Font size
WorksheetsForensic Investigator - Quiz Exam
Total questions: 170
Worksheet time: 2hrs 39mins
Digital evidence can't be time sensitive.
TRUE
FALSE
Digital evidence can be altered, damaged or destroyed with little effort.
TRUE
FALSE
At which stage of the digital forensics process would a write-blocker be used?
Acquisition
Reporting
Verification
Analysis
The process of copying data is known as:
data acquisition
data analysis
data documentation
data recovery
Harold, a fraud examiner, collects a computer hard drive as potential evidence in an investigation. He creates a memorandum to record the chain of custody and documents what item was received, when it was received, and from whom it was received. To meet the minimum standard for a chain of custody memorandum, what else would Harold need to include?
The name of the judge who signed the seizure order, if applicable,
The value of the noncash item received,
An explanation of why the item was collected,
Where the item is maintained
_______ is the practice of concealing a file, message, image, or video within another file, message, image, or video.
Steganography
Cryptography
File hidding
Media Analysis
Command to find out the internal ip using the dos prompt is ?
ipscan
itconfig
ipconflict
ipconfig
___is an example of social engineering techniques being used to deceive users. Users are often lured by communications purporting to be from trusted parties such as social web sites, auction sites, banks, online payment processors or IT administrators
Phishing
SQL Injection
SMS Bombing
Denial of Service
Hash Value is used to check the
_________________
Confidentiality of the file
Integrity of the file
rationality of the file
availability of the file
A ____value is a numeric value of a fixed length that uniquely identifies data.
A. Hash
B. Decimal
C. Number
D. Variable
The practice of forensic document examination is called graphology.
True
False
Which of the following is FALSE
A. The digital forensic investigator must maintain absolute objectivity
B. It is the investigator’s job to determine someone’s guilt or innocence.
C. It is the investigator’s responsibility to accurately report the relevant facts of a case.
D. The investigator must maintain strict confidentiality, discussing the results of an investigation on only a “need to know” basis
____ is the route the evidence takes from the time you find it until the case is closed or goes to court.
A. Hashing
B. Chain of Custody
C. Imaging
D. Data Recovery.
A keyword search is part of the analysis process within what forensic function?
A. reporting
B. reconstruction
C. extraction
D. acquisition
A
B
C
D
Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?
A. #06#*
B. *#06#
C. #*06*#
D. *IMEI#
For forensic Experts, it is important to understand the Internet’s protocols so that they:
A. Can write code to collect courtroom evidence.
B. Can hire a professional to handle the problem.
C. Understand electronic courtroom procedures.
D. Understand the nature of a cyber attack.
1. This refers to the unauthorized monitoring of other people's communications, such as simply looking over the shoulder of a legitimate computer user to learn his login name and password.
A. Phishing
B. Spamming
C. Spoofing
D. Eavesdropping
A
B
C
D
Billy, a computer forensics expert, has recovered a large number of OST files during
forensic investigation of a laptop. Which of the following email clients he can use to analyze
the OST?
A. Microsoft Outlook
B. Microsoft Outlook Express
C. Mozilla Thunderbird
D. Eudora
When a forensic investigator is seizing a running computer for examination, he can retrieve data from the computer directly via its normal interface if the evidence needed exists only in the form of volatile data.
A. True
B. False
If a fraud examiner was gathering information about a fraud suspect, which of the following types of information would likely require access to nonpublic sources of information to obtain?
A. The subject's phone history records,
B. The subject's habits and lifestyle,
C. Where the subject currently resides,
D. All of the above
When shutting down a computer what information is typically lost?
Data in a RAM memory
Running Processes
Current Network connections
All of the above
The volatile memory of the computer is known as
Binary Input Output System (BIOS)
Random Access Memory (RAM)
Read Only Memory (ROM)
Central Processing Unit (CPU)
Physical address of a computer is known as
MAC address
IP address
Network Interface Card
Address Resolution Protocol
In a digital forensics investigation,______________ describes the route that evidence takes from the time you find it until the case is closed or goes to court.
