Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 2Objective 3

Defeating Anti-Forensics Techniques CHFI Practice Questions (Page 7)

Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.

43questions here
9free pages
6concepts

Questions 31–35

  1. 31foundation · easy

    An investigator is examining a Windows system and suspects that a suspect hid data within an existing file without affecting its visible content. Which of the following is a common technique for hiding data in such a way?

    Select an answer first
  2. 32application · medium

    A forensic examiner is reviewing Windows Event Logs from a compromised server. The logs show a gap of 45 minutes during the suspected intrusion window, and the last event before the gap has an Event ID 1102 (audit log cleared). The examiner also notices that the system time was set back by 2 hours just before the gap. Which combination of anti-forensics techniques is most likely present?

    Select an answer first
  3. 33application · medium

    A forensic examiner is analyzing a Windows system where the suspect is believed to have used a tool to change file timestamps to avoid detection. The examiner has identified several files with timestamps that do not match the system's event logs. Which forensic technique would BEST confirm the timestamp manipulation?

    Select an answer first
  4. 34application · medium

    A forensic examiner is analyzing a Linux system where the 'last' command shows no logins after a certain date, but the 'wtmp' file has a modification time that is later than the last recorded login. The examiner also finds that the system's 'utmp' file is empty. What is the most likely anti-forensics technique being used?

    Select an answer first
  5. 35foundation · easy

    A forensic examiner is analyzing a disk image and suspects that a suspect hid sensitive information in the unused space between the end of a file's data and the end of the allocated cluster. Which area of the disk is being used for this concealment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.