Computer Hacking Forensic Investigator (v10) Free Sample Questions

20 free sample questions264 in the full practice test Other version: 312-49v11(198)

Try simulator

312-49v10 Sample Questions

  1. Question 1

    An investigator is analyzing a memory dump from a compromised Linux server that hosted multiple Docker containers. The attacker allegedly used a fileless malware variant that executed entirely in memory. The investigator suspects the malware manipulated system calls using a kernel module. Which Volatility 3 plugin would be most effective for initially identifying anomalous kernel modules and their hooks?

    Answer and explanation

    Correct answer: C

    The linux_check_syscall plugin is specifically designed to check the system call table for hooks, which is a common technique used by rootkits and fileless malware to intercept and manipulate system functions. While linux_pslist shows processes and linux_lsmod lists loaded modules, linux_check_syscall directly addresses the suspected manipulation of system calls, making it the most effective initial step. linux_check_creds is used for checking process credentials for signs of privilege escalation.

  2. Question 2

    A financial institution's internal audit team is investigating a case of suspected insider trading facilitated through corporate email. The investigation is subject to strict eDiscovery protocols under the EDRM framework. The legal team has issued a hold on all relevant mailboxes. At which stage of the EDRM cycle would the forensic team use keyword searching, date filtering, and de-duplication on the collected mailbox data?

    Answer and explanation

    Correct answer: B

    In the Electronic Discovery Reference Model (EDRM), the 'Processing' stage involves reducing the volume of electronically stored information (ESI) and converting it into forms more suitable for review and analysis. Activities like keyword searching, filtering by date, and removing duplicate files (de-duplication) are core to this stage. 'Collection' is the acquisition of data, 'Review' is the analysis of the processed data for relevance, and 'Identification' is locating potential sources of ESI.

  3. Question 3

    During a forensic investigation of a compromised web server, an analyst discovers that the attacker manipulated the timestamps of several critical log files using the touch command to cover their tracks. This action is a form of trail obfuscation. Which of the following artifacts is most likely to reveal the discrepancy between the modified timestamps and the actual time of file system changes?

    Answer and explanation

    Correct answer: C

    On an NTFS file system, a file has two main sets of timestamps stored in the Master File Table (MFT): one in the $STANDARD_INFORMATION attribute and another in the $FILE_NAME attribute. Many user-level tools, including touch, only modify the timestamps in the $STANDARD_INFORMATION attribute. Forensic tools can compare these timestamps against those in the $FILE_NAME attribute, which are not as easily modified. A mismatch between these two sets of timestamps is a strong indicator of timestomping. Inode metadata serves a similar purpose on ext4, but the MFT attributes are specific to NTFS.

  4. Question 4

    A forensic investigator in the European Union is conducting an investigation into corporate fraud that involves employee data from Germany and France. The investigator must ensure compliance with the General Data Protection Regulation (GDPR). Which GDPR principle is most critical when deciding how much data to collect and ensuring that only data strictly relevant to the fraud case is acquired?

    Answer and explanation

    Correct answer: C

    The principle of Data Minimization (Article 5(1)(c) of GDPR) dictates that personal data collected must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. In a forensic investigation, this means the investigator must make a concerted effort to only acquire data strictly relevant to the case, rather than collecting entire hard drives indiscriminately. Purpose Limitation refers to using the data only for the specified purpose, and Storage Limitation refers to not keeping it longer than necessary.

  5. Question 5

    Multiple answers

    A forensic analyst is examining an Android device and needs to recover deleted SQLite database entries from a third-party messaging application. The database file itself is intact, but records have been removed. Which artifact within the SQLite file structure should the analyst focus on to potentially recover the deleted content? (Select TWO).

    Answer and explanation

    Correct answers: B, C

    Freeblocks are pages within the SQLite database file that were previously allocated to a table but are now unused. When records are deleted, the pages they occupied are often marked as freeblocks but not immediately overwritten, making them a prime location for recovering deleted data.

    The Write-Ahead Log (WAL) is a mechanism used by SQLite to implement atomic transactions. It stores changes to the database before they are committed to the main database file. The WAL file can contain copies of pages that have since been changed or deleted in the main file, providing another valuable source for data recovery.

  6. Question 6

    A CHFI is tasked with creating a forensic image of a 2TB NVMe SSD from a suspect's laptop. To ensure the integrity of the evidence, the investigator must use a hardware write blocker. The primary reason for using a hardware write blocker over a software-based one in this scenario is that hardware blockers:

    Answer and explanation

    Correct answer: B

    Hardware write blockers are physically placed between the evidence drive and the forensic workstation. They intercept and block any write commands at the hardware level, regardless of the operating system or software running on the workstation. This independence prevents accidental writes from OS-level processes (like automounting or indexing), which a software blocker running within that same OS might not be able to prevent, making hardware blockers more reliable and forensically sound.

  7. Question 7

    True or False: In a RAID 5 configuration consisting of four 1TB drives, a forensic investigator can reconstruct the full data set even if two of the drives have failed simultaneously.

    Answer and explanation

    Correct answer: B

    RAID 5 uses distributed parity, which allows it to withstand the failure of a single drive. The data from the failed drive can be rebuilt using the parity information from the remaining drives. However, if two drives fail simultaneously, there is not enough information (data and parity) to reconstruct the missing data from both failed drives, resulting in data loss.

  8. Question 8

    An investigator is analyzing network traffic from a suspected ransomware attack. They observe a large volume of DNS queries for domains ending in .onion. This activity is a strong indicator that the malware is attempting to communicate with a Command and Control (C2) server hosted on:

    Answer and explanation

    Correct answer: C

    The .onion top-level domain is used exclusively for hidden services accessible only through the Tor network. Ransomware and other malware frequently use Tor for C2 communications to anonymize the location of their servers and make them difficult to take down. Observing DNS queries for .onion domains indicates that a client on the network is attempting to resolve these addresses, likely through a Tor gateway or proxy, to establish a C2 channel.

  9. Question 9

    A forensic investigator is using Python to automate the extraction of EXIF data from a large set of image files. The investigator writes a script to parse GPS coordinates, camera model, and timestamps. Which Python library is most commonly used and specifically suited for this task?

    Answer and explanation

    Correct answer: B

    Pillow (a fork of the Python Imaging Library, PIL) is the de facto standard library for image manipulation in Python. It has robust built-in capabilities for reading and parsing EXIF (Exchangeable Image File Format) data from various image formats like JPEG and TIFF. Scapy is for network packet manipulation, PyPDF2 is for PDF files, and Requests is for making HTTP requests.

  10. Question 10

    A hospital's IT security team is responding to a breach where a medical IoT device (an infusion pump) was compromised. The forensic investigator needs to acquire data from the device, which has limited storage and a proprietary embedded operating system. The device is still running. According to the order of volatility, which of the following pieces of evidence should be collected FIRST?

    Answer and explanation

    Correct answer: C

    The order of volatility dictates collecting evidence from most volatile to least volatile. Memory (RAM) is the most volatile evidence; its contents will be lost the moment the device loses power. Therefore, capturing a memory dump from the live device must be the first priority. Firmware on flash memory, network logs on a switch, and configuration files are all more persistent and should be collected after the RAM.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 462 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon