Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 2Objective 3

Defeating Anti-Forensics Techniques CHFI Practice Questions (Page 9)

Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.

43questions here
9free pages
6concepts

Questions 41–43

  1. 41expert · hard

    A forensic examiner is analyzing a compromised server where the attacker used a rootkit to hide processes and modified the system's logs to remove traces of their activity. The examiner has a forensic image of the server. Which approach would BEST uncover the hidden processes and the log tampering?

    Select an answer first
  2. 42expert · hard

    A forensic examiner is investigating a Windows system where the suspect is known to have used a VPN and a proxy to hide their IP address. The examiner finds that the system's 'ipconfig' shows a VPN adapter, but the VPN client logs are missing. The examiner also finds that the 'hosts' file has been modified to redirect a known security website to a local address. Which combination of anti-forensics techniques is present?

    Select an answer first
  3. 43application · medium

    You are leading a forensic team investigating a suspected insider threat. The suspect's computer has a large number of image files, and you suspect steganography. The team has limited time and must prioritize. Which approach is the most effective to identify hidden data across many images?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CHFI

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.