wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Forensic Investigator - Quiz Exam

Total questions: 170

Worksheet time: 2hrs 39mins

Name
Class
Date
1.

Digital evidence can't be time sensitive.

a)

TRUE

b)

FALSE

2.

Digital evidence can be altered, damaged or destroyed with little effort.

a)

TRUE

b)

FALSE

3.

At which stage of the digital forensics process would a write-blocker be used?

a)

Acquisition

b)

Reporting

c)

Verification

d)

Analysis

4.

The process of copying data is known as:

a)

data acquisition

b)

data analysis

c)

data documentation

d)

data recovery

5.

Harold, a fraud examiner, collects a computer hard drive as potential evidence in an investigation. He creates a memorandum to record the chain of custody and documents what item was received, when it was received, and from whom it was received. To meet the minimum standard for a chain of custody memorandum, what else would Harold need to include?

a)

The name of the judge who signed the seizure order, if applicable,

b)

The value of the noncash item received,

c)

An explanation of why the item was collected,

d)

Where the item is maintained

6.

_______ is the practice of concealing a file, message, image, or video within another file, message, image, or video.

a)

Steganography

b)

Cryptography

c)

File hidding

d)

Media Analysis

7.

Command to find out the internal ip using the dos prompt is ?

a)

ipscan

b)

itconfig

c)

ipconflict

d)

ipconfig

8.

___is an example of social engineering techniques being used to deceive users. Users are often lured by communications purporting to be from trusted parties such as social web sites, auction sites, banks, online payment processors or IT administrators

a)

Phishing

b)

SQL Injection

c)

SMS Bombing

d)

Denial of Service

9.

Hash Value is used to check the

_________________

a)

Confidentiality of the file

b)

Integrity of the file

c)

rationality of the file

d)

availability of the file

10.

A ____value is a numeric value of a fixed length that uniquely identifies data.

a)

A. Hash

b)

B. Decimal

c)

C. Number

d)

D. Variable

11.

The practice of forensic document examination is called graphology.

a)

True

b)

False

12.

Which of the following is FALSE

a)

A. The digital forensic investigator must maintain absolute objectivity

b)

B. It is the investigator’s job to determine someone’s guilt or innocence.

c)

C. It is the investigator’s responsibility to accurately report the relevant facts of a case.

d)

D. The investigator must maintain strict confidentiality, discussing the results of an investigation on only a “need to know” basis

13.

____ is the route the evidence takes from the time you find it until the case is closed or goes to court.

a)

A. Hashing

b)

B. Chain of Custody

c)

C. Imaging

d)

D. Data Recovery.

14.

A keyword search is part of the analysis process within what forensic function?

A. reporting

B. reconstruction

C. extraction

D. acquisition

a)

A

b)

B

c)

C

d)

D

15.

Ron, a computer forensics expert, is investigating a case involving corporate espionage. He has recovered several mobile computing devices from the crime scene. One of the evidence that Ron possesses is a mobile phone from Nokia that was left in ON condition. Ron needs to recover the IMEI number of the device to establish the identity of the device owner. Which of the following key combinations can he use to recover the IMEI number?

a)

A. #06#*

b)

B. *#06#

c)

C. #*06*#

d)

D. *IMEI#

16.

For forensic Experts, it is important to understand the Internet’s protocols so that they:

a)

A. Can write code to collect courtroom evidence.

b)

B. Can hire a professional to handle the problem.

c)

C. Understand electronic courtroom procedures.

d)

D. Understand the nature of a cyber attack.

17.

1. This refers to the unauthorized monitoring of other people's communications, such as simply looking over the shoulder of a legitimate computer user to learn his login name and password.

A. Phishing

B. Spamming

C. Spoofing

D. Eavesdropping

a)

A

b)

B

c)

C

d)

D

18.

Billy, a computer forensics expert, has recovered a large number of OST files during

forensic investigation of a laptop. Which of the following email clients he can use to analyze

the OST?

a)

A. Microsoft Outlook

b)

B. Microsoft Outlook Express

c)

C. Mozilla Thunderbird

d)

D. Eudora

19.

When a forensic investigator is seizing a running computer for examination, he can retrieve data from the computer directly via its normal interface if the evidence needed exists only in the form of volatile data.

a)

A. True

b)

B. False

20.

If a fraud examiner was gathering information about a fraud suspect, which of the following types of information would likely require access to nonpublic sources of information to obtain?

a)

A. The subject's phone history records,

b)

B. The subject's habits and lifestyle,

c)

C. Where the subject currently resides,

d)

D. All of the above

21.

When shutting down a computer what information is typically lost?

a)

Data in a RAM memory

b)

Running Processes

c)

Current Network connections

d)

All of the above

22.

