โ† All CHFI Flashcard Decks

Email and Social Media Forensics Flashcards

6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Email and Social Media Forensics flashcards as text
  1. Which protocol is used to retrieve email from a mail server and keeps messages stored server-side, making it critical for cloud-based email forensics?

    Answer: IMAP

    IMAP (Internet Message Access Protocol) keeps emails stored on the server, meaning evidence may be preserved in the cloud even after local deletion.

  2. What is 'email spoofing' and what forensic technique helps identify it?

    Answer: Forging the From address to impersonate another sender; identified by analyzing Received headers and DKIM/SPF results

    Email spoofing forges the From header to impersonate a trusted sender; investigators identify it by tracing Received headers to the true originating IP and checking DKIM/SPF authentication failures.

  3. Which artifact on a Windows system stores evidence of web-based email access (e.g., Gmail via browser) useful in email forensics?

    Answer: Browser cache, history, and cookies

    Browser cache files may contain cached email content and attachments, browser history shows Gmail/webmail access timestamps, and cookies can reveal authenticated sessions.

  4. In investigating a Twitter/X account for evidence, which API does law enforcement reference for legal data requests to the platform?

    Answer: Twitter's Legal Request Submission portal under the Stored Communications Act

    Law enforcement submits legal requests for Twitter/X user data through Twitter's official legal request portal, following the Stored Communications Act framework for subpoenas and warrants.

  5. What is the purpose of analyzing the 'Bcc' (Blind Carbon Copy) field in email forensics investigations?

    Answer: Bcc recipients are hidden from other recipients but may appear in server logs or sender's sent folder, revealing hidden communication parties

    While Bcc recipients are invisible to To/Cc recipients, mail server logs, the sender's sent items, and mail server transaction logs may reveal who received Bcc copies.

  6. Which hashing algorithm is recommended by NIST for generating forensic integrity hashes of email evidence files such as PST archives?

    Answer: SHA-256 or SHA-3

    NIST recommends SHA-256 or stronger algorithms for forensic evidence integrity verification, as MD5 and SHA-1 are considered cryptographically weak and vulnerable to collision attacks.