โ† All CHFI Flashcard Decks

Forensic Investigation Process Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Forensic Investigation Process flashcards as text
  1. A suspect claims a file was never opened. Which forensic artifact would BEST refute or support this claim on a Windows system?

    Answer: Prefetch files and LNK files (shell items)

    Prefetch files record application execution history, and LNK (shortcut) files record recently accessed files, directly countering or corroborating the suspect's claim.

  2. During an investigation, an examiner must testify that a forensic tool correctly acquired evidence. What is the best way to establish tool reliability?

    Answer: Cite independent validation studies or tool qualification results from NIST CFTT

    NIST's Computer Forensics Tool Testing (CFTT) program provides independent validation of forensic tools, establishing their reliability in court.

  3. Which international standard provides guidance on digital evidence collection and handling?

    Answer: ISO/IEC 27037

    ISO/IEC 27037 provides international guidelines for the identification, collection, acquisition, and preservation of digital evidence.

  4. An investigator finds that the MAC times on key files have been modified. What type of anti-forensic technique was most likely used?

    Answer: Timestomping

    Timestomping is an anti-forensic technique where an attacker alters file MAC (Modified, Accessed, Created) timestamps to obscure the timeline.

  5. What is the primary goal of the 'containment' step when a forensic investigation overlaps with an active incident response?

    Answer: Stop the spread of the incident while minimizing disruption and preserving evidence

    Containment aims to prevent further damage or spread of the incident while balancing the need to preserve as much forensic evidence as possible.

  6. A forensic investigator is documenting the scene before touching any evidence. Which documentation method provides the most comprehensive scene record?

    Answer: Photographs, video, sketches, and written notes combined

    Combining photographs, video, sketches, and written notes provides the most thorough and legally defensible documentation of the original crime scene.

  7. In the context of CHFI, what does 'anti-forensics' refer to?

    Answer: Methods used to obstruct, manipulate, or eliminate evidence to hinder a forensic investigation

    Anti-forensics encompasses techniques like wiping, encryption, timestomping, and steganography used by attackers to hinder forensic investigations.