312-49v10 Sample Questions

312-49v10 Sample Questions & Answers

Anti-forensics countermeasures and file, system, and network analysis get the largest share, next to forensic science basics and data acquisition, legal compliance, operating-system and log evidence, investigation methodology, and the tools involved.

Launch the full 312-49v10 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Procedures and Methodology · Data Acquisition Methodology

    A CHFI is tasked with creating a forensic image of a 2TB NVMe SSD from a suspect's laptop. To ensure the integrity of the evidence, the investigator must use a hardware write blocker. The primary reason for using a hardware write blocker over a software-based one in this scenario is that hardware blockers:

    Show answer & explanation

    Correct answer: B

    Hardware write blockers are physically placed between the evidence drive and the forensic workstation. They intercept and block any write commands at the hardware level, regardless of the operating system or software running on the workstation. This independence prevents accidental writes from OS-level processes (like automounting or indexing), which a software blocker running within that same OS might not be able to prevent, making hardware blockers more reliable and forensically sound.

  2. Question 2Beginner

    Digital Evidence · RAID Storage System

    True or False: In a RAID 5 configuration consisting of four 1TB drives, a forensic investigator can reconstruct the full data set even if two of the drives have failed simultaneously.

    Show answer & explanation

    Correct answer: B

    RAID 5 uses distributed parity, which allows it to withstand the failure of a single drive. The data from the failed drive can be rebuilt using the parity information from the remaining drives. However, if two drives fail simultaneously, there is not enough information (data and parity) to reconstruct the missing data from both failed drives, resulting in data loss.

  3. Question 3Beginner

    Forensic Science · Dark Web Forensics

    An investigator is analyzing network traffic from a suspected ransomware attack. They observe a large volume of DNS queries for domains ending in .onion. This activity is a strong indicator that the malware is attempting to communicate with a Command and Control (C2) server hosted on:

    Show answer & explanation

    Correct answer: C

    The .onion top-level domain is used exclusively for hidden services accessible only through the Tor network. Ransomware and other malware frequently use Tor for C2 communications to anonymize the location of their servers and make them difficult to take down. Observing DNS queries for .onion domains indicates that a client on the network is attempting to resolve these addresses, likely through a Tor gateway or proxy, to establish a C2 channel.

  4. Question 4Intermediate

    Digital Forensics Techniques · Python Digital Forensics

    A forensic investigator is using Python to automate the extraction of EXIF data from a large set of image files. The investigator writes a script to parse GPS coordinates, camera model, and timestamps. Which Python library is most commonly used and specifically suited for this task?

    Show answer & explanation

    Correct answer: B

    Pillow (a fork of the Python Imaging Library, PIL) is the de facto standard library for image manipulation in Python. It has robust built-in capabilities for reading and parsing EXIF (Exchangeable Image File Format) data from various image formats like JPEG and TIFF. Scapy is for network packet manipulation, PyPDF2 is for PDF files, and Requests is for making HTTP requests.

  5. Question 5Intermediate

    Procedures and Methodology · IoT Forensics

    A hospital's IT security team is responding to a breach where a medical IoT device (an infusion pump) was compromised. The forensic investigator needs to acquire data from the device, which has limited storage and a proprietary embedded operating system. The device is still running. According to the order of volatility, which of the following pieces of evidence should be collected FIRST?

    Show answer & explanation

    Correct answer: C

    The order of volatility dictates collecting evidence from most volatile to least volatile. Memory (RAM) is the most volatile evidence; its contents will be lost the moment the device loses power. Therefore, capturing a memory dump from the live device must be the first priority. Firmware on flash memory, network logs on a switch, and configuration files are all more persistent and should be collected after the RAM.

  6. Question 6Advanced

    Digital Forensics Techniques · Windows File Analysis

    During the analysis of a Windows 10 system, an investigator finds evidence of a program that was executed directly from a network share. Which artifact would provide the strongest proof of this program's execution, including the full network path from which it was run?

