100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CHFI Missed Questions and Answers | Latest update 100% Pass

Rating
-
Sold
-
Pages
32
Grade
A+
Uploaded on
22-10-2024
Written in
2024/2025

CHFI Missed Questions and Answers | Latest update 100% Pass

Institution
Classroom
Course
Classroom











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Classroom
Course
Classroom

Document information

Uploaded on
October 22, 2024
Number of pages
32
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CHFI Missed Questions and Answers | Latest update
100% Pass


When searching through file headers for picture file formats, what should be searched to find
a JPEG file in hexadecimal format?



A. FF D8 FF E0 00 10

B. FF FF FF FF FF FF

C. FF 00 FF 00 FF 00

D. EF 00 EF 00 EF 00 - ✔✔A. FF D8 FF E0 00 10



What type of file is represented by a colon (:) with a name following it in the Master
FileTable (MFT) of an NTFS disk?



A. Compressed file

B. Data stream file

C. Encrypted file

D. Reserved file - ✔✔B. Data stream file



When carrying out a forensics investigation, why should you never delete a partition on a
dynamic disk?

,A. All virtual memory will be deleted

B. The wrong partition may be set to active

C. This action can corrupt the disk

D. The computer will be set in a constant reboot state - ✔✔C. This action can corrupt the disk



Jacob is a computer forensics investigator with over 10 years experience in investigations and
has written over 50 articles on computer forensics. He has been called upon as a qualified
witness to testify the accuracy and integrity of the technical log files gathered in an
investigation into computer fraud. What is the term used for Jacob testimony in this
case?computer fraud. What is the term used for Jacob? testimony in this case?



A. Justification

B. Authentication

C. Reiteration

D. Certification - ✔✔B. Authentication



What is the slave device connected to the secondary IDE controller on a Linux OS referred to?



A. hda

B. hdd

C. hdb

D. hdc - ✔✔B. hdd

,During an investigation, an employee was found to have deleted harassing emails that were sent
to someone else. The company was using Microsoft Exchange and had message tracking
enabled. Where could the investigator search to find the message tracking log file on the
Exchange server?



A. C:\Program Files\Exchsrvr\servername.log

B. D:\Exchsrvr\Message Tracking\servername.log

C. C:\Exchsrvr\Message Tracking\servername.log

D. C:\Program Files\Microsoft Exchange\srvr\servername.log - ✔✔A.
C:\Program Files\Exchsrvr\servername.log



What file is processed at the end of a Windows XP boot to initialize the logon dialog box?



A. NTOSKRNL.EXE

B. NTLDR

C. LSASS.EXE

D. NTDETECT.COM - ✔✔C. LSASS.EXE



Paraben Lockdown device uses which operating system to write hard drive
data?Paraben?Lockdown device uses which operating system to write hard drive data?



A. Mac OS

B. Red Hat

, C. Unix

D. Windows - ✔✔D. Windows



A picture file is recovered from a computer under investigation. During the investigation
process, the file is enlarged 500% to get a better view of its contents. The picture quality is not
degraded at all from this process. What kind of picture is this file?its contents. The picture?
quality is not degraded at all from this process. What kind of picture is this file?



A. Raster image

B. Vector image

C. Metafile image

D. Catalog image - ✔✔B. Vector image



What advantage does the tool Evidor have over the built-in Windows search?



A. It can find deleted files even after they have been physically removed

B. It can find bad sectors on the hard drive

C. It can search slack space

D. It can find files hidden within ADS - ✔✔C. It can search slack space



In the context of file deletion process, which of the following statement holds true?



A. When files are deleted, the data is overwritten and the cluster marked as available

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
QUINTER New York College Of Dentistry
View profile
Follow You need to be logged in order to follow users or courses
Sold
339
Member since
2 year
Number of followers
104
Documents
38211
Last sold
4 days ago

3.4

57 reviews

5
25
4
8
3
7
2
1
1
16

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions