Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

ECCouncil 312-49v11 - Computer Hacking Forensic Investigator (CHFIv11)

Page: 13 / 14
Total 443 questions

In the course of a detailed investigation into a potential breach, forensic analysts scrutinize the logs of an organization’s security devices and uncover an unexpected pattern of activity originating from an internal IP address. These activities involve frequent communication with an external server located in a foreign country, previously not associated with any authorized business functions. The volume of interactions is significantly higher than what is typically seen in standard operations for this particular system. Some of the requests reveal an unusual type of data—large binary files—that are atypical for the kind of processes the internal systems typically perform. Upon further analysis, the data exchanges appear to be irregular, as they do not align with any known workflows, and the destination server is outside the organization ' s usual trusted zones. Which indicator of compromise (IoC) does this behavior most likely signify?

A.

Multiple failed attempts to connect to unauthorized external IPs.

B.

Unusual login behavior from internal systems during non business hours.

C.

Abnormal outbound traffic suggesting data exfiltration.

D.

Unusual internal system reboots causing a disruption in normal operations.

A company’s online banking platform has recently been experiencing security breaches, with unauthorized access to customer accounts. Upon investigation, it is suspected that a brute force attack is being employed to gain entry.

In the scenario described, what does the term " brute force attack " likely refer to?

A.

An attack where hackers manipulate user interface elements to gain access to sensitive data.

B.

A social engineering tactic involving tricking employees into revealing login credentials.

C.

A method of exploiting vulnerabilities in the company ' s network infrastructure.

D.

A technique where attackers systematically guess passwords or encryption keys to gain unauthorized access.

In a suspected malware outbreak at a financial services company in Chicago, investigators observe that the organization ' s mail server is relaying suspicious traffic and generating unusual message errors across multiple systems. The behavior suggests that the system may be compromised and distributing unsolicited messages. What indicator of malware should investigators prioritize to validate this suspicion?

A.

Unexplained bounced emails

B.

Alerts of spam messages from the system or email

C.

Numerous unwanted emails and social posts

D.

System slowdown and longer reboot times

You are a forensic investigator working for a cybersecurity firm tasked with analyzing a suspicious Microsoft Office document named “infected_doc.” The document was discovered in an email attachment sent to multiple employees at a large corporation. Concerns have been raised about potential malware embedded within the document, particularly involving VBA macros.

As a forensic investigator examining the “infected_doc” Microsoft Office document, what initial step would you take to identify suspicious or malicious components within the file?

A.

Execute the command oleid " " on a Linux workstation to review all components for suspicious elements.

B.

Open the document in a sandbox environment to observe any unusual behavior.

C.

Run the command analyze_doc " " to scan the document for potential threats.

D.

Utilize a browser-based tool to inspect the document ' s metadata for any anomalies.

During a document-recovery effort at a publishing house in New York City, forensic examiners carve fragmented text strings from a suspect ' s deleted email archive. The recovered characters represent only English letters, numbers, and basic punctuation encoded in a compact 7-bit format limited to 128 specified symbols. Which encoding standard best matches this constraint for reconstructing readable English content?

A.

UTF-16

B.

ASCII

C.

UNICODE

D.

UTF-8

During a late-night investigation at a tech firm ' s office in Seattle, the first responder arrives to find multiple computers displaying active sessions. To ensure a comprehensive record that supports later evidence recreation, which action should the first responder prioritize at the crime scene?

A.

Maintain a log of all actions taken during every investigation phase

B.

Document witness statements along with other relevant information if identified

C.

Take a photograph of the computer monitor screen and note what is seen

D.

Note the location where the evidence is securely stored for further examination

In a trade-secret investigation in Detroit, agents obtain judicial authorization to image a suspect ' s home server. To ensure the search remains limited to what the court has approved, the warrant must clearly define its scope. Which warrant requirement provides this limitation?

A.

Specifies the place to be searched and the items to be seized

B.

Directs law enforcement to search for evidence under judicial order

C.

Establishes the duration for which the warrant remains valid

D.

Authorizes investigators to consult a service provider

William, a forensic specialist, was assigned to investigate a system breach by extracting artifacts related to the Tor browser from a memory dump obtained from the victim ' s machine. As part of the investigation, William analyzed the memory dump and discovered that it contained the maximum possible number of artifacts related to the Tor browser. William understood that to fully understand the extent of the evidence, he needed to identify which condition would result in the maximum number of artifacts being present in the memory dump. Which of the following conditions provided William with the maximum possible number of artifacts?

A.

Tor browser opened

B.

Tor browser uninstalled

C.

Tor browser installed

D.

Tor browser closed

During an internal audit following suspected misuse of privileged credentials at a technology services firm, investigators must review detailed activity records related to configuration changes, API calls, and access attempts made against cloud-hosted resources. The organization operates entirely within a single cloud provider ' s infrastructure, and the investigation requires a native service that records management-plane actions with precise timestamps, source addresses, and request parameters for later reconstruction of user activity. Which platform would investigators rely on to reconstruct this activity timeline?

A.

Azure Monitor Logs

B.

AWS CloudTrail

C.

Microsoft Sentinel

D.

Google Logs Explorer

You work as a forensic analyst for a prominent tech company that suspects one of its software developers has been selling proprietary source code. The suspect’s computer, a macOS machine, has been secured and awaits examination. You ' ve been tasked with obtaining a forensically sound copy of the suspect ' s system data. Given the situation and the potential for macOS-specific malware on the suspect ' s computer, which method would be the best approach to obtain a forensically sound copy of the data?

A.

Disconnect the suspect ' s hard drive and connect it to a forensic workstation.

B.

Conduct a live acquisition using a software write-blocker.

C.

Remotely acquire the data via network-based acquisition

D.

Use a forensic boot disk to bypass the macOS and directly access the disk for acquisition.