Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Computer Crime, Information Security & Digital Forensics

Total questions: 17

Worksheet time: 9mins

Name
Class
Date
1.

Which of the statements best describes Digital Forensics?

a)

Applying computer scientific tests or techniques to help solve a crime

b)

Is a legal order issued by the Courts that allows officers to arrest someone

c)

When someone enters a building with the intent to steal something or commit a crime

d)

Analysing and examining clothes, blood, hair, footprints or marks left by tools or weapons.

2.

____________ is a data and image preview tool that allows you to browse files and folders on local hard drives, network drives, CD / DVD and review the content of forensic images or memory dumps.

a)

FTK Imager

b)

Volatility

c)

HashCalc

3.

An investigation can only be carried out when ....

a)

there is a suspicion that a crime has been committed.

b)

a person has a criminal history

c)

a witness to an incident owns a mobile device

d)

when working within a 'high security' company

4.

Which three of the following are benefits of forensic readiness?

a)

Forensic readiness reduces the costs of a digital forensic investigation.

b)

Forensic readiness makes it easier for organisations to gather evidence.

c)

Forensic readiness ensures that as much evidence as possible is available.

d)

Forensic readiness makes it harder for a malicious hacker to access a network

5.

Refers to any technique, device or software designed to hinder a computer investigation.

a)

Anti-forensic computing.

b)

Encryption.

c)

File headers.

6.

Where possible, the original contents of a device are copied and preserved, leaving the original data untouched.

The tool that does this is called...

a)

Write Blocker

b)

Copy Machine

c)

Universal Serial Bus

d)

WinZip

7.

At which stage of the digital forensics process would a write-blocker be used?

a)

Acquisition

b)

Reporting

c)

Verification

d)

Analysis

8.

Digital evidence can't be time sensitive.

a)

TRUE

b)

FALSE

9.

Digital evidence can be altered, damaged or destroyed with little effort.

a)

TRUE

b)

FALSE

10.

The process of copying data is known as:

a)

data acquisition

b)

data analysis

c)

data documentation

d)

data recovery

11.

Hash Value is used to check the

_________________

a)

Confidentiality of the file

b)

Integrity of the file

c)

rationality of the file

d)

availability of the file

12.

Which of the following is FALSE

a)

The digital forensic investigator must maintain absolute objectivity

b)

It is the investigator’s job to determine someone’s guilt or innocence.

c)

It is the investigator’s responsibility to accurately report the relevant facts of a case.

d)

The investigator must maintain strict confidentiality, discussing the results of an investigation on only a “need to know” basis

13.

____ is the route the evidence takes from the time you find it until the case is closed or goes to court.

a)

Hashing

b)

Chain of Custody

c)

Imaging

d)

Data Recovery.

14.

A keyword search is part of the analysis process within what forensic function?

a)

Reporting

b)

Reconstruction

c)

Extraction

d)

Acquisition

15.

When a forensic investigator is seizing a running computer for examination, he can retrieve data from the computer directly via its normal interface if the evidence needed exists only in the form of volatile data.

a)

True

b)

False

16.

A verifiable procedure for sanitizing a defined area of digital media by overwriting each byte with a known value

a)

Forensic Wipe

b)

File Format

c)

Extraction

17.

You are save from attacker when your device contains no valuable information.

a)

True

b)

False