
EC-CouncilComputer Hacking Forensic Investigator
Domain 6Objective 2
Email and Social Media Forensics CHFI Practice Questions (Page 6)
Part of the Cloud and Communication Forensics domain, which makes up ~14% of our current practice bank.
55questions here
11free pages
11concepts
Questions 26–30
- 26
What type of information can be extracted from email server logs to help reconstruct email activity?
Select an answer first - 27
A company's mail server logs show that a user's account sent a large volume of emails to an external address at 2:00 AM. The user claims they were asleep and did not send the emails. The emails have a 'Received' header showing the originating IP as a VPN service provider. The company uses multi-factor authentication (MFA) for email access. Which conclusion is most defensible?
Select an answer first - 28
A forensic analyst is examining a photo posted on a suspect's Twitter account. The photo was downloaded from the tweet. The analyst wants to determine the device that took the photo and the exact time it was taken. Which of the following is the most reliable method?
Select an answer first - 29
An investigator is tasked with building a digital footprint of a suspect based on publicly available social media profiles. The suspect is known to use the username 'shadow_walker' on multiple platforms. The investigator needs to document evidence that will be admissible in court. Which approach best balances thoroughness and legal admissibility?
Select an answer first - 30
Which of the following is a common location for social media app data on an Android device?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.