wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Computer Forensics Investigation Process

Total questions: 20

Worksheet time: 13mins

Name
Class
Date
1.

The process of copying data is known as:

a)

data acquisition

b)

data analysis

c)

data documentation

d)

data recovery

2.

There are 2 types of data acquisition: static and (a)   .

3.

Warrants are NOT needed during the search and seizure stage if:

a)

we are very sure the suspect is guilty.

b)

destruction of evidence is imminent.

c)

person with authority consents.

d)

the crime committed is in plain sight.

4.

True or false: live acquisition can file metadata, like date and time values.

a)

True

b)

False

5.

True or False: static acquisition will produce the same results no matter how many times the data is acquired.

a)

True

b)

False

6.

The (a)   format is an older, open source disk-to-image file format.

7.

What are the advantages of the raw format?

a)

Fast data transfer

b)

Capability to ignore minor data read errors on the source drive.

c)

Does not require as much storage space as the original disk.

d)

Most forensic tools can read the raw format.

8.

Common hash functions used for validation checks of forensic images are:

a)

MD5

b)

SHA-1 or higher

c)

CRC32

d)

DES3

9.

In the (a)   stage, documentation/reporting and testifying as an expert witness are the key main tasks.

10.

In the investigation phase, there are _____ sub-stages that take place.

a)

4

b)

5

c)

6

d)

7

11.

The main goals of a first responder are (a)   and early response.

12.

Identify and protect the crime scene occur at the

a)

data analysis stage.

b)

search and seizure stage.

c)

evidence collection stage.

d)

first responder stage.

13.

Malaysia's computer security incident response team is known as:

a)

MyCIRT

b)

MyCERT

c)

Cyber999

d)

DigiCERT

14.

True or False: A computer that is potential evidence at a crime scene; if it is off, we switch it on.

a)

True

b)

False

15.

The stage that occurs after search and seizure is:

a)

securing the evidence

b)

acquiring the evidence

c)

collecting the evidence

d)

analysing the evidence

16.

An (a)   witness is a person who has thorough knowledge on a given subject.

17.

Estimating the impact of a computer incident occurs at the

a)

data acquisition stage.

b)

data assessment stage.

c)

data collection stage.

d)

first responder stage.

18.

A digital forensics report must be clear and (a)   .

19.

Preliminary interviews with witnesses are conducted during the

a)

search and seizure stage.

b)

securing the evidence stage.

c)

acquiring the evidence stage.

d)

assessing the evidence stage.

20.

The following are examples of data acquisition tools EXCEPT:

a)

EnCase

b)

dd

c)

FTK Imager

d)

Autopsy