The volatile memory of the computer is known as

a)

Binary Input Output System (BIOS)

b)

Random Access Memory (RAM)

c)

Read Only Memory (ROM)

d)

Central Processing Unit (CPU)

23.

Physical address of a computer is known as

a)

MAC address

b)

IP address

c)

Network Interface Card

d)

Address Resolution Protocol

24.

In a digital forensics investigation,______________ describes the route that evidence takes from the time you find it until the case is closed or goes to court.

a)

Rules of evidence

b)

Law of probability

c)

Chain of custody

d)

Policy of separation

25.

The first responder toolkit essentially consists of the following items:

a)

Storage media & Software

b)

Package & transportation

c)

Miscellaneous items like gloves, evidence stickers etc.

d)

All of the above

26.

What is the most significant legal issue in computer forensics?

a)

Preserving Evidence

b)

Seizing Evidence

c)

Admissibility of Evidence

d)

Discovery of Evidence

27.

Which of following is not a rule of digital forensics?

a)

An examination should be performed on the original data

b)

A copy is made onto forensically sterile media. New media should always be used if available

c)

The copy of the evidence must be an exact, bit-by-bit copy

d)

The examination must be conducted in such a way as to prevent any modification of theevidence

28.

Using what, data hiding in encrypted images be carried out in digital forensics?

a)

Acquisition

b)

Stenography

c)

Live analysis

d)

Hashing

29.

Analysis should use ____________________ to avoid introduction of data from some other source

a)

clean storage media

b)

write-blocker

c)

both a & b

d)

none of these

30.

……………………… is the science of extracting forensic information from digital storage media like Hard disk, USB devices, Fire wire devices, CD, DVD, Flash drives etc

a)

Network Forensics

b)

Computer Forensics

c)

Live Forensics

d)

Disk Forensics

31.
What is the primary objective of the forensic investigation process?
a)
To repair damaged systems.
b)
To prevent future cyberattacks.
c)
To identify, collect, and preserve digital evidence.
d)
To assess financial losses due to cybercrimes.
32.
During the pre-investigation phase, what is the key task for a Computer Hacking Forensic Investigator (CHFI)?
a)
Conducting forensic analysis.
b)
Preparing a forensic report.
c)
Gathering initial information and assessing the case.
d)
Interrogating suspects.
33.
What is the primary goal of the "First Response" phase in digital forensics?
a)
To conduct a detailed analysis of evidence.
b)
To secure and preserve the crime scene and evidence.
c)
To generate forensic reports for legal proceedings.
d)
To recover deleted files from the suspect's device.
34.
What is the primary focus of the "Investigation" phase in digital forensics?
a)
Restoring the system to its original state.
b)
Identifying potential suspects.
c)
Analyzing collected evidence and drawing conclusions.
d)
Documenting the investigation process.
35.
What is a crucial task during the post-investigation phase?
a)
Arresting the suspects.
b)
Sharing findings with the media.
c)
Preparing a final forensic report.
d)
Gathering more initial information.
36.
In the context of the forensic investigation process, what does "chain of custody" refer to?
a)
A chronological order of events.
b)
The process of securing the crime scene.
c)
The documentation and tracking of evidence.
d)
A network security protocol.
37.
During the pre-investigation phase, what is the importance of creating an incident response policy?
a)
It ensures legal prosecution of suspects.
b)
It establishes guidelines for handling cyber incidents.
c)
It recovers lost data.
d)
It repairs damaged systems.
38.
What is the primary purpose of the "First Response" phase?
a)
To secure and preserve evidence.
b)
To identify potential suspects.
c)
To assess financial losses.
d)
To analyze collected data.
39.
What is the main responsibility of a forensic investigator during the "Investigation" phase?
a)
Recovering lost data.
b)
Interrogating suspects.
c)
Preparing a budget for the investigation.
d)
Analyzing collected evidence.
40.
What is the primary goal of the "Post-investigation" phase?
a)
Preparing a final forensic report.
b)
Gathering initial information.
c)
Continuing the investigation process.
d)
Identifying potential vulnerabilities.
41.
What is the primary purpose of conducting a forensic analysis during the "Investigation" phase in digital forensics?
a)
To secure and preserve evidence.
b)
To recover lost data.
c)
To identify potential suspects.
d)
To extract valuable information from collected evidence.
42.
Why is it essential for a forensic investigator to maintain a well-documented chain of custody during the investigation phase?
a)
To determine the scope of the incident.
b)
To track the location and handling of evidence to ensure its integrity.
c)
To establish a timeline of events.
d)
To identify potential vulnerabilities in the system.
43.
During the investigation phase, what is the primary goal of forensic imaging?
a)
To create a mirror image of the suspect's hard drive.
b)
To recover deleted files.
c)
To analyze network traffic.
d)
To encrypt sensitive data.
44.
In the context of the investigation phase, what is the significance of data carving?
a)
It involves searching for clues at the crime scene.
b)
It is the process of extracting data fragments from unallocated space.
c)
It focuses on analyzing log files.
d)
It refers to the recovery of lost passwords.
45.
During the pre-investigation phase, why is it essential to establish a clear chain of custody for evidence?
a)
To track the location and handling of evidence to ensure its integrity.
b)
To determine the scope of the incident.
c)
To secure the crime scene.
d)
To identify potential suspects.
46.
Why is careful planning essential when conducting a search and seizure in a digital forensics investigation?
a)
To ensure that the evidence is collected legally and in compliance with established procedures.
b)
To increase the chances of capturing cybercriminals in the act.
c)
To minimize the collection of digital evidence.
d)
To expedite the investigation process and save time and resources.
47.
Why is it important to document a crime scene in digital forensics through techniques such as photography and sketching?
a)
To record the scene for media coverage.
b)
To establish the motive behind the crime
c)
To create artistic representations of the crime scene.
d)
To preserve a visual record of the scene and the relative placement of evidence.
48.
When encountering a powered-off computer as part of a digital forensics investigation, what is the first step an investigator should take to ensure proper evidence handling?
a)
Attempt to turn on the computer to assess its contents.
b)
Immediately disconnect it from any power source to preserve evidence.
c)
ake a photograph of the computer and its surrounding environment.
d)
Begin the forensic analysis of the computer's hard drive.
49.
During which phase of a computer investigation are forensic imaging and evidence collection typically conducted, and what is the primary goal of this phase?
a)
Identification phase; to secure and preserve the crime scene.
b)
Analysis phase; to extract valuable information from collected evidence.
c)
Recovery phase; to recover lost data files.
d)
First Response phase; to document the incident and identify potential suspects.
50.
Dlm suatu kolam trdpat 12 ekor ikan. Suatu hari 5 ikan dimakan bangau, 3 tnggelam, dan 1 dimakan kucing. Berapa sisanya?
a)
Enam
b)
Tujuh
c)
Delapan
d)
Sebelas
51.

