Digital Forensics & Cyber Fraud Flashcards
7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital Forensics & Cyber Fraud flashcards as text
In a digital fraud investigation involving deleted files, which concept explains why deleted files may still be recoverable from a hard drive?
Answer: Deleting a file typically removes only the directory entry while the actual data blocks remain until overwritten
Most operating systems mark deleted file space as available but don't immediately overwrite data blocks, allowing forensic tools to recover file content until those blocks are reused.
An e-commerce fraud scheme uses 'card-not-present' (CNP) fraud. Which characteristic defines this fraud type?
Answer: Stolen card data is used for online or phone transactions where the physical card is not required
Card-not-present fraud exploits online or telephone transactions where only card numbers, expiration dates, and CVV codes are needed, making physical card possession unnecessary.
When serving legal process to obtain electronic evidence from a U.S.-based social media company, which legal instrument compels the company to produce subscriber information and content?
Answer: A subpoena or court order under 18 U.S.C. § 2703 (Stored Communications Act)
The Stored Communications Act (18 U.S.C. § 2703) establishes the legal framework requiring government entities to use subpoenas, court orders, or warrants to compel electronic service providers to disclose user data.
A fraud examiner is reviewing IP address logs to locate a suspect. The suspect used a VPN service. Which next step is MOST appropriate?
Answer: Identify the VPN provider and serve legal process to obtain connection logs linking the VPN IP to the subscriber's real IP
VPN providers maintain connection logs that can link their assigned IPs back to subscribing users' real IPs and identities, obtainable through proper legal process depending on the provider's jurisdiction.
Which artifact found on a Windows system records the last time each application was executed, providing evidence that a fraud tool was run on a specific machine?
Answer: Prefetch files (.pf) in C:\Windows\Prefetch\
Windows Prefetch files record application execution history including the program name and the last eight execution timestamps, directly linking a user's activity to specific programs.
In the context of cyber fraud, 'credential stuffing' attacks rely on which fundamental vulnerability?
Answer: Users reusing the same username/password combinations across multiple websites
Credential stuffing automates testing of previously breached username/password pairs against other services, exploiting the widespread practice of password reuse across multiple accounts.
During a forensic investigation of a suspected fraud scheme, you discover encrypted containers (e.g., VeraCrypt volumes). Under what legal doctrine might a U.S. court compel the suspect to provide decryption keys or passwords?
Answer: Fifth Amendment self-incrimination protections complicate compulsion, but courts may apply the 'foregone conclusion' doctrine if the government already knows the files exist
The 'foregone conclusion' doctrine allows courts to compel decryption if the government can independently establish the existence and authenticity of the files, circumventing Fifth Amendment protections.