| Exam Code/Number: | 312-49v11Join the discussion |
| Exam Name: | Computer Hacking Forensic Investigator (CHFI-v11) |
| Certification: | EC-COUNCIL |
| Question Number: | 637 |
| Publish Date: | Jul 18, 2026 |
|
Rating
100%
|
|
Edgar is part of the FBI's forensic media and malware analysis team; he is analyzing a current malware and is conducting a thorough examination of the suspect system, network, and other connected devices. Edgar's approach is to execute the malware code to know how it interacts with the host system and its impacts on it. He is also using a virtual machine and a sandbox environment. What type of malware analysis is Edgar performing?
During an incident response at a hospital in Chicago, Illinois, a suspect application server is still powered ON with active user sessions. The team must prioritize capturing fragile, volatile information (e.g., contents of RAM, cache, and dynamic process state) that would be lost if the system shuts down. What type of acquisition approach best satisfies this requirement?
During a forensic investigation involving an Android device, the investigator needs to establish communication between the device and a computer running the Android Software Developer Kit (SDK). This communication will allow the investigator to access system files, logs, and other relevant data for analysis. To facilitate this, the investigator enables a specific Android developer feature on the device.
Which feature must be enabled to allow the device to communicate with the workstation running the Android SDK?
Mark, a forensic investigator, is examining a suspicious executable file for signs of malicious activity. He needs to search the file for embedded strings that could indicate the file's malicious behavior, such as URLs, file paths, or registry keys. Which of the following tools can Mark use to extract strings from the executable file for further analysis?
John, a system administrator at a growing e-commerce company, is tasked with configuring a RAID 5 array to support the company's increasing data storage needs. He needs to set up the array using three hard drives, ensuring that the data is both protected and accessible in the event of a drive failure. While configuring the array, John needs to understand how the RAID 5 system handles data redundancy and how parity data is distributed across the drives. How is the parity data stored and distributed in RAID 5?