(CHFIv11) Test Exam 2026- Verified
Solutions download Instant PDF
Questions and Answers | 100% Pass
Guaranteed | Graded A+.
D
1. What is the primary goal of computer forensics?
O
A. Prevent hacking
B. Identify vulnerabilities
N
C. Preserve, analyze, and present digital evidence
O
D. Monitor network traffic
T
Answer: C
Rationale: Digital forensics focuses on collecting, preserving, analyzing,
C
and presenting evidence in a legally admissible manner.
O
PY
2. Which hashing algorithm is commonly used to verify forensic image
integrity?
A. AES
B. SHA-256
C. RSA D. DES
Answer: B
Rationale: SHA-256 is widely used to validate forensic images and
ensure integrity.
,3. What is the purpose of a write blocker?
A. Encrypt data
B. Prevent modification of original evidence
C. Speed up acquisition
D. Format drives
Answer: B
Rationale: Write blockers ensure no data is altered during forensic
D
acquisition.
O
N
4. Which file system is commonly found on modern Windows systems?
O
A. FAT32
B. EXT4
T
C. NTFS
D. HFS+
C
Answer: C
O
PY
5. What is volatile data?
A. Encrypted files
B. Data stored in cloud
C. Data lost when system powers off
D. Archived logs
Answer: C
,Rationale: Volatile data includes RAM contents, active network
connections, and running processes.
6. What is the correct order of volatility (highest first)?
A. Hard drive → RAM → CPU cache
B. CPU cache → RAM → Disk
C. RAM → CPU cache → Disk
D. Disk → RAM → Cache
D
Answer: B
O
Rationale: CPU cache is most volatile, followed by RAM, then persistent
storage.
N
O
7. Which tool is commonly used for disk imaging?
T
A. Nmap
C
B. FTK Imager
O
C. Wireshark
D. Metasploit
PY
Answer: B
8. What is steganography?
A. Encrypting traffic
B. Hiding data within another file
C. Cracking passwords
D. Wiping disks
, Answer: B
9. What is a chain of custody?
A. Firewall rule set
B. Documentation tracking evidence handling
C. Encryption certificate
D. Malware log
D
Answer: B
O
10. Which Windows registry hive contains user-specific settings?
N
O
A. HKEY_LOCAL_MACHINE
B. HKEY_USERS
T
C. HKEY_CURRENT_USER
D. HKEY_CLASSES_ROOT
C
Answer: C
O
PY
11. What artifact can indicate USB device usage?
A. SAM file
B. setupapi.dev.log
C. ntldr
D. pagefile.sys
Answer: B