Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 2Objective 3

Defeating Anti-Forensics Techniques CHFI Practice Questions (Page 3)

Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.

43questions here
9free pages
6concepts

Questions 11–15

  1. 11application · medium

    A forensic examiner is investigating a Windows system where the user's Recycle Bin is empty, but the 'INFO2' file (or the $I files) shows entries for recently deleted files. The examiner also finds that the 'Recent' folder has been cleared. What is the most likely anti-forensics technique?

    Select an answer first
  2. 12expert · hard

    A forensic examiner is analyzing a Windows system where the suspect is believed to have used a tool to modify the timestamps of files and also used steganography to hide data in images. The examiner has identified several images with suspicious characteristics. Which combination of forensic techniques would BEST confirm both the timestamp manipulation and the steganography?

    Select an answer first
  3. 13application · medium

    You are examining a USB drive that was used by a suspect. The drive is formatted with FAT32 and contains several image files. You notice that the 'file size' of one image is 2 MB, but when you open it in a hex editor, the data after the JPEG end-of-image marker (FF D9) contains a large amount of non-image data. What is the most likely anti-forensics technique?

    Select an answer first
  4. 14expert · hard

    A forensic examiner is analyzing a disk image and finds a file that appears to be a JPEG image. The file's header is correct, but the file's footer (FF D9) is missing. The examiner also notices that the file's size is larger than the sum of its visible data. What is the most likely explanation?

    Select an answer first
  5. 15application · medium

    During a forensic examination of a Windows 10 workstation, you find a suspicious file named 'notes.txt' in the C:\Users\Public\Documents folder. The file's size on disk is 4 KB, but the file's logical size is only 12 bytes. You suspect hidden data. Which technique should you use to check for hidden data in this file?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.