Recycle Bin ada sebagai metafora untuk membuang file, tetapi juga memungkinkan pengguna untuk mengambil dan memulihkan file. Setelah file dipindahkan ke Recycle Bin, sebuah catatan akan ditambahkan ke file log yang ada di Recycle Bin. Manakah dari file berikut ini yang berisi catatan yang sesuai dengan setiap file yang dihapus di Recycle Bin?

a)

INFO2

b)
LOGINFO1
c)
L0GINF02
d)
INFO 1
52.

Amber, a black hat hacker, has embedded a malware into a small enticing advertisement and posted it on a popular ad-network that displays across various websites. What is she doing?

Compromising a legitimate site 1

Spearphishmg

Click-jacking

Malvertislng

a)
Click-jacking
b)
Spearphishing
c)
Compromising a legitimate site
d)
Malvertising
53.

Which of the following methods of mobile device data acquisition captures ail the data present on the device, as weli as all deleted data and access to unallocated space?

a)
Physical acquisition
b)
Logical acquisition
c)
Manual acquisition
d)
Direct acquisition
54.

An EC2 instance storing critical data of a company got infected with malware. The forensics team took the EBS volume snapshot of the affected instance to perform further analysis and collected other data of evidentiary value. What should be their next step?

a)
They should terminate the instance after taking necessary backup
b)
They should keep the instance running as it stores critical data
c)
They should pause the running instance
d)
They should terminate all instances connected via the same VPC
55.

Which of the following are small pieces of data sent from a website and stored on the user’s computer by the user's web browser to track,validate, and maintain specific user information?

a)
Web Browser Cache
b)
Cookies
c)
Temporary Files
d)
Open files
56.

POP3 is an Internet protocol used to retrieve emails from a mail server. Through which port does an email client connect with a POP3 server?

a)
25
b)
993
c)
110
d)
143
57.

To which phase of the computer forensics investigation process does "planning and budgeting of a forensics lab" belong?

a)
Reporting phase
b)
Investigation phase
c)
Post-Investigation phase
d)
Pre-investigation phase
58.

................ allows a forensic investigator to identify the missing links during investigation,

a)
Evidence preservation
b)
Exhibit numbering
c)
Chain of custody
d)
Evidence reconstruction
59.

What command-line tool enables forensic investigator to establish communication between an Android device and a forensic workstation in order to perform data acquisition from the device?

a)
APK Analyzer
b)
SDK Manager
c)
Xcode
d)
Android Debug Bridge
60.

