Question 1
Which file should be used to restore archived email messages for someone using Microsoft Outlook?
Correct Answer:
Outlook pst
Explanation:
Outlook stores local mail data in PST files, which are used for personal storage and archiving. When messages are archived, they are typically saved in a PST file (often named Archive.pst). To restore those archived messages, you open or import that PST file in Outlook, which adds the archived emails back to the mailbox view. An OST file is a cached offline copy of a mailbox from an Exchange/IMAP account, and it isn’t meant for restoring archived messages. NK2 is just the nickname cache for autocomplete, not mail data. A .bak is simply a backup copy and would only be used if you have a backup of a PST and need to recover from it, but it’s not the standard archive file Outlook uses for restoring archived messages.
Question 2
To determine source, nature, and time of an attack from Application and Web server logs, you should:
Correct Answer:
Analyzing log files
Explanation:
Analyzing log files from applications and web servers is the most effective way to determine where an attack came from, what the attacker did, and when it happened. Logs capture timestamps, source IPs, requested resources, response codes, user agents, and error messages. By examining these records, you can identify the origin (the source IP or proxy), the nature of the attack (for example, repeated login failures, unusual URLs, SQL injection patterns, or scripted probes), and the sequence of events (using timestamps to build a timeline). Correlating entries across web and application logs, and across different systems like firewalls, strengthens attribution and timing. Ensuring synchronized clocks and preserving log integrity are important for credible reconstruction. Other data types don’t provide the same forensic value for this task: the SAM file contains user account information and security metadata, not attack activity; rainbow tables are used for password cracking rather than documenting events; boot records relate to the system’s startup sequence and don’t reflect ongoing network activity.
Question 3
The newer Macintosh Operating System (MacOS X) is based on which of the following?
Correct Answer:
BSD Unix
Explanation:
MacOS X is built on a Unix-based foundation, specifically BSD Unix. The kernel (XNU) is a hybrid that combines Mach with BSD components, and the Darwin layer provides the open-source core that includes BSD-style userland utilities and interfaces. This Unix lineage gives MacOS X its POSIX compatibility and many familiar Unix tools, even though its GUI was shaped by NeXTSTEP. Because of this, MacOS X is not based on OS/2, Windows, or Linux—the direct lineage is BSD Unix.
Question 4
If you discover a criminal act while investigating a corporate policy abuse, it becomes a public-sector investigation and should be referred to law enforcement?
Correct Answer:
True
Explanation:
When you uncover a criminal act during an internal investigation, the matter shifts from policy review to law enforcement territory. Criminal offenses are handled by authorities empowered to investigate, arrest, and prosecute; internal teams don’t have the authority to pursue criminal charges or conduct formal criminal proceedings. Because evidence in criminal cases must be collected and preserved under proper legal procedures, you should promptly escalate the issue to law enforcement and coordinate with corporate counsel to report it. Preserve and document all evidence with a clear chain of custody, provide investigators with access to relevant materials, and follow legal and regulatory requirements for reporting. This approach protects the integrity of the investigation, helps ensure admissibility of evidence, and aligns with legal and regulatory expectations.
Question 5
During the cataloging of digital evidence, what is the primary objective?
Correct Answer:
Preserve evidence integrity
Explanation:
The main concept being tested is preserving evidence integrity. When cataloging digital evidence, the goal is to create a precise, verifiable record of what was found, where it came from, its condition, and how it has been handled, so the evidence remains unchanged and trustworthy from collection to presentation. This includes documenting metadata (such as device type and identifiers), recording the chain of custody, and using hash values to prove the data hasn’t been altered. While other actions like imaging drives or keeping a system powered on are part of the broader process, the cataloging step specifically focuses on ensuring the evidence remains authentic and traceable.
Question 1
Exam overview

About this Exam

Prepare with the Computer Hacking Forensic Investigator (CHFI) v11 Practice Test practice quiz. This question bank includes 10 questions covering attack, server, imaging, computer, and hacking. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Computer Hacking Forensic Investigator (CHFI) v11 Practice Test

This practice set contains 10 questions from the matching question bank and focuses on attack, server, imaging, computer, and hacking. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions