Timelining

Timelining

12th Grade

10 Qs

quiz-placeholder

Similar activities

General Education Question

General Education Question

10th - 12th Grade

10 Qs

Brawl Stars

Brawl Stars

KG - Professional Development

14 Qs

Flamingo

Flamingo

KG - 12th Grade

10 Qs

Alberta Natural Resources #2

Alberta Natural Resources #2

KG - University

12 Qs

vehicle transmission and driveline units(a)

vehicle transmission and driveline units(a)

KG - 12th Grade

10 Qs

Lesson1_Quizz

Lesson1_Quizz

11th - 12th Grade

10 Qs

Iron Man

Iron Man

1st Grade - University

12 Qs

Review Quiz

Review Quiz

12th Grade

10 Qs

Timelining

Timelining

Assessment

Quiz

Other

12th Grade

Practice Problem

Medium

Created by

shyrlyn valdez

Used 2+ times

FREE Resource

AI

Enhance your content in a minute

Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...

10 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which of the following artifacts are considered as the Windows Forensic Trinity?

Filesystem Metadata

Registry

Windows Event Logs

Windows Startup

Answer explanation

The three core areas of focus are filesystem metadata, windows artifact data, and Windows registry information.

Understanding all three areas and how they interrelate is a skill worth working towards.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What point is used to examine the temporal proximity in the timeline?

Slope Point

Pivot Point

Parrot Point

No Point

Answer explanation

Use the pivot to look before and after in your timeline to get a better idea of what

happened on the system

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

NTFS Timestamps: Time the data content of a file was last modified

M

A

C

B

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The most famous super timeline tool is Plaso

True

False

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

If you are in a rush, is it better to create a supertimeline? Why or Why not?

Yes. Supertimeline is quicker to generate than filesystem timeline.

No. Just do filesystem timeline. Supertimeline is not a quick process to run

No. I don't want to do timelining

Yes. Supertimeline is not a quick to generate and I like to provide the analysis the next day.

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What tool outputs metadata about the events extracted from log2timeline

plasm

pinfo

fls

mactime

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following can be detected by timeline analysis?

Anti-Forensics

Covert Tunneling

Covid

Influenza

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?