← All CFS Flashcard Decks

Digital Forensics & Cyber Fraud Flashcards

7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Forensics & Cyber Fraud flashcards as text
  1. Which type of malware encrypts a victim's files and demands payment for the decryption key, and has been increasingly used to extort businesses into paying fraudulently obtained funds?

    Answer: Ransomware

    Ransomware encrypts victim data and demands a ransom (often in cryptocurrency) for the decryption key, making it a powerful cyber extortion tool.

  2. In digital forensics, 'write blockers' are used to:

    Answer: Prevent any writes to the evidence drive during acquisition, preserving its integrity

    Write blockers are hardware or software devices that allow forensic examiners to read data from a storage medium while preventing any modifications to the original evidence.

  3. An employee is suspected of exfiltrating trade secrets via personal email. Which digital artifact would BEST confirm the specific files sent?

    Answer: Email server logs combined with attachment metadata from the sent folder

    Email server logs capture message metadata including sender, recipient, timestamps, and attachment names, while the sent folder retains actual content, together providing the strongest evidence.

  4. Which federal law primarily governs unauthorized access to computers and networks in the United States, making cyber fraud activities prosecutable?

    Answer: Computer Fraud and Abuse Act (CFAA)

    The Computer Fraud and Abuse Act (CFAA) is the primary U.S. federal statute criminalizing unauthorized computer access, hacking, and related cyber fraud activities.

  5. A fraud examiner discovers that a suspect used Tor browser for all communications. What is the PRIMARY investigative challenge this presents?

    Answer: Tor anonymizes internet traffic by routing it through multiple encrypted relays, obscuring the user's IP

    Tor routes internet traffic through multiple volunteer-operated nodes, each knowing only the previous and next hop, making it extremely difficult to trace traffic back to its origin.

  6. 'Pharming' attacks differ from standard phishing attacks in that pharming:

    Answer: Redirects users to fraudulent websites by corrupting DNS resolution, without requiring any user click

    Pharming attacks compromise DNS servers or local host files to redirect legitimate website requests to fraudulent sites, bypassing the need for users to click malicious links.

  7. When analyzing network packet captures (PCAP files) for fraud evidence, which protocol would most likely contain plaintext credentials if an attacker used a legacy system?

    Answer: FTP (port 21)

    FTP transmits usernames, passwords, and file data in cleartext, making it a prime target for credential harvesting via packet capture analysis.