Digital & Cyber Investigation Flashcards
7 cards from real CFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital & Cyber Investigation flashcards as text
When a fire investigation involves a suspected cyber intrusion into a facility's fire alarm panel, which federal law is most applicable to the criminal prosecution of the intruder?
Answer: The Computer Fraud and Abuse Act (CFAA)
The Computer Fraud and Abuse Act (18 U.S.C. § 1030) criminalizes unauthorized access to computer systems, including networked fire alarm and suppression control panels.
A fire investigator is examining a damaged solid-state drive (SSD). Compared to a traditional hard drive, what unique challenge does an SSD present for data recovery?
Answer: TRIM commands may have permanently erased deleted data sectors
SSDs use TRIM to preemptively clear deleted data blocks for performance, which can permanently destroy forensic artifacts that would remain recoverable on a traditional HDD.
During a fire scene examination, an investigator finds a Raspberry Pi device connected to the building's electrical panel. This most likely indicates:
Answer: A legitimate energy monitoring setup or a potentially unauthorized control device requiring investigation
A Raspberry Pi connected to an electrical panel could be legitimate energy monitoring equipment or an unauthorized device used to manipulate electrical loads — both scenarios require investigation.
What is the significance of 'metadata' in fire investigation digital evidence, particularly in photos taken at or near the scene?
Answer: It can contain GPS coordinates, timestamps, and device identifiers placing a person at the scene
Photo metadata (EXIF data) can include GPS coordinates, precise timestamps, and camera/device identifiers that can corroborate or contradict a suspect's claimed whereabouts.
A fire investigator needs to analyze a fire suppression system's network traffic logs. The logs show repeated failed authentication attempts to the suppression controller 30 minutes before the fire. This pattern is MOST consistent with:
Answer: A brute-force attack attempting to gain unauthorized access
Repeated failed authentication attempts in a short timeframe are a classic indicator of a brute-force attack attempting to guess credentials for unauthorized system access.
When preparing a digital evidence report for a CFI case, which element is essential to establish the chain of custody for electronically stored information?
Answer: A documented log of every person who accessed the evidence and when
Chain of custody requires a documented chronological record of every individual who handled the evidence, ensuring it has not been tampered with from collection through court presentation.
In a fire investigation involving an IoT-enabled industrial control system, what term describes the security vulnerability where a device uses default factory credentials that were never changed?
Answer: Default credential vulnerability
Default credential vulnerability occurs when manufacturers ship devices with preset username/password combinations that operators fail to change, making them trivially easy to compromise.