Rules of evidence
Law of probability
Chain of custody
Policy of separation
The first responder toolkit essentially consists of the following items:
Storage media & Software
Package & transportation
Miscellaneous items like gloves, evidence stickers etc.
All of the above
What is the most significant legal issue in computer forensics?
Preserving Evidence
Seizing Evidence
Admissibility of Evidence
Discovery of Evidence
Which of following is not a rule of digital forensics?
An examination should be performed on the original data
A copy is made onto forensically sterile media. New media should always be used if available
The copy of the evidence must be an exact, bit-by-bit copy
The examination must be conducted in such a way as to prevent any modification of theevidence
Using what, data hiding in encrypted images be carried out in digital forensics?
Acquisition
Stenography
Live analysis
Hashing
Analysis should use ____________________ to avoid introduction of data from some other source
clean storage media
write-blocker
both a & b
none of these
……………………… is the science of extracting forensic information from digital storage media like Hard disk, USB devices, Fire wire devices, CD, DVD, Flash drives etc
Network Forensics
Computer Forensics
Live Forensics
Disk Forensics
Recycle Bin ada sebagai metafora untuk membuang file, tetapi juga memungkinkan pengguna untuk mengambil dan memulihkan file. Setelah file dipindahkan ke Recycle Bin, sebuah catatan akan ditambahkan ke file log yang ada di Recycle Bin. Manakah dari file berikut ini yang berisi catatan yang sesuai dengan setiap file yang dihapus di Recycle Bin?
INFO2
Amber, a black hat hacker, has embedded a malware into a small enticing advertisement and posted it on a popular ad-network that displays across various websites. What is she doing?
Compromising a legitimate site 1
Spearphishmg
Click-jacking
Malvertislng
Which of the following methods of mobile device data acquisition captures ail the data present on the device, as weli as all deleted data and access to unallocated space?
An EC2 instance storing critical data of a company got infected with malware. The forensics team took the EBS volume snapshot of the affected instance to perform further analysis and collected other data of evidentiary value. What should be their next step?
Which of the following are small pieces of data sent from a website and stored on the user’s computer by the user's web browser to track,validate, and maintain specific user information?
POP3 is an Internet protocol used to retrieve emails from a mail server. Through which port does an email client connect with a POP3 server?
To which phase of the computer forensics investigation process does "planning and budgeting of a forensics lab" belong?
................ allows a forensic investigator to identify the missing links during investigation,
What command-line tool enables forensic investigator to establish communication between an Android device and a forensic workstation in order to perform data acquisition from the device?
Which ISO standard enables laboratories to demonstrate that they comply with quality assurance and provide valid results?
Sally accessed the computer system that holds trade secrets of the company where she is employed. She knows she accessed it without authorization and all access (authorized and unauthorized) to this computer is monitored.To cover her tracks. Sally deleted the log entries on this computer. What among the following best describes her action?
Storage location of Recycle Bin for NTFS file systems (Windows Vista and later) is located at:
Drive:\ $Recyde.Bin
Drive:\RECYCLER
Drive:\RECYCLE.Bir .
Drive:\REvCLEE
in a Filesystem Hierarchy Standard (FHS), which of the following directories contains the binary files required for working?
Williamson is a forensic investigator. While investigating a case of data breach at a company, he is maintaining a document that records derails such as the forensic processes applied on the collected evidence, particulars of people handling it, the dates and times when it is being handled, and the place of storage of the evidence. What do you call this document?
ISO/IEC 17025 is an accreditation for which of the following:
Derrick, a forensic specialist, was investigating an active computer that was executing various processes. Derrick wanted to check whether this system was used in an incident that occurred earlier. He started inspecting and gathering the contents of RAM, cache, and DLLs to identify incident signatures, identify the data acquisition method employed by Derrick in the above scenario.
To understand the impact of a malicious program after the booting process and to collect recent information from the disk partition, an investigator should evaluate the content of the:
Which command can provide investigators with details of all the loaded modules on a Linux-based system?
The working of the Tor browser is based on which of the following concepts?
