312-49v11 Computer Hacking Forensic Investigator (CHFI v11) Practice Questions
Prepare for 312-49v11 with more than an answer.
Unlock the full exam and previous versions
- v1Computer Hacking Forensic Investigator (CHFI v11) 198 questions Current
- 312-49v10Legacy Computer Hacking Forensic Investigator (v10) 264 questions Locked
- Exam fee
- $650 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Forensic Science15%
- Regulations, Policies and Ethics10%
- Digital Evidence18%
- Procedures and Methodology17%
- Digital Forensics Devices29%
- Tools/Systems/Programs11%
- 1
You are analyzing a Windows 10 workstation to determine if a specific USB drive was connected. Which Windows Event Log is the MOST relevant source for identifying Plug and Play events for external storage devices?
Show answer details
Correct answer: D
While System.evtx (Event ID 20001/20003) is useful, the 'Microsoft-Windows-Partition/Diagnostic' and 'Microsoft-Windows-DriverFrameworks-UserMode/Operational' logs provide detailed Plug and Play events, including connection timestamps and volume serial numbers for USB devices.
- 2
Which file system is the default for modern iOS devices (iOS 10.3 and later) and features native encryption, clone capability, and space sharing?
Show answer details
Correct answer: A
APFS replaced HFS+ as the default file system for iOS, macOS, watchOS, and tvOS. It is optimized for Flash/SSD storage and includes features like strong encryption, copy-on-write, and space sharing.
- 3
An investigator is analyzing a raw hex dump of a file header to determine the file type. The first few bytes are
49 44 33. Which file format does this signature correspond to?Show answer details
Correct answer: D
49 44 33is the ASCII representation of 'ID3', which is the standard metadata container for MP3 audio files. - 4
When analyzing a Microsoft SQL Server database for forensic evidence, which file type contains the transaction logs that can be used to recover deleted records or reconstruct the database state at a specific point in time?
Show answer details
Correct answer: B
In MSSQL, the
.ldffile is the Log Data File. It records all transactions and database modifications. This is critical for forensics as it allows for 'point-in-time' recovery and analysis of queries executed, even if the data was subsequently deleted from the main data file. - 5
Which of the following describes the 'Locard's Exchange Principle' which forms the basis of forensic science?
Show answer details
Correct answer: B
Locard's Exchange Principle states 'Every contact leaves a trace'. In digital forensics, this means an attacker interacting with a system will inevitably leave artifacts (logs, registry changes, files) and take data.
- 6
A forensic investigator is tasked with establishing a forensic readiness plan for a financial institution that utilizes a hybrid cloud environment. The institution wants to ensure that they can legally collect evidence without disrupting business operations during a potential incident. Which of the following proactive measures would BEST satisfy the requirement for minimizing business disruption while ensuring evidence admissibility according to the ISO/IEC 27037 standard?
Show answer details
Correct answer: A
Centralized logging with secure forwarding ensures that potential evidence (logs) is preserved in near real-time outside the compromised environment. This allows investigators to analyze events without needing to take critical business systems offline immediately for imaging, aligning with forensic readiness goals of minimizing disruption. Full-disk imaging daily is impractical for performance, and relying solely on local logs risks deletion by attackers.
- 7
During an investigation into a suspected data exfiltration case involving a Linux-based web server, the lead investigator identifies a suspicious running process that does not map to a standard executable on the disk. The investigator suspects a fileless malware attack leveraging
memfd_create(). Which of the following acquisition methods must be prioritized to capture the payload before the system is powered down?Show answer details
Correct answer: C
Fileless malware using
memfd_create()resides solely in RAM and does not have a persistent file on the disk. Pulling the plug (dead acquisition) would destroy the RAM and thus the evidence of the malware. A live memory acquisition is critical to capture the process memory where the payload resides. - 8
Which of the following describes the correct order of volatility (from most volatile to least volatile) that a forensic investigator must follow when collecting evidence from a compromised workstation?
Show answer details
Correct answer: C
According to RFC 3227, the order of volatility is: CPU Registers/Cache (most volatile) -> Routing Table/ARP Cache/Process Table/Kernel Statistics/Memory -> Temporary File Systems -> Disk -> Remote Logging and Monitoring Data -> Physical Configuration/Topology -> Archival Media (least volatile).
- 9
A multinational corporation suspects an insider threat is leaking intellectual property via the Dark Web using the Tor network. The investigator needs to analyze the suspect's workstation for artifacts indicating Tor usage. Which of the following file paths or artifacts is MOST likely to contain evidence of Tor Browser execution on a Windows system?
Show answer details
Correct answer: C
The Tor Browser is often portable and does not always install registry keys like standard software. However, Windows Prefetch files (
.pf) inC:\Windows\Prefetchare created automatically when an application is executed. Findingtor.exe.pfor afirefox.exe.pf(since Tor is based on Firefox) running from a non-standard directory (like Desktop or USB) is a strong indicator of Tor usage. - 10
While investigating a compromised IoT deployment in a smart factory, the investigator encounters a proprietary embedded device that does not support standard acquisition interfaces. To acquire the firmware and data directly from the flash memory chip without damaging the device logic, which forensic technique should be employed?
Show answer details
Correct answer: B
JTAG forensics involves connecting to the Test Access Ports (TAPs) on the device's printed circuit board (PCB) to read the memory contents directly from the chip. This is a non-destructive method compared to 'Chip-off' (which involves desoldering) and allows acquisition when standard software ports are disabled or unavailable.
