← All CDFI Flashcard Decks

Mixed Deck — All CDFI Topics Flashcards

100 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CDFI Topics flashcards as text
  1. Which NetFlow data element is most useful for identifying the volume of data transferred between two hosts?

    Answer: Byte count

    The byte count field in NetFlow records indicates the total bytes transferred in a flow, which is key to detecting data exfiltration.

  2. What forensic artifact would BEST help an investigator determine which Wi-Fi networks a mobile device has previously connected to?

    Answer: The device's saved/preferred Wi-Fi network list stored in configuration files

    Mobile devices maintain a list of previously connected Wi-Fi networks (SSIDs and credentials) in configuration files, which can place the device at specific physical locations associated with those networks.

  3. Which factor MOST impacts the usefulness of documentation & best practices outputs in Certified Digital Forensics Investigator?

    Answer: Timeliness, accuracy, and relevance to the intended audience

    Information is most useful when it is timely, accurate, and relevant to the needs of the people who will use it.

  4. Why is chain of custody important in digital forensics?

    Answer: To prevent evidence tampering and maintain integrity

    Chain of custody is a critical legal principle in digital forensics that establishes a chronological record of evidence handling. It ensures that evidence has not been tampered with, altered, or compromised from the moment it's collected until it's presented in court, thereby preserving its integrity and admissibility.

  5. When implementing project planning & deployment changes in Certified Digital Forensics Investigator, what factor is MOST critical?

    Answer: Stakeholder buy-in and a clear change management plan

    Stakeholder buy-in and a structured change management plan significantly increase the likelihood of successful implementation.

  6. Which metric BEST indicates successful project planning & deployment in Certified Digital Forensics Investigator?

    Answer: Achievement of defined key performance indicators and stakeholder satisfaction

    KPI achievement and stakeholder satisfaction directly measure whether management activities are producing desired outcomes.

  7. What is the PRIMARY benefit of standardizing system architecture & design practices in Certified Digital Forensics Investigator?

    Answer: Consistency, easier maintenance, and improved collaboration among team members

    Standardization promotes consistency across the organization, simplifies maintenance, and enables better collaboration between team members.

  8. In memory forensics, what does the malware technique known as 'process hollowing' involve?

    Answer: Injecting malicious code into a suspended process after unmapping its original memory

    Process hollowing is a code injection technique where a legitimate process is started in suspended state, its memory is unmapped, and replaced with malicious code to evade detection.

  9. Which factor BEST indicates mastery of security & access control in Certified Digital Forensics Investigator?

    Answer: The ability to adapt knowledge and skills to varying contexts while maintaining standards

    True mastery is demonstrated by the ability to apply knowledge flexibly across different contexts while consistently maintaining quality standards.

  10. Which practice helps prevent contamination of digital evidence?

    Answer: Wearing gloves and using clean tools

    To prevent contamination of digital evidence, it is crucial to handle devices with care and minimize any potential for alteration or introduction of foreign material. Wearing gloves prevents the transfer of fingerprints and oils, while using clean, forensically sound tools ensures no new data is written to the device. These practices maintain the integrity of the evidence for analysis and legal admissibility, preserving its evidential value.

  11. What is the PRIMARY objective of implementation & configuration within the Certified Digital Forensics Investigator profession?

    Answer: To ensure quality outcomes through standardized practices and continuous improvement

    The primary objective is ensuring quality outcomes through established standards while continuously improving practices and processes.

  12. In Certified Digital Forensics Investigator, how does security & access control contribute to professional credibility?

    Answer: By demonstrating competence, maintaining standards, and delivering consistent results

    Professional credibility is built through demonstrated competence, consistent adherence to standards, and reliable delivery of quality results.

  13. What is the forensic significance of finding a process in memory whose executable image path differs from its expected on-disk location?

    Answer: It may indicate process masquerading or a code injection technique used by malware

    A mismatch between the in-memory image path and the expected on-disk location is a strong indicator of process name spoofing or malware injecting into a legitimate process.

  14. When implementing data management & integration changes in Certified Digital Forensics Investigator, what factor is MOST critical?

    Answer: Stakeholder buy-in and a clear change management plan

    Stakeholder buy-in and a structured change management plan significantly increase the likelihood of successful implementation.

  15. Why is recovery a critical phase?

    Answer: It restores normal operations

    Recovery is a critical phase in incident response because its primary goal is to restore affected systems and services to normal, secure operation. This involves rebuilding systems, restoring data from backups, and verifying functionality after the threat has been eradicated. A successful recovery minimizes business disruption, ensures continuity, and reinforces the organization's resilience.

  16. Which metric BEST indicates successful data management & integration in Certified Digital Forensics Investigator?

    Answer: Achievement of defined key performance indicators and stakeholder satisfaction

    KPI achievement and stakeholder satisfaction directly measure whether management activities are producing desired outcomes.

  17. Which Volatility plugin best detects processes hidden by DKOM by scanning raw memory pool tags rather than walking linked lists?

    Answer: psscan

    `psscan` scans physical memory for EPROCESS pool tags directly, finding processes that DKOM has unlinked from the active process list.

  18. Which extraction method provides the most complete data from a modern locked Android device during a CDFI investigation?

    Answer: Physical extraction using chip-off or JTAG methods

    Physical extraction methods like chip-off or JTAG access raw flash memory, bypassing device locks to obtain the most complete dataset including deleted data.

  19. In cloud forensics, what is a 'legal hold' and why is it critical to issue one quickly?

    Answer: A formal notification to a cloud provider to preserve data and suspend normal deletion processes

    A legal hold instructs the cloud provider to suspend routine data deletion and preserve relevant evidence; delayed issuance risks evidence being permanently destroyed by automatic retention policies.

  20. What role does software analysis play in forensics?

    Answer: It analyzes software behavior for evidence

    Software analysis in forensics involves examining applications, operating systems, and other software components to understand their functionality, identify malicious behavior, or extract relevant data. This process helps uncover how a system was used, what actions were performed, and whether any unauthorized software was present, providing crucial evidence for an investigation.