← All CySA+ Test Flashcard Decks

Forensic Analysis Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Forensic Analysis flashcards as text
  1. An analyst performing reverse engineering of a suspicious DLL notices that the import address table (IAT) contains references to VirtualAlloc, WriteProcessMemory, and CreateRemoteThread. What capability does this MOST suggest?

    Answer: Process injection to execute code in another process's memory space

    The combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread is the classic Windows API triad used for injecting and executing code in a remote process.

  2. A CySA+ analyst is investigating a suspected data exfiltration event. PCAP analysis shows large HTTPS POST requests to an IP address with an expired, self-signed certificate. What should the analyst do NEXT?

    Answer: Capture the SSL/TLS certificate details and pivot to threat intel for the IP and certificate fingerprint

    Pivoting on the SSL certificate fingerprint and destination IP against threat intelligence feeds can attribute the traffic to known malware families or C2 infrastructure.

  3. Which forensic artifact on macOS is equivalent to Windows Prefetch and can help an analyst determine what applications were recently executed?

    Answer: macOS Unified Logs (log show command)

    macOS Unified Logs (accessed via the `log show` command) record detailed process execution events and are the primary source for application execution history on macOS.

  4. During forensic triage, an analyst must prioritize which data to collect first based on volatility. Which represents the CORRECT order from most to least volatile?

    Answer: CPU registers → RAM → Network connections → Disk image

    The RFC 3227 order of volatility goes from CPU registers (lost on context switch) to RAM to network state to disk, as each level persists longer.

  5. An analyst examines a malware sample and finds it queries the registry key HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid at startup. What is the MOST likely purpose of this behavior?

    Answer: To fingerprint the specific machine and avoid executing in sandbox or VM environments

    MachineGuid is a unique identifier; malware reads it to fingerprint the host, detect sandboxes (where the GUID may be generic), and avoid analysis environments.

  6. A forensic analyst is examining an email header and finds the 'Received-SPF' field shows 'fail' while the 'From' header displays a legitimate corporate domain. What does this MOST likely indicate?

    Answer: The email is a spoofed phishing message sent from an unauthorized server

    An SPF fail means the sending mail server is not authorized to send on behalf of the domain in the From header, which is the primary indicator of email spoofing.

  7. During post-incident analysis, the team discovers attackers used WMI (Windows Management Instrumentation) for persistence. Which Windows artifact would provide evidence of malicious WMI event subscriptions?

    Answer: WMI repository files at C:\Windows\System32\wbem\Repository

    Malicious WMI event subscriptions (filters, consumers, and bindings) are stored in the WMI repository database files and persist across reboots.