
EC-CouncilComputer Hacking Forensic Investigator
Domain 1Objective 2
Computer Forensics Investigation Process CHFI Practice Questions (Page 7)
Part of the Forensic Fundamentals and Process domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
7concepts
Questions 31–35
- 31
An investigator is examining a suspect's laptop for evidence of unauthorized data exfiltration. The investigator finds a suspicious file that appears to be a compressed archive. What is the MOST appropriate next step in the examination?
Select an answer first - 32
A forensic examiner is preparing the final report for a case involving a company's internal investigation. The report will be reviewed by the legal team and possibly used in court. Which element is ESSENTIAL to include in the report?
Select an answer first - 33
During cross-examination, a forensic expert is asked whether a specific tool used in the investigation is 'forensically sound.' How should the expert respond?
Select an answer first - 34
A forensic examiner is preparing to testify as an expert witness in a case involving email evidence. The examiner used a forensic tool to recover deleted emails from a suspect's computer. During direct examination, the prosecutor asks the examiner to explain the process used. What is the BEST way for the examiner to respond?
Select an answer first - 35
An investigator is collecting evidence from a network server that is part of a botnet. The server is located in a different country with different data protection laws. The investigator needs to collect the server's logs and memory. What is the MOST important consideration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.