Digital Forensics & Cyber Fraud Flashcards
7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital Forensics & Cyber Fraud flashcards as text
Which file system artifact is MOST valuable for establishing a timeline of when files were created, accessed, or modified on a Windows NTFS volume?
Answer: $MFT (Master File Table)
The $MFT stores metadata for every file on an NTFS volume including MAC (Modified, Accessed, Created) timestamps, making it essential for timeline analysis.
A fraudster uses a cryptocurrency tumbler (mixer) to launder proceeds. What is the PRIMARY purpose of this technique?
Answer: To obfuscate the transaction trail by mixing funds from multiple sources
Cryptocurrency tumblers break the transaction chain by pooling coins from many users and redistributing different coins, making blockchain tracing significantly harder.
During a phishing investigation, you identify a spoofed email domain 'paypa1.com' used instead of 'paypal.com'. This technique is called:
Answer: Typosquatting
Typosquatting (also called URL hijacking) involves registering domains that are common misspellings or visual substitutions of legitimate brand names to deceive users.
When conducting forensic analysis of cloud-based storage (e.g., Google Drive, OneDrive), which challenge is UNIQUE compared to local storage forensics?
Answer: Evidence may be stored across multiple jurisdictions with varying legal requirements
Cloud data often resides on servers in multiple countries simultaneously, creating complex legal jurisdiction issues requiring proper legal process in each relevant country.
A business email compromise (BEC) scheme typically involves which initial step before executing a fraudulent wire transfer?
Answer: Gaining unauthorized access to or spoofing a trusted executive's email account
BEC schemes typically begin with compromising or impersonating a high-level executive's email to issue fraudulent payment instructions that appear legitimate to employees.
Which of the following BEST describes 'steganography' in the context of cyber fraud?
Answer: Hiding data within ordinary files (images, audio) to conceal fraudulent communications
Steganography conceals the existence of a message by embedding it within an innocuous carrier file like an image, making it invisible to casual inspection.
When a suspect's hard drive is seized, the FIRST action a digital forensics examiner should take is:
Answer: Create a forensic bit-for-bit image of the drive before any analysis
Creating a verified forensic image preserves the original evidence in its exact state, allowing all analysis to be performed on copies without risking alteration of the original.