โ† All CSI Flashcard Decks

Cybersecurity & Digital Evidence Handling Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Digital Evidence Handling flashcards as text
  1. During a corporate data breach investigation, investigators identify exfiltration via DNS tunneling. What characteristic best identifies DNS tunneling activity in log analysis?

    Answer: Abnormally long or high-frequency DNS queries to a single external domain

    DNS tunneling encodes data inside DNS queries, resulting in unusually long subdomains or an abnormally high volume of queries to one domain.

  2. Which chain of custody principle ensures that digital evidence collected at a scene can be traced from collection through court presentation?

    Answer: Continuity of evidence documentation

    Continuity of evidence documentation (chain of custody) records every person who handled evidence and all transfers, ensuring traceability.

  3. A forensic image of a suspect hard drive differs in hash value from the original drive after acquisition. What does this MOST likely indicate?

    Answer: The evidence may have been altered or the acquisition process was flawed

    A hash mismatch means the image does not exactly match the source, indicating possible evidence tampering or an acquisition error.

  4. In cybersecurity investigations, what does the term 'persistence mechanism' refer to?

    Answer: A technique malware uses to survive system reboots and remain active

    Persistence mechanisms (registry run keys, scheduled tasks, services) allow malicious code to re-execute after reboots.

  5. Which volatile data source should a CSI investigator capture FIRST on a live Windows system before powering it down?

    Answer: Running processes and active network connections

    Running processes and network connections exist only in RAM and disappear when the system is shut down, making them the highest-priority volatile artifact.

  6. A suspect deleted files and then used a disk-wiping tool on a Windows NTFS volume. Which forensic artifact might still reveal what files existed before deletion?

    Answer: The $MFT (Master File Table) and $LogFile journal remnants

    Even after wiping, MFT entry remnants and journal records can reveal file names, metadata, and timestamps of previously existing files.

  7. What is the legal significance of the 'plain view doctrine' in a digital forensic investigation?

    Answer: Evidence discovered incidentally while conducting a lawful search may be seized without an additional warrant

    The plain view doctrine allows investigators to seize evidence found in plain view during a lawful search without needing a separate warrant.