wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Digital Forensics

Total questions: 30

Worksheet time: 6mins

Name
Class
Date
1.

What is The Full form of CART

a)

Computer Analysis and Response Team

b)

Cathode Analog Ray Tube

c)

Computer Accessories Repairing team

2.

Full Form Of IOCE

a)

Internet of Computer Evidence

b)

International Organization on Computer Evidence

c)

Internet of Computer Education

d)

None

3.

How Many Rules in Digital forensic

a)

6

b)

10

c)

18

d)

12

4.

Investigator should satisfy the following point:

a)

Contribute to the society and human being

b)

)Avoid harm to others

c)

honest and trustworthy

d)

All Of the Above

5.

Digital Evidence in the form of the:

a)

Office File

b)

E-mail Messages

c)

Either A or B

d)

Both A and B

6.

In Computer intrusions the attacker will be leave multiple traces of there presence in:

a)

)File System

b)

Registry

c)

System Logs

d)

All of the Above

7.

What are the Form of Electronic Evidence:

a)

Hard Drive

b)

E-mail

c)

Either A or B

d)

Both A and B

8.

The Digital evidence are used to established a credible link between……….

a)

Attacker and victim and the crime scene

b)

)Attacker And information

c)

)Either A or B

d)

Both A and B

9.

The evidence and proof that can be obtained from the electronic source is called the…….

a)

Digital Evidence

b)

Explainable evidence

c)

Either A or B

d)

)Both A and B

10.

Which of the following is not type of volatile evidence:

a)

Cached Data

b)

Log Files

c)

Main Memory

d)

Routing Tables

11.

Digital Evidence must follow the requirement of the

a)

Exchange Rule

b)

Best Evidence Rule

c)

Ideal Evidence Rule

d)

All of the mentioned

12.

White hat Hacker is known as the

a)

Grey Hat

b)

Cracker

c)

Ethical

d)

Script Kiddies

13.

A Hacker who identifies and exploits weakness in telephones instead of computers is known as:

a)

Phreaker

b)

Ethical hacker

c)

Hacktivist

d)

Grey Hat hacker

14.

Computers can play the following roles in a crime:

a)

target, object, and subject

b)

evidence, instrumentality, contraband, or fruit of crime

c)

object, evidence, and tool

d)

symbol, instrumentality, and source of evidence

15.

Computers and mobile devices are treated as _________ crime scenes in violent crime investigations.

a)

temporary

b)

immediate

c)

secondary

d)

remote

16.

Download copy, extract data from an open system done fraudulently is treated as _________

a)

cyber-warfare

b)

data-backup

c)

cyber-crime

d)

cyber-security act

17.

The crime scene preservation process includes all but which of the following:

a)

protecting against unauthorized alterations

b)

confirming system date and time

c)

acquiring digital evidence

d)

controlling access to the crime scene

18.

Which of the following is NOT an artifact that will be irrevocably lost if the computer is shut down?

a)

Running processes

b)

Open network ports

c)

Data stored in memory

d)

System date and time

19.

What is used to validate the tools and verify the evidence integrity?

a)

hashing algorithms

b)

steganography

c)

digital certificates

d)

watermarks

20.

A written report is frequently a(n) ____ or a declaration.

a)

subpoena

b)

affidavit

c)

perjury

d)

deposition

21.

E-mail messages are distributed from one central server to many connected client computers, a

configuration called ____.

a)

client/server architecture

b)

client architecture

c)

central distribution architecture

d)

peer-to-peer architecture

22.

Some e-mail systems store messages in flat plaintext files, known as a(n) ____ format.

a)

MIME

b)

POP3

c)

mbox

d)

SMTP

23.

____ is the art of hiding information inside image files.

a)

Steganography

b)

Steganalysis

c)

Steganos

d)

Graphie

24.

Which of following is not a rule of digital forensics?

a)

An examination should be performed on the original data

b)

A copy is made onto forensically sterile media. New media should always be used if available.

c)

The copy of the evidence must be an exact, bit-bybit copy

d)

The examination must be conducted in such a way as to prevent any modification of the evidence.

25.

What is the most significant legal issue in computer forensics?

a)

Admissibility of Evidence

b)

Seizing Evidence

c)

Discovery of Evidence

d)

Preserving Evidence

26.

You are a computer forensic examiner at a scene and have determined you will seize a Linux server, which according to your source of information contains the database records for the company under investigation for fraud. The best practice for "taking down" the server for collection is to photograph the screen, note any running programs or messages and so on, and __________.

a)

Use the normal shutdown procedure

b)

Pull the plug from the wall

c)

Pull the plug from the rear of the computer

d)

Ask the user at the scene to shut down the server

27.

When a forensic copy is made, in what format are the contents of the hard

a)

As compressed images.

b)

As bootable files.

c)

As executable files.

d)

As operating system files

28.

Which of the following is a proper acquisition technique?

a)

Disk to Image

b)

Disk to Disk

c)

Sparse Acquisition

d)

All of the above

29.

_____________ devices prevent altering data on drives attached to the suspect computer and also offer very fast acquisition speeds.

a)

Encryption

b)

Imaging

c)

Write Blocking

d)

Hashing

30.

Which duplication method produces an exact replica of the original drive?

a)

Bit-Stream Copy

b)

Image Copy

c)

Mirror Copy

d)

Drive Image