Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 6Objective 2

Email and Social Media Forensics CHFI Practice Questions (Page 11)

Part of the Cloud and Communication Forensics domain, which makes up ~14% of our current practice bank.

55questions here
11free pages
11concepts

Questions 51–55

  1. 51application · medium

    A company's mail server administrator notices a large number of outbound emails from a single user account during off-hours. The emails are being sent to external addresses and contain unusual attachments. As a forensic investigator, you need to determine whether the account was compromised or the user is sending data externally. Which server-side artifact would provide the most comprehensive evidence of the email activity, including sender IP, recipient addresses, and timestamps?

    Select an answer first
  2. 52application · medium

    During an investigation, you need to trace the origin of a phishing email that was received by an employee. You have the full email headers and access to the company's mail server logs. The 'Received' chain shows the message passed through three servers: the company's Exchange server, an external relay, and an unknown server. The last 'Received' header (the first one listed) contains an IP address. What is the most reliable next step to identify the sender's IP address?

    Select an answer first
  3. 53application · medium

    A suspect posted a photo on Instagram that allegedly shows a confidential document. The investigator wants to determine the exact time and location where the photo was taken. The photo was downloaded from Instagram. Which metadata source would be most reliable for this purpose?

    Select an answer first
  4. 54foundation · easy

    Which of the following is a primary source for recovering deleted webmail messages from a computer?

    Select an answer first
  5. 55application · medium

    During an internal investigation, you need to recover emails that a user sent and received via Microsoft Outlook on a Windows 10 workstation. The user's mailbox is hosted on an on-premises Exchange server, but the user also used Outlook in cached mode. The user has since deleted several emails from the mailbox. Which forensic artifact would most likely contain remnants of the deleted emails?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CHFI

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.