最新的EC-COUNCIL Computer Hacking Forensic Investigator (CHFI-v11) - 312-49v11免費考試真題
In a sophisticated cloud attack, assailants strategically deploy virtual machines (VMs) in close proximity to target servers. Leveraging shared physical resources, they execute side-channel attacks, extracting sensitive data through timing vulnerabilities. Subsequently, they exploit stolen credentials to impersonate legitimate users, posing a grave security risk. How do attackers compromise cloud security by exploiting the proximity of virtual machines (VMs) to target servers?
正確答案: B
說明:(僅 Fast2test 成員可見)
Maria has executed a suspicious executable file in a controlled environment and wants to see if the file adds/modifies any registry value after execution via Windows Event Viewer. Which of the following event ID should she look for in this scenario?
正確答案: C
During a healthcare IoT breach in Houston, Texas, examiners find multiple wearables still using out-of-box credentials. Attackers leveraged these settings to bypass basic access controls and intercept data. Which security issue in the IoT stack most directly enabled this exposure?
正確答案: C
說明:(僅 Fast2test 成員可見)
Which of the following is considered as the starting point of a database and stores user data and database objects in an MS SQL server?
正確答案: A
During a corporate insider threat investigation at a tech company in New York, forensic analysts review security event logs from a workstation to trace unauthorized access attempts. The logs indicate a successful authentication where the user physically entered credentials at the console without network involvement. Which logon type corresponds to this local, in-person access method?
正確答案: C
說明:(僅 Fast2test 成員可見)
Working as an investigator at a digital forensic firm, Mike has been handed a case involving a Windows computer suspected of being used for illegal activities. Mike has been tasked with examining the metadata of numerous files to look for any signs of illicit activity. He is considering various tools including FTK Imager, OSForensics, ExifTool, and EnCase. Which tool should Mike select for his specific requirement of analyzing file metadata?
正確答案: A
說明:(僅 Fast2test 成員可見)
In the course of a wireless network forensics operation at a technology firm in Austin, Texas, investigators deploy standard capture tools to collect live traffic from a suspected internal intrusion. Despite maintaining proximity to the affected area, they obtain only partial packet captures, and the extracted logs show significant gaps that prevent correlating device identifiers with timestamps. What condition most directly accounts for this limitation?
正確答案: B
說明:(僅 Fast2test 成員可見)
In a corporate environment, a senior executive's Android smartphone is secured for internal forensic review following indicators of unauthorized data access. The inquiry is administrative in nature, and the executive remains available to assist with the investigation. The device is protected by a passcode, preventing immediate access to potential evidence. Investigators are required to obtain access without altering existing data or invoking escalated technical measures.
To proceed lawfully while preserving evidential integrity, which approach is most appropriate?
To proceed lawfully while preserving evidential integrity, which approach is most appropriate?
正確答案: C
說明:(僅 Fast2test 成員可見)
During a data breach investigation at a financial firm in Houston, forensic examiners analyze an event log file to determine its integrity status after a system crash. The log indicates that records were written but the file was not properly closed, suggesting potential corruption. Which flag in the ELF_LOGFILE_HEADER structure reflects this condition of uncommitted changes?
正確答案: C
說明:(僅 Fast2test 成員可見)
During an investigation, an examiner opens an Excel file with a .xism extension, indicating that the document is capable of containing malicious code. Upon closer inspection, the investigator must determine if the file poses a threat. What should the investigator focus on to identify potential risks?
正確答案: B
說明:(僅 Fast2test 成員可見)
During a botnet takedown case in Los Angeles, California, an ISP's abuse desk keeps receiving legal complaints about malicious traffic traced to an IP that belongs to Tor infrastructure.
Investigators explain that, although the traffic did not originate there, this Tor component is the one seen by destination servers as the source and therefore attracts most abuse complaints and shutdown demands. Which Tor component are they referring to?
Investigators explain that, although the traffic did not originate there, this Tor component is the one seen by destination servers as the source and therefore attracts most abuse complaints and shutdown demands. Which Tor component are they referring to?
正確答案: A
說明:(僅 Fast2test 成員可見)
A major financial institution recently observed an unusually high number of failed login attempts on a critical server. The security analyst uses Splunk Enterprise Security (ES) to investigate the logs and suspect a possible brute-force attack. After examining the Windows Event Viewer logs, the analyst detects a series of event ID 4625 (failed logins) and event ID 4624 (successful logins).
Which of the following SIEM features would be MOST beneficial for the analyst to accurately pinpoint the source of the potential attack and investigate it further?
Which of the following SIEM features would be MOST beneficial for the analyst to accurately pinpoint the source of the potential attack and investigate it further?
正確答案: A
說明:(僅 Fast2test 成員可見)
At a logistics warehouse in Phoenix, investigators conduct a coordinated, court-authorized seizure of multiple devices suspected of relaying malicious traffic. While handling and packaging the devices, the team focuses on preventing any foreign data, environmental interference, or handling errors that could alter the original state of the items. What procedural focus best supports this objective at the point of seizure?
正確答案: A
說明:(僅 Fast2test 成員可見)
During a cybercrime investigation, Detective Smith accessed original data during a cybercrime investigation but lacked the expertise to understand the implications, compromising evidence integrity. The failure to document processes raises concerns about evidence admissibility in court. In the scenario described, which principle of the Association of Chief Police Officers (ACPO) Principles of Digital Evidence was violated by Detective Smith?
正確答案: A
說明:(僅 Fast2test 成員可見)