Which ISO standard enables laboratories to demonstrate that they comply with quality assurance and provide valid results?

a)
ISO/IEC 17025
b)
ISO/lEC 18025
c)
ISO/IEC I9025
d)
ISO/IEC 16025
61.

Sally accessed the computer system that holds trade secrets of the company where she is employed. She knows she accessed it without authorization and all access (authorized and unauthorized) to this computer is monitored.To cover her tracks. Sally deleted the log entries on this computer. What among the following best describes her action?

a)
Password sniffing
b)
Brute-force attack
c)
Anti-forensics
d)
Network intrusion
62.

Storage location of Recycle Bin for NTFS file systems (Windows Vista and later) is located at:

a)

Drive:\ $Recyde.Bin

b)

Drive:\RECYCLER

c)

Drive:\RECYCLE.Bir .

d)

Drive:\REvCLEE

63.

in a Filesystem Hierarchy Standard (FHS), which of the following directories contains the binary files required for working?

a)
/media
b)
/sbin
c)
/proc
d)
/mnt
64.

Williamson is a forensic investigator. While investigating a case of data breach at a company, he is maintaining a document that records derails such as the forensic processes applied on the collected evidence, particulars of people handling it, the dates and times when it is being handled, and the place of storage of the evidence. What do you call this document?

a)
Consent
b)
Chain of form custody
c)
Log book
d)
Authorization form
65.

ISO/IEC 17025 is an accreditation for which of the following:

a)
Chain of custody
b)
CHFi issuing agency
c)
Encryption
d)
Forensics lab licensing
66.

Derrick, a forensic specialist, was investigating an active computer that was executing various processes. Derrick wanted to check whether this system was used in an incident that occurred earlier. He started inspecting and gathering the contents of RAM, cache, and DLLs to identify incident signatures, identify the data acquisition method employed by Derrick in the above scenario.

a)
Dead data acquisition
b)
Live data acquisition
c)
Non-volatile data acquisition
d)
Static data acquisition
67.

To understand the impact of a malicious program after the booting process and to collect recent information from the disk partition, an investigator should evaluate the content of the:

a)
BIOS
b)
UEFI
c)
GRUB
d)
MBR
68.

Which command can provide investigators with details of all the loaded modules on a Linux-based system?

a)
plist mod -a
b)
list modules -a
c)
Isof -m
d)
Ismod
69.

The working of the Tor browser is based on which of the following concepts?

a)
Both static and default routing
b)
Static routing
c)
Default routing
d)
Onion routing
70.

An investigator is examining a file to identify any potentially malicious content. To avoid code execution and still be able to uncover hidden indicators of compromise (IOC ), which type of examination should the investigator perform:

a)
Dynamic analysis
b)
Static analysis
c)
Threat hunting
d)
Threat analysis
71.

Forensic Science is

a)

microscopes used for vapor

b)

the applications of testing

c)

applying principles of science to the law

d)

the application of evidence to testing

72.

DNA is

a)

deoxygenated acid

b)

deoxyribnucleic acid

c)

deoxetrate acid

d)

deoxyrib antacid

73.

Identical twins have identical fingerprints.

a)

True

b)

False

74.

Chromatography is

a)

a laboratory test used to identify particular substances

b)

a photographic process

c)

a mapping technique

d)

used to identify shoe size

75.

A suspect is

a)

a person claiming innocence

b)

someone with beady eyes

c)

someone who is thought to have possibly committed the crime

d)

a person who has a solid alibi

76.

A medical examiner determines the cause of death through autopsy.

a)

True

b)

False

77.

Fingerprints can be lifted from carpeting.

a)

True

b)

False

78.

Loops, whorls and arches are used to describe

a)

hair evidence

b)

DNA

c)

fingerprints

d)

handwriting evidence

79.

All evidence gathered at a crime scene must be

a)

labeled and documented

b)

analyzed in a scientific manner

c)

handled carefully so not to contaminate the specimen

d)

all of the above

80.

The first job of a police officer is to

a)

take photographs

b)

secure the area with crime scene tape

c)

make sure the scene is safe

d)

gather evidence

81.

A person harmed, injured, or killed as a result of a crime

a)

officer

b)

victim

c)

out of luck

d)

suspect

82.

What pattern of fingerprint is shown?

a)

Loop

b)

Arch

c)

Whorl

83.

What pattern of the fingerprint is shown?

a)

arch

b)

whorl

c)

loop

d)

none of these

84.

Identify the fingerprint pattern shown.

a)

loop

b)

arch

c)

whorl

85.

What are fingerprints used for?

a)

determine eye color

b)

Identification

c)

To help you fight crime.

