mobile forensics, what is 'app data sandboxing' and how does it affect evidence collection?
- A cloud backup mechanism for app settings
- A testing environment for malware analysis
- A feature that deletes app data after 30 days
- iOS/Android isolation of each app's data in its own directory, limiting cross-app access and requiring elevated privileges to extract (Correct answer)
Correct answer: iOS/Android isolation of each app's data in its own directory, limiting cross-app access and requiring elevated privileges to extract
App sandboxing restricts each app's data to its own protected directory; forensic investigators typically need a jailbreak/root or physical extraction to access sandboxed app data from competing apps.
Question 30: When forensically examining a SIM card from a mobile device, which type of data can be extracted?
- International Mobile Subscriber Identity (IMSI), stored contacts, and limited SMS records (Correct answer)
- Photos and videos
- Full device encryption keys
- Installed application binaries
Correct answer: International Mobile Subscriber Identity (IMSI), stored contacts, and limited SMS records
A SIM card stores the IMSI (subscriber identity), carrier information, some contacts, and a limited number of SMS messages independent of the device's internal storage.
Question 31: What is the PRIMARY objective of security & access control within the Certified Digital Forensics Investigator profession?
- To create additional requirements for practitioners
- To limit the scope of professional activities
- To maintain the status quo without change
- To ensure quality outcomes through standardized practices and continuous improvement (Correct answer)
Correct answer: To ensure quality outcomes through standardized practices and continuous improvement
The primary objective is ensuring quality outcomes through established standards while continuously improving practices and processes.
Certified Digital Forensic Investigator (CDFI)
The CDFI is a master-level certification from Mile2 that validates expertise in conducting comprehensive digital forensic investigations, combining computer/disk forensics, mobile and cloud evidence acquisition, network forensics, and forensic case management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds