wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DF - Quiz - Term Work

Total questions: 20

Worksheet time: 15mins

Name
Class
Date
1.

What is a common method used by cyber criminals to gain unauthorized access to systems?

a)

Regular software updates

b)

Two-factor authentication

c)

Social engineering techniques

d)

Using strong passwords

2.

Match the following

a)

Identification

1.

Recognizing potential evidence

b)

Collection

2.

Gathering digital evidence

c)

Analysis

3.

Determining relevance of evidence

d)

Reporting

4.

Final documentation of findings

3.

  1. (a)   Rule is used to assess the admissibility of scientific evidence in court.

4.
  1. Which phase comes immediately after the detection of a security incident?

a)

Containment

b)

Eradication

c)

Identification

d)

Reporting

5.

Group the following types of digital forensics under appropriate categories:

Categorize the following

Hard Drive Analysis

Mobile Forensics

Network Forensics

Email Analysis

Device Forensics
Network Forensics
6.

Put these phases after detection of an incident in the correct order

a)

Containment

b)

Eradication

c)

Recovery

d)

Notification

1)
2)
3)
4)
7.
  1. The examiner plans to use a hardware write blocker. What is the primary benefit of a hardware write blocker in forensic duplication?

a)

It prevents modification of the original evidence drive

b)

It increases data transfer speed

c)

It can recover deleted files

d)

It formats the target drive automatically

8.

Categorize the following as hardware or software write blockers

Categorize the following

USB write blocker

SATA write blocker

Virtual machine with read-only mount

Forensic software with write protection

Hardware WB
Software WB
9.

The Encase (E01) forensic image format supports (a)   which is not a feature of the raw DD image format.

10.

he forensic examiner examines the ​ (a)   key in the Windows Registry to determine when an account was last used

Choose from the below words
LastLogon
UserAssist
ProfileList
SAM Data
11.

A forensic investigator is tasked with analyzing a suspect's computer to determine user activity related to a security breach. Arrange the investigation steps in the correct order

a)
  • Profiling user accounts

b)
  • Examining the Windows Registry

c)
  • Determining account usage

d)
  • Reviewing last login and password change timestamps

1)
2)
3)
4)
12.

Select all that apply: Which artifacts can reveal user activity regarding recently used files or programs?

a)
  • Jump Lists

b)
  • Thumb Cache

c)
  • Shimcache

d)

WLAN Event Log

13.

Classify the following forensic artifacts as belonging to File System Analysis or RAM Analysis

Categorize the following

Prefetch

Recycle Bin

Bulk Extractor

RAM Capture Tool

File System Analysis
RAM Analysis
14.

(a)   files are shortcuts used in Windows to link to documents, programs, and network shares and are useful in user activity investigations.

15.

During a breach investigation, the forensic team collects network traffic data to trace malicious activity and identify exfiltrated data.What type of evidence is the team primarily collecting?

a)

File System Evidence

b)

Router Table Information

c)

Network-Based Evidence

d)

Mobile Forensics

16.

Police seize a mobile phone at a crime scene and need to acquire forensic images for analysis without altering data.Which acquisition method provides a bit-for-bit copy of the phone's storage?​ ​ ​ (a)  

Choose from the below words
Physical Acquisition
Logical Acquisition
Network Acquisition
File System Acquisition
17.

You have just taken possession of a victims powered-on, locked phone. What is the most critical first step to preserve the integrity of the data?​ ​ ​

a)
Place the device in a Faraday bag or enable airpla
b)

Power the device off to prevent data from being written

c)

Immediately plug it into your forensics workstation to start the acquisition.

d)

Try to guess the passcode based on her known passwords.

18.

You are performing a physical acquisition of a mobile device, the only data you can expect to recover from the phone is her active contacts, visible text messages, and photos.​ (a)  

Choose from the below words
False
True
19.

You log into the router and see a new, high-priority static route that sends all traffic destined for RazorPays payment server (10.10.1.5) to an unknown IP address (172.16.6.6). This is a classic example of

a)

A password cracking attack

b)

A SYN flood attack.

c)

Router table manipulation.

d)

A physical acquisition

20.

Which email component is responsible for encoding non-text files (like images or documents) so they can be sent within a text-based email message?

a)

The To: header

b)

SMTP (Simple Mail Transfer Protocol)

c)
  • MIME (Multipurpose Internet Mail Extensions)

d)

The Received: header