CFE Virtual Facilitation & Technology 3 — Questions and Answers
Question 1: A forensic examiner conducting a remote interview via video conferencing must ensure the integrity of witness statements. Which practice BEST preserves evidentiary value of a virtual interview?
- Conducting the interview without any recording to avoid GDPR concerns
- Recording the session with consent, using a separate capture device as backup (Correct answer)
- Relying solely on the examiner's written notes taken during the call
- Using the platform's built-in transcription feature as the sole record
Correct answer: Recording the session with consent, using a separate capture device as backup
Recording with consent and maintaining a secondary capture device ensures a complete, tamper-evident record and guards against platform failure.
Question 2: When using screen-sharing technology to present evidence during a virtual forensic examination, what security risk must the examiner mitigate?
- Overloading the suspect's network bandwidth
- Inadvertently exposing unrelated sensitive case files visible on the shared screen (Correct answer)
- Degrading the quality of forensic images during sharing
- Causing the suspect to disconnect from the call
Correct answer: Inadvertently exposing unrelated sensitive case files visible on the shared screen
Screen sharing can reveal other open windows or files; examiners must use application-specific sharing to restrict visible content.
Question 3: A CFE is investigating potential embezzlement conducted through automated wire transfers triggered by a compromised email account. Which digital artifact is MOST critical to establishing who initiated the unauthorized transfers?
- The bank's physical security camera footage
- Email server authentication logs showing IP address and login timestamps (Correct answer)
- The victim's printed bank statements
- Social media posts by the suspect
Correct answer: Email server authentication logs showing IP address and login timestamps
Authentication logs tie a specific IP address and timestamp to login events, directly linking access to the fraudulent transfers.
Question 4: During a virtual facilitation session for fraud training, a participant asks about the admissibility of screenshots as evidence. What is the MOST important factor affecting screenshot admissibility?
- The resolution of the screenshot
- Authentication that the screenshot accurately represents what was displayed at a specific time (Correct answer)
- Whether the screenshot was taken on a mobile or desktop device
- The file format used to save the screenshot
Correct answer: Authentication that the screenshot accurately represents what was displayed at a specific time
Screenshots must be authenticated to show they accurately and unalteredly represent the original content at the time it was captured.
Question 5: An investigator needs to preserve a suspect's live virtual machine (VM) running on a corporate server without shutting it down. Which method BEST captures volatile evidence?
- Taking a traditional bit-for-bit image of the VM's disk files only
- Suspending the VM and capturing both memory and disk state simultaneously (Correct answer)
- Rebooting the VM into a forensic boot environment
- Cloning only the VM's snapshot history
Correct answer: Suspending the VM and capturing both memory and disk state simultaneously
Suspending a VM captures the live memory state alongside disk, preserving volatile data such as running processes and encryption keys.
Question 6: A company uses a SaaS collaboration tool hosted entirely by a third-party vendor. To lawfully obtain user activity data in a US-based fraud investigation, what is typically the FIRST legal step?
- Contact the vendor's customer support and request the data informally
- Serve the vendor with a subpoena, court order, or search warrant under the Stored Communications Act (Correct answer)
- Access the data directly using the company's administrator credentials
- File a civil lawsuit against the vendor to compel disclosure
Correct answer: Serve the vendor with a subpoena, court order, or search warrant under the Stored Communications Act
The Stored Communications Act governs access to third-party electronic data; a valid legal process such as a subpoena or warrant is required.
Question 7: A CFE discovers that a fraud suspect used a deepfake video during a virtual investor presentation to impersonate an executive. Which forensic technique is MOST effective at detecting video deepfakes?
- Reviewing the video's file extension and container format
- Analyzing facial landmark inconsistencies and temporal artifacts using AI-detection tools (Correct answer)
- Checking whether the video was uploaded from a mobile device
- Comparing the video file size to known authentic recordings
Correct answer: Analyzing facial landmark inconsistencies and temporal artifacts using AI-detection tools
AI deepfake detection tools analyze micro-expressions, blinking patterns, and pixel-level temporal inconsistencies that are difficult to replicate perfectly.
A forensic examiner conducting a remote interview via video conferencing must ensure the integrity of witness statements.
Which practice BEST preserves evidentiary value of a virtual interview?