86.
The technique by which DNA fragments are placed in a gel and charged with electricity is referred to as?
a)
DNA profiling 
b)
DNA electrophoresis 
c)
DNA typing 
d)
DNA Fragmenting 
87.

Of the following, select all the things which can be probable evidence from the crime scene.

a)

Tyre impressions

b)

Soil from crime scene

c)

Teeth impressions

d)

Fiber particles

88.

The adjoining figure depicts which analysis technique?

a)

Gel electrophoresis

b)

Polymerase chain reaction

c)

Paper chromatography

d)

Soil pH analysis using indicators

89.

The adjoining figure shows apparatus set-up of which analysis technique?

a)

Gel electrophoresis

b)

Polymerase chain reaction

c)

Paper chromatography

d)

Soil analysis using pH indicators

90.

Direct Evidence includes all but the following...

a)

blood left at the scene

b)

eye witness

c)

victim's testimony

d)

suspect's alibi

91.

What is computer forensics?

a)

It is an attempt to expose, alter, destabilize, destroy, remove to gain unauthorized access or use an asset.

b)

It is the discipline that combines the elements of law and computer science to collect and analyze data from computer Systems, network, Wireless communications and storage devices in a way that is admisible as evidence in a court of law.

92.

What are the examples of latent data? choose 3.

a)

Belkasoft Live RAM capturer

b)

Information that is in the computer's storage but is not easily mentioned in the file allocation tables.

c)

Data that has been deliberately removed.

d)

Information that the operating System or commonly used software Application cannot easily see.

93.

1. A _______ has occurred, collecting all relevant evidence is of the utmost importance in answering the questions described above.

a)

file headers.

b)

forensic investigator.

c)

cyber attack.

94.

What are the main types of computer forensics?

a)

Of operating Systems

b)

Of security

c)

Of network.

d)

On the cloud.

e)

On Mobile devices

95.

It is the process of retrieving useful Information from the computer or mobile device in questions.

a)

Of network

b)

On the cloud

c)

Of operating Systems

96.

It aims to retrieve digital evidence or relevant data from a mobile device in a way that preserves the evidence in a sound forensic condition.

a)

On the cloud

b)

Of operating Systems

c)

On mobile devices

97.

It refers to the collection, monitoring, and analysis of network activities to discover the source of attacks, viruses, intrusions, or security breaches that occur On a network or in network traffic.

a)

On the cloud

b)

On mobile devices

c)

Of operating Systems

d)

Of network

98.

Refers to any technique, device or software designed to hinder a computer investigation.

a)

Anti-forensic computing.

b)

Encryption.

c)

File headers.

99.

Focuses primarily On gathering digital forensic Information from a cloud infrastructure.

a)

On mobile devices.

b)

On the cloud.

c)

FTK Imager

100.

You use a complex set of rules called an algorithm to make data unreadable.

a)

Encryption

b)

Metadata

c)

Computer forensic analysis

101.

Is a data and image preview tool that allows you to browse files and folders on local hard drives, network drives, CD / DVD and review the content of forensic images or memory dumps.

a)

FTK Imager

b)

Volatility

c)

HashCalc

102.

Es un programa de calculadora desarrollado por SlavaSoft

a)

HashCalc

b)

Belkasoft Live RAM capturer

c)

Volatility

103.

For volatile memory analysis there are several tools such as:

a)

Volatility

b)

Belkasoft Live RAM capturer

c)

HashCalc

104.

It must be accurate, comprehensive, unbiased, recorded, repeatable, and completed within the available time frames and allocated resources.

a)

Computer forensic analysis

b)

The computer expert

c)

Volatility

105.

It is used behind the scenes in Autopsy and in many other commercial and open source forensic tools.

a)

Encase Forensics

b)

Sleuth kit

c)

SIFT Workstation 3

106.

Quickly search, identify and prioritize potential evidence, on computers and mobile devices, to determine if further investigation is warranted.

a)

Encase Forensics

b)

Digital forensics

c)

safety

d)

Forensics v6

107.

It is a group of open source free incident response and forensic tools designed to perform detailed digital forensic examinations in a variety of environments.

a)

Access Data Registry Viewer.

b)

SIFT Workstation 3

c)

Sleuthkit

108.

Provides one of the fastest and most powerful ways to locate files On a Windows computer. You can search by file Name, size, creation and modification dates, and other criteria

a)

OsForensics v6

b)

SIFT Workstation 3

c)

Forense digital

109.

Reveal when a document first appeared On a computer, when it was last edited, when it was last saved or printed, and which user performed these actions.

a)

Defense in depth

b)

Safety

c)

Computer forensic examination

110.

The implementation of this type of security model in which the principles of computer forensics are also adopted is also known as:

a)

Defense in depth

b)

Safety

c)

Criminology

d)

Vulnerability and testing

111.

