WorksheetsCybersecurity & Digital Forensics Quiz
Total questions: 50
Worksheet time: 25mins
Which is the first step in a digital forensic investigation?
Analyzing the evidence
Collecting digital devices
Securing the crime scene
Reporting findings
Which tool is most commonly used for creating forensic disk images?
Wireshark
FTK Imager
Metasploit
Snort
The chain of custody ensures:
Evidence is destroyed after use
Evidence integrity is maintained
Evidence is encrypted
Evidence is public
What does 'write blocker' prevent during forensics?
Data compression
Data recovery
Data modification
Data encryption
Which file system is mostly used in Windows?
EXT4
NTFS
HFS+
FAT16
Volatile memory refers to:
Hard disk
RAM
SSD
CD-ROM
The primary purpose of hash functions in forensics is:
Data encryption
Data hiding
Integrity verification
Speeding access
Which Linux tool is widely used for forensic analysis?
Nmap
Autopsy
Aircrack-ng
Cain & Abel
Digital evidence must be:
Circumstantial
Admissible, Authentic, Reliable
Confidential only
Destroyed after trial
Which is a network forensic tool?
Gparted
EnCase
Wireshark
Autopsy
The CIA triad stands for:
Confidentiality, Integrity, Availability
Control, Integrity, Access
Cybersecurity, Internet, Authentication
Confidentiality, Investigation, Analysis
Converting plaintext into ciphertext is called:
Decryption
Encryption
Hashing
Encoding
Which protocol is more secure for web communication?
HTTP
HTTPS
FTP
Telnet
The process of verifying user identity is called:
Authorization
Authentication
Accounting
Auditing
A strong password should have:
Only letters
Only numbers
Repeated characters
Combination of letters, numbers, and symbols
What type of malware demands payment?
Worm
Trojan
Ransomware
Spyware
A firewall works at which layer of OSI model?
Application
Network
Session
Physical
A phishing attack usually targets:
Hardware
User credentials
Firewalls
Operating systems
A DoS attack aims to:
Steal data
Encrypt files
Overload systems
Gain admin access
SQL Injection targets:
Databases
Networks
Firewalls
Cloud
In symmetric encryption, the same key is used for:
Encryption and Decryption
Hashing
Steganography
Authentication
Public key cryptography uses:
One key only
Two keys (public & private)
Random numbers only
Hash functions
The RSA algorithm is used for:
Public key encryption
Hashing
Compression
Steganography
Which algorithm is considered a hashing function?
RSA
AES
SHA-256
DES
Which is a wireless security protocol?
FTP
SSL
WPA2
IMAP
SSL/TLS provides:
Secure communication over networks
Faster browsing
Spam filtering
File compression
Which port does HTTPS use by default?
21
25
80
443
Which device separates networks into zones of trust?
Switch
Router
Firewall
Proxy
A digital certificate is issued by:
Web browsers
ISPs
Certificate Authorities
Hackers
Steganography is the practice of:
Encrypting text
Hiding data inside other files
Cracking passwords
Creating viruses
A man-in-the-middle attack involves:
Bypassing antivirus
Intercepting communication
Phishing emails
DoS attacks
Which malware records keystrokes?
Worm
Trojan
Keylogger
Rootkit
Social engineering attacks exploit:
Firewalls
Human psychology
Encryption
Network protocols
Which is an example of biometric authentication?
PIN
Password
Fingerprint
Security question
The Stuxnet worm targeted:
Financial data
Email servers
Industrial control systems
Social media accounts
A zero-day attack exploits:
Old vulnerabilities
Unknown vulnerabilities
Weak passwords
Firewalls
Which virus hides inside another program?
Trojan
Worm
Keylogger
Ransomware
A botnet is:
Antivirus software
A secure network
A network of infected computers
Firewall rules
Spoofing refers to:
Encrypting traffic
Faking an identity or source
Blocking websites
Network scanning
Which malware disguises itself as legitimate software?
Trojan Horse
Worm
Rootkit
Spyware
Which law governs electronic evidence in the US?
IPC
GDPR
Federal Rules of Evidence
DMCA
In cloud security, 'multi-tenancy' means:
One user per server
Multiple users share same resources
Exclusive servers
Private VPN only
The primary purpose of IDS (Intrusion Detection System) is:
Block traffic
Monitor and detect attacks
Encrypt data
Manage firewalls
Which forensic method is best for live memory analysis?
Disk cloning
RAM acquisition
File carving
Log analysis
Data hidden in image files is usually detected using:
Sniffers
Debuggers
Steganalysis
Keyloggers
Which cybersecurity framework is published by NIST?
ISO 27001
NIST CSF
GDPR
PCI DSS
A honeypot is used to:
Encrypt files
Block IP addresses
Lure and monitor attackers
Delete malware
Which technique recovers deleted files?
Keylogging
Spoofing
File carving
DoS attack
Logs of user activity are stored in:
Switches
Routers
Audit trails
Antiviruses
Which type of backup stores only changes made since the last backup?
Full backup
Differential backup
Incremental backup
Redundant backup
