← All CFI Flashcard Decks

Digital & Cyber Investigation Flashcards

7 cards from real CFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital & Cyber Investigation flashcards as text
  1. An investigator suspects an electric vehicle (EV) charging station caused a fire. What proprietary data source is most likely to contain charging session records?

    Answer: The EVSE (charging station) cloud management platform

    EVSE cloud platforms log each charging session including start/stop times, energy delivered, fault codes, and communication errors that may indicate a malfunction.

  2. During a fire investigation, a write blocker is used when imaging a hard drive primarily to:

    Answer: Prevent any changes to the original evidence drive

    A write blocker prevents the forensic workstation from inadvertently writing data to the evidence drive, preserving its original state and ensuring admissibility.

  3. A fire investigator is analyzing router logs to establish whether an arsonist remotely disabled fire suppression systems. Which log entry type is most relevant?

    Answer: Outbound traffic to suppression system IP addresses at the time of ignition

    Outbound traffic logs showing connections to suppression system IP addresses near the time of ignition would indicate remote access attempts to disable the systems.

  4. When a fire investigator testifies about digital evidence, the Daubert standard primarily requires that the forensic methodology used be:

    Answer: Scientifically valid, peer-reviewed, and generally accepted in the field

    The Daubert standard requires expert testimony be based on scientifically valid methodology that has been tested, peer-reviewed, and generally accepted in the relevant scientific community.

  5. A fire investigator recovers a PLC (programmable logic controller) from an industrial fire scene. Which data should be extracted to determine if a process override caused the fire?

    Answer: Ladder logic program and alarm/event history logs

    The ladder logic program defines process control parameters, while alarm and event history logs record when setpoints were exceeded or overridden, potentially revealing the fire cause.

  6. In the context of fire investigation, 'anti-forensics' techniques by an arsonist might include which of the following?

    Answer: Using remote-access tools that delete logs after triggering a device malfunction

    Arsonists using cyber methods may deploy tools that initiate a device failure and then automatically delete activity logs to eliminate evidence of their intrusion.

  7. A CFI discovers that a fire started near a 3D printer that was operating unattended overnight via a remote monitoring app. Which digital evidence is MOST probative of the cause?

    Answer: The app's print job logs showing temperature settings and any error codes

    Print job logs reveal the programmed temperatures, actual temperatures reached, duration, and any error codes — directly indicating whether a thermal fault caused the fire.