Cybersecurity & Digital Evidence Handling Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity & Digital Evidence Handling flashcards as text
An investigator analyzing a phishing email campaign needs to trace the true origin of the messages. Which email header field is MOST reliable for this purpose?
Answer: Received: headers (read bottom-up)
The Received: headers, read from bottom to top, trace the actual routing path of an email and are the most reliable source for origin identification.
During an insider threat investigation, an employee is suspected of exfiltrating IP via personal cloud storage. Which log source would BEST confirm this activity?
Answer: Endpoint DLP (Data Loss Prevention) and proxy/web gateway logs
DLP tools flag sensitive data transfers and proxy logs capture outbound HTTPS traffic to cloud storage domains, providing direct evidence of exfiltration.
Which of the following best describes a 'Man-in-the-Middle' (MitM) attack in the context of a digital investigation?
Answer: An adversary who secretly intercepts and potentially alters communications between two parties
In a MitM attack, the adversary positions themselves between two communicating parties to intercept, read, or modify data in transit.
A CSI investigator is asked to examine cloud-stored evidence. Which legal instrument is typically required to compel a US-based cloud provider to disclose customer data?
Answer: A subpoena, court order, or search warrant under the Stored Communications Act
The Stored Communications Act (part of ECPA) governs law enforcement access to cloud-stored data and requires the appropriate legal process.
What is the purpose of conducting a 'memory dump' (RAM capture) during a live forensic investigation?
Answer: To capture running processes, encryption keys, passwords, and network connections that exist only in volatile memory
RAM captures volatile artifacts like running processes, decrypted data, active connections, and credentials that are lost when the system powers off.
Which cyber attack technique involves an adversary sending crafted packets to determine which ports are open on a target system before an intrusion?
Answer: Port scanning/reconnaissance
Port scanning identifies open ports and services on a target, giving attackers a map of potential entry points before launching an intrusion.
An investigator finds that a suspect communicated using an end-to-end encrypted messaging app with disappearing messages enabled. What is the BEST investigative approach to recover this content?
Answer: Perform a live device extraction before messages expire, or seek backup data from cloud storage
With true E2E encryption, server-side content is inaccessible; extracting the unlocked device or finding unencrypted cloud backups are the primary recovery paths.