Forensic Analysis Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Forensic Analysis flashcards as text
An analyst performing timeline analysis discovers file MAC times (Modified, Accessed, Changed) that predate the file's creation timestamp on the same volume. What does this MOST likely indicate?
Answer: Timestomping used to disguise malicious file activity
Timestomping is a technique where attackers modify file timestamps to evade detection; illogical timestamp ordering (e.g., modified before created) is a common indicator.
During a Linux forensic investigation, which file would an analyst examine to find a history of commands executed as root using sudo, even if the user's bash history was cleared?
Answer: /var/log/auth.log or /var/log/secure
The auth.log (Debian/Ubuntu) or secure (RHEL/CentOS) log records all sudo command executions with timestamps and the originating user.
A forensic analyst extracts strings from a malware sample and finds Base64-encoded content that, when decoded, reveals a PowerShell script. This technique is BEST described as:
Answer: Obfuscation to evade signature-based detection
Encoding payloads in Base64 is a common obfuscation technique used to evade static signature detection by antivirus and IDS tools.
Which Volatility framework plugin would BEST help an analyst identify injected code in a running Windows process during memory forensics?
Answer: malfind
The `malfind` plugin scans process memory for regions with suspicious characteristics such as executable permissions and MZ headers not associated with mapped DLLs.
An examiner finds a file with a .jpg extension but the magic bytes at the file header read '50 4B 03 04'. What is the MOST accurate conclusion?
Answer: The file has been renamed and is actually a ZIP archive
The magic bytes 50 4B 03 04 (PK\x03\x04) are the signature for ZIP archives; the .jpg extension is misleading and the file is a renamed ZIP.
When performing dead-box forensics on a suspect drive, which action should be taken FIRST before connecting the drive to the forensic workstation?
Answer: Attach a hardware write blocker to the suspect drive
A hardware write blocker must be attached first to prevent any writes to the suspect drive, preserving forensic integrity before any other action.
A CySA+ analyst reviews a memory dump and finds a process named 'svchost.exe' running from C:\Users\Public\svchost.exe. Why is this suspicious?
Answer: Legitimate svchost.exe always runs from C:\Windows\System32
Legitimate svchost.exe processes always originate from C:\Windows\System32; a process using the same name from a different path is a masquerading technique.