wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Data Acquisition Quiz

Total questions: 41

Worksheet time: 21mins

Name
Class
Date
1.

In digital forensics, data acquisition refers to:

a)

Editing digital evidence for better clarity

b)

Copying data from electronic media for investigation

c)

Encrypting and storing forensic data

d)

Deleting unused data from storage devices

2.

Which of the following is not a type of data acquisition mentioned?

a)

Static acquisition

b)

Live acquisition

c)

Hybrid acquisition

d)

Both A and B are mentioned

3.

Static acquisitions capture data that:

a)

Changes frequently while being collected

b)

Is not accessed or altered by other processes

c)

Exists only in RAM memory

d)

Is encrypted during the acquisition process

4.

Why are live acquisitions becoming more common in newer operating systems?

a)

Because they are faster

b)

Due to increased use of whole disk encryption

c)

Because static acquisitions are no longer possible

d)

Live acquisitions require less training

5.

One disadvantage of live acquisition is that:

a)

It cannot collect RAM data

b)

Metadata such as date and time values may change during acquisition

c)

It does not work on encrypted drives

d)

It alters the original media permanently

6.

Making a second live acquisition while a computer is running will:

a)

Collect the exact same data

b)

Collect new data due to OS changes

c)

Fail due to encryption

d)

Be identical to static acquisition

7.

The primary goal of static acquisition is:

a)

Encrypt the data for security

b)

Preserve digital evidence reliably

c)

Compress the data for storage

d)

Modify evidence for presentation

8.

Why learn multiple acquisition tools?

a)

To reduce costs

b)

Because some tools may fail during acquisition

c)

To make data harder to recover

d)

To speed up investigation

9.

The older open-source disk-to-image format is:

a)

AFF

b)

E01

c)

Raw

d)

FAT

10.

An advantage of raw format is:

a)

Requires less storage

b)

Can ignore minor read errors

c)

Cannot be read by most tools

d)

Always compresses automatically

11.

A disadvantage of raw format is:

a)

Incompatible with Linux tools

b)

Requires storage equal to original disk size

c)

Cannot do bit-by-bit copying

d)

Has a 650 MB limit

12.

Which hashing functions are used for validating raw acquisitions?

a)

CRC32, MD5, SHA-1

b)

AES, SHA-2, RSA

c)

SHA-256, Blowfish, CRC16

d)

MD5, DES, SHA-512

13.

Proprietary formats may include all except:

a)

Image compression options

b)

Metadata integration

c)

Image splitting into segments

d)

Unlimited cross-vendor compatibility

14.

Developer of Advanced Forensic Format (AFF):

a)

Guidance Software team

b)

Dr. Simson L. Garfinkel

c)

Microsoft Security Division

d)

Basis Technology Engineers

15.

Which is not a design goal of AFF?

a)

No size restriction for disk-to-image files

b)

Internal consistency checks

c)

Vendor-specific implementation restrictions

d)

Extensibility

16.

In AFF, .afm is used for:

a)

Segmented image files

b)

Metadata

c)

Compressed volumes only

d)

FAT partition maps

17.

Preferred acquisition type for digital evidence:

a)

Live acquisition

b)

Static acquisition

c)

Logical acquisition

d)

Sparse acquisition

18.

Live acquisition is performed when:

a)

Computer is off

b)

Drive is not encrypted

c)

Encrypted drive is accessible while powered on/logged in

d)

Drive is damaged

19.

Which is not one of the four data collection methods?

a)

Disk-to-image file

b)

Disk-to-disk copy

c)

Logical disk-to-data file

d)

Cloud-to-cloud copy

20.

Most common method offering flexibility:

a)

Sparse acquisition

b)

Logical acquisition

c)

Disk-to-image file

d)

Disk-to-disk copy

21.

Method capturing only specific files:

a)

Static acquisition

b)

Logical acquisition

c)

Disk-to-disk copy

d)

Lossless compression

22.

Sparse acquisition also collects:

a)

All files on the drive

b)

Fragments of unallocated data

c)

Compressed image only

d)

File system metadata

23.

Preferred method in e-discovery for large storage systems:

a)

Logical acquisition

b)

Sparse acquisition

c)

Live acquisition

d)

Static acquisition

24.

Lossy compression is avoided because:

a)

It is slow

b)

It alters original data

c)

Not compatible with MD5

d)

Requires expensive tools

25.

Lossless compression can reduce size by up to:

a)

25%

b)

50%

c)

75%

d)

90%

26.

If drive contains many zip files, compression:

a)

Greatly reduces size

b)

Has little effect

c)

Damages files

d)

Converts them to lossy format

27.

To verify lossless compression integrity:

a)

Count files

b)

Use MD5 and SHA-1 before and after

c)

Open in WinZip

d)

Compare file sizes only

28.

Which is not a concern when acquiring RAID data?

a)

Type of RAID

b)

Storage needed

c)

OS FAT32 support

d)

Capability of acquisition tool

29.

Older RAID 1 sometimes required:

a)

One drive connected

b)

Both drives connected

c)

Conversion to RAID 0

d)

Lossy compression

30.

Proprietary format with compression on RAID data:

a)

Increases storage

b)

Reduces storage

c)

Makes data unreadable

d)

Removes need for RAID knowledge

31.

Tools supporting RAID acquisition:

a)

EnCase

b)

X-Ways Forensics

c)

FTK

d)

All of the above

32.

Tool copying RAID to raw file for restoration:

a)

R-Studio

b)

RAID Reconstructor

c)

EnCase

d)

FTK

33.

When dealing with large RAID servers, you should:

a)

Break array into single drives

b)

Consult vendor for best capture method

c)

Use JPEG compression

d)

Convert to proprietary format only

34.

Remote acquisition tools allow:

a)

Installing new OS

b)

Acquiring disk data or fragments over a network

c)

Seizing the computer physically

d)

Encrypting all files

35.

Most remote acquisitions are:

a)

Static

b)

Live

c)

Sparse only

d)

Disk-to-disk copy

36.

Some tools copy data secretly by:

a)

Sending phishing email

b)

Pushing remote access program via encrypted link

c)

Installing antivirus

d)

Forcing reboot

37.

A major benefit of remote acquisition:

a)

Requires no skills

b)

Saves time and reduces chance of detection

c)

Works only with wireless networks

d)

Requires no permissions

38.

Remote acquisitions usually require:

a)

Admin privileges to push agents

b)

Physical possession of drive

c)

Antivirus license

d)

Disabling network card

39.

Which could hinder remote acquisition?

a)

Lossless compression

b)

Antivirus/antispyware/firewall tools

c)

MD5 hashing

d)

Proprietary format

40.

How can security tools allow remote access programs?

a)

Disable encryption

b)

Configure to ignore remote access programs

c)

Uninstall firewall

d)

Force safe mode

41.

Suspects may detect remote acquisition because:

a)

They can install security tools with alarms

b)

It always triggers OS updates

c)

Tools leave visible icons

d)

All require restarts