wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Digital Forensics Practise

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

Which of the following is the first step in the digital forensic process?

a)

Analysis

b)

Acquisition

c)

Reporting

d)

Preservation

2.

What does the term “chain of custody” refer to?

a)

Encrypting evidence

b)

Documenting evidence handling

c)

Recovering deleted files

d)

Analyzing metadata

3.

Which phase involves creating a forensic image of the evidence?

a)

Collection

b)

Examination

c)

Analysis

d)

Reporting

4.

Why is hashing used during acquisition?

a)

To compress data

b)

To verify integrity

c)

To encrypt files

d)

To hide data

5.

Which of these is NOT a principle of digital forensics?

a)

Evidence must be preserved

b)

Evidence can be altered if documented

c)

Chain of custody must be maintained

d)

Analysis must be repeatable

6.

What is the purpose of forensic imaging?

a)

To create a backup

b)

To create an exact copy for analysis

c)

To compress files

d)

To encrypt data

7.

Which type of analysis is performed on a running system?

a)

Dead analysis

b)

Live analysis

c)

Static analysis

d)

Dynamic analysis

8.

Which of the following is considered volatile data?

a)

Hard disk contents

b)

RAM contents

c)

USB drive files

d)

CD-ROM data

9.

Which document summarizes findings in a forensic investigation?

a)

Chain of custody

b)

Forensic report

c)

Acquisition log

d)

Metadata sheet

10.

Which of these is a reason for documenting every step in forensics?

a)

To speed up analysis

b)

To ensure legal admissibility

c)

To encrypt evidence

d)

To hide sensitive data

11.

Which of the following is NOT part of the forensic process?

a)

Identification

b)

Preservation

c)

Destruction

d)

Analysis

12.

What is the main goal of digital forensics?

a)

To punish criminals

b)

To recover deleted files

c)

To identify, preserve, and analyse evidence

d)

To encrypt sensitive data

13.

Which term refers to ensuring evidence remains unchanged?

a)

Integrity

b)

Confidentiality

c)

Availability

14.

Which of these is considered non-volatile data?

a)

RAM

b)

CPU cache

c)

Hard disk

d)

Network packets

15.

Which forensic principle ensures that analysis can be verified by others?

a)

Repeatability

b)

Confidentiality

c)

Encryption

d)

Obfuscation

16.

Which metadata field typically contains the date a file was created?

a)

EXIF

b)

MAC times

c)

Hash value

d)

File signature

17.

What does EXIF metadata relate to?

a)

Audio files

b)

Image files

c)

Video files

d)

Text documents

18.

Which of these is NOT an example of metadata?

a)

File size

b)

File content

c)

Creation date

d)

Author name

19.

Which tool is commonly used to view metadata in images?

a)

Autopsy

b)

ExifTool

c)

Wireshark

d)

FTK Imager

20.

Which metadata can reveal the location where a photo was taken?

a)

Hash value

b)

GPS coordinates

c)

File extension

d)

MAC address

21.

Which of these can be easily altered by a user?

a)

Hash value

b)

Metadata

c)

File signature

d)

File system

22.

Which type of metadata is stored in NTFS file systems?

a)

EXIF

b)

Alternate Data Streams

c)

GPS tags

d)

ICC profiles

23.

Which of these is NOT a type of metadata?

a)

Descriptive

b)

Structural

c)

Administrative

d)

Cryptographic

24.

Which metadata can help identify the software used to create a file?

a)

EXIF

b)

ICC profile

c)

Application metadata

d)

Hash value

25.

Which metadata is most useful in timeline analysis?

a)

File size

b)

MAC times

c)

Hash value

d)

File extension

26.

What is steganography primarily used for?

a)

Encrypting files

b)

Hiding data within other files

27.

Which of these is an example of steganography?

a)

Encrypting a ZIP file

b)

Hiding text in an image

c)

Using a VPN

d)

Hashing a password

28.

Which tool is commonly used for steganography detection?

a)

StegExpose

b)

Wireshark

c)

FTK Imager

d)

Autopsy

29.

Which file type is most commonly used for steganography?

a)

.exe

b)

.jpg

c)

.txt

d)

.zip

30.

Which technique conceals data in the least significant bits of an image?

a)

Hashing

b)

LSB technique

c)

Compression

d)

Encryption

31.

Which of these is NOT a steganography method?

a)

Image-based

b)

Audio-based

c)

Video-based

d)

Hash-based

32.