What does Digital Forensics mean?

a)

Applying computer scientific tests or techniques to help solve a crime

b)

Is a legal order issued by the Courts that allows officers to arrest someone

c)

When someone enters a building with the intent to steal something or commit a crime

d)

Analysing and examining clothes, blood, hair, footprints or marks left by tools or weapons.

112.
The Computer Misuse Act 1990 makes it an offence to plant or transfer viruses
a)
True
b)
False
113.
The Regulation of Investigatory Powers Act 2000, allows organisations to access digital communication, ISPs, Businesses and individual communications and storage
a)
True
b)
False
114.
Why was the Computer Misuse Act of 1990 introduced?
a)
To help protect computer software
b)
To help protect computer hardware
c)
To stop the spread of computer viruses
d)
To stop people from accessing unauthorised information. 
115.

What does RIPA stand for?

a)

Regulation of Investigatory Powers Act

b)

Regulation of Information Powers Act

c)

Recovery of Investigatory Powers Act

d)

Recovery of Information Powers Act

116.

The most relevant part of the Human Rights Act in relation to Digital Forensics is...

a)

The right to privacy

b)

Freedom of thought, conscience and religion

c)

Freedom of expression

d)

The right to life

117.

It is the responsibility of who to supervise the execution of a warrant and the security of the site and potential evidence.

a)

Lead investigator

b)

First officer on scene

c)

Highest ranking officer within the district

d)

All people who enter the crime scene

118.

Where possible, the original contents of a device are copied and preserved, leaving the original data untouched.

The tool that does this is called...

a)

Write Blocker

b)

Copy Machine

c)

Universal Serial Bus

d)

WinZip

119.

Forensic readiness means that the company or organisation has built-in the ability to collect, preserve, protect and analyse any potential digital evidence from their computers

a)

True

b)

False

120.

An investigation can only be carried out when ....

a)

there is a suspicion that a crime has been committed.

b)

a person has a criminal history

c)

a witness to an incident owns a mobile device

d)

when working within a 'high security' company

121.

At which stage of the digital forensics process would a write-blocker be used?

a)

Acquisition

b)

Reporting

c)

Verification

d)

Analysis

122.

Which three of the following statement s describes forensic readiness?

a)

How prepared a digital forensic investigator is to present their evidence in a court of law

b)

How easy it is for the digital forensic investigator to find evidence which proves that someone is guilty

c)

A machine which has been imaged for the forensic purposes

d)

How prepared an organisation is to respond to an incident

123.

Which three of the following are benefits of forensic readiness?

a)

Forensic readiness reduces the costs of a digital forensic investigation.

b)

Forensic readiness makes it easier for organisations to gather evidence.

c)

Forensic readiness ensures that as much evidence as possible is available.

d)

Forensic readiness makes it harder for a malicious hacker to access a network

124.

Which one of the following acts states that individuals have a right to respect for the privacy of their e-mails

a)

Copyright, Designs and Patents Act

b)

Criminal Justice and Police Act

c)

Human Rights Act

d)

Computer Misuse Act

125.
An example of Digital Forensics is
a)
 suspect's email
b)
suspect's cell phone records
c)
suspect's computer
d)
all of the above
126.

Which one of the following acts states that individuals have a right to respect for the privacy of their e-mails

a)

Copyright, Designs and Patents Act

b)

Criminal Justice and Police Act

c)

Human Rights Act

d)

Computer Misuse Act

127.

Which two of the following show why it is important to conduct an investigation on a copy of the data instead of the original

a)

To allow other investigators to work on the data to speed up the investigation

b)

To allow the investigation to be replicated

c)

some tools will only work on copied data

d)

To prevent any aspect of the investigation from tampering with the original evidence

128.

At which stage of the digital forensics process would a write-blocker be used?

a)

Acquisition

b)

Reporting

c)

Verification

d)

Analysis

129.

Applying preservation techniques during data acquisition can help to identify which of the following?

a)

The name of the person who last logged in

b)

Mac Number

c)

Running programs

d)

The IP address

130.

Which two of the following software tools could be used during the analysis phase of the digital forensics process?

a)

A word processor

b)

A hex-editor

c)

A network packet analyser

d)

A file encryption tool

131.

Which three of the following statement s describes forensic readiness?

a)

How prepared a digital forensic investigator is to present their evidence in a court of law

b)

How easy it is for the digital forensic investigator to find evidence which proves that someone is guilty

c)

A machine which has been imaged for the forensic purposes

d)

How prepared an organisation is to respond to an incident

132.

Which one of the following files could be retrieved during browser forensics?

a)

index.dat

b)

history.ffx

c)

passwords.txt

d)

google.cache

133.

