CFE Certified Fraud Examiner Digital Forensics and Technology Fraud 2 — Questions and Answers
Question 1: When a CFE preserves digital evidence, what is the first critical step to ensure admissibility and integrity?
- Copy files directly onto the investigator's laptop
- Create a forensic image and verify it with a hash value (Correct answer)
- Delete temporary files to reduce storage
- Open and review files on the original device
Correct answer: Create a forensic image and verify it with a hash value
Creating a bit-for-bit forensic image and verifying it with a cryptographic hash (MD5 or SHA) ensures the copy is identical to the original and preserves chain of custody.
Question 2: Which metadata attribute can help a CFE determine when a document was originally created on a computer?
- File size
- File creation timestamp (Correct answer)
- File extension
- Font embedded in the document
Correct answer: File creation timestamp
File creation timestamps stored in metadata can indicate when a document was first created, though they can be altered, so corroboration with other evidence is essential.
Question 3: In digital forensics, what does the term 'chain of custody' refer to?
- The sequence of financial transactions in a fraud scheme
- The documented handling of evidence from collection through trial (Correct answer)
- The hierarchy of management involved in approving transactions
- The order in which computer files were accessed
Correct answer: The documented handling of evidence from collection through trial
Chain of custody is the chronological documentation showing the seizure, custody, control, transfer, analysis, and disposition of physical or digital evidence.
Question 4: Which tool is most commonly used by forensic examiners to recover deleted files from a hard drive?
- SQL query analyzer
- EnCase or FTK (forensic imaging software) (Correct answer)
- Wireshark (network packet analyzer)
- Splunk (log management platform)
Correct answer: EnCase or FTK (forensic imaging software)
Forensic imaging software such as EnCase or FTK (Forensic Toolkit) can recover deleted files by accessing unallocated disk space before it is overwritten.
Question 5: What is 'steganography' in the context of digital fraud?
- Encrypting financial data using advanced algorithms
- Hiding secret data within ordinary digital files such as images or audio (Correct answer)
- Creating fake digital invoices with embedded macros
- Spoofing IP addresses to hide network activity
Correct answer: Hiding secret data within ordinary digital files such as images or audio
Steganography is the practice of concealing information within other non-secret data or files (e.g., hiding text inside an image) to avoid detection.
Question 6: Under the Federal Rules of Evidence, electronically stored information (ESI) is considered which type of evidence?
- Hearsay evidence inadmissible without exception
- Documentary evidence subject to authenticity requirements (Correct answer)
- Demonstrative evidence only
- Privileged evidence exempt from discovery
Correct answer: Documentary evidence subject to authenticity requirements
ESI is treated as documentary evidence and must meet authenticity requirements under FRE Rule 901 to be admissible, demonstrating it is what the proponent claims.
When a CFE preserves digital evidence, what is the first critical step to ensure admissibility and integrity?