What is the main difference between steganography and cryptography?

a)

Steganography hides data, cryptography encrypts it

b)

Both hide data in images

c)

Both encrypt data

d)

Steganography uses hashing

33.

Which of these is a risk of steganography?

a)

Data compression

b)

Malware hiding

c)

Faster transmission

d)

Increased file size

34.

Which of these can indicate steganography in a file?

a)

Unusual file size

b)

Normal hash value

c)

Standard metadata

d)

Common file extension

35.

Which steganography detection method analyzes statistical anomalies?

a)

Hashing

b)

Steganalysis

c)

Encryption

d)

Compression

36.

Which UK law addresses unauthorized access to computer systems?

a)

GDPR

b)

Computer Misuse Act 1990

c)

Data Protection Act 2018

d)

Freedom of Information Act

37.

Which regulation focuses on personal data protection in the UK?

a)

GDPR

b)

CMA

c)

FOIA

d)

RIPA

38.

Which principle ensures evidence is admissible in court?

a)

Chain of custody

b)

Encryption

c)

Compression

d)

Obfuscation

39.

Which of these is considered unethical in digital forensics?

a)

Maintaining confidentiality

b)

Altering evidence

40.

Which act allows lawful interception of communications?

a)

CMA

b)

RIPA

c)

GDPR

d)

FOIA

41.

Which of these is NOT a good forensic practise?

a)

Documenting all actions

b)

Using write blockers

c)

Modifying original evidence

d)

Maintaining integrity

42.

Which law criminalises hacking in the UK?

a)

CMA

b)

GDPR

c)

FOIA

d)

DPA

43.

Which principle ensures privacy during investigations?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Authenticity

44.

Which of these is a legal requirement for handling personal data in the United Kingdom?

a)

CMA

b)

GDPR

c)

RIPA

d)

FOIA

45.

Which act governs surveillance in the UK?

a)

CMA

b)

GDPR

c)

RIPA

d)

FOIA

46.

Which of these is considered professional misconduct?

a)

Following ACPO guidelines

b)

Sharing evidence without consent

c)

Maintaining chain of custody

d)

Using validated tools

47.

Which guideline is widely followed in UK forensics?

a)

ISO 27001

b)

ACPO principles

c)

GDPR only

d)

FOIA

48.

Which principle ensures transparency in forensic work?

a)

Repeatability

b)

Confidentiality

c)

Encryption

d)

Obfuscation

49.

Which of these is NOT covered by the GDPR?

a)

Personal data

b)

Corporate secrets

c)

Data subject rights

d)

Data breach notifications

50.

Which law applies to cybercrime investigations in the UK?

a)

CMA

b)

GDPR

c)

FOIA

d)

RIPA

51.

Which tool is commonly used for disk imaging?

a)

Wireshark

b)

FTK Imager

c)

StegExpose

d)

Cain & Abel

52.

Which tool is used for network packet analysis?

a)

Autopsy

b)

Wireshark

53.

Which tool is open-source for forensic analysis?

a)

Autopsy

b)

EnCase

c)

FTK

d)

Cellebrite

54.

Which tool is used for mobile device forensics?

a)

Cellebrite

b)

Wireshark

c)

FTK Imager

d)

ExifTool

55.

Which tool is best for analyzing Windows registry?

a)

Registry Viewer

b)

Wireshark

c)

Autopsy

d)

ExifTool

56.

Which of these tools is used for password recovery?

a)

Cain & Abel

b)

Autopsy

c)

FTK Imager

d)

Wireshark

57.

Which tool is widely used for timeline analysis?

a)

Plaso

b)

Wireshark

c)

FTK Imager

d)

ExifTool

58.

Which tool is used for analyzing memory dumps?

a)

Volatility

b)

Wireshark

c)

Autopsy

d)

FTK Imager

59.

Which tool is used for email analysis?

a)

X-Ways

b)

Wireshark

c)

Autopsy

d)

ExifTool

60.

Which tool is used for carving deleted files?

a)

Scalpel

b)

Wireshark

c)

FTK Imager

d)

ExifTool

61.

Which tool is used for log analysis?

a)

Log2Timeline

b)

Wireshark

c)

FTK Imager

d)

ExifTool

62.

Which tool is used for browser artefact analysis?

a)

Browser History Viewer

b)

Wireshark

c)

Autopsy

d)

ExifTool

63.

Which tool is used for Linux forensic analysis?

a)

Sleuth Kit

b)

Wireshark

c)

FTK Imager

d)

ExifTool

64.

Which tool is used for hashing files?

a)

HashCalc

b)

Wireshark

c)

Autopsy

d)

ExifTool

65.

