ExamDumpster

Free 312-49v11 sample questions

Real questions from the Computer Hacking Forensic Investigator (CHFI v11) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A forensic investigator is tasked with establishing a forensic readiness plan for a financial institution that utilizes a hybrid cloud environment. The institution wants to ensure that they can legally collect evidence without disrupting business operations during a potential incident. Which of the following proactive measures would BEST satisfy the requirement for minimizing business disruption while ensuring evidence admissibility according to the ISO/IEC 27037 standard?

Question 2Choose one

During an investigation into a suspected data exfiltration case involving a Linux-based web server, the lead investigator identifies a suspicious running process that does not map to a standard executable on the disk. The investigator suspects a fileless malware attack leveraging `memfd_create()`. Which of the following acquisition methods must be prioritized to capture the payload before the system is powered down?

Question 3Choose one

Which of the following describes the correct order of volatility (from most volatile to least volatile) that a forensic investigator must follow when collecting evidence from a compromised workstation?

Question 4Choose one

A multinational corporation suspects an insider threat is leaking intellectual property via the Dark Web using the Tor network. The investigator needs to analyze the suspect's workstation for artifacts indicating Tor usage. Which of the following file paths or artifacts is MOST likely to contain evidence of Tor Browser execution on a Windows system?

Question 5Choose one

While investigating a compromised IoT deployment in a smart factory, the investigator encounters a proprietary embedded device that does not support standard acquisition interfaces. To acquire the firmware and data directly from the flash memory chip without damaging the device logic, which forensic technique should be employed?

Question 6Choose one

An investigator is analyzing a suspicious email header to trace the origin of a phishing attack. The header contains the following field: `Received: from mail.attacker.com ([192.168.1.50]) by mail.victim.com with ESMTP id 12345`. What is the primary limitation of relying solely on this 'Received' header for attribution?

Question 7Choose one

During a malware analysis, you discover a script that checks for the presence of `VMwareService.exe` and `VBoxService.exe` processes before executing its payload. If these processes are found, the script terminates immediately. What is this behavior called?

Question 8Choose one

In a legal proceeding involving digital evidence, the defense attorney challenges the admissibility of a hard drive image, claiming it may have been altered during analysis. Which of the following is the BEST way for the forensic investigator to prove the integrity of the evidence?

Question 9Choose one

According to the 'Best Evidence Rule', which of the following is generally required in court when the content of a writing, recording, or photograph is in dispute?

Question 10Choose one

An investigator is conducting a cross-border investigation involving user data stored in a data center in Ireland. The investigator is based in the United States. Which regulation MUST the investigator primarily consider to ensure they do not violate privacy rights when transferring personal data of EU citizens to the US for analysis?

10 more free samples are waiting

Create a free account to unlock the whole 312-49v11 sample bank, or get full access to all 198 practice questions in the simulator.

Create account