WorksheetsCyber Forensics Under Cyber Closet Project
Total questions: 10
Worksheet time: 5mins
When shutting down a computer what information is typically lost?
Data in a RAM memory
Running Processes
Current Network connections
All of the above
The volatile memory of the computer is known as
Binary Input Output System (BIOS)
Random Access Memory (RAM)
Read Only Memory (ROM)
Central Processing Unit (CPU)
Physical address of a computer is known as
MAC address
IP address
Network Interface Card
Address Resolution Protocol
In a digital forensics investigation,______________ describes the route that evidence takes from the time you find it until the case is closed or goes to court.
Rules of evidence
Law of probability
Chain of custody
Policy of separation
The first responder toolkit essentially consists of the following items:
Storage media & Software
Package & transportation
Miscellaneous items like gloves, evidence stickers etc.
All of the above
What is the most significant legal issue in computer forensics?
Preserving Evidence
Seizing Evidence
Admissibility of Evidence
Discovery of Evidence
Which of following is not a rule of digital forensics?
An examination should be performed on the original data
A copy is made onto forensically sterile media. New media should always be used if available
The copy of the evidence must be an exact, bit-by-bit copy
The examination must be conducted in such a way as to prevent any modification of theevidence
Using what, data hiding in encrypted images be carried out in digital forensics?
Acquisition
Stenography
Live analysis
Hashing
Analysis should use ____________________ to avoid introduction of data from some other source
clean storage media
write-blocker
both a & b
none of these
……………………… is the science of extracting forensic information from digital storage media like Hard disk, USB devices, Fire wire devices, CD, DVD, Flash drives etc
Network Forensics
Computer Forensics
Live Forensics
Disk Forensics