    Show answer & explanation

    Correct answer: C

    While Prefetch files and Amcache entries confirm execution, Shell Link (.LNK) files are created when a user interacts with a file (including executing it). Crucially, a .LNK file stores metadata about the target file, including its original full path. If the program was run from \\SERVER\share\program.exe, the .LNK file will contain this exact path, providing definitive evidence of execution from a network location. It also stores volume information of the host, such as the MAC address.

  7. Question 7Intermediate

    Regulations, Policies and Ethics · ACPO Principles of Digital Evidence

    An organization is setting up a computer forensics lab and wants to adhere to the best practices defined by the Association of Chief Police Officers (ACPO). Which of the following statements best represents the first principle of the ACPO guidelines for handling digital evidence?

    Show answer & explanation

    Correct answer: B

    The first ACPO principle is the foundation of digital forensic evidence handling. It states that no action should alter the original data. If changes are necessary to access the data (e.g., changing a password), these actions must be performed on a forensic copy, and the process must be fully documented and explainable. The other options represent other ACPO principles (Principle 2, 3, and 4), but this is the first and most fundamental one.

  8. Question 8Intermediate

    Tools/Systems/Programs · File System Analysis Tools

    A forensic investigator is analyzing a disk image from a macOS computer with an APFS file system. The investigator needs to identify when files were created, modified, and accessed by the user. Which specific command-line tool from The Sleuth Kit (TSK) is used to create a detailed timeline of file system activity by parsing metadata from the APFS image?

    Show answer & explanation

    Correct answer: C

    mactime is a tool within The Sleuth Kit that creates a chronological timeline of file activity (Modified, Accessed, Changed, Birth times) based on metadata collected from the file system. It takes the output from tools like fls (which lists files) and formats it into a human-readable timeline, which is invaluable for reconstructing event sequences. istat displays metadata for a specific file/inode, and fsstat displays general file system details.

  9. Question 9Beginner

    Tools/Systems/Programs · Password Cracking Tools

    A CHFI is investigating a data exfiltration incident where a large amount of data was compressed into a password-protected ZIP file and uploaded to a cloud storage provider. The investigator has the ZIP file but not the password. To gain access to the contents, the investigator decides to perform a dictionary attack. Which of the following tools is specifically designed for cracking passwords of encrypted archives like ZIP, RAR, and 7z?

    Show answer & explanation

    Correct answer: B

    John the Ripper (JtR) is a powerful and popular password cracking tool. It includes helper utilities (like zip2john) that can extract the password hash from an encrypted ZIP file. The main JtR program can then run dictionary, brute-force, or hybrid attacks against this hash to recover the password. Hashcat is another powerful password cracker, but JtR is widely recognized for its direct support of various archive formats. Wireshark is for network analysis and Volatility is for memory analysis.

  10. Question 10Intermediate

    Digital Forensics Techniques · Cloud Forensics

    An investigator is performing a forensic analysis of a compromised AWS EC2 instance. The instance has been isolated, and a snapshot of its EBS volume has been created. To perform the analysis without altering the original snapshot, what is the correct sequence of steps?

    1. Create a new EBS volume from the snapshot.
    2. Attach the new EBS volume to a forensic workstation EC2 instance.
    3. Mount the attached volume as read-only on the workstation.
    4. Isolate the compromised EC2 instance using security groups.
    Show answer & explanation

    Correct answer: A

    The correct forensic procedure is to first isolate the compromised instance to prevent further damage or evidence tampering (4). Next, you create a new EBS volume from the previously taken snapshot; this preserves the original snapshot as pristine evidence (1). Then, you attach this new volume to a trusted forensic analysis EC2 instance (2). Finally, you mount the volume on the workstation in read-only mode to prevent any modification during analysis (3).

Ready for the real thing?

The full 312-49v10 simulator has every exam-style question, timed mode, and instant scoring.