An investigator is examining a file to identify any potentially malicious content. To avoid code execution and still be able to uncover hidden indicators of compromise (IOC ), which type of examination should the investigator perform:
Forensic Science is
microscopes used for vapor
the applications of testing
applying principles of science to the law
the application of evidence to testing
DNA is
deoxygenated acid
deoxyribnucleic acid
deoxetrate acid
deoxyrib antacid
Identical twins have identical fingerprints.
True
False
Chromatography is
a laboratory test used to identify particular substances
a photographic process
a mapping technique
used to identify shoe size
A suspect is
a person claiming innocence
someone with beady eyes
someone who is thought to have possibly committed the crime
a person who has a solid alibi
A medical examiner determines the cause of death through autopsy.
True
False
Fingerprints can be lifted from carpeting.
True
False
Loops, whorls and arches are used to describe
hair evidence
DNA
fingerprints
handwriting evidence
All evidence gathered at a crime scene must be
labeled and documented
analyzed in a scientific manner
handled carefully so not to contaminate the specimen
all of the above
The first job of a police officer is to
take photographs
secure the area with crime scene tape
make sure the scene is safe
gather evidence
A person harmed, injured, or killed as a result of a crime
officer
victim
out of luck
suspect
What pattern of fingerprint is shown?
Loop
Arch
Whorl
What pattern of the fingerprint is shown?
arch
whorl
loop
none of these
Identify the fingerprint pattern shown.
loop
arch
whorl
What are fingerprints used for?
determine eye color
Identification
To help you fight crime.
Of the following, select all the things which can be probable evidence from the crime scene.
Tyre impressions
Soil from crime scene
Teeth impressions
Fiber particles
The adjoining figure depicts which analysis technique?
Gel electrophoresis
Polymerase chain reaction
Paper chromatography
Soil pH analysis using indicators
The adjoining figure shows apparatus set-up of which analysis technique?
Gel electrophoresis
Polymerase chain reaction
Paper chromatography
Soil analysis using pH indicators
Direct Evidence includes all but the following...
blood left at the scene
eye witness
victim's testimony
suspect's alibi
What is computer forensics?
It is an attempt to expose, alter, destabilize, destroy, remove to gain unauthorized access or use an asset.
It is the discipline that combines the elements of law and computer science to collect and analyze data from computer Systems, network, Wireless communications and storage devices in a way that is admisible as evidence in a court of law.
What are the examples of latent data? choose 3.
Belkasoft Live RAM capturer
Information that is in the computer's storage but is not easily mentioned in the file allocation tables.
Data that has been deliberately removed.
Information that the operating System or commonly used software Application cannot easily see.
1. A _______ has occurred, collecting all relevant evidence is of the utmost importance in answering the questions described above.
file headers.
forensic investigator.
cyber attack.
What are the main types of computer forensics?
Of operating Systems
Of security
Of network.
On the cloud.
On Mobile devices
It is the process of retrieving useful Information from the computer or mobile device in questions.
Of network
On the cloud
Of operating Systems
It aims to retrieve digital evidence or relevant data from a mobile device in a way that preserves the evidence in a sound forensic condition.
On the cloud
Of operating Systems
On mobile devices
It refers to the collection, monitoring, and analysis of network activities to discover the source of attacks, viruses, intrusions, or security breaches that occur On a network or in network traffic.
On the cloud
On mobile devices
Of operating Systems
Of network
Refers to any technique, device or software designed to hinder a computer investigation.
Anti-forensic computing.
Encryption.
File headers.
Focuses primarily On gathering digital forensic Information from a cloud infrastructure.
On mobile devices.
On the cloud.
FTK Imager
You use a complex set of rules called an algorithm to make data unreadable.
Encryption
Metadata
Computer forensic analysis
Is a data and image preview tool that allows you to browse files and folders on local hard drives, network drives, CD / DVD and review the content of forensic images or memory dumps.
