Digital Investigation

Digital Investigation

University

15 Qs

quiz-placeholder

Similar activities

Digital Forensics

Digital Forensics

University

15 Qs

Digital Forensics 2

Digital Forensics 2

University

15 Qs

Computer Software and Hardware Quiz

Computer Software and Hardware Quiz

University

20 Qs

Cyber and Information Security

Cyber and Information Security

University

20 Qs

JAVA I/O

JAVA I/O

University

10 Qs

Linux File Permissions Quiz

Linux File Permissions Quiz

University

20 Qs

QUIZ #1 - SPSS

QUIZ #1 - SPSS

University

10 Qs

PHP File Handling

PHP File Handling

University

12 Qs

Digital Investigation

Digital Investigation

Assessment

Quiz

Computers

University

Hard

Created by

Wan Ismail

Used 4+ times

FREE Resource

15 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

1.

A better way to ignore known files is to compare the __________of every file in a forensic duplication with a known set of hashes and ignore any matches.

MD5 hashes

Active hashes

Forensic hashes

Cryptography

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Use______________ to create a partition for the destination drive.

Win_XP

Fdisk

Duplicate disk

Forensic duplications

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

1.      In forensics, each piece of hardware must be                           with make model, serial number, evidence tag number, etc.

Put in closet

Documented

Signed

Shared

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

1.      One very well known software used for forensic analysis is                              .

IBM

Google

Encase

Forensic-ripper

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The evidence custodian should,

Give the evidence to the secretary

Place evidence in the storage place

Keep logs of who has the evidence, when was it check out, etc.

Use the evidence for personal use.

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

1.      when  working on computer forensics always work from                          of the evidence and never from the original to prevent damage to the evidence.

A.     Original hard drive

Live computer

Remote desktop

An image

7.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

1.                                             preserving evidence means that that the information contained on the drive down to the last bit never changes during seizing, analysis and storage.

Mentally

Logically

Physically

Carefully

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?