Mixed Deck — All CHFI Topics Flashcards
100 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CHFI Topics flashcards as text
A malware analyst is examining a sample that encrypts its C2 communications using a custom XOR cipher with a single-byte key. What analysis technique would MOST efficiently recover the key?
Answer: Frequency analysis of the ciphertext
Single-byte XOR encryption is vulnerable to frequency analysis because the most common byte in the plaintext (often 0x00 or 0x20 in protocols) reveals the key when XORed with the most frequent ciphertext byte.
In the context of email forensics, which header field reveals the originating IP address of the sender's mail client?
Answer: Received:
The 'Received:' header chain in an email message traces the path of the message and typically includes the originating IP address of the sending client.
In NTFS, which metadata file stores the location of all other metadata files and is always located at the beginning of the volume?
Answer: $MFT
The $MFT (Master File Table) is the first file in an NTFS volume and contains records for every file and directory on the volume.
Which analysis technique examines the timing intervals between network packets to identify covert communication channels even when content is encrypted?
Answer: Traffic timing analysis / inter-arrival time analysis
Traffic timing analysis examines inter-packet arrival times to detect patterns that may indicate covert channels where timing itself encodes information, bypassing content-level inspection.
What is the standard hashing algorithm recommended by NIST for generating forensic hash values to verify evidence integrity?
Answer: SHA-256
NIST recommends SHA-256 for generating forensic hash values as it provides stronger collision resistance than MD5 or SHA-1.
What is the forensic significance of the `Referer` HTTP header found in web server logs?
Answer: It shows the URL from which the request originated, helping trace attack navigation paths
The Referer header shows what page or resource the request came from, helping investigators trace how an attacker navigated through an application.
What is 'email spoofing' and what forensic technique helps identify it?
Answer: Forging the From address to impersonate another sender; identified by analyzing Received headers and DKIM/SPF results
Email spoofing forges the From header to impersonate a trusted sender; investigators identify it by tracing Received headers to the true originating IP and checking DKIM/SPF authentication failures.
In which location does Microsoft Outlook store emails, contacts, and calendar data in a local file format?
Answer: .pst or .ost file
Outlook stores local email data in Personal Storage Table (.pst) files for local storage and Offline Storage Table (.ost) files for cached Exchange mailbox data.
A forensic examiner wants to extract data from a locked Android device using the JTAG method. What does this technique access?
Answer: Raw memory via test access ports
JTAG accesses the device's memory by connecting to Joint Test Action Group debug ports on the motherboard.
An investigator finds ARP replies with no preceding ARP request in a packet capture. This is a sign of:
Answer: ARP cache poisoning
Unsolicited ARP replies (gratuitous ARP) sent by an attacker are the primary mechanism of ARP cache poisoning, used to associate the attacker's MAC with a legitimate IP.
In HTTPS traffic analysis, what information CAN be obtained without decrypting the traffic?
Answer: Server Name Indication (SNI) hostname
SNI is transmitted in plaintext during the TLS handshake, revealing the target hostname even when payload content remains encrypted.
In Windows forensics, what does the acronym LNK file refer to and why is it forensically significant?
Answer: A Windows shortcut file that records metadata about accessed files including original path and timestamps
LNK (shortcut) files automatically created in Recent Items contain metadata about accessed files including MAC times, file size, and original volume serial number.
Which hash algorithm is currently recommended by NIST for forensic image verification due to collision resistance concerns with MD5?
Answer: SHA-256
NIST recommends SHA-256 (or stronger) for forensic integrity verification because MD5 and SHA-1 are vulnerable to collision attacks.
In a GPT-partitioned disk, where is the backup copy of the partition table stored?
Answer: At the end of the disk
GPT stores a secondary (backup) copy of the partition table at the last sectors of the disk to allow recovery if the primary GPT header is damaged.
When performing a forensic hash verification of a disk image, which combination of algorithms is considered best practice to minimize collision risk?
Answer: MD5 and SHA-256 together
Using both MD5 (for legacy compatibility) and SHA-256 (for cryptographic strength) together minimizes the risk of an undetected collision or tampering in forensic evidence.
What type of data can be recovered from a Facebook account's 'Download Your Information' feature that is useful in forensic investigations?
Answer: Messages, posts, friends list, login activity, and location history
Facebook's Download Your Information feature exports a comprehensive archive including private messages, post history, friend connections, IP-based login activity, and location data.
Which tool is commonly used by CHFI investigators to analyze email headers and trace email origins?
Answer: MXToolbox Email Header Analyzer
MXToolbox Email Header Analyzer parses raw email headers to display the routing path, timestamps, and originating IP addresses in an investigator-friendly format.
A forensic analyst is examining a macOS system suspected of running malware. Which location should be checked FIRST for user-level persistence launch agents?
Answer: ~/Library/LaunchAgents/
~/Library/LaunchAgents/ stores per-user launch agents that run when the user logs in; malware without root access commonly places plist persistence files here.
What is the purpose of performing a 'disk-to-disk' clone versus a 'disk-to-image' acquisition?
Answer: Disk-to-disk creates a bootable working copy while disk-to-image creates an investigative archive
Disk-to-disk cloning produces a bootable duplicate that can replace the original for examination, while disk-to-image creates a compressed archive used for analysis and preservation.
Which of the following best describes the 'first responder' role in a digital forensic investigation?
Answer: The first person on the scene who secures and documents the environment without altering evidence
The first responder secures the scene, documents the environment, and protects evidence from contamination before forensic specialists arrive.