โ† All CFS Flashcard Decks

Digital Forensics & Cyber Fraud Flashcards

7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Forensics & Cyber Fraud flashcards as text
  1. In a cryptocurrency fraud investigation, what is the significance of identifying a 'hot wallet' versus a 'cold wallet'?

    Answer: Hot wallets are internet-connected and more accessible for investigation; cold wallets are offline and may require physical seizure

    Hot wallets maintain internet connectivity enabling real-time transaction monitoring, while cold wallets store private keys offline, often requiring physical access to the device for forensic examination.

  2. During an email fraud investigation, the 'Reply-To' header differs from the 'From' header. What does this typically indicate?

    Answer: The sender may be trying to redirect responses to a different controlled account, a common phishing tactic

    Fraudsters set a different Reply-To address so that victims' responses (containing sensitive information or authorization) go to an attacker-controlled mailbox rather than the spoofed sender.

  3. Which hashing algorithm is currently recommended for verifying digital forensic evidence integrity due to its collision resistance?

    Answer: SHA-256

    SHA-256 is currently recommended for forensic integrity verification as MD5 and SHA-1 have known collision vulnerabilities that could theoretically be exploited to challenge evidence authenticity.

  4. A 'SIM swapping' attack enables cyber fraud by:

    Answer: Social engineering a mobile carrier to transfer a victim's phone number to a fraudster-controlled SIM, bypassing SMS-based MFA

    SIM swapping exploits mobile carrier authentication weaknesses to redirect a victim's phone number, enabling the fraudster to receive SMS-based two-factor authentication codes and gain account access.

  5. When an organization suspects an insider fraud scheme involving database manipulation, which database artifact would be MOST useful for detecting unauthorized record changes?

    Answer: Transaction logs and audit trails recording DML operations

    Database transaction logs record all Data Manipulation Language (INSERT, UPDATE, DELETE) operations with timestamps and user identities, providing an audit trail of unauthorized data changes.

  6. The 'dark web' differs from the 'deep web' in that the dark web:

    Answer: Requires specialized software like Tor to access and is intentionally hidden, often hosting illicit marketplaces

    The dark web is an intentionally hidden overlay network requiring special software (Tor) and configurations to access, distinct from the deep web which is simply unindexed legitimate content.

  7. Which social engineering technique involves creating a fabricated scenario or identity (e.g., posing as IT support) to manipulate victims into revealing sensitive information?

    Answer: Pretexting

    Pretexting involves constructing a fabricated scenario (the pretext) to establish false trust with a victim, enabling the attacker to extract credentials, financial data, or access.