Search Header Logo

Digital Forensics Quiz

Authored by Roshna Ravindran

Information Technology (IT)

University

Digital Forensics Quiz
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

8 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

When did Alex Jensen most likely log into his Windows account?

20:48

21:02

18:30

20:55

2.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

Which artifact provides the strongest direct evidence that Alex knew the location of the confidential file `final_design.fzz`?

The Prefetch file for `NOTEPAD.EXE`

The `OpenPidlMRU` registry value

The browser history showing `dropsend.com`

The MFT entry for `temp_export.png`

3.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

What is the most likely sequence of program execution based on the evidence?

Chrome → Notepad → PowerShell → Cmd

PowerShell → Notepad → Cmd → Chrome

Cmd → PowerShell → Chrome → Notepad

Notepad → Chrome → PowerShell → Cmd

4.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

The command `cmd /c del C:\Users\AJensen\Downloads\temp_export.png` suggests what?

Alex was trying to open the file.

Alex was attempting to hide his actions by avoiding the Recycle Bin.

Alex was installing a new program.

The file was deleted by a system process.

5.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

What is the significance of the browser history entries for `dropsend.com`?

It proves Alex visited a social media site.

It suggests the use of a web-based service to send a file.

It shows Alex was researching competitors.

It indicates the browser was infected with malware.

6.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

Which two artifacts, when combined, provide the strongest evidence of data exfiltration?

ProfileList LastWriteTime and Notepad Prefetch

OpenPidlMRU and MFT entry for `temp_export.png`

RunMRU (delete command) and Browser History (Dropsend visit)

PowerShell Prefetch and Chrome Prefetch

7.

MULTIPLE CHOICE QUESTION

10 mins • 1 pt

If you could recover only one deleted file to strengthen the case, which would it be?

`final_design.fzz`

`temp_export.png`

A Prefetch file

A random system DLL

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?