CHFI - Computer Hacking Forensic Investigator Practice Test
CHFI Anti-Forensics Techniques 3
How can a forensic investigator detect timestomping on a Windows NTFS volume?
Select your answer
A
By comparing file MD5 hashes against known-good databases
B
By comparing $MFT timestamps against $LogFile and $UsnJrnl entries for inconsistencies
C
By running a full antivirus scan on the volume
D
By capturing and analyzing live network traffic logs
Hint