FTK Imager
Volatility
HashCalc
Es un programa de calculadora desarrollado por SlavaSoft
HashCalc
Belkasoft Live RAM capturer
Volatility
For volatile memory analysis there are several tools such as:
Volatility
Belkasoft Live RAM capturer
HashCalc
It must be accurate, comprehensive, unbiased, recorded, repeatable, and completed within the available time frames and allocated resources.
Computer forensic analysis
The computer expert
Volatility
It is used behind the scenes in Autopsy and in many other commercial and open source forensic tools.
Encase Forensics
Sleuth kit
SIFT Workstation 3
Quickly search, identify and prioritize potential evidence, on computers and mobile devices, to determine if further investigation is warranted.
Encase Forensics
Digital forensics
safety
Forensics v6
It is a group of open source free incident response and forensic tools designed to perform detailed digital forensic examinations in a variety of environments.
Access Data Registry Viewer.
SIFT Workstation 3
Sleuthkit
Provides one of the fastest and most powerful ways to locate files On a Windows computer. You can search by file Name, size, creation and modification dates, and other criteria
OsForensics v6
SIFT Workstation 3
Forense digital
Reveal when a document first appeared On a computer, when it was last edited, when it was last saved or printed, and which user performed these actions.
Defense in depth
Safety
Computer forensic examination
The implementation of this type of security model in which the principles of computer forensics are also adopted is also known as:
Defense in depth
Safety
Criminology
Vulnerability and testing
What does Digital Forensics mean?
Applying computer scientific tests or techniques to help solve a crime
Is a legal order issued by the Courts that allows officers to arrest someone
When someone enters a building with the intent to steal something or commit a crime
Analysing and examining clothes, blood, hair, footprints or marks left by tools or weapons.
What does RIPA stand for?
Regulation of Investigatory Powers Act
Regulation of Information Powers Act
Recovery of Investigatory Powers Act
Recovery of Information Powers Act
The most relevant part of the Human Rights Act in relation to Digital Forensics is...
The right to privacy
Freedom of thought, conscience and religion
Freedom of expression
The right to life
It is the responsibility of who to supervise the execution of a warrant and the security of the site and potential evidence.
Lead investigator
First officer on scene
Highest ranking officer within the district
All people who enter the crime scene
Where possible, the original contents of a device are copied and preserved, leaving the original data untouched.
The tool that does this is called...
Write Blocker
Copy Machine
Universal Serial Bus
WinZip
Forensic readiness means that the company or organisation has built-in the ability to collect, preserve, protect and analyse any potential digital evidence from their computers
True
False
An investigation can only be carried out when ....
there is a suspicion that a crime has been committed.
a person has a criminal history
a witness to an incident owns a mobile device
when working within a 'high security' company
At which stage of the digital forensics process would a write-blocker be used?
Acquisition
Reporting
Verification
Analysis
Which three of the following statement s describes forensic readiness?
How prepared a digital forensic investigator is to present their evidence in a court of law
How easy it is for the digital forensic investigator to find evidence which proves that someone is guilty
A machine which has been imaged for the forensic purposes
How prepared an organisation is to respond to an incident
Which three of the following are benefits of forensic readiness?
Forensic readiness reduces the costs of a digital forensic investigation.
Forensic readiness makes it easier for organisations to gather evidence.
Forensic readiness ensures that as much evidence as possible is available.
Forensic readiness makes it harder for a malicious hacker to access a network
Which one of the following acts states that individuals have a right to respect for the privacy of their e-mails
Copyright, Designs and Patents Act
Criminal Justice and Police Act
Human Rights Act
Computer Misuse Act
Which one of the following acts states that individuals have a right to respect for the privacy of their e-mails
Copyright, Designs and Patents Act
Criminal Justice and Police Act
Human Rights Act
Computer Misuse Act
Which two of the following show why it is important to conduct an investigation on a copy of the data instead of the original
To allow other investigators to work on the data to speed up the investigation
To allow the investigation to be replicated
some tools will only work on copied data
To prevent any aspect of the investigation from tampering with the original evidence
At which stage of the digital forensics process would a write-blocker be used?
