Forensic Analysis Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Forensic Analysis flashcards as text
During an investigation, an analyst needs to recover deleted files from an ext4 Linux filesystem. Which tool is MOST appropriate for carving files based on known file signatures?
Answer: Foremost or Scalpel
Foremost and Scalpel are file carving tools that scan raw disk images for file header/footer signatures to recover deleted files regardless of filesystem metadata.
An analyst is reviewing Windows Prefetch files and notices that an executable was run once but the Prefetch file shows references to files in a temp directory that no longer exist. This MOST likely indicates:
Answer: A self-deleting malware dropper that cleaned up after execution
Self-deleting malware often drops a payload, executes it, then removes the temporary files, but Prefetch retains references to all files accessed during execution.
Which MITRE ATT&CK technique involves an attacker using a legitimate, signed Windows binary to execute malicious code, thereby bypassing application whitelisting?
Answer: Living off the Land Binaries — LOLBins (T1218)
LOLBins (Living off the Land Binaries) are legitimate Windows signed executables that can be abused to execute arbitrary code while appearing legitimate to security controls.
An analyst examines a suspect workstation and finds an unusual scheduled task that runs a PowerShell command encoded with -EncodedCommand. Which Windows artifact would BEST corroborate this finding?
Answer: Task Scheduler operational event logs (Event ID 4698, 4702)
Windows Task Scheduler logs Event ID 4698 (task created) and 4702 (task updated) in the Security log, providing corroborating evidence of scheduled task manipulation.
A forensic analyst is examining browser artifacts on a Windows system. Which SQLite database file stores Chrome browsing history?
Answer: C:\Users\\AppData\Local\Google\Chrome\User Data\Default\History
Chrome stores browsing history in a SQLite database named 'History' located in the user's Chrome Default profile directory.
During an IR engagement, an analyst needs to determine the last time a specific user account logged into a Windows domain workstation. Which is the MOST reliable source?
Answer: Active Directory's lastLogonTimestamp attribute replicated across all DCs
lastLogonTimestamp is replicated across all domain controllers and provides a consistent view, while lastLogon is only updated on the authenticating DC and not replicated.
An analyst discovers that an attacker used the 'net use' command to map a drive to a remote share. Which Windows artifact would preserve evidence of this lateral movement?
Answer: Security Event Log Event ID 4648 (logon with explicit credentials) and 4624 Type 3
Event ID 4648 captures explicit credential usage and Event ID 4624 Logon Type 3 records the resulting network logon, together evidencing drive mapping activity.