Digital Forensics & Cybercrime Flashcards
7 cards from real CFC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Digital Forensics & Cybercrime flashcards as text
Which memory forensics artifact can reveal the full command-line arguments used to launch a malicious process, even after the process has terminated?
Answer: Windows Event ID 4688 (process creation) in Security logs
Windows Security Event ID 4688 logs process creation events including full command-line arguments when process auditing is enabled, persisting on disk even after the process ends.
A social engineering attack where criminals call employees posing as IT support to obtain credentials is best classified as which type of attack?
Answer: Vishing (voice phishing)
Vishing (voice phishing) uses telephone calls where attackers impersonate trusted entities such as IT support to manipulate victims into revealing credentials or sensitive information.
During forensic analysis of a Linux system, which log file typically contains authentication failures, SSH login attempts, and sudo usage?
Answer: /var/log/auth.log (or /var/log/secure on RHEL)
/var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL/CentOS) records PAM authentication events, SSH sessions, and privilege escalation attempts via sudo.
What is 'living off the land' (LotL) in the context of cybercrime investigations, and why does it complicate digital forensics?
Answer: Attackers use legitimate built-in system tools (e.g., PowerShell, WMI) to carry out attacks, reducing malware artifacts
Living off the land attacks leverage native OS utilities and signed binaries, leaving minimal malware artifacts and making detection harder because the tools themselves are legitimate.
A chain of custody document for digital evidence must include which MINIMUM set of information for each transfer?
Answer: Date/time, transferring party, receiving party, and purpose of transfer
A valid chain of custody record must capture when the transfer occurred, who released the evidence, who received it, and the reason for the transfer at each handoff.
Which technique allows an attacker to execute arbitrary code by overflowing a buffer in the stack and overwriting the saved return address?
Answer: Stack-based buffer overflow
A stack-based buffer overflow overwrites adjacent stack memory including the saved return address, redirecting execution flow to attacker-controlled shellcode or a ROP gadget chain.
In cryptocurrency forensic investigations, which analytical technique clusters multiple Bitcoin addresses into a single entity based on their co-spending patterns in transactions?
Answer: Common-input ownership heuristic (co-spending clustering)
The common-input ownership heuristic groups addresses that appear together as inputs in the same transaction, inferring they are controlled by the same wallet or entity.