Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CHFI QUIZ

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Recycle Bin ada sebagai metafora untuk membuang file, tetapi juga memungkinkan pengguna untuk mengambil dan memulihkan file. Setelah file dipindahkan ke Recycle Bin, sebuah catatan akan ditambahkan ke file log yang ada di Recycle Bin. Manakah dari file berikut ini yang berisi catatan yang sesuai dengan setiap file yang dihapus di Recycle Bin?

a)

INFO2

b)
LOGINFO1
c)
L0GINF02
d)
INFO 1
2.

Amber, a black hat hacker, has embedded a malware into a small enticing advertisement and posted it on a popular ad-network that displays across various websites. What is she doing?

Compromising a legitimate site 1

Spearphishmg

Click-jacking

Malvertislng

a)
Click-jacking
b)
Spearphishing
c)
Compromising a legitimate site
d)
Malvertising
3.

Which of the following methods of mobile device data acquisition captures ail the data present on the device, as weli as all deleted data and access to unallocated space?

a)
Physical acquisition
b)
Logical acquisition
c)
Manual acquisition
d)
Direct acquisition
4.

An EC2 instance storing critical data of a company got infected with malware. The forensics team took the EBS volume snapshot of the affected instance to perform further analysis and collected other data of evidentiary value. What should be their next step?

a)
They should terminate the instance after taking necessary backup
b)
They should keep the instance running as it stores critical data
c)
They should pause the running instance
d)
They should terminate all instances connected via the same VPC
5.

Which of the following are small pieces of data sent from a website and stored on the user’s computer by the user's web browser to track,validate, and maintain specific user information?

a)
Web Browser Cache
b)
Cookies
c)
Temporary Files
d)
Open files
6.

POP3 is an Internet protocol used to retrieve emails from a mail server. Through which port does an email client connect with a POP3 server?

a)
25
b)
993
c)
110
d)
143
7.

To which phase of the computer forensics investigation process does "planning and budgeting of a forensics lab" belong?

a)
Reporting phase
b)
Investigation phase
c)
Post-Investigation phase
d)
Pre-investigation phase
8.

................ allows a forensic investigator to identify the missing links during investigation,

a)
Evidence preservation
b)
Exhibit numbering
c)
Chain of custody
d)
Evidence reconstruction
9.

What command-line tool enables forensic investigator to establish communication between an Android device and a forensic workstation in order to perform data acquisition from the device?

a)
APK Analyzer
b)
SDK Manager
c)
Xcode
d)
Android Debug Bridge
10.

Which ISO standard enables laboratories to demonstrate that they comply with quality assurance and provide valid results?

a)
ISO/IEC 17025
b)
ISO/lEC 18025
c)
ISO/IEC I9025
d)
ISO/IEC 16025
11.

Sally accessed the computer system that holds trade secrets of the company where she is employed. She knows she accessed it without authorization and all access (authorized and unauthorized) to this computer is monitored.To cover her tracks. Sally deleted the log entries on this computer. What among the following best describes her action?

a)
Password sniffing
b)
Brute-force attack
c)
Anti-forensics
d)
Network intrusion
12.

Storage location of Recycle Bin for NTFS file systems (Windows Vista and later) is located at:

a)

Drive:\ $Recyde.Bin

b)

Drive:\RECYCLER

c)

Drive:\RECYCLE.Bir .

d)

Drive:\REvCLEE

13.

in a Filesystem Hierarchy Standard (FHS), which of the following directories contains the binary files required for working?

a)
/media
b)
/sbin
c)
/proc
d)
/mnt
14.

Williamson is a forensic investigator. While investigating a case of data breach at a company, he is maintaining a document that records derails such as the forensic processes applied on the collected evidence, particulars of people handling it, the dates and times when it is being handled, and the place of storage of the evidence. What do you call this document?

a)
Consent
b)
Chain of form custody
c)
Log book
d)
Authorization form
15.

ISO/IEC 17025 is an accreditation for which of the following:

a)
Chain of custody
b)
CHFi issuing agency
c)
Encryption
d)
Forensics lab licensing
16.

Derrick, a forensic specialist, was investigating an active computer that was executing various processes. Derrick wanted to check whether this system was used in an incident that occurred earlier. He started inspecting and gathering the contents of RAM, cache, and DLLs to identify incident signatures, identify the data acquisition method employed by Derrick in the above scenario.

a)
Dead data acquisition
b)
Live data acquisition
c)
Non-volatile data acquisition
d)
Static data acquisition
17.

To understand the impact of a malicious program after the booting process and to collect recent information from the disk partition, an investigator should evaluate the content of the:

a)
BIOS
b)
UEFI
c)
GRUB
d)
MBR
18.

Which command can provide investigators with details of all the loaded modules on a Linux-based system?

a)
plist mod -a
b)
list modules -a
c)
Isof -m
d)
Ismod
19.

The working of the Tor browser is based on which of the following concepts?

a)
Both static and default routing
b)
Static routing
c)
Default routing
d)
Onion routing
20.

An investigator is examining a file to identify any potentially malicious content. To avoid code execution and still be able to uncover hidden indicators of compromise (IOC ), which type of examination should the investigator perform:

a)
Dynamic analysis
b)
Static analysis
c)
Threat hunting
d)
Threat analysis