
EC-CouncilComputer Hacking Forensic Investigator
Domain 1Objective 2
Computer Forensics Investigation Process CHFI Practice Questions (Page 10)
Part of the Forensic Fundamentals and Process domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
7concepts
Questions 46–50
- 46
An analyst is examining a forensic image and finds a file that appears to be a deleted spreadsheet. The file's metadata shows it was last modified after the suspect's computer was seized. What should the analyst conclude?
Select an answer first - 47
A forensic examiner is called to testify in court about the analysis of a suspect's smartphone. The defense attorney asks the examiner to explain how the data was extracted. What is the examiner's best response?
Select an answer first - 48
A forensic investigator is preparing a report for a case that will be reviewed by a judge. The investigator wants to ensure the report is clear and defensible. Which practice is most important?
Select an answer first - 49
An investigator is collecting evidence from a Windows workstation involved in a data breach. The investigator needs to preserve the original hard drive while also obtaining a copy for analysis. Which action best preserves the integrity of the original evidence?
Select an answer first - 50
A first responder arrives at a scene where a computer is running and the user is still logged in. The responder must secure the scene. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.