โ† All CHFI Flashcard Decks

General MCQ Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 General MCQ flashcards as text
  1. Which file system artifact records the last time a file was accessed on an NTFS volume?

    Answer: $MFT entry timestamps

    The $MFT (Master File Table) entry stores MACB timestamps, including last access time, for every file on an NTFS volume.

  2. During a live forensic acquisition, an investigator wants to capture volatile memory. Which tool is most appropriate?

    Answer: WinPmem

    WinPmem is a memory acquisition tool used to dump live RAM to a file on Windows systems.

  3. What is the primary purpose of the 'chain of custody' document in digital forensics?

    Answer: Track evidence handling to preserve admissibility

    Chain of custody tracks who handled evidence, when, and how to ensure it remains unaltered and legally admissible.

  4. An investigator finds a file with a .jpg extension but its hex header shows '50 4B 03 04'. What is the actual file type?

    Answer: ZIP archive

    The magic bytes '50 4B 03 04' are the signature for ZIP archive files, regardless of the file extension.

  5. Which Windows registry hive stores user-specific settings and is loaded from the user's profile directory?

    Answer: HKEY_CURRENT_USER (NTUSER.DAT)

    HKEY_CURRENT_USER maps to NTUSER.DAT in the user's profile folder and stores user-specific configuration.

  6. What does the term 'write blocker' refer to in digital forensics?

    Answer: Hardware or software that prevents modification of source media

    A write blocker prevents any write operations to the evidence drive, ensuring the original data is not altered during acquisition.

  7. In network forensics, which protocol is analyzed to reconstruct email communications sent over an unencrypted channel?

    Answer: SMTP

    SMTP (Simple Mail Transfer Protocol) is used for sending emails and can be captured and reconstructed in packet captures when unencrypted.