wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Everything Computer Forensics

Total questions: 90

Worksheet time: 15mins

Name
Class
Date
1.

Windows 95 was the first OS to support this older file system?

a)

FAT32

b)

NTFS

c)

ReFS

2.

This is about obfuscating a message so that it cannot be read?

a)

Cryptography

b)

Steganography

c)

Scientology

3.

This calculation is used to calculate single loss expectency?

a)

SLE

b)

ALE

c)

NIST

4.

_______________ memory analysis is a live-system forensic technique in which you collect a memory dump and perform analysis in an isolated environment?

a)

Static

b)

Volatile

c)

System

5.

If the computer is turned on when you arrive, what does the Secret Service recommend you do?

a)

Begin investigation immediately

b)

Shut the computer down according to the recommended Secret Service procedure

c)

Transport the computer with power on

6.

Which of the following might contain data that was live in memory and not stored on the hard-drive?

a)

Swap File

b)

Registry Hive

c)

Log File

7.

What is the most important reason that you not touch the actual original evidence any more than you have to?

a)

Each time you touch digital data, there is some chance of altering it.

b)

You might be accused of planting evidence

c)

You might accidentally decrypt files

8.

The MD5 message-digest algorithm is used to _____.

a)

Hash a disk to verify that a disk is not altered when you examine it

b)

Wipe magnetic media before recycling it

c)

Make directories on an evidence drive

9.

What Linux command helps you delete or remove a file?

a)

rm

b)

cd

c)

del

10.

Which below is a technique for file system repair that involves recovering data from a damaged partition with limited knowledge of the file system?

a)

Zero-knowledge analysis

b)

Point-Blank analysis

c)

low-level analysis

11.

Spyware is legal?

a)

True

b)

False

12.

Business Continuity Plan development depends most on:

a)

the Business Impact Analysis (BIA)

b)

scope and plan initiation

c)

directives from senior management

13.

What is the primary reason to take cyberstalking seriously?

a)

It can be a prelude to real-world violence.

b)

It can damage your system

c)

In can be annoying and distracting

14.

Encrypting files/folders would be an example of:

a)

cryptography

b)

steganography

c)

scientology

15.

Which of the following drives would be least susceptible to damage when dropped?

a)

SCSI

b)

SSD

c)

SATA

16.

Which log file contains failed user logins?

a)

/var/log/kern.log

b)

/var/log/faillog

c)

/var/log/lpr.log

17.

What is the essence of the Daubert standard?

a)

The only tools or techniques that have been accepted by the scientific community are admissible in trial

b)

Only experts can testify at a trial

c)

The Chain of Custody can be broken in criminal investigations

18.

What file system does Windows 10 use?

a)

FAT32

b)

NTFS

c)

HPFS

19.

RAID-____ is known as a MIRROR and is essentially two-hard drives with one being an identical copy of the other.

a)

0

b)

1

c)

5

20.

What Linux command can be used to wipe a target drive?

a)

Del

b)

nc

c)

dd

21.

Evidence need not be locked if it is at a police station.

a)

True

b)

False

22.

Which backup will backup all changes?

a)

Full

b)

Differential

c)

Incremental

23.

In Windows 10, the swap file ends with what extension?

a)

.sys

b)

.swap

c)

.dir

24.

Many forensic tools and software have the option to do a forensic wipe for you. This Linux command can also do that:

a)

.del

b)

dd

c)

format_wipe

25.

Which of the following is the Linux equivalent of a shortcut?

a)

Hard Link

b)

Symbolic Link

c)

Partial Link

26.

Once a incident has been detected, you should then:

a)

Eradicate it

b)

Contain it

c)

Detect it a second time

27.

Which of the following focuses on keeping the organization functioning as well as possible until a full recovery can be made?

a)

Business Continuity Plan

b)

Business Recovery Plan

c)

Disaster Recovery Plan

28.

ReFS is the newest file system for Windows. What has been the popular file system used by Windows for the last 10-20 years?

a)

HFS+

b)

FAT32

c)

NTFS

29.

What file system does MAC OS use?

a)

EXT3

b)

HFS+

c)

NTFS

30.

What type of attack results from an attacker sending specially crafted packets to a web server that cause it to crash?

a)

DoS

b)

Malware

c)

MITM

31.