Acquisition
Reporting
Verification
Analysis
Applying preservation techniques during data acquisition can help to identify which of the following?
The name of the person who last logged in
Mac Number
Running programs
The IP address
Which two of the following software tools could be used during the analysis phase of the digital forensics process?
A word processor
A hex-editor
A network packet analyser
A file encryption tool
Which three of the following statement s describes forensic readiness?
How prepared a digital forensic investigator is to present their evidence in a court of law
How easy it is for the digital forensic investigator to find evidence which proves that someone is guilty
A machine which has been imaged for the forensic purposes
How prepared an organisation is to respond to an incident
Which one of the following files could be retrieved during browser forensics?
index.dat
history.ffx
passwords.txt
google.cache
Which one of the following acts allows certain organisations to get access to an individuals sent and received text messages?
Computer Misuse Act
Criminal Justice and Police Act
Copyright, Designs and Patents Act
Regulation of Investigatory Powers Act
Which three of the following are benefits of forensic readiness?
Forensic readiness reduces the costs of a digital forensic investigation.
Forensic readiness makes it easier for organisations to gather evidence.
Forensic readiness ensures that as much evidence as possible is available.
Forensic readiness makes it harder for a malicious hacker to access a network
Which two of the following are the role of the reporting stage of the digital forensic process?
The report describes the evidence which was obtained from the investigation.
The report is used to work out how much money to pay the investigator.
The report describes the investigation so that it can be understood by a non-technical person.
The report states whether or no the accused is guilty.
Which two of the following statements describing the steps in the digital forensic process are true?
The steps can be completed in any order.
The are laws explaining how the steps must be completed.
The steps must be completed in the order of accusation, analysis and reporting.
There are guidelines explaining how the steps should be completed.
The image shows a screenshot of some data.
Which one of the following is where data like this can be found?
Network infrastructure window
My computer
Recycle bin
External hard drive
Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?
Process Explore
nbtstat
netstat
Autopsy
Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?
Swap file
Slack space
Process memory
Event logs
Drake is an incident handler in Dark CLoud Inc. He is intended to perform log analysis in order to detect traces of malicious activities within the network infrastructure. Which of the following tools Drake must employ in order to view logs in real time and identify malware propagation within the network?
HULK
LOIC
Hydra
Splunk
Eric who is an incident responder is working on developing incident-handling plans and procedures. As part of this process, he is performing analysis on the organizational network to generate a report and to develop policies based on the acquired results.
Which of the following tools will help him in analyzing network and its related traffic?
Burp Suite
Whois
Wireshark
FaceNiff
Which of the following malware detection technique is employed in intrusion analysis to identify the transfer of any unwanted traffic to malicious or unknown external entities?
Covert Malware Beaconing
SSDT Patching
Kernel Filter Drivers
Covert C&C Communication
Which of the following terms refers to an organization’s ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?
Data analysis
Risk assessment
Threat assessment
Forensic readiness
Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during incident response process. She was also told that the system backup can also be used for further investigation of the incident.
In which of the following stages of the incident handling and response (IH&R) process Alice has to take the complete backup of the infected system?
Containment
Eradication
Incident recording
Incident triage
Which of the following techniques prevent or mislead incident-handling process and may also affect the collection, preservation, and identification phases of the forensic investigation process?
Scanning
Footprinting
Anti-forensics
Enumeration
In which of the following stages of incident handling does classification and prioritization of incidents take place?
Incident Containment
Incident Triage
Incident Recording and Assignment
Post-Incident Activities
Alex is an incident handler for Tech-o-Tech Inc. and he is intended to identify any possible insider threats in his organization.
Which of the following insider threat detection techniques can be used by him to detect insider threats based on the behavior of a doubtful employee both individually and in a group?
