wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CNET151 Chapt 14 - Introduction to Forensics

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

Frequently, the first responder to a computer crime is __________.

a)

The network administrator

b)

A law enforcement officer

c)

The news media

d)

A private investigator

2.

If you fail to handle evidence properly __________.

a)

You may damage the hard drive

b)

It may be unusable in court

c)

Law enforcement may not look at it

d)

None of the above

3.

You may use Linux to make a __________ of the hard drive.

a)

Bootable copy

b)

Screenshot

c)

New version

d)

Forensically valid copy

4.

Use the Linux __________ command-line command to wipe the target drive in a forensics examination.

a)

cc

b)

dd

c)

nc

d)

md5sum

5.

Use the Linux __________ command-line command to back up your hard drive if you want to create a hash.

a)

cc

b)

dd

c)

nd

d)

md5sum

6.

Documentation of every person who had access to evidence, how they interacted with it, and where it was stored is called the __________.

a)

Forensic trail

b)

Chain of custody

c)

Audit trail

d)

Inspection report

7.

Usually, the first thing you do to a computer to prevent further tampering is to __________.

a)

Make a backup

b)

Make a copy

c)

Take it offline

d)

Lock it in a secure room

8.

__________ can include logs, portable storage devices, emails, tablets, and cell phones.

a)

Computer evidence

b)

Ancillary hardware

c)

Network devices

d)

The Windows Registry

9.

Windows stores information on web addresses, search queries, and recently opened files in a file called__________.

a)

internet.txt

b)

index.dat

c)

default.dat

d)

explore.exe

10.

In Windows, the log that stores events from a single application or component rather than events that might have a systemwide impact is the __________ log.

a)

Application

b)

System

c)

ForwardedEvents

d)

Applications and Services

11.

In Windows, the log that contains events collected from remote computers is the __________ log.

a)

Application

b)

System

c)

ForwardedEvents

d)

Applications and Services

12.

The Linux log file that contains activity related to the web server is __________.

a)

/var/log/kern.log

b)

/var/log/apache2/*

c)

/var/log/lpr.log

d)

/var/log/apport.log

13.

The Linux log file that can reveal attempts to compromise the system or the presence of a virus or spyware is __________.

a)

/var/log/kern.log

b)

/var/log/apache2/*

c)

/var/log/lpr.log

d)

/var/log/apport.log

14.

__________ is a free tool that can be used to recover Windows files.

a)

SearchIt

b)

DiskDigger

c)

FileRecover

d)

FTK Imager

15.

Which cell phone state identified by the U.S. National Institute of Standards is a dormant mode that conserves battery life while maintaining user data and performing other background functions?

a)

Quiescent

b)

Active

c)

Nascent/factory default

d)

Semi-active