
GAQM Certified Forensic Analyst (CFA) - CFA-001 Exam Questions
QUESTION NO: 1
Recovery of the deleted partition is the process by which the investigator evaluates and extracts the deleted partitions.
Recovery of the deleted partition is the process by which the investigator evaluates and extracts the deleted partitions.
Correct Answer: A
QUESTION NO: 2
You can interact with the Registry through intermediate programs. Graphical user interface (GUI) Registry editors such as Regedit.exe or Regedt32 exe are commonly used as intermediate programs in Windows 7. Which of the following is a root folder of the registry editor?
You can interact with the Registry through intermediate programs. Graphical user interface (GUI) Registry editors such as Regedit.exe or Regedt32 exe are commonly used as intermediate programs in Windows 7. Which of the following is a root folder of the registry editor?
Correct Answer: D
QUESTION NO: 3
You have been given the task to investigate web attacks on a Windows-based server.
Which of the following commands will you use to look at which sessions the machine has opened with other systems?
You have been given the task to investigate web attacks on a Windows-based server.
Which of the following commands will you use to look at which sessions the machine has opened with other systems?
Correct Answer: D
QUESTION NO: 4
Which of the following is not correct when documenting an electronic crime scene?
Which of the following is not correct when documenting an electronic crime scene?
Correct Answer: A
QUESTION NO: 5
You should always work with original evidence
You should always work with original evidence
Correct Answer: B
QUESTION NO: 6
Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server's root directory?
Which of the following attacks allows an attacker to access restricted directories, including application source code, configuration and critical system files, and to execute commands outside of the web server's root directory?
Correct Answer: C
QUESTION NO: 7
Email spoofing refers to:
Email spoofing refers to:
Correct Answer: C
QUESTION NO: 8
What is the goal of forensic science?
What is the goal of forensic science?
Correct Answer: B
QUESTION NO: 9
Identify the attack from following sequence of actions?
Step 1: A user logs in to a trusted site and creates a new session
Step 2: The trusted site stores a session identifier for the session in a cookie in the web browser Step 3: The user is tricked to visit a malicious site Step 4: the malicious site sends a request from the user's browser using his session cookie
Identify the attack from following sequence of actions?
Step 1: A user logs in to a trusted site and creates a new session
Step 2: The trusted site stores a session identifier for the session in a cookie in the web browser Step 3: The user is tricked to visit a malicious site Step 4: the malicious site sends a request from the user's browser using his session cookie
Correct Answer: C
QUESTION NO: 10
Which of the following password cracking techniques works like a dictionary attack, but adds some numbers and symbols to the words from the dictionary and tries to crack the password?
Which of the following password cracking techniques works like a dictionary attack, but adds some numbers and symbols to the words from the dictionary and tries to crack the password?
Correct Answer: B
QUESTION NO: 11
Data files from original evidence should be used for forensics analysis
Data files from original evidence should be used for forensics analysis
Correct Answer: B
QUESTION NO: 12
The disk in the disk drive rotates at high speed, and heads in the disk drive are used only to read data.
The disk in the disk drive rotates at high speed, and heads in the disk drive are used only to read data.
Correct Answer: B
QUESTION NO: 13
Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.
Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.
Correct Answer: A