Profiling
Physical detection
Mole detection
Behavioral analysis
Employee Code:
Name of the Employee:
1. What is the primary purpose of incident reporting in healthcare?
To assign blame to individuals involved
To identify areas for improvement in patient care
To penalize healthcare providers
To avoid legal liabilities
2. Which of the following incidents should be reported in healthcare?
Minor errors without any patient harm
Near misses
Adverse events causing harm to patients
All of the above
3. What is the primary goal of incident reporting systems in healthcare institutions?
To increase insurance premiums
To create unnecessary paperwork for staff
To improve patient safety and quality of care
To discourage staff from reporting incidents
4. What does a near miss imply in incident reporting?
Incidents that do not require reporting
Patient safety event that reaches the patient but does not cause harm
Incidents that involve minor errors
Incidents caused by patient-related factors
5. When should healthcare professionals report incidents?
Only during regular office hours
Immediately after the incident occurs
Within 48 hours after the incident
At the end of the week
Which of the following terms may be defined as “a measure of possible inability to achieve a goal,
objective, or target within a defined security, cost plan and technical limitations that adversely
affects the organization’s operation and revenues?
Incident Respons
Threat
Vulnerability
Risk
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single
system is targeted by a large number of infected machines over the Internet. In a DDoS attack,
attackers first infect multiple systems which are known as:
Trojan
Zombies
Spyware
Worms
The goal of incident response is to handle the incident in a way that minimizes damage and reduces
recovery time and cost. Which of the following does NOT constitute a goal of incident response?
Dealing properly with legal issues that may arise during incidents
Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft
and disruption of services
Using information gathered during incident handling to prepare for handling future incidents in a
better way and to provide stronger protection for systems and data
Dealing with human resources department and various employee conflict behaviors
An organization faced an information security incident where a disgruntled employee passed
sensitive access control information to a competitor. The organization’s incident response manager,
upon investigation, found that the incident must be handled within a few hours on the same day to
maintain business continuity and market competitiveness. How would you categorize such
information security incident?
Middle level incident
Low level incident
High level incident
Ultra-High level incident
Business continuity is defined as the ability of an organization to continue to function even after a
disastrous event, accomplished through the deployment of redundant hardware and software, the
use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which
is mandatory part of a business continuity plan?
Sales and Marketing plan
Forensics Procedure Plan
Business Recovery Plan
New business strategy plan
Which of the following is an appropriate flow of the incident recovery steps?
System Operation-System Restoration-System Validation-System Monitoring
System Restoration-System Monitoring-System Validation-System Operations
System Restoration-System Validation-System Operations-System Monitoring
System Validation-System Operation-System Restoration-System Monitoring
A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with
computer security incidents. Identify the procedure that is NOT part of the computer risk policy?
Procedure for the ongoing training of employees authorized to access the system
Procedure to identify security funds to hedge risk
Procedure to monitor the efficiency of security controls
Provisions for continuing support if there is an interruption in the system or if the system crashes
Identify the network security incident where intended authorized users are prevented from using
system, network, or applications by flooding the network with high volume of traffic that consumes
all existing network resources.
URL Manipulation
XSS Attack
Denial of Service Attack
SQL Injection
Incident handling and response steps help you to detect, identify, respond and manage an incident.
Which of the following steps focus on limiting the scope and extent of an incident?
Eradication
Identification
Data collection
Containment
Policies are designed to protect the organizational resources on the network by establishingthe set rules and procedures. Which of the following policies authorizes a group of users to perform aset of actions on a set of resources
Documentation policy
Access control policy
Logging policy
Audit trail policy
The data on the affected system must be backed up so that it can be retrieved if it is damagedduring incident response. The system backup can also be used for further investigations of theincident. Identify the stage of the incident response and handling process in which complete backupof the infected system is carried out
Eradication
Incident recording
Incident investigation
Containment
The role that applies appropriate technology and tries to eradicate and recover from theincident is known as
Incident coordinator
Incident Handler
Incident Analyst
Incident Manager
Why do we investigate and report incidents
for moral reasons
identifying root causes
financial reasons
all of the above
Accident reports are considered as
Leading indicator
Lagging indicator
the picture is an example of
unsafe act
unsafe condition
accident
nearmiss
what is Hazard
A potential source of harm
Likelihood of harm to occur
Rating of consequences
Relation between severity and probability
