NEW
Font size
WorksheetsDigital Forensics
Total questions: 20
Worksheet time: 10mins
Digital evidence can't be time sensitive.
TRUE
FALSE
Digital evidence can be altered, damaged or destroyed with little effort.
TRUE
FALSE
At which stage of the digital forensics process would a write-blocker be used?
Acquisition
Reporting
Verification
Analysis
The process of copying data is known as:
data acquisition
data analysis
data documentation
data recovery
Harold, a fraud examiner, collects a computer hard drive as potential evidence in an investigation. He creates a memorandum to record the chain of custody and documents what item was received, when it was received, and from whom it was received. To meet the minimum standard for a chain of custody memorandum, what else would Harold need to include?
The name of the judge who signed the seizure order, if applicable,
The value of the noncash item received,
An explanation of why the item was collected,
Where the item is maintained
_______ is the practice of concealing a file, message, image, or video within another file, message, image, or video.
Steganography
Cryptography
File hidding
Media Analysis
Command to find out the internal ip using the dos prompt is ?
ipscan
itconfig
ipconflict
ipconfig
___is an example of social engineering techniques being used to deceive users. Users are often lured by communications purporting to be from trusted parties such as social web sites, auction sites, banks, online payment processors or IT administrators
Phishing
SQL Injection
SMS Bombing
Denial of Service
Hash Value is used to check the
_________________
Confidentiality of the file
Integrity of the file
rationality of the file
availability of the file
A ____value is a numeric value of a fixed length that uniquely identifies data.
A. Hash
B. Decimal
C. Number
D. Variable
The practice of forensic document examination is called graphology.
True
False
Which of the following is FALSE
A. The digital forensic investigator must maintain absolute objectivity
B. It is the investigator’s job to determine someone’s guilt or innocence.
C. It is the investigator’s responsibility to accurately report the relevant facts of a case.
D. The investigator must maintain strict confidentiality, discussing the results of an investigation on only a “need to know” basis
____ is the route the evidence takes from the time you find it until the case is closed or goes to court.
A. Hashing
B. Chain of Custody
C. Imaging
D. Data Recovery.
A keyword search is part of the analysis process within what forensic function?
A. reporting
B. reconstruction
C. extraction
D. acquisition
A
B
C
D
Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?
A. #06#*
B. *#06#
C. #*06*#
D. *IMEI#
For forensic Experts, it is important to understand the Internet’s protocols so that they:
A. Can write code to collect courtroom evidence.
B. Can hire a professional to handle the problem.
C. Understand electronic courtroom procedures.
D. Understand the nature of a cyber attack.
1. This refers to the unauthorized monitoring of other people's communications, such as simply looking over the shoulder of a legitimate computer user to learn his login name and password.
A. Phishing
B. Spamming
C. Spoofing
D. Eavesdropping
A
B
C
D
Billy, a computer forensics expert, has recovered a large number of OST files during
forensic investigation of a laptop. Which of the following email clients he can use to analyze
the OST?
A. Microsoft Outlook
B. Microsoft Outlook Express
C. Mozilla Thunderbird
D. Eudora
When a forensic investigator is seizing a running computer for examination, he can retrieve data from the computer directly via its normal interface if the evidence needed exists only in the form of volatile data.
A. True
B. False
If a fraud examiner was gathering information about a fraud suspect, which of the following types of information would likely require access to nonpublic sources of information to obtain?
A. The subject's phone history records,
B. The subject's habits and lifestyle,
C. Where the subject currently resides,
D. All of the above
