Computer Hacking Forensic Investigator (CHFI v11) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 198 questions. Use the simulator for timed and flashcard mode. Or, view 264 more questions in the alternate version 312-49v10 264 Questions.

Try Simulator

312-49v11 Sample Questions

  1. Question 1

    Q1

    A forensic investigator is tasked with establishing a forensic readiness plan for a financial institution that utilizes a hybrid cloud environment. The institution wants to ensure that they can legally collect evidence without disrupting business operations during a potential incident. Which of the following proactive measures would BEST satisfy the requirement for minimizing business disruption while ensuring evidence admissibility according to the ISO/IEC 27037 standard?

    Show answer & explanation

    Correct answer: B

    Centralized logging with secure forwarding ensures that potential evidence (logs) is preserved in near real-time outside the compromised environment. This allows investigators to analyze events without needing to take critical business systems offline immediately for imaging, aligning with forensic readiness goals of minimizing disruption. Full-disk imaging daily is impractical for performance, and relying solely on local logs risks deletion by attackers.

  2. Question 2

    Q2

    During an investigation into a suspected data exfiltration case involving a Linux-based web server, the lead investigator identifies a suspicious running process that does not map to a standard executable on the disk. The investigator suspects a fileless malware attack leveraging memfd_create(). Which of the following acquisition methods must be prioritized to capture the payload before the system is powered down?

    Show answer & explanation

    Correct answer: B

    Fileless malware using memfd_create() resides solely in RAM and does not have a persistent file on the disk. Pulling the plug (dead acquisition) would destroy the RAM and thus the evidence of the malware. A live memory acquisition is critical to capture the process memory where the payload resides.

  3. Question 3

    Q3

    Which of the following describes the correct order of volatility (from most volatile to least volatile) that a forensic investigator must follow when collecting evidence from a compromised workstation?

    Show answer & explanation

    Correct answer: A

    According to RFC 3227, the order of volatility is: CPU Registers/Cache (most volatile) -> Routing Table/ARP Cache/Process Table/Kernel Statistics/Memory -> Temporary File Systems -> Disk -> Remote Logging and Monitoring Data -> Physical Configuration/Topology -> Archival Media (least volatile).

  4. Question 4

    Q4

    A multinational corporation suspects an insider threat is leaking intellectual property via the Dark Web using the Tor network. The investigator needs to analyze the suspect's workstation for artifacts indicating Tor usage. Which of the following file paths or artifacts is MOST likely to contain evidence of Tor Browser execution on a Windows system?

    Show answer & explanation

    Correct answer: A

    The Tor Browser is often portable and does not always install registry keys like standard software. However, Windows Prefetch files (.pf) in C:\Windows\Prefetch are created automatically when an application is executed. Finding tor.exe.pf or a firefox.exe.pf (since Tor is based on Firefox) running from a non-standard directory (like Desktop or USB) is a strong indicator of Tor usage.

  5. Question 5

    Q5

    While investigating a compromised IoT deployment in a smart factory, the investigator encounters a proprietary embedded device that does not support standard acquisition interfaces. To acquire the firmware and data directly from the flash memory chip without damaging the device logic, which forensic technique should be employed?

    Show answer & explanation

    Correct answer: A

    JTAG forensics involves connecting to the Test Access Ports (TAPs) on the device's printed circuit board (PCB) to read the memory contents directly from the chip. This is a non-destructive method compared to 'Chip-off' (which involves desoldering) and allows acquisition when standard software ports are disabled or unavailable.

  6. Question 6

    Q6

    An investigator is analyzing a suspicious email header to trace the origin of a phishing attack. The header contains the following field: Received: from mail.attacker.com ([192.168.1.50]) by mail.victim.com with ESMTP id 12345. What is the primary limitation of relying solely on this 'Received' header for attribution?

    Show answer & explanation

    Correct answer: A

    Email headers are added from bottom to top. The receiving server adds the topmost 'Received' header, which is generally trusted. However, attackers can inject fake 'Received' headers at the bottom of the chain to mislead investigators about the true origin. Investigators must analyze the chain from top to bottom to verify continuity.

  7. Question 7

    Q7

    During a malware analysis, you discover a script that checks for the presence of VMwareService.exe and VBoxService.exe processes before executing its payload. If these processes are found, the script terminates immediately. What is this behavior called?

    Show answer & explanation

    Correct answer: A

    This is a classic anti-forensic technique known as VM Detection or Anti-Sandboxing. Malware authors use it to prevent security researchers and automated sandboxes from analyzing the malware's behavior. If the malware detects it is running in a virtual environment (common for analysis labs), it stays dormant.

  8. Question 8

    Q8

    In a legal proceeding involving digital evidence, the defense attorney challenges the admissibility of a hard drive image, claiming it may have been altered during analysis. Which of the following is the BEST way for the forensic investigator to prove the integrity of the evidence?

    Show answer & explanation

    Correct answer: A

    Cryptographic hashes (like MD5, SHA-1, SHA-256) act as a digital fingerprint. If a single bit of the data changes, the hash value changes completely. Matching hashes prove mathematically that the evidence has not been altered since acquisition.

  9. Question 9

    Q9

    According to the 'Best Evidence Rule', which of the following is generally required in court when the content of a writing, recording, or photograph is in dispute?

    Show answer & explanation

    Correct answer: A

    The Best Evidence Rule states that the original writing, recording, or photograph is required to prove its content. In digital forensics, an accurate bit-stream duplicate (forensic image) is legally accepted as an 'original' under Federal Rules of Evidence (e.g., FRE 1001(d)), provided it is authenticated.

  10. Question 10

    Q10

    An investigator is conducting a cross-border investigation involving user data stored in a data center in Ireland. The investigator is based in the United States. Which regulation MUST the investigator primarily consider to ensure they do not violate privacy rights when transferring personal data of EU citizens to the US for analysis?

    Show answer & explanation

    Correct answer: A

    The GDPR imposes strict restrictions on the transfer of personal data of EU citizens to countries outside the EEA. Investigators must ensure mechanisms like Standard Contractual Clauses (SCCs) or mutual legal assistance treaties (MLATs) are in place before transferring evidence containing PII to the US.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 312-49v11 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 462 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon