NEW
Font size
WorksheetsDigital Forensics
Total questions: 30
Worksheet time: 6mins
What is The Full form of CART
Computer Analysis and Response Team
Cathode Analog Ray Tube
Computer Accessories Repairing team
Full Form Of IOCE
Internet of Computer Evidence
International Organization on Computer Evidence
Internet of Computer Education
None
How Many Rules in Digital forensic
6
10
18
12
Investigator should satisfy the following point:
Contribute to the society and human being
)Avoid harm to others
honest and trustworthy
All Of the Above
Digital Evidence in the form of the:
Office File
E-mail Messages
Either A or B
Both A and B
In Computer intrusions the attacker will be leave multiple traces of there presence in:
)File System
Registry
System Logs
All of the Above
What are the Form of Electronic Evidence:
Hard Drive
Either A or B
Both A and B
The Digital evidence are used to established a credible link between……….
Attacker and victim and the crime scene
)Attacker And information
)Either A or B
Both A and B
The evidence and proof that can be obtained from the electronic source is called the…….
Digital Evidence
Explainable evidence
Either A or B
)Both A and B
Which of the following is not type of volatile evidence:
Cached Data
Log Files
Main Memory
Routing Tables
Digital Evidence must follow the requirement of the
Exchange Rule
Best Evidence Rule
Ideal Evidence Rule
All of the mentioned
White hat Hacker is known as the
Grey Hat
Cracker
Ethical
Script Kiddies
A Hacker who identifies and exploits weakness in telephones instead of computers is known as:
Phreaker
Ethical hacker
Hacktivist
Grey Hat hacker
Computers can play the following roles in a crime:
target, object, and subject
evidence, instrumentality, contraband, or fruit of crime
object, evidence, and tool
symbol, instrumentality, and source of evidence
Computers and mobile devices are treated as _________ crime scenes in violent crime investigations.
temporary
immediate
secondary
remote
Download copy, extract data from an open system done fraudulently is treated as _________
cyber-warfare
data-backup
cyber-crime
cyber-security act
The crime scene preservation process includes all but which of the following:
protecting against unauthorized alterations
confirming system date and time
acquiring digital evidence
controlling access to the crime scene
Which of the following is NOT an artifact that will be irrevocably lost if the computer is shut down?
Running processes
Open network ports
Data stored in memory
System date and time
What is used to validate the tools and verify the evidence integrity?
hashing algorithms
steganography
digital certificates
watermarks
A written report is frequently a(n) ____ or a declaration.
subpoena
affidavit
perjury
deposition
E-mail messages are distributed from one central server to many connected client computers, a
configuration called ____.
client/server architecture
client architecture
central distribution architecture
peer-to-peer architecture
Some e-mail systems store messages in flat plaintext files, known as a(n) ____ format.
MIME
POP3
mbox
SMTP
____ is the art of hiding information inside image files.
Steganography
Steganalysis
Steganos
Graphie
Which of following is not a rule of digital forensics?
An examination should be performed on the original data
A copy is made onto forensically sterile media. New media should always be used if available.
The copy of the evidence must be an exact, bit-bybit copy
The examination must be conducted in such a way as to prevent any modification of the evidence.
What is the most significant legal issue in computer forensics?
Admissibility of Evidence
Seizing Evidence
Discovery of Evidence
Preserving Evidence
You are a computer forensic examiner at a scene and have determined you will seize a Linux server, which according to your source of information contains the database records for the company under investigation for fraud. The best practice for "taking down" the server for collection is to photograph the screen, note any running programs or messages and so on, and __________.
Use the normal shutdown procedure
Pull the plug from the wall
Pull the plug from the rear of the computer
Ask the user at the scene to shut down the server
When a forensic copy is made, in what format are the contents of the hard
As compressed images.
As bootable files.
As executable files.
As operating system files
Which of the following is a proper acquisition technique?
Disk to Image
Disk to Disk
Sparse Acquisition
All of the above
_____________ devices prevent altering data on drives attached to the suspect computer and also offer very fast acquisition speeds.
Encryption
Imaging
Write Blocking
Hashing
Which duplication method produces an exact replica of the original drive?
Bit-Stream Copy
Image Copy
Mirror Copy
Drive Image