Once an intrusion into your organizations information system has been detected, which of the following actions should be performed first?

a)

Eliminate all means of intruder access

b)

Contain the intrusion

c)

Determine to what extent systems and data are compromised

32.

Which is a common method for scoring system vulnerabilities?

a)

SLE

b)

CVSS

c)

NIST

33.

It is legal for employers to monitor work computers?

a)

True

b)

False

34.

Which of the following focuses on sustaining an organizations business functions during and after a disruption?

a)

Business Continuity Plan

b)

Business Recovery Plan

c)

Disaster Recovery Plan

35.

Damage to how data is stored, such as file system corruption, is known as:

a)

Physical Damage

b)

Logical Damage

c)

Stricking Damage

36.

Your roommate can give consent to search your computer.

a)

True

b)

False

c)

Maybe

37.

Which backup will backup all changes since last full backup?

a)

Full

b)

Differential

c)

Incremental

38.

What is the most commonly used hashing algorithm?

a)

SHA1

b)

MD5

c)

Whirlpool

39.

Which of the following is an asymmetric cryptography algorithm invented by 3 mathematicians in the 1970s?

a)

DES

b)

AES

c)

RSA

40.

Deep Sound is a tool that allows you to:

a)

encrypt files, hard-drives and volumes

b)

hide files in mp3, wav, cda and other file formats

c)

wipe a hard-drive completely clean

41.

Logic bombs are often perpetrated by:

a)

Terrorists

b)

Hackers

c)

Disgruntled employees

42.

Using "science and technology to investigate and establish facts in criminal or civil courts of law" is called:

a)

Forensics

b)

Accounting

c)

Hardening

43.

Why can you undelete files in Windows 7?

a)

Nothing is deleted; it is just removed from MFT

b)

Fragments might exist; even though the file is deleted

c)

You cannot

44.

What Windows Log is most-likely the most important log from a forensics point of view?

a)

Application log

b)

System log

c)

Security log

45.

The art and science of writing hidden messages is known as:

a)

cryptography

b)

steganography

c)

scientology

46.

Which of the following is an asymmetric cryptography algorithm invented by 3 mathematicians in the 1970s?

a)

NSA

b)

RSA

c)

AES

47.

What type of encryption uses a different key to encrypt the message than it uses to decrypt the message?

a)

Asymmetric

b)

Symmetric

c)

Private-Key

48.

Where would you seek evidence that ophcrack had been used on a Windows Server 2008 machine?

a)

In the logs of the server; look for the reboot of the system

b)

In the logs of the server; look for the loading of a CD

c)

in the firewall logs

49.

When cataloging digital evidence, the primary goal is to do what?

a)

Keep evidence in one location and not allow it to be removed from premises

b)

Preserve evidence integrity

c)

Keep the computer from being turned off

50.

_____________ is commonly used name for a command-line utility that provides disk partitiioning functions in an operating system?

a)

format

b)

fdisk

c)

parted

51.

In a computer forensics investigation, describe the route that evidence takes from the time you find it until the case is closed or goes to court.

a)

Policy of Journey

b)

Chain of custody

c)

Least Principle

52.

Why should you note all cable connections for a computer you want to seize as evidence?

a)

It’s just a standard

b)

To know what peripheral devices were there

c)

in case other devices were connected

53.

When a Windows system books, the BIOS helps perform a:

a)

BIOS start

b)

POST

c)

MITM

54.

_________________________is a process used in computer forensics to extract data from a drive without the assistance of the file system; perhaps because the file has become corrupted?

a)

file extraction

b)

file carving

c)

file restoration

55.

Which backup will backup all change since last backup of any type”

a)

Full

b)

Differential

c)

Incremental

56.

What Linux command lists the contents of the current directory?

a)

ls

b)

dir

c)

mkdir

57.

Which of the following crimes is most likely to leave email evidence?

a)

Cyberstalking

b)

DoS

c)

Fraud

58.

This is an attempt to trick a victim into giving up personal information?

a)

Trust

b)

Phishing

c)

Ransomware

59.

RAID-____ combines three or more disks in a way that protects data against the loss of any one disk.

a)

0

b)

1

c)

5

60.

What is the most commonly used file system with Linux?

a)

NTFS

b)

Ext

c)

ReFS

61.

