Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

ECCouncil 312-49v11 - Computer Hacking Forensic Investigator (CHFIv11)

Page: 2 / 14
Total 443 questions

Emily, a seasoned digital forensics investigator, has been tasked with conducting an investigation on a Linux system running the ext2 file system. The system was involved in a suspected data exfiltration incident, and Emily needs to gather detailed information about the metadata of a specific file that may have been accessed or modified during the attack. After reviewing the system ' s file system structure, Emily aims to focus on the source that contains the file’s metadata, such as timestamps, permissions, and file size. Which of the following would be the best source for this critical information?

A.

The file ' s data blocks

B.

The dentry cache

C.

The superblock

D.

The inode table

In the aftermath of a sophisticated cyber-attack on a financial institution, forensic investigators are tasked with retrieving critical evidence from a compromised server. However, upon examination, they encounter encrypted files and password-protected directories, indicating attempts to thwart forensic analysis through password protection.

To counter these anti-forensic measures effectively, which of the following strategies would be most effective?

A.

Conducting a brute-force attack to systematically guess the passwords of encrypted files and protected directories.

B.

Utilizing a dictionary attack to systematically test common passwords against encrypted files and directories.

C.

Deploying a targeted phishing campaign to obtain passwords or encryption keys safeguarding files and directories.

D.

Utilizing rainbow tables to expedite the decryption process and bypass password protection mechanisms.

Jessica is conducting a forensic analysis on a Windows machine suspected of being involved in data exfiltration. She wants to identify any suspicious login attempts and track the number of failed login attempts to see if a brute-force attack was attempted. Which of the following event IDs will provide this information?

A.

4727

B.

4732

C.

4758

D.

4625

During an insider threat investigation at a software company in Boston, forensic analysts suspect that a malicious utility was repeatedly executed to exfiltrate sensitive source code. They use WinPrefetchView to analyze Prefetch files from the compromised workstation. Which specific detail displayed by this tool helps investigators confirm the most recent execution of the utility?

A.

Process EXE

B.

Run Counter

C.

File Size

D.

Last Run Time

During a targeted phishing follow-up at a financial firm in New York, forensic analysts parse a compromised endpoint ' s raw Event Log File Format records to validate a timeline. They need to differentiate per-event timestamps from overall file-level status flags to see whether late writes occurred around shutdown. In this format, which component provides the per-event timestamps needed for that comparison?

A.

EVENTLOGRECORD structure

B.

ELF_LOGFILE_HEADER_WRAP

C.

ELF_LOGFILE_HEADER structure

After a significant malware attack on a corporation, Bob, a forensic analyst, was asked to investigate. The malware had made numerous modifications in files and folders across the system to cover its tracks. Bob decides to monitor these changes closely to understand the malware ' s operation. What tool can Bob use to monitor and log all the changes happening in the system ' s files and folders?

A.

IDA Pro

B.

EnCase

C.

Sysmon

D.

FTK Imager

Michael, a forensic examiner, is conducting a forensic analysis of an image file obtained from a suspect ' s machine. While examining the file using a hex editor, he discovers that the hex value of the file starts with the sequence " 89 50 4c. " The file appears to be suspicious, so Michael needs to identify the type of the file to understand its structure and determine whether it contains any malicious content. Given this information, what type of file is Michael looking at?

A.

BMP

B.

JPEG

C.

PDF

D.

PNC

During a malware investigation at a financial institution in New York, forensic investigators executed a suspicious file on a Windows forensic workstation. Using the netstat -an command, they discovered that port 1177 had been opened and was actively connected. The investigators now need to determine whether the observed port activity is associated with legitimate services or indicative of malicious behavior. How should investigators evaluate the significance of this port activity?

A.

Review the list for any suspicious port number that is opened on the workstation

B.

Refer to online port databases

C.

Execute the suspect file on the forensic workstation

D.

Display all active TCP/IP connections along with a list of active ports using netstat -an

During a cybercrime investigation, investigators obtain a warrant to search a suspect ' s computer system for evidence of hacking activities. As they collect data from the suspect ' s electronic devices, they inadvertently access information revealing the identities of other users connected to the system.

Which step in the cybercrime investigation process raises concerns related to privacy issues?

A.

Implementing network security measures

B.

Conducting forensic analysis

C.

Preserving the anonymity of other users

D.

Obtaining search warrants

Lucas, a forensic investigator, encounters a laptop during his investigation that is locked with a BIOS password. The laptop ' s owner does not remember the BIOS password, and Lucas needs to bypass it in order to continue the forensic analysis. He decides to use a method that involves removing and reinserting the CMOS battery. What is the purpose of removing the CMOS battery in this scenario?

A.

To remove encryption from the hard drive

B.

To bypass user account passwords

C.

To reset the system password in BIOS

D.

To reset the BIOS password