wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Digital Forensics

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Digital evidence can't be time sensitive.

a)

TRUE

b)

FALSE

2.

Digital evidence can be altered, damaged or destroyed with little effort.

a)

TRUE

b)

FALSE

3.

At which stage of the digital forensics process would a write-blocker be used?

a)

Acquisition

b)

Reporting

c)

Verification

d)

Analysis

4.

The process of copying data is known as:

a)

data acquisition

b)

data analysis

c)

data documentation

d)

data recovery

5.

Harold, a fraud examiner, collects a computer hard drive as potential evidence in an investigation. He creates a memorandum to record the chain of custody and documents what item was received, when it was received, and from whom it was received. To meet the minimum standard for a chain of custody memorandum, what else would Harold need to include?

a)

The name of the judge who signed the seizure order, if applicable,

b)

The value of the noncash item received,

c)

An explanation of why the item was collected,

d)

Where the item is maintained

6.

_______ is the practice of concealing a file, message, image, or video within another file, message, image, or video.

a)

Steganography

b)

Cryptography

c)

File hidding

d)

Media Analysis

7.

Command to find out the internal ip using the dos prompt is ?

a)

ipscan

b)

itconfig

c)

ipconflict

d)

ipconfig

8.

___is an example of social engineering techniques being used to deceive users. Users are often lured by communications purporting to be from trusted parties such as social web sites, auction sites, banks, online payment processors or IT administrators

a)

Phishing

b)

SQL Injection

c)

SMS Bombing

d)

Denial of Service

9.

Hash Value is used to check the

_________________

a)

Confidentiality of the file

b)

Integrity of the file

c)

rationality of the file

d)

availability of the file

10.

A ____value is a numeric value of a fixed length that uniquely identifies data.

a)

A. Hash

b)

B. Decimal

c)

C. Number

d)

D. Variable

11.

The practice of forensic document examination is called graphology.

a)

True

b)

False

12.

Which of the following is FALSE

a)

A. The digital forensic investigator must maintain absolute objectivity

b)

B. It is the investigator’s job to determine someone’s guilt or innocence.

c)

C. It is the investigator’s responsibility to accurately report the relevant facts of a case.

d)

D. The investigator must maintain strict confidentiality, discussing the results of an investigation on only a “need to know” basis

13.

____ is the route the evidence takes from the time you find it until the case is closed or goes to court.

a)

A. Hashing

b)

B. Chain of Custody

c)

C. Imaging

d)

D. Data Recovery.

14.

A keyword search is part of the analysis process within what forensic function?

A. reporting

B. reconstruction

C. extraction

D. acquisition

a)

A

b)

B

c)

C

d)

D

15.

Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?

a)

A. #06#*

b)

B. *#06#

c)

C. #*06*#

d)

D. *IMEI#

16.

For forensic Experts, it is important to understand the Internet’s protocols so that they:

a)

A. Can write code to collect courtroom evidence.

b)

B. Can hire a professional to handle the problem.

c)

C. Understand electronic courtroom procedures.

d)

D. Understand the nature of a cyber attack.

17.

1. This refers to the unauthorized monitoring of other people's communications, such as simply looking over the shoulder of a legitimate computer user to learn his login name and password.

A. Phishing

B. Spamming

C. Spoofing

D. Eavesdropping

a)

A

b)

B

c)

C

d)

D

18.

Billy, a computer forensics expert, has recovered a large number of OST files during

forensic investigation of a laptop. Which of the following email clients he can use to analyze

the OST?

a)

A. Microsoft Outlook

b)

B. Microsoft Outlook Express

c)

C. Mozilla Thunderbird

d)

D. Eudora

19.

When a forensic investigator is seizing a running computer for examination, he can retrieve data from the computer directly via its normal interface if the evidence needed exists only in the form of volatile data.

a)

A. True

b)

B. False

20.

If a fraud examiner was gathering information about a fraud suspect, which of the following types of information would likely require access to nonpublic sources of information to obtain?

a)

A. The subject's phone history records,

b)

B. The subject's habits and lifestyle,

c)

C. Where the subject currently resides,

d)

D. All of the above