โ† All CFE Flashcard Decks

Virtual Facilitation & Technology Flashcards

7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Virtual Facilitation & Technology flashcards as text
  1. A forensic examiner conducting a remote interview via video conferencing must ensure the integrity of witness statements. Which practice BEST preserves evidentiary value of a virtual interview?

    Answer: Recording the session with consent, using a separate capture device as backup

    Recording with consent and maintaining a secondary capture device ensures a complete, tamper-evident record and guards against platform failure.

  2. When using screen-sharing technology to present evidence during a virtual forensic examination, what security risk must the examiner mitigate?

    Answer: Inadvertently exposing unrelated sensitive case files visible on the shared screen

    Screen sharing can reveal other open windows or files; examiners must use application-specific sharing to restrict visible content.

  3. A CFE is investigating potential embezzlement conducted through automated wire transfers triggered by a compromised email account. Which digital artifact is MOST critical to establishing who initiated the unauthorized transfers?

    Answer: Email server authentication logs showing IP address and login timestamps

    Authentication logs tie a specific IP address and timestamp to login events, directly linking access to the fraudulent transfers.

  4. During a virtual facilitation session for fraud training, a participant asks about the admissibility of screenshots as evidence. What is the MOST important factor affecting screenshot admissibility?

    Answer: Authentication that the screenshot accurately represents what was displayed at a specific time

    Screenshots must be authenticated to show they accurately and unalteredly represent the original content at the time it was captured.

  5. An investigator needs to preserve a suspect's live virtual machine (VM) running on a corporate server without shutting it down. Which method BEST captures volatile evidence?

    Answer: Suspending the VM and capturing both memory and disk state simultaneously

    Suspending a VM captures the live memory state alongside disk, preserving volatile data such as running processes and encryption keys.

  6. A company uses a SaaS collaboration tool hosted entirely by a third-party vendor. To lawfully obtain user activity data in a US-based fraud investigation, what is typically the FIRST legal step?

    Answer: Serve the vendor with a subpoena, court order, or search warrant under the Stored Communications Act

    The Stored Communications Act governs access to third-party electronic data; a valid legal process such as a subpoena or warrant is required.

  7. A CFE discovers that a fraud suspect used a deepfake video during a virtual investor presentation to impersonate an executive. Which forensic technique is MOST effective at detecting video deepfakes?

    Answer: Analyzing facial landmark inconsistencies and temporal artifacts using AI-detection tools

    AI deepfake detection tools analyze micro-expressions, blinking patterns, and pixel-level temporal inconsistencies that are difficult to replicate perfectly.