General Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 General flashcards as text
Which file system metadata attribute in NTFS records the time a file's metadata was last changed, separate from its content modification time?
Answer: $STANDARD_INFORMATION Modified time
The $STANDARD_INFORMATION attribute holds four timestamps including the metadata change time, which is updated when file attributes change.
What is the primary forensic significance of Windows Volume Shadow Copies (VSS)?
Answer: They provide historical point-in-time snapshots of files that may have been deleted or modified
VSS snapshots are forensically valuable because they preserve previous versions of files, enabling recovery of deleted or ransomware-encrypted data.
During an intrusion investigation, which log source on a Windows system would best reveal successful and failed login attempts?
Answer: Security Event Log
The Windows Security Event Log records authentication events including successful logins (Event ID 4624) and failed attempts (Event ID 4625).
What is 'data exfiltration' in the context of a cybersecurity incident investigation?
Answer: Unauthorized transfer of data from an organization to an external destination
Data exfiltration is the unauthorized copying or transfer of organizational data to an attacker-controlled location.
Which forensic concept describes the practice of ensuring that the investigation process itself does not alter or contaminate the evidence?
Answer: Forensic soundness
Forensic soundness means that acquisition and analysis methods do not modify the original evidence and can be validated by hash verification.
In cloud forensics investigations, which challenge is most unique compared to traditional disk forensics?
Answer: Multi-tenancy and lack of direct physical access to infrastructure
Cloud environments involve shared infrastructure across multiple tenants, making direct media access impossible and requiring cooperation with providers.
Which type of malware analysis involves executing a suspicious file in an isolated environment to observe its behavior without reverse engineering its code?
Answer: Dynamic analysis
Dynamic analysis runs malware in a controlled sandbox to capture runtime behaviors such as network connections, file drops, and registry modifications.