← All CSI Flashcard Decks

Cybersecurity & Digital Evidence Handling Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cybersecurity & Digital Evidence Handling flashcards as text
  1. In digital forensics, what does the term 'anti-forensics' refer to?

    Answer: Methods suspects use to destroy, hide, or obfuscate digital evidence

    Anti-forensics encompasses techniques like data wiping, encryption, timestomping, and steganography used to hinder forensic investigations.

  2. Which of the following is an example of a 'watering hole' attack that a CSI investigator might encounter?

    Answer: Compromising a website frequented by a target group to infect their systems

    A watering hole attack compromises websites that the target group regularly visits, passively infecting them when they browse to the site.

  3. When testifying about digital evidence findings, a CSI investigator should characterize their role as a:

    Answer: Neutral expert witness who presents factual findings regardless of which party they favor

    A digital forensics expert witness must remain objective and impartial, presenting accurate findings that support truth regardless of which side retained them.

  4. A forensic analyst is examining Windows event logs and finds Event ID 4624 followed by 4672 for the same logon session. What does this combination indicate?

    Answer: A successful logon where the account was also assigned special/elevated privileges

    Event ID 4624 is a successful logon; Event ID 4672 indicates special privileges (often administrative) were assigned to that session.

  5. What is 'timestomping' and why is it significant in a digital forensic investigation?

    Answer: Deliberately altering file system timestamps to mislead investigators about when files were created or modified

    Timestomping changes MACB (Modified, Accessed, Changed, Born) timestamps to conceal when malicious files were placed on a system.

  6. A CSI investigator needs to identify all USB devices ever connected to a Windows suspect machine without physically examining every USB device. Where should they look?

    Answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR registry key

    The USBSTOR registry key records every USB storage device connected to the system, including device ID, vendor, and first/last connection times.

  7. Which internationally recognized framework provides a standardized process model for digital forensic investigations, covering identification through presentation?

    Answer: ACPO Guidelines / NIST SP 800-86 four-phase model (Collection, Examination, Analysis, Reporting)

    NIST SP 800-86 defines the four-phase forensic process — Collection, Examination, Analysis, and Reporting — widely adopted as the standard investigative model.