Which tool is used for forensic imaging in Linux?

a)

dd

b)

Wireshark

c)

Autopsy

66.

What is the significance of an inode in Linux?

a)

Stores file content

b)

Stores file metadata

c)

Stores file hash

d)

Stores file permissions only

67.

Which Linux command creates a disk image?

a)

dd

b)

ls

c)

cp

d)

mv

68.

Which file system is commonly used in Linux?

a)

NTFS

b)

FAT32

c)

ext4

d)

HFS+

69.

Which command lists inode information?

a)

ls -i

b)

ls -l

c)

df

d)

du

70.

Which directory contains user home folders?

a)

/bin

b)

/home

c)

/etc

d)

/usr

71.

Which directory stores system configuration files?

a)

/bin

b)

/home

c)

/etc

d)

/usr

72.

Which command shows disk usage?

a)

du

b)

ls

c)

df

d)

ps

73.

Which command shows mounted file systems?

a)

mount

b)

ls

c)

df

d)

du

74.

Which Linux artefact stores login history?

a)

/var/log/wtmp

b)

/etc/passwd

c)

/home/user/.bashrc

d)

/bin/login

75.

Which file stores user account details?

a)

/etc/passwd

b)

/etc/shadow

c)

/var/log/auth.log

d)

/home/user/.profile

76.

Which file stores password hashes?

a)

/etc/passwd

b)

/etc/shadow

c)

/var/log/auth.log

d)

/home/user/.bashrc

77.

Which command shows running processes?

a)

ps

b)

ls

c)

df

d)

du

78.

Which command is used to recover deleted files in Linux?

a)

extundelete

b)

ls

c)

dd

79.

Which Linux artefact stores bash history?

a)

~/.bash_history

b)

/etc/passwd

c)

/var/log/syslog

d)

/home/user/.profile

80.

Which command calculates file hash in Linux?

a)

md5sum

b)

ls

c)

df

d)

du

81.

Which artefact indicates recent web browsing activity?

a)

Browser history

b)

Hash value

c)

File signature

d)

Chain of custody

82.

Which artefact stores Wi-Fi connection details?

a)

Windows registry

b)

Browser cache

c)

EXIF metadata

d)

Linux inode

83.

Which artefact can reveal USB device usage?

a)

Registry keys

b)

EXIF metadata

c)

MAC times

d)

Hash values

84.

Which artefact stores email attachments?

a)

PST file

b)

EXIF metadata

c)

Alternate Data Streams

d)

Hash value

85.

Which artefact stores chat logs?

a)

Application data folder

b)

EXIF metadata

c)

File signature

d)

Hash value

86.

Which artefact indicates file deletion?

a)

Recycle Bin entries

b)

Hash value

c)

EXIF metadata

d)

File signature

87.

Which artefact stores installed programs in Windows?

a)

Registry

b)

EXIF metadata

c)

MAC times

d)

Hash value

88.

Which artefact stores login timestamps?

a)

Event logs

b)

EXIF metadata

c)

File signature

d)

Hash value

89.

Which artefact stores browser cookies?

a)

Browser cache

b)

Registry

c)

EXIF metadata

d)

Hash value

90.

Which artefact stores system boot times?

a)

Event logs

b)

EXIF metadata

c)

File signature

d)

Hash value

91.

Which artefact stores clipboard data?

a)

RAM

b)

Registry

c)

EXIF metadata

92.

Which artefact stores temporary internet files?

a)

Browser cache

b)

Registry

c)

EXIF metadata

d)

Hash value

93.

Which artefact stores user profile information?

a)

NTUSER.DAT

b)

EXIF metadata

c)

File signature

d)

Hash value

94.

Which artefact stores DNS cache?

a)

System memory

b)

Registry

c)

EXIF metadata

d)

Hash value

95.

Which artefact stores recent documents list?

a)

Registry

b)

EXIF metadata

c)

File signature

d)

Hash value

96.

Which artefact stores printer usage?

a)

Event logs

b)

Registry

c)

EXIF metadata

d)

Hash value

97.

Which artefact stores wireless SSIDs?

a)

Registry

b)

EXIF metadata

c)

File signature

d)

Hash value

98.

Which artefact stores scheduled tasks?

(a)  

99.

Which artefact stores system crash dumps?

a)

Memory dump files

b)

Registry

c)

EXIF metadata

d)

Hash value

100.

Which artefact stores browser download history?

a)

Browser history database

b)

Registry

c)

EXIF metadata

d)

Hash value