312-49v10 Computer Hacking Forensic Investigator (v10) Practice Questions
Prepare for 312-49v10 with more than an answer.
Unlock the full exam and previous versions
- v1Computer Hacking Forensic Investigator (CHFI v11) 198 questions Locked
- 312-49v10Legacy Computer Hacking Forensic Investigator (v10) 264 questions Current
- Exam fee
- $550 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Forensic Science15%
- Regulations, Policies and Ethics10%
- Digital Evidence18%
- Procedures and Methodology17%
- Digital Forensics Devices29%
- Tools/Systems/Programs11%
- 1
A case study involves a manufacturing company that experienced a ransomware attack on its Operational Technology (OT) network, affecting several Programmable Logic Controllers (PLCs). The first responder, an IT administrator with no OT experience, immediately powered down the affected PLCs to stop the spread. Why was this action potentially detrimental to the forensic investigation?
Show answer details
Correct answer: B
PLCs and other OT devices often store critical runtime information, diagnostic data, and the current state of the industrial process in volatile memory (RAM). In the case of a malware infection, this RAM could also contain the malicious code itself, C2 communication details, or other critical artifacts. Immediately powering down the device erases all this volatile data, making it significantly harder to determine the root cause, the extent of the compromise, and the malware's behavior. This is a critical first responder mistake in OT environments.
- 2
The boot process of a modern Windows system using UEFI firmware and a GPT partition scheme differs significantly from the legacy BIOS-MBR method. In the UEFI-GPT boot process, what is the role of the EFI System Partition (ESP)?
Show answer details
Correct answer: C
The EFI System Partition (ESP) is a small, FAT32-formatted partition that is essential for UEFI-based systems. The UEFI firmware loads files directly from the ESP to start the boot process. This partition contains the boot loaders for installed operating systems (e.g., bootmgfw.efi for Windows), device driver files needed for booting, and system utility programs. It replaces the function of the MBR's boot code and the active partition's boot sector in the legacy BIOS system.
- 3
An examiner is investigating a fileless malware attack where the malicious payload was injected into the memory space of a legitimate process (
svchost.exe). To analyze the injected code and other memory artifacts, the examiner should use a tool specifically designed for memory forensics. Which of the following tools is the industry standard for this type of analysis?Show answer details
Correct answer: C
The Volatility Framework is a powerful, open-source collection of tools for analyzing volatile memory (RAM) dumps. It is specifically designed to extract digital artifacts from memory samples, including running processes, network connections, loaded DLLs, and registry keys. Plugins like
malfindandhollowfindare purpose-built to detect code injection techniques used by fileless malware. FTK Imager is primarily for disk imaging, and Wireshark is for network packet analysis. - 4
What is the primary purpose of creating and verifying a hash value (e.g., SHA-256) of a digital evidence file immediately after acquisition and before analysis?
Show answer details
Correct answer: C
Hashing is a fundamental principle in digital forensics used to maintain the integrity of evidence. A cryptographic hash function like SHA-256 produces a unique digital fingerprint for a file. By calculating the hash upon acquisition and then re-calculating it anytime the evidence is accessed or presented in court, an investigator can prove that the file has not been modified in any way. Any change to the file, even a single bit, will result in a completely different hash value.
- 5
Case Study:
A retail company suffered a data breach where customer credit card information was exfiltrated from its point-of-sale (POS) systems. The initial investigation reveals that the attacker gained access through a phishing email sent to a store manager, which led to the installation of RAM-scraping malware on the POS terminals.
The forensic team has acquired memory dumps and disk images from the affected terminals. The malware is not found on the disk images, suggesting it was a fileless variant that ran only in memory. The team needs to determine the malware's capabilities, its C2 infrastructure, and the extent of the data loss.
Which forensic procedures are essential to successfully complete this investigation? (Select TWO).
sequenceDiagram participant Attacker participant Manager participant POS_Terminal participant C2_Server Attacker->>Manager: Sends Phishing Email Manager->>Attacker: Clicks Link, Submits Credentials Attacker->>POS_Terminal: Authenticates with stolen credentials Attacker->>POS_Terminal: Deploys fileless RAM scraper POS_Terminal-->>C2_Server: Exfiltrates scraped card dataShow answer details
Correct answer: B, D
Since the malware is fileless and resides in memory, analyzing the RAM dumps is the most critical step. Using Volatility, investigators can identify suspicious processes, find injected code within legitimate processes (a common RAM scraper technique), and extract active network connections to identify the C2 server's IP address.
