312-49v11 Sample Questions

312-49v11 Sample Questions & Answers

Anti-forensics techniques and Windows, Linux, and Android file analysis dominate the weighting, alongside how ready an investigator is to acquire data, the rules for searching and seizing evidence, event-log analysis, the investigation process, and the tools used.

Launch the full 312-49v11 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Forensic Science · Technology Fundamentals

    An investigator is analyzing a suspicious email header to trace the origin of a phishing attack. The header contains the following field: Received: from mail.attacker.com ([192.168.1.50]) by mail.victim.com with ESMTP id 12345. What is the primary limitation of relying solely on this 'Received' header for attribution?

    Show answer & explanation

    Correct answer: B

    Email headers are added from bottom to top. The receiving server adds the topmost 'Received' header, which is generally trusted. However, attackers can inject fake 'Received' headers at the bottom of the chain to mislead investigators about the true origin. Investigators must analyze the chain from top to bottom to verify continuity.

  2. Question 2Beginner

    Forensic Science · Cybercrimes and Investigation Challenges

    During a malware analysis, you discover a script that checks for the presence of VMwareService.exe and VBoxService.exe processes before executing its payload. If these processes are found, the script terminates immediately. What is this behavior called?

    Show answer & explanation

    Correct answer: D

    This is a classic anti-forensic technique known as VM Detection or Anti-Sandboxing. Malware authors use it to prevent security researchers and automated sandboxes from analyzing the malware's behavior. If the malware detects it is running in a virtual environment (common for analysis labs), it stays dormant.

  3. Question 3Beginner

    Regulations, Policies and Ethics · Evidence Rules and Legal Procedures

    In a legal proceeding involving digital evidence, the defense attorney challenges the admissibility of a hard drive image, claiming it may have been altered during analysis. Which of the following is the BEST way for the forensic investigator to prove the integrity of the evidence?

    Show answer & explanation

    Correct answer: C

    Cryptographic hashes (like MD5, SHA-1, SHA-256) act as a digital fingerprint. If a single bit of the data changes, the hash value changes completely. Matching hashes prove mathematically that the evidence has not been altered since acquisition.

  4. Question 4Intermediate

    Regulations, Policies and Ethics · Evidence Rules and Legal Procedures

    According to the 'Best Evidence Rule', which of the following is generally required in court when the content of a writing, recording, or photograph is in dispute?

    Show answer & explanation

    Correct answer: C

    The Best Evidence Rule states that the original writing, recording, or photograph is required to prove its content. In digital forensics, an accurate bit-stream duplicate (forensic image) is legally accepted as an 'original' under Federal Rules of Evidence (e.g., FRE 1001(d)), provided it is authenticated.

  5. Question 5Intermediate

    Regulations, Policies and Ethics · Legal Compliance and Standards

    An investigator is conducting a cross-border investigation involving user data stored in a data center in Ireland. The investigator is based in the United States. Which regulation MUST the investigator primarily consider to ensure they do not violate privacy rights when transferring personal data of EU citizens to the US for analysis?

    Show answer & explanation

    Correct answer: B

    The GDPR imposes strict restrictions on the transfer of personal data of EU citizens to countries outside the EEA. Investigators must ensure mechanisms like Standard Contractual Clauses (SCCs) or mutual legal assistance treaties (MLATs) are in place before transferring evidence containing PII to the US.

  6. Question 6Advanced

    Regulations, Policies and Ethics · Legal Compliance and Standards

    You are preparing to testify as an expert witness in a cybercrime trial. The opposing counsel asks you a hypothetical question about a technology you are vaguely familiar with but have not analyzed in this specific case. According to the CHFI code of ethics and expert witness best practices, what is the MOST appropriate response?

    Show answer & explanation

    Correct answer: B

    An expert witness must remain objective and only testify within the boundaries of their expertise and the facts of the case. Guessing or speculating on unfamiliar topics damages credibility and violates ethical standards. It is correct and professional to admit limitations.

  7. Question 7Intermediate

    Regulations, Policies and Ethics · Legal Compliance and Standards

    Which ISO standard specifically provides guidelines for the identification, collection, acquisition, and preservation of digital evidence?

    Show answer & explanation

    Correct answer: D

    ISO/IEC 27037:2012 provides guidelines for specific activities in the handling of digital evidence, including identification, collection, acquisition, and preservation. It is the primary standard referenced for digital evidence handling.

  8. Question 8Intermediate

    Digital Evidence · Storage Systems and File Systems

    You are acquiring a forensic image of a SATA SSD. Unlike traditional spinning HDDs, SSDs have a feature called 'Garbage Collection' and 'TRIM' that can alter data even without user intervention. Which hardware device is essential to prevent the SSD controller from modifying data during the imaging process?

    Show answer & explanation

    Correct answer: C

    A hardware write blocker intercepts write commands from the host computer to the drive. For SSDs, it is crucial because mounting the drive (even read-only in software) might trigger background controller processes like TRIM or garbage collection that could permanently wipe deleted data blocks. The hardware blocker prevents these signals from reaching the drive.

  9. Question 9Advanced

    Digital Evidence · Storage Systems and File Systems

    A server utilizing RAID 5 has crashed. The array consists of 4 disks. You have successfully acquired images of all 4 disks. To reconstruct the RAID array virtually in a forensic tool, what minimum information do you need besides the disk images?

    Show answer & explanation

    Correct answer: C

    To rebuild a RAID 5 array, you must know the order of the disks (Disk 1, Disk 2, etc.), the stripe size (block size of data written before moving to next disk), and the parity rotation scheme (e.g., Left Asynchronous, Right Synchronous). Without these parameters, the data will be scrambled.

  10. Question 10Intermediate

    Digital Evidence · Operating System Boot and Architecture

    In a UEFI-based Windows system, which partition contains the boot loaders (like bootmgfw.efi) and is formatted with the FAT32 file system?

    Show answer & explanation

    Correct answer: D

    The EFI System Partition (ESP) is a dedicated partition on GPT disks used by UEFI firmware to load the OS. It is formatted as FAT32 and contains boot loaders, device drivers, and system utilities. This is distinct from the NTFS system partition where Windows resides.

Ready for the real thing?

The full 312-49v11 simulator has every exam-style question, timed mode, and instant scoring.