Which one of the following acts allows certain organisations to get access to an individuals sent and received text messages?

a)

Computer Misuse Act

b)

Criminal Justice and Police Act

c)

Copyright, Designs and Patents Act

d)

Regulation of Investigatory Powers Act

134.

Which three of the following are benefits of forensic readiness?

a)

Forensic readiness reduces the costs of a digital forensic investigation.

b)

Forensic readiness makes it easier for organisations to gather evidence.

c)

Forensic readiness ensures that as much evidence as possible is available.

d)

Forensic readiness makes it harder for a malicious hacker to access a network

135.

Which two of the following are the role of the reporting stage of the digital forensic process?

a)

The report describes the evidence which was obtained from the investigation.

b)

The report is used to work out how much money to pay the investigator.

c)

The report describes the investigation so that it can be understood by a non-technical person.

d)

The report states whether or no the accused is guilty.

136.

Which two of the following statements describing the steps in the digital forensic process are true?

a)

The steps can be completed in any order.

b)

The are laws explaining how the steps must be completed.

c)

The steps must be completed in the order of accusation, analysis and reporting.

d)

There are guidelines explaining how the steps should be completed.

137.

The image shows a screenshot of some data.

Which one of the following is where data like this can be found?

a)

Network infrastructure window

b)

My computer

c)

Recycle bin

d)

External hard drive

138.

Which of the following tools helps incident handlers to view the file system, retrieve deleted data, perform timeline analysis, web artifacts, etc., during an incident response process?

a)

Process Explore

b)

nbtstat

c)

netstat

d)

Autopsy

139.

Which of the following digital evidence temporarily stored on a digital device that requires a constant power supply and is deleted if the power supply is interrupted?

a)

Swap file

b)

Slack space

c)

Process memory

d)

Event logs

140.

Drake is an incident handler in Dark CLoud Inc. He is intended to perform log analysis in order to detect traces of malicious activities within the network infrastructure. Which of the following tools Drake must employ in order to view logs in real time and identify malware propagation within the network?

a)

HULK

b)

LOIC

c)

Hydra

d)

Splunk

141.

Eric who is an incident responder is working on developing incident-handling plans and procedures. As part of this process, he is performing analysis on the organizational network to generate a report and to develop policies based on the acquired results.

Which of the following tools will help him in analyzing network and its related traffic?

a)

Burp Suite

b)

Whois

c)

Wireshark

d)

FaceNiff

142.

Which of the following malware detection technique is employed in intrusion analysis to identify the transfer of any unwanted traffic to malicious or unknown external entities?

a)

Covert Malware Beaconing

b)

SSDT Patching

c)

Kernel Filter Drivers

d)

Covert C&C Communication

143.

Which of the following terms refers to an organization’s ability to make optimal use of digital evidence in a limited period of time and with minimal investigation costs?

a)

Data analysis

b)

Risk assessment

c)

Threat assessment

d)

Forensic readiness

144.

Alice is an incident handler and she has been informed by her lead that the data on affected systems must be backed up so that it can be retrieved if it is damaged during incident response process. She was also told that the system backup can also be used for further investigation of the incident.

In which of the following stages of the incident handling and response (IH&R) process Alice has to take the complete backup of the infected system?

a)

Containment

b)

Eradication

c)

Incident recording

d)

Incident triage

145.

Which of the following techniques prevent or mislead incident-handling process and may also affect the collection, preservation, and identification phases of the forensic investigation process?

a)

Scanning

b)

Footprinting

c)

Anti-forensics

d)

Enumeration

146.

In which of the following stages of incident handling does classification and prioritization of incidents take place?

a)

Incident Containment

b)

Incident Triage

c)

Incident Recording and Assignment

d)

Post-Incident Activities

147.

Alex is an incident handler for Tech-o-Tech Inc. and he is intended to identify any possible insider threats in his organization.

Which of the following insider threat detection techniques can be used by him to detect insider threats based on the behavior of a doubtful employee both individually and in a group?

a)

Profiling

b)

Physical detection

c)

Mole detection

d)

Behavioral analysis

148.

Employee Code:

4 lines
149.

