Digital Forensics & Cybercrime Flashcards
7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Forensics & Cybercrime flashcards as text
Which steganographic detection technique analyzes statistical irregularities in the least significant bits of image pixel values to identify hidden data?
Answer: Chi-square analysis
Chi-square analysis detects LSB steganography by comparing the expected statistical distribution of pixel values to the actual distribution, revealing anomalies caused by hidden data embedding.
What is the legal significance of the 'plain view doctrine' in digital forensics searches?
Answer: Evidence discovered inadvertently during a lawful search may be seized without an additional warrant
The plain view doctrine allows seizure of evidence that is immediately apparent as contraband or evidence when encountered during an otherwise lawful search, without requiring a separate warrant.
In malware forensics, a sample repeatedly calls CreateRemoteThread() targeting other processes. This behavior most likely indicates which technique?
Answer: Process injection
CreateRemoteThread() is a Windows API call commonly used by malware to inject and execute code within the address space of another running process.
A forensic examiner must authenticate a copy of a hard drive image. Which combination of hash values provides the strongest evidentiary integrity verification?
Answer: MD5 of the original drive and SHA-256 of the image
Computing both MD5 and SHA-256 on the original drive and the forensic image at the time of acquisition provides dual-algorithm verification that guards against collision attacks and confirms bit-for-bit accuracy.
Under what legal authority can US law enforcement compel a third-party cloud provider to disclose stored communications content?
Answer: The Electronic Communications Privacy Act (ECPA) via a search warrant
Under the Stored Communications Act (part of ECPA), law enforcement must obtain a search warrant supported by probable cause to compel disclosure of stored content from third-party providers.
During ransomware incident response, what is the MOST critical first step after confirming active ransomware encryption?
Answer: Isolate affected systems from the network to prevent lateral spread
Immediate network isolation of infected systems stops ransomware from spreading to additional network resources and encrypting further files, limiting the damage footprint.
Which artifact in macOS is analogous to the Windows Prefetch files and can reveal which applications were recently executed?
Answer: Spotlight index (store.db)
The Spotlight metadata store (store.db) on macOS records file metadata including last-used timestamps, and unified logs/audit logs can reveal application execution, though macOS lacks a direct Prefetch equivalent.