← All CFC Flashcard Decks

Digital Forensics & Cybercrime Flashcards

7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Forensics & Cybercrime flashcards as text
  1. An investigator finds an encrypted TrueCrypt/VeraCrypt container on a suspect's device. The suspect refuses to provide the password. Which legal doctrine may compel password disclosure in a US federal case?

    Answer: The foregone conclusion doctrine may allow a court to compel decryption

    Under the foregone conclusion doctrine, a court may compel decryption if the government can independently establish the existence, location, and authenticity of the encrypted files, limiting Fifth Amendment protection.

  2. Which type of cyberattack involves sending specially crafted DNS responses to redirect a victim's legitimate domain queries to a malicious IP address?

    Answer: DNS cache poisoning (Kaminsky attack)

    DNS cache poisoning injects fraudulent DNS records into a resolver's cache so that subsequent queries for a legitimate domain resolve to an attacker-controlled IP address.

  3. In forensic timeline analysis, which Windows artifact is most valuable for reconstructing a comprehensive timeline of file system activity including file creation, modification, access, and MFT entry changes?

    Answer: NTFS $MFT with MACB timestamps

    The NTFS Master File Table contains four timestamps per file entry (Modified, Accessed, Changed/$MFT Entry Modified, Born/Created) enabling MACB timeline reconstruction of all file system activity.

  4. A cybercriminal uses a botnet to conduct a distributed denial-of-service (DDoS) attack. Under federal law, which statute most directly criminalizes operating such a botnet?

    Answer: 18 U.S.C. § 1030 (CFAA) — transmission of programs causing damage

    18 U.S.C. § 1030(a)(5) of the CFAA criminalizes knowingly transmitting programs or commands that intentionally cause damage to protected computers, directly covering botnet-driven DDoS operations.

  5. During mobile forensic examination, an analyst uses 'ADB pull' to retrieve files from an Android device. Which extraction type does this represent?

    Answer: Logical extraction

    ADB (Android Debug Bridge) pull commands retrieve files through the operating system layer, making it a logical extraction that returns files as the OS presents them rather than raw disk sectors.

  6. Which anti-forensics technique involves overwriting file metadata timestamps to mislead investigators about when a file was created or modified?

    Answer: Timestomping

    Timestomping is the deliberate manipulation of file system timestamps (MACB times) to conceal the true timeline of file activity and impede forensic investigation.

  7. A forensic consultant is called to testify as an expert witness. Under Federal Rule of Evidence 702, which criterion is NOT a requirement for admissibility of expert testimony?

    Answer: The expert's opinion is shared by a majority of practitioners in the field

    FRE 702 does not require majority agreement in the field (general acceptance is a Frye standard element); under Daubert/FRE 702, reliability and methodological soundness are the key criteria.

Digital Forensics & Cybercrime Flashcards — CFC Study Cards with Answers