Font size
WorksheetsDF - Quiz - Term Work
Total questions: 20
Worksheet time: 15mins
What is a common method used by cyber criminals to gain unauthorized access to systems?
Regular software updates
Two-factor authentication
Social engineering techniques
Using strong passwords
Match the following
Identification
Recognizing potential evidence
Collection
Gathering digital evidence
Analysis
Determining relevance of evidence
Reporting
Final documentation of findings
(a) Rule is used to assess the admissibility of scientific evidence in court.
Which phase comes immediately after the detection of a security incident?
Containment
Eradication
Identification
Reporting
Group the following types of digital forensics under appropriate categories:
Hard Drive Analysis
Mobile Forensics
Network Forensics
Email Analysis
Put these phases after detection of an incident in the correct order
Containment
Eradication
Recovery
Notification
The examiner plans to use a hardware write blocker. What is the primary benefit of a hardware write blocker in forensic duplication?
It prevents modification of the original evidence drive
It increases data transfer speed
It can recover deleted files
It formats the target drive automatically
Categorize the following as hardware or software write blockers
USB write blocker
SATA write blocker
Virtual machine with read-only mount
Forensic software with write protection
The Encase (E01) forensic image format supports (a) which is not a feature of the raw DD image format.
he forensic examiner examines the (a) key in the Windows Registry to determine when an account was last used
A forensic investigator is tasked with analyzing a suspect's computer to determine user activity related to a security breach. Arrange the investigation steps in the correct order
Profiling user accounts
Examining the Windows Registry
Determining account usage
Reviewing last login and password change timestamps
Select all that apply: Which artifacts can reveal user activity regarding recently used files or programs?
Jump Lists
Thumb Cache
Shimcache
WLAN Event Log
Classify the following forensic artifacts as belonging to File System Analysis or RAM Analysis
Prefetch
Recycle Bin
Bulk Extractor
RAM Capture Tool
(a) files are shortcuts used in Windows to link to documents, programs, and network shares and are useful in user activity investigations.
During a breach investigation, the forensic team collects network traffic data to trace malicious activity and identify exfiltrated data.What type of evidence is the team primarily collecting?
File System Evidence
Router Table Information
Network-Based Evidence
Mobile Forensics
Police seize a mobile phone at a crime scene and need to acquire forensic images for analysis without altering data.Which acquisition method provides a bit-for-bit copy of the phone's storage? (a)
You have just taken possession of a victims powered-on, locked phone. What is the most critical first step to preserve the integrity of the data?
Power the device off to prevent data from being written
Immediately plug it into your forensics workstation to start the acquisition.
Try to guess the passcode based on her known passwords.
You are performing a physical acquisition of a mobile device, the only data you can expect to recover from the phone is her active contacts, visible text messages, and photos. (a)
You log into the router and see a new, high-priority static route that sends all traffic destined for RazorPays payment server (10.10.1.5) to an unknown IP address (172.16.6.6). This is a classic example of
A password cracking attack
A SYN flood attack.
Router table manipulation.
A physical acquisition
Which email component is responsible for encoding non-text files (like images or documents) so they can be sent within a text-based email message?
The To: header
SMTP (Simple Mail Transfer Protocol)
MIME (Multipurpose Internet Mail Extensions)
The Received: header
