Cybercrime Investigator Exam Prep
Free practice questions

Free RCCI Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The RCCI exam has 100 questions and runs 2 hours.

These 10 free RCCI questions are organized by exam domain, so you can see how each part of the Cybercrime Investigator blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Cybercrime, Law & Evidence

Question 1

A U.S. cybercrime investigator is reviewing online grooming reports when a 15-year-old sends a live message that the suspect is outside the child's home and is threatening to force the child into a car. The investigator has verified the child's current address and preserved the messages already received. What takes priority?

Show answer & explanation

Correct answer: C - Notify local emergency services immediately with the verified location and threat.

Question 2

Written authority for a corporate fraud investigation permits collecting and searching one employee's work mailbox for 1-30 June; it expressly excludes personal cloud accounts. A work email contains a link that would open the employee's personal storage using a saved session. A tested export can collect the authorized mailbox material without following that link. The investigator should:

Show answer & explanation

Correct answer: A - Proceed with the scoped mailbox export and leave the personal cloud account unopened.

Domain 2: IR & Evidence Acquisition

Question 3

During an authorized examination, an unlocked workstation has a mounted encrypted volume whose recovery key is unavailable. The network team has isolated all communications, and no destructive activity is occurring. The examiner has live-acquisition tools validated for this configuration and authority to collect memory and the volume's contents. Which acquisition plan best preserves access to the available evidence?

Show answer & explanation

Correct answer: B - Capture RAM, then acquire the accessible decrypted volume while maintaining power.

Question 4

An examiner acquires a disk as a compressed E01 evidence container. The acquisition completes without read errors. SHA-256 of the reconstructed source byte stream matches the disk's acquisition digest, but SHA-256 of the E01 container file does not. Source identifiers and acquisition scope have been checked. What should the examiner do with this result?

Show answer & explanation

Correct answer: C - Accept the source-stream verification and record the container digest separately.

Domain 3: Forensic Analysis & Timelines

Question 5

On a Windows file server, the Security log contains: 02:14:08 - Event 4624, account FIN\jlee, Logon Type 3, Logon ID 0x64A. 02:14:11 - Event 4663, Subject Logon ID 0x64A, Object Type File, Object Name D:\Finance\forecast.xlsx, Accesses ReadData. What do these correlated records establish?

Show answer & explanation

Correct answer: A - The account established a network logon and exercised read access to the file.

Question 6

A payment-change email has been forwarded through a mailing service. The recipient's trusted gateway records SPF = fail and DKIM = pass with d=supplier.example. The visible From address is billing@supplier.example, and the valid signature covers the From field. With strict DMARC alignment in effect, the gateway's determination should be:

Show answer & explanation

Correct answer: A - DMARC passes because the valid DKIM signature aligns with the From domain.

Question 7

A server log records creation of an archive at 00:08:00 on 18 September, using UTC+02:00. Comparison with a trusted time source shows that the server clock was consistently five minutes fast during the incident. An independently timed proxy log records the archive upload starting at 22:05:00 UTC on 17 September. Place the archive-creation event on the normalized timeline.

Show answer & explanation

Correct answer: D - 22:03 UTC on 17 September, two minutes before the upload began.

Question 8

Signature carving recovers only the opening portion of a deleted NTFS video. Its surviving Master File Table record lists the file's logical sequence as physical clusters 8000-8099, then 2000-2099, then 5000-5099. All three data runs remain intact in the forensic image. How should the examiner recover the remaining content?

Show answer & explanation

Correct answer: C - Reassemble the runs in their recorded logical order and validate the recovered video.

Domain 4: Specialized Investigations

Question 9

An investigator searches an AWS CloudTrail export for GetObject operations against a confidential S3 bucket and finds none. The export contains only management events, and the bucket's S3 object data events were not being recorded during the incident. A manager proposes closing the alleged-download investigation. What is the material flaw in that proposal?

Show answer & explanation

Correct answer: B - The collected event category does not establish whether the objects were downloaded.

Domain 5: Court-Ready Reporting & Capstone

Question 10

An endpoint log records an archive upload to an unapproved external service. Through lawful process, the service supplies the received object and its upload record; the transaction identifier matches the endpoint record, and the object's SHA-256 matches the local archive. The upload used an account shared by three administrators. No evidence identifies the operator. Select the statement that belongs in the executive summary.

Show answer & explanation

Correct answer: D - The archive reached the external service; the shared account's operator remains unidentified.

That's 10 of 1,030

The full bank has 1,020 more RCCI questions with explanations.

Continue in the free practice test →

View plans