โ† All CFE Flashcard Decks

Forensic Analysis and Investigation Techniques Flashcards

7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Forensic Analysis and Investigation Techniques flashcards as text
  1. During a forensic investigation, an examiner discovers that log files on a suspect's server have been selectively deleted. Which technique is most appropriate to recover metadata about deleted log entries?

    Answer: Analyze journal or transaction logs from the file system

    File system journals and transaction logs record metadata about file operations, including deletions, and can reveal information about deleted log entries.

  2. A forensic examiner is analyzing volatile memory captured from a running system. Which artifact is LEAST likely to be found in a RAM dump?

    Answer: Historical browser cookies stored on disk

    Browser cookies stored on disk are persistent artifacts and are not part of volatile memory; they reside in the file system rather than RAM.

  3. When reconstructing a timeline of events in a fraud investigation, which timestamp attribute on NTFS file systems is most commonly manipulated by anti-forensic tools?

    Answer: $STANDARD_INFORMATION timestamps

    $STANDARD_INFORMATION timestamps are easily modified by user-mode tools, while $FILE_NAME timestamps require kernel-level access and are harder to alter.

  4. An investigator is examining a suspect's smartphone and finds encrypted messaging app data. The encryption keys are stored in the device's Secure Enclave. What is the most effective approach to access the plaintext messages?

    Answer: Obtain a lawful order compelling the suspect to provide the passcode

    When encryption keys are protected by a Secure Enclave tied to the user's passcode, compelling the user via legal process is often the most practical avenue.

  5. During network forensics, an examiner finds that an attacker used DNS tunneling to exfiltrate data. Which characteristic of the captured DNS traffic best confirms this technique?

    Answer: Abnormally long subdomain strings in DNS queries

    DNS tunneling encodes data within subdomain labels, resulting in unusually long, high-entropy subdomain strings in query traffic.

  6. A CFE is reconstructing financial transactions from a hard drive where the file allocation table has been corrupted. Which carving technique should be used first?

    Answer: Header-footer carving based on known file signatures

    Header-footer carving identifies files by their known magic bytes and file signatures, bypassing the need for a functional file allocation table.

  7. In an investigation involving insider trading, a forensic examiner reviews email metadata. Which metadata field is most useful for proving that an email was sent before a specific market event?

    Answer: The 'Date' header with server-stamped Received timestamps

    The 'Date' header combined with Received timestamps added by mail servers provides a verifiable chronological record that is difficult to falsify across multiple servers.