
[Apr-2025] The Best GAQM CFA CFA-001 Professional Exam Questions
Try 100% Updated CFA-001 Exam Questions [2025]
GAQM CFA-001 Certification Exam, also known as the Certified Forensic Analyst (CFA) Certification Exam, is a globally recognized certification for professionals in the field of digital forensics. CFA-001 exam is designed to validate the knowledge, skills, and abilities of candidates in conducting forensic analysis of digital devices and data.
NEW QUESTION # 22
LBA (Logical Block Address) addresses data by allotting a ___________to each sector of the hard disk.
- A. Sector number
- B. Sequential number
- C. Index number
- D. Operating system number
Answer: B
NEW QUESTION # 23
Billy, a computer forensics expert, has recovered a large number of DBX files during forensic investigation of a laptop. Which of the following email clients he can use to analyze the DBX files?
- A. Mozilla Thunderoird
- B. Microsoft Outlook
- C. Microsoft Outlook Express
- D. Eudora
Answer: C
NEW QUESTION # 24
System software password cracking is defined as cracking the operating system and all other utilities that enable a computer to function
- A. True
- B. False
Answer: A
NEW QUESTION # 25
Shortcuts are the files with the extension .Ink that are created and are accessed by the users. These files provide you with information about:
- A. Application logs
- B. Running application
- C. Files or network shares
- D. System logs
Answer: C
NEW QUESTION # 26
What is the First Step required in preparing a computer for forensics investigation?
- A. Suspend automated document destruction and recycling policies that may pertain to any relevant media or users at Issue
- B. Identify the type of data you are seeking, the Information you are looking for, and the urgency level of the examination
- C. Secure any relevant media
- D. Do not turn the computer off or on, run any programs, or attempt to access data on a computer
Answer: D
NEW QUESTION # 27
Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.
- A. True
- B. False
Answer: A
NEW QUESTION # 28
Microsoft Security IDs are available in Windows Registry Editor. The path to locate IDs in Windows 7 is:
- A. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule
- B. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentsVersion \setup
- C. HKEY_LOCAL_MACHlNE\SOFTWARE\Microsoft\Windows NT\CurrentVersion \NetworkList
- D. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Currentversion \ProfileList
Answer: D
NEW QUESTION # 29
Deposition enables opposing counsel to preview an expert witness's testimony at trial. Which of the following deposition is not a standard practice?
- A. Opposing counsel asks questions
- B. No jury or judge
- C. Only one attorneys is present
- D. Both attorneys are present
Answer: C
NEW QUESTION # 30
Physical security recommendations: There should be only one entrance to a forensics lab
- A. True
- B. False
Answer: A
NEW QUESTION # 31
Raw data acquisition format creates ____________of a data set or suspect drive.
- A. Segmented image files
- B. Segmented files
- C. Simple sequential flat files
- D. Compressed image files
Answer: C
NEW QUESTION # 32
Smith, an employee of a reputed forensic Investigation firm, has been hired by a private organization to investigate a laptop that is suspected to be involved in hacking of organization DC server. Smith wants to find all the values typed into the Run box in the Start menu. Which of the following registry key Smith will check to find the above information?
- A. UserAssist Key
- B. TypedURLs key
- C. MountedDevices key
- D. RunMRU key
Answer: D
NEW QUESTION # 33
A computer forensic report is a report which provides detailed information on the complete forensics investigation process.
- A. True
- B. False
Answer: A
NEW QUESTION # 34
Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.
- A. True
- B. False
Answer: A
NEW QUESTION # 35
Computer forensics report provides detailed information on complete computer forensics investigation process. It should explain how the incident occurred, provide technical details of the incident and should be clear to understand. Which of the following attributes of a forensics report can render it inadmissible in a court of law?
- A. It includes relevant extracts referred to In the report that support analysis or conclusions
- B. It maintains a single document style throughout the text
- C. It is based on logical assumptions about the incident timeline
- D. It includes metadata about the incident
Answer: C
NEW QUESTION # 36
JPEG is a commonly used method of compressing photographic Images. It uses a compression algorithm to minimize the size of the natural image, without affecting the quality of the image. The JPEG lossy algorithm divides the image in separate blocks of____________.
- A. 4x4 pixels
- B. 32x32 pixels
- C. 8x8 pixels
- D. 16x16 pixels
Answer: C
NEW QUESTION # 37
When collecting evidence from the RAM, where do you look for data?
- A. Data file
- B. SAM file
- C. Log file
- D. Swap file
Answer: D
NEW QUESTION # 38
If a file (readme.txt) on a hard disk has a size of 2600 bytes, how many sectors are normally allocated to this file?
- A. 6 Sectors
- B. 5 Sectors
- C. 7 Sectors
- D. 4 Sectors
Answer: A
NEW QUESTION # 39
Networks are vulnerable to an attack which occurs due to overextension of bandwidth, bottlenecks, network data interception, etc.
Which of the following network attacks refers to a process in which an attacker changes his or her IP address so that he or she appears to be someone else?
- A. Man-in-the-middle attack
- B. IP address spoofing
- C. Session sniffing
- D. Denial of Service attack
Answer: B
NEW QUESTION # 40
Which of the following statements is incorrect when preserving digital evidence?
- A. Verily if the monitor is in on, off, or in sleep mode
- B. Document the actions and changes that you observe in the monitor, computer, printer, or in other peripherals
- C. Remove the power cable depending on the power state of the computer i.e., in on. off, or in sleep mode
- D. Turn on the computer and extract Windows event viewer log files
Answer: D
NEW QUESTION # 41
Which of the following statements is incorrect related to acquiring electronic evidence at crime scene?
- A. The equipment is seized which is connected to the case, knowing the role of the computer which will indicate what should be taken
- B. Sample banners are used to record the system activities when used by the unauthorized user
- C. At the time of seizing process, you need to shut down the computer immediately
- D. In warning banners, organizations give clear and unequivocal notice to intruders that by signing onto the system they are expressly consenting to such monitoring
Answer: C
NEW QUESTION # 42
TCP/IP (Transmission Control Protocol/Internet Protocol) is a communication protocol used to connect different hosts in the Internet. It contains four layers, namely the network interface layer. Internet layer, transport layer, and application layer.
Which of the following protocols works under the transport layer of TCP/IP?
- A. UDP
- B. FTP
- C. HTTP
- D. SNMP
Answer: A
NEW QUESTION # 43
An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well as misuse.
Which of the following intrusion detection systems audit events that occur on a specific host?
- A. File integrity checking
- B. Log file monitoring
- C. Network-based intrusion detection
- D. Host-based intrusion detection
Answer: D
NEW QUESTION # 44
Which of the following commands shows you the username and IP address used to access the system via a remote login session and the Type of client from which they are accessing the system?
- A. Net file
- B. Net sessions
- C. Net config
- D. Net share
Answer: B
NEW QUESTION # 45
Cyber-crime is defined as any Illegal act involving a gun, ammunition, or its applications.
- A. False
- B. True
Answer: A
NEW QUESTION # 46
Quality of a raster Image is determined by the _________________and the amount of information in each pixel.
- A. Compression method
- B. Image file size
- C. Image file format
- D. Total number of pixels
Answer: D
NEW QUESTION # 47
......
CFA-001 Exam Questions Get Updated [2025] with Correct Answers: https://www.prepawaypdf.com/GAQM/CFA-001-practice-exam-dumps.html
Pass CFA-001 Exam - Real Questions and Answers: https://drive.google.com/open?id=1td_raxAP8U9ZCTvs63UWUZu6S7-lC_0J