The use of analytical and investigative techniques to identify, collect, examine and preserve evidence is called:

a)

Computer Forensics

b)

Network Accounting

c)

System Oversight

62.

This is the primary standard for Contingency Planning Guide for Information Technology System?

a)

ISO 27001

b)

NIST 800-34

c)

NFPA 1600

63.

What is the purpose of hashing a copy of a suspect drive?

a)

To make it secure

b)

To remove viruses

c)

To check for changes

64.

In steganography, the _________________ is the data to be covertly communicated. In other words, it is the message you want to hide.

a)

Payload

b)

Carrier

c)

Signal

65.

What is the starting point for investigating denial of service attacks?

a)

Firewall Logs

b)

System Logs

c)

Tracing the Packets

66.

What kind of attack results from an attacker sending specially crafted packets to a web server to cause it to crash?

a)

MITM Attack

b)

DoS Attack

c)

Cross-over Attack

67.

This holds passwords with precalculated hashses of all password?

a)

Rainbow Table

b)

System Table

c)

Hash Table

68.

It takes _____ occurrence(s) of overextending yourself during testimony to ruin your reputation.

a)

only one

b)

several

c)

at least two

69.

How many HIVES are in the Windows Registry?

a)

1

b)

5

c)

11

70.

What assesses potential loss that could be caused by a disaster?

a)

Business Assessment (BA)

b)

Business Impact Analysis (BIA)

c)

Business Continuity Plan (BCP)

71.

What Linux command can be used to create a hash?

a)

SHA

b)

MD5sum

c)

MD5

72.

When investigating a virus, what is the first step?

a)

Check firewall logs

b)

Document the Virus

c)

Trace the origin of Virus

73.

What do you call a list of people who have had physical possession of the evidence?

a)

Affidavit

b)

Chain of custody

c)

Evidence Team List

74.

Hiding messages inside another medium is referred to as:

a)

cryptography

b)

steganography

c)

cryptology

75.

Which port below is associated with HTTPS?

a)

25

b)

443

c)

3389

76.

Which type of attack involves an attackers sending a large amount of ICMP packets to a target in hopes to overwhelm it?

a)

Ping Flood (DDos)

b)

Teardrop Attack

c)

Spoof Flood

77.

The synchronization bits in the TCP header can yield important information. Which below is a flag use to Reset a connection?

a)

URG

b)

ACK

c)

RST

78.

The Private Class B IP Range is:

a)

150 - 160.x.x.x

b)

172.16.0.0 - 172.31.255.255

c)

Anything 170.x.x.x through 171.x.x.x

79.

The synchronization bits in the TCP header can yeild important information. Which flag generally indicates the communication is ended?

a)

URG

b)

FIN

c)

RST

80.

Which port below is associated with DNS?

a)

25

b)

53

c)

69

81.

What TYPE of firewall is most likely to prevent SYN Floods, where an attacker sends unlimited SYNchronize requests to a host system?

a)

Packet Filtering

b)

Stateful Packet Inspection

c)

Dynamic

82.

When using Volatility, this command can examine the registry and is probably the one most useful in examining DLL injection?

a)

printkey

b)

volatilescan

c)

onescan

83.

Which malware below is software that appears to have some legitimate purpose, but when executied a second payload of malware is delivered instead?

a)

Logic Bomb

b)

Worm

c)

Trojan Horse

84.

This command is very command and is used to list details of all services that were in memory when a memory dump is taken?

a)

svcscan

b)

servscan

c)

sfcscan

85.

Which GUI program has a graphical user interface for Volatility and includes a Volatilty Workbench?

a)

DumpFall.exe

b)

OSForensics

c)

ProDiscover-Gold

86.

This table is a data structure that maps virtual addresses to physical addresses?

a)

Heap

b)

Page

c)

Stack

87.

The _____________ is memory that programs can allocate as needed; it is not the organized automatically allocated memory area?

a)

stack

b)

MDR

c)

Heap

88.

Which cloud technology applies to renting/using an entire network infrastructure that is virtulatized online?

a)

IaaS

b)

PaaS

c)

SaaS

89.

Which cloud technology applies to the ability to access software as a service on demand through the cloud?

a)

IaaS

b)

PaaS

c)

SaaS

90.

Which cloud technology applies to providing individual operating systems as a service so they can create programs and develop code?

a)

IaaS

b)

PaaS

c)

SaaS