Forensic Analysis and Investigation Techniques Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Forensic Analysis and Investigation Techniques flashcards as text
A forensic examiner is asked to analyze a suspect's cloud storage account. Which legal instrument is typically required to compel a US-based cloud provider to disclose a foreign national's data?
Answer: A warrant under the Stored Communications Act (18 U.S.C. § 2703)
The Stored Communications Act governs compelled disclosure of stored electronic communications from US-based providers, including data belonging to foreign nationals.
During a fraud investigation, an examiner applies Benford's Law to a dataset of expense reimbursements. Which finding would be MOST suspicious?
Answer: An unusually high frequency of entries beginning with the digit 9
Benford's Law predicts that digit 1 leads most frequently; an excess of entries starting with 9 suggests fabricated or manipulated figures.
When conducting a forensic examination of a Linux system, which command provides the most reliable list of recently executed commands, even after the bash history file has been cleared?
Answer: Review auditd logs configured to capture execve system calls
When Linux auditd is configured to log execve system calls, it captures command execution records in a tamper-evident audit log independent of bash history.
An examiner is analyzing a financial fraud case where the suspect used shell companies across multiple jurisdictions. Which investigative technique is most effective for tracing the ultimate beneficial owner?
Answer: Analyzing correspondent banking records and SWIFT message trails
Correspondent banking records and SWIFT message trails document the movement of funds between institutions and can reveal the true controlling parties behind shell structures.
A forensic examiner receives a hard drive that may contain evidence of child exploitation. Before beginning analysis, what is the most critical first step?
Answer: Create a forensic image and verify it with a cryptographic hash
Creating a verified forensic image preserves the original evidence in a legally defensible state and ensures that all subsequent analysis is performed on the copy.
During a corporate espionage investigation, a forensic examiner finds evidence that a suspect printed sensitive documents. Which artifact on a Windows system is most useful for identifying recently printed documents?
Answer: The print spool directory and associated shadow copy metadata
The print spool directory retains spool files and metadata for recent print jobs, and shadow copies may preserve this data even after spool files are deleted.
An investigator is analyzing a suspect's web browser artifacts. Which browser artifact provides the strongest evidence that the suspect intentionally visited a specific URL rather than arriving there through a redirect?
Answer: A typed URL entry in the browser's address bar history
Typed URL history specifically records URLs that the user manually typed into the address bar, distinguishing intentional navigation from redirects or link clicks.