CFI Digital & Cyber Investigation 3 โ Questions and Answers
Question 1: Which type of malware is most directly associated with causing physical damage to industrial control systems that could result in fire?
- Ransomware
- Spyware
- SCADA-targeting malware (e.g., Stuxnet-type) (Correct answer)
- Adware
Correct answer: SCADA-targeting malware (e.g., Stuxnet-type)
SCADA-targeting malware like Stuxnet can override safety limits on industrial equipment, causing overloads or mechanical failures that lead to fires.
Question 2: When examining a fire-damaged smartphone, investigators should prioritize extracting data from which storage location first?
- The SIM card
- The cloud backup (Correct answer)
- The internal NAND flash storage
- The microSD card
Correct answer: The cloud backup
Cloud backups are offsite and unaffected by the fire, making them the easiest and most intact source of data to retrieve quickly.
Question 3: A CFI investigates a fire at a cryptocurrency mining facility. Which specific hazard unique to mining operations should be documented?
- High-bandwidth internet connections
- Overloaded electrical circuits from continuous high-draw GPUs (Correct answer)
- Use of proprietary cooling software
- Network switches running 24/7
Correct answer: Overloaded electrical circuits from continuous high-draw GPUs
Cryptocurrency mining rigs run GPUs at near-maximum load continuously, often overloading circuits not designed for such sustained high amperage draw.
Question 4: In a fire investigation involving a corporate server room, the investigator needs to preserve volatile evidence. Which item contains data that will be LOST when power is cut?
- Hard drive RAID array
- RAM containing running processes (Correct answer)
- Backup tape cartridge
- NAS device storage
Correct answer: RAM containing running processes
RAM is volatile memory โ all data including running processes, network connections, and encryption keys is permanently lost when power is removed.
Question 5: What is the primary legal requirement for obtaining cloud-stored evidence from a U.S.-based provider during a fire investigation with criminal implications?
- A written request on official letterhead
- A subpoena or court order under the Stored Communications Act (Correct answer)
- A verbal authorization from the property owner
- An NFPA 921 documentation form
Correct answer: A subpoena or court order under the Stored Communications Act
The Stored Communications Act (18 U.S.C. ยง 2703) requires law enforcement to obtain a subpoena, court order, or warrant to compel cloud providers to disclose user data.
Question 6: A fire investigator finds a network-attached surveillance DVR that survived a fire. The DVR is still powered. What is the FIRST action to take?
- Immediately unplug it to stop further recording
- Note the time displayed and compare it to a known accurate time source (Correct answer)
- Download all footage remotely via the network
- Reset the device to factory settings to clear malware
Correct answer: Note the time displayed and compare it to a known accurate time source
Noting the DVR's displayed time versus actual time establishes any time offset, which is critical for accurately interpreting recorded footage timestamps.
Question 7: Which NFPA standard provides guidance on the investigation of fires involving electrical equipment and digital systems?
- NFPA 72
- NFPA 70
- NFPA 921 (Correct answer)
- NFPA 1033
Correct answer: NFPA 921
NFPA 921, Guide for Fire and Explosion Investigations, provides the primary scientific methodology guidance including investigation of electrical and electronic equipment.
Which type of malware is most directly associated with causing physical damage to industrial control systems that could result in fire?