RAM-scraping malware works by reading memory to find credit card data (Track 1 and Track 2) before it is encrypted. A key analysis step is to run string searches and regular expressions against the memory dumps to find patterns that match credit card numbers. This helps to confirm the malware's function and provides a direct way to estimate the number of compromised cards.
- 6
An investigator is analyzing a memory dump from a compromised Linux server that hosted multiple Docker containers. The attacker allegedly used a fileless malware variant that executed entirely in memory. The investigator suspects the malware manipulated system calls using a kernel module. Which Volatility 3 plugin would be most effective for initially identifying anomalous kernel modules and their hooks?
Show answer details
Correct answer: C
The
linux_check_syscallplugin is specifically designed to check the system call table for hooks, which is a common technique used by rootkits and fileless malware to intercept and manipulate system functions. Whilelinux_pslistshows processes andlinux_lsmodlists loaded modules,linux_check_syscalldirectly addresses the suspected manipulation of system calls, making it the most effective initial step.linux_check_credsis used for checking process credentials for signs of privilege escalation. - 7
A financial institution's internal audit team is investigating a case of suspected insider trading facilitated through corporate email. The investigation is subject to strict eDiscovery protocols under the EDRM framework. The legal team has issued a hold on all relevant mailboxes. At which stage of the EDRM cycle would the forensic team use keyword searching, date filtering, and de-duplication on the collected mailbox data?
Show answer details
Correct answer: B
In the Electronic Discovery Reference Model (EDRM), the 'Processing' stage involves reducing the volume of electronically stored information (ESI) and converting it into forms more suitable for review and analysis. Activities like keyword searching, filtering by date, and removing duplicate files (de-duplication) are core to this stage. 'Collection' is the acquisition of data, 'Review' is the analysis of the processed data for relevance, and 'Identification' is locating potential sources of ESI.
- 8
During a forensic investigation of a compromised web server, an analyst discovers that the attacker manipulated the timestamps of several critical log files using the
touchcommand to cover their tracks. This action is a form of trail obfuscation. Which of the following artifacts is most likely to reveal the discrepancy between the modified timestamps and the actual time of file system changes?Show answer details
Correct answer: C
On an NTFS file system, a file has two main sets of timestamps stored in the Master File Table (MFT): one in the $STANDARD_INFORMATION attribute and another in the $FILE_NAME attribute. Many user-level tools, including
touch, only modify the timestamps in the $STANDARD_INFORMATION attribute. Forensic tools can compare these timestamps against those in the $FILE_NAME attribute, which are not as easily modified. A mismatch between these two sets of timestamps is a strong indicator of timestomping. Inode metadata serves a similar purpose on ext4, but the MFT attributes are specific to NTFS. - 9
A forensic investigator in the European Union is conducting an investigation into corporate fraud that involves employee data from Germany and France. The investigator must ensure compliance with the General Data Protection Regulation (GDPR). Which GDPR principle is most critical when deciding how much data to collect and ensuring that only data strictly relevant to the fraud case is acquired?
Show answer details
Correct answer: C
The principle of Data Minimization (Article 5(1)(c) of GDPR) dictates that personal data collected must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. In a forensic investigation, this means the investigator must make a concerted effort to only acquire data strictly relevant to the case, rather than collecting entire hard drives indiscriminately. Purpose Limitation refers to using the data only for the specified purpose, and Storage Limitation refers to not keeping it longer than necessary.
- 10
A forensic analyst is examining an Android device and needs to recover deleted SQLite database entries from a third-party messaging application. The database file itself is intact, but records have been removed. Which artifact within the SQLite file structure should the analyst focus on to potentially recover the deleted content? (Select TWO).
Show answer details
Correct answer: B, C
Freeblocks are pages within the SQLite database file that were previously allocated to a table but are now unused. When records are deleted, the pages they occupied are often marked as freeblocks but not immediately overwritten, making them a prime location for recovering deleted data.
The Write-Ahead Log (WAL) is a mechanism used by SQLite to implement atomic transactions. It stores changes to the database before they are committed to the main database file. The WAL file can contain copies of pages that have since been changed or deleted in the main file, providing another valuable source for data recovery.