Name of the Employee:

4 lines
150.
  1. 1. What is the primary purpose of incident reporting in healthcare?

a)

To assign blame to individuals involved

b)

To identify areas for improvement in patient care

c)

To penalize healthcare providers

d)

To avoid legal liabilities

151.
  1. 2. Which of the following incidents should be reported in healthcare?

a)

Minor errors without any patient harm

b)

Near misses

c)

Adverse events causing harm to patients

d)

All of the above

152.
  1. 3. What is the primary goal of incident reporting systems in healthcare institutions?

a)

To increase insurance premiums

b)

To create unnecessary paperwork for staff

c)

To improve patient safety and quality of care

d)

To discourage staff from reporting incidents

153.
  1. 4. What does a near miss imply in incident reporting?

a)

Incidents that do not require reporting

b)

Patient safety event that reaches the patient but does not cause harm

c)

Incidents that involve minor errors

d)

Incidents caused by patient-related factors

154.
  1. 5. When should healthcare professionals report incidents?

a)

Only during regular office hours

b)

Immediately after the incident occurs

c)

Within 48 hours after the incident

d)

At the end of the week

155.

Which of the following terms may be defined as “a measure of possible inability to achieve a goal,

objective, or target within a defined security, cost plan and technical limitations that adversely

affects the organization’s operation and revenues?

a)

Incident Respons

b)

Threat

c)

Vulnerability

d)

Risk

156.

A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single

system is targeted by a large number of infected machines over the Internet. In a DDoS attack,

attackers first infect multiple systems which are known as:

a)

Trojan

b)

Zombies

c)

Spyware

d)

Worms

157.

The goal of incident response is to handle the incident in a way that minimizes damage and reduces

recovery time and cost. Which of the following does NOT constitute a goal of incident response?

a)

Dealing properly with legal issues that may arise during incidents

b)

Helping personal to recover quickly and efficiently from security incidents, minimizing loss or theft

and disruption of services

c)

Using information gathered during incident handling to prepare for handling future incidents in a

better way and to provide stronger protection for systems and data

d)

Dealing with human resources department and various employee conflict behaviors

158.

An organization faced an information security incident where a disgruntled employee passed

sensitive access control information to a competitor. The organization’s incident response manager,

upon investigation, found that the incident must be handled within a few hours on the same day to

maintain business continuity and market competitiveness. How would you categorize such

information security incident?

a)

Middle level incident

b)

Low level incident

c)

High level incident

d)

Ultra-High level incident

159.

Business continuity is defined as the ability of an organization to continue to function even after a

disastrous event, accomplished through the deployment of redundant hardware and software, the

use of fault tolerant systems, as well as a solid backup and recovery strategy. Identify the plan which

is mandatory part of a business continuity plan?

a)

Sales and Marketing plan

b)

Forensics Procedure Plan

c)

Business Recovery Plan

d)

New business strategy plan

160.

Which of the following is an appropriate flow of the incident recovery steps?

a)

System Operation-System Restoration-System Validation-System Monitoring

b)

System Restoration-System Monitoring-System Validation-System Operations

c)

System Restoration-System Validation-System Operations-System Monitoring

d)

System Validation-System Operation-System Restoration-System Monitoring

161.

A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with

computer security incidents. Identify the procedure that is NOT part of the computer risk policy?

a)

Procedure for the ongoing training of employees authorized to access the system

b)

Procedure to identify security funds to hedge risk

c)

Procedure to monitor the efficiency of security controls

d)

Provisions for continuing support if there is an interruption in the system or if the system crashes

162.

Identify the network security incident where intended authorized users are prevented from using

system, network, or applications by flooding the network with high volume of traffic that consumes

all existing network resources.

a)

URL Manipulation

b)

XSS Attack

c)

Denial of Service Attack

d)

SQL Injection

163.

Incident handling and response steps help you to detect, identify, respond and manage an incident.

Which of the following steps focus on limiting the scope and extent of an incident?

a)

Eradication

b)

Identification

c)

Data collection

d)

Containment

164.

Policies are designed to protect the organizational resources on the network by establishingthe set rules and procedures. Which of the following policies authorizes a group of users to perform aset of actions on a set of resources

a)

Documentation policy

b)

Access control policy

c)

Logging policy

d)

Audit trail policy

165.

The data on the affected system must be backed up so that it can be retrieved if it is damagedduring incident response. The system backup can also be used for further investigations of theincident. Identify the stage of the incident response and handling process in which complete backupof the infected system is carried out

a)

Eradication

b)

Incident recording

c)

Incident investigation

d)

Containment

166.

The role that applies appropriate technology and tries to eradicate and recover from theincident is known as

a)

Incident coordinator

b)

Incident Handler

c)

Incident Analyst

d)

Incident Manager

167.

Why do we investigate and report incidents

a)

for moral reasons

b)

identifying root causes

c)

financial reasons

d)

all of the above

168.

Accident reports are considered as

a)

Leading indicator

b)

Lagging indicator

169.

the picture is an example of

a)

unsafe act

b)

unsafe condition

c)

accident

d)

nearmiss

170.

what is Hazard

a)

A potential source of harm

b)

Likelihood of harm to occur

c)

Rating of consequences

d)

Relation between severity and probability