CFL Electronic Security Forensics 2 — Questions and Answers
Question 1: When forensically examining an electronic access control system, which log entry type is MOST valuable for reconstructing an unauthorized entry timeline?
- System reboot logs
- Failed authentication attempts with timestamps (Correct answer)
- Battery voltage readings
- Firmware version history
Correct answer: Failed authentication attempts with timestamps
Failed authentication attempts with timestamps directly document when and how many times unauthorized access was tried, forming the backbone of an entry timeline.
Question 2: A forensic locksmith finds that a magnetic stripe card reader shows evidence of a skimming device having been attached. What physical evidence on the reader housing is MOST indicative of skimmer attachment?
- Worn paint on the card insertion slot edges
- Adhesive residue or tool marks around the bezel (Correct answer)
- Scratches on the keypad surface
- Discoloration from UV exposure
Correct answer: Adhesive residue or tool marks around the bezel
Adhesive residue indicates a device was glued over the reader, and tool marks suggest the bezel was pried to attach a skimmer or tap into internal wiring.
Question 3: Which RFID frequency range is used by most modern commercial access control proximity cards?
- 13.56 MHz (HF)
- 125 kHz (LF) (Correct answer)
- 433 MHz (UHF)
- 2.4 GHz (microwave)
Correct answer: 125 kHz (LF)
125 kHz low-frequency proximity cards (such as HID Prox and EM4100) remain the most widely deployed standard in legacy commercial access control installations.
Question 4: During a forensic investigation, an electronic lock's audit log shows a valid credential was used at 2:47 AM but the assigned cardholder was confirmed to be out of the country. What is the MOST likely explanation?
- The clock in the access control system was misconfigured
- The credential was cloned and used by an unauthorized person (Correct answer)
- The cardholder remotely triggered the lock via an app
- The log entry is a system-generated test event
Correct answer: The credential was cloned and used by an unauthorized person
Credential cloning allows an attacker to duplicate a card and use it independently of the original cardholder, explaining a valid credential used when the legitimate holder was absent.
Question 5: A Wiegand interface between a card reader and access controller is found to have been tapped. What security vulnerability does this attack exploit?
- Encrypted data transmission
- Unencrypted plaintext credential data on the wire (Correct answer)
- Two-factor authentication bypass
- Network packet injection
Correct answer: Unencrypted plaintext credential data on the wire
The Wiegand protocol transmits card data in unencrypted plaintext, making it trivial to intercept and replay credential data if an attacker gains physical access to the wiring.
Question 6: What does the term 'tailgating' refer to in electronic access control forensics?
- Cloning an RFID credential from a distance
- An unauthorized person following an authorized person through a controlled door (Correct answer)
- Bypassing a door sensor by using a relay attack
- Intercepting card data during transmission
Correct answer: An unauthorized person following an authorized person through a controlled door
Tailgating (also called piggybacking) occurs when an unauthorized individual gains entry by closely following an authorized person through a secured door before it closes.
Question 7: When examining a biometric fingerprint reader for forensic evidence, which component would you document to determine if the device was subjected to a spoofing attack?
- The network MAC address of the controller
- Liveness detection capability and its log records (Correct answer)
- The power supply voltage regulator
- The door position sensor wiring
Correct answer: Liveness detection capability and its log records
Liveness detection determines whether a biometric reader can distinguish real fingers from artificial replicas; its presence and log records show whether spoof attempts would have been detected.
When forensically examining an electronic access control system, which log entry type is MOST valuable for reconstructing an unauthorized entry timeline?