โ† All CFE Flashcard Decks

Virtual Facilitation & Technology Flashcards

7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Virtual Facilitation & Technology flashcards as text
  1. A forensic examiner is tasked with recovering deleted messages from a cloud-based collaboration platform like Microsoft Teams. Which artifact location is most likely to contain recoverable message data on a Windows endpoint?

    Answer: IndexedDB files in the application's local cache directory

    Microsoft Teams stores message data locally in IndexedDB files within the app's local cache, making it a primary recovery target.

  2. When conducting a forensic investigation of a Zoom meeting recording stored in the cloud, which chain of custody step is most critical before downloading the file?

    Answer: Capture a cryptographic hash of the file before downloading

    Capturing a hash before download establishes the original file's integrity and protects against claims of tampering.

  3. A suspect allegedly exfiltrated confidential data via a virtual private network (VPN). What is the MOST reliable forensic artifact on the suspect's machine to confirm VPN usage?

    Answer: VPN connection logs and configuration files stored locally

    VPN configuration files and connection logs provide direct evidence of VPN use, including connection timestamps and server endpoints.

  4. During a virtual fraud investigation, an examiner needs to establish the timeline of a suspect's online activity. Which artifact provides the MOST precise timestamping across different time zones?

    Answer: Server-side logs with UTC timestamps

    Server-side logs use UTC timestamps, eliminating time zone ambiguity and providing a consistent, authoritative timeline.

  5. An investigator analyzing a video-conferencing tool on a corporate laptop discovers ephemeral (end-to-end encrypted) chat messages that were deleted. Which approach offers the BEST chance of recovery?

    Answer: Acquire a forensic image of the device and analyze unallocated space

    Deleted data may persist in unallocated disk space; a forensic image allows file carving and recovery before overwriting occurs.

  6. Which metadata field in a Zoom cloud recording is most useful for proving a specific participant was actively speaking at a given moment?

    Answer: Active speaker timeline embedded in the recording metadata

    Zoom's active speaker timeline metadata logs which participant was speaking at each timestamp, providing strong attribution evidence.

  7. A forensic examiner is analyzing Slack workspace data exported by a corporate administrator. Which limitation must be disclosed when presenting this evidence?

    Answer: Administrator-exported data may exclude direct messages in free workspaces

    Slack's free-tier export does not include direct messages, meaning key communications may be absent from the evidence set.