wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CHFI Module 4 Review

Total questions: 20

Worksheet time: 13mins

Name
Class
Date
1.

Live Data Acquisition involves collecting volatile information that resides in registries,cache and RAM.

a)

True

b)

False

2.

Static Data Acquisition is the gathering of data that remains unaltered even if the system is powered off.

a)

True

b)

False

3.

There are two types of volatile data. They are _____ and ____

a)

Computer Information, server information

b)

System information, network information

c)

Network information, computer information

d)

Server information, system information

4.

Which is the correct Order of Volatility?

a)

  1. Registers, and cache
  2. Temporary file systems
  3. Physical configuration, and network topology
  4. Routing table, process table, kernel statistics, and memory
  5. Archival media
  6. Disk or other storage media
  7. Remote logging and monitoring data that is relevant to the system in question

b)

  1. Registers, and cache
  2. Routing table, process table, kernel statistics, and memory
  3. Temporary file systems
  4. Disk or other storage media
  5. Remote logging and monitoring data that is relevant to the system in question
  6. Physical configuration, and network topology
  7. Archival media

5.

It is a preferred practice to use the original machine for building your forensic case.

a)

True

b)

False

6.

There are three steps to the Volatile Data collection methodology. They are (in order):

a)

Step 1: Incident Response Preparation

Step 2: Policy Verification

Step 3: Incident Documentation

b)

Step 1: Incident Documentation

Step 2: Policy Verification

Step 3: Incident Response Preparation

c)

Step 1: Incident Response Preparation

Step 2: Incident Documentation

Step 3: Policy Verification

d)

None of the above

7.

When collecting volatile data you should establish a trusted command shell.

a)

True

b)

False

8.

When collecting volatile data you can assume the integrity of forensic tool output is accurate.

a)

True

b)

False

9.

Static data is considered to be which type of data?:

a)

non-volatile

b)

volatile

c)

Both

d)

None of the above

10.

Examples of static data would include:

a)

emails, word processing documents, Web activity, slack space

b)

ram, cache, BIOS

c)

All of the above

d)

None of the above

11.

How many copies of the original digital evidence should you create?

a)

1

b)

3

c)

2

d)

4

12.

Linux Validation Methods use command lines instead of hardware software tools to gather and validate evidence.

a)

True

b)

False

13.

There are two types of data acquisition. They are:

a)

Bit Stream Image and Timestamps

b)

Live file imaging and Indexing

c)

Bit Stream Image and Backups

d)

Any of the above are acceptable

14.

According to the National Institute of Justice, write protection should be initiated, if available, to preserve and protect original evidence

a)

True

b)

False

15.

Which of the following commands is used to gather data from Linux machines? (Choose two)

a)

dfcld

b)

dd

c)

dcfldd

d)

ddfcl

16.

How many data acquisition formats are there that investigators can use to gather data?

a)

4

b)

2

c)

3

d)

Many

17.

There are two other methods of data acquisition. They are Logical and Sparse.

a)

True

b)

False

18.

Rapid Image 7020 X2 IT, HardCopy 3P, ROADMASSTER-3 2X, and UktraKit are examples of software acquisition and duplication tools.

a)

True

b)

False

19.

Encase Forensic, DriveSpy, R-Drive Image, and RAID Recovery for Windows are examples of software Data Acquisition and Duplication tools.

a)

True

b)

False

20.

READ THIS QUESTION CAREFULLY!!! - Digital evidence validation involves using hash algorithm utilities to create a decimal number that represents the uniqueness of a data set such as a disk drive or file.

a)

True

b)

False