Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Digital Forensics Worksheet

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

Which of the following is a primary reason digital investigators analyze email headers during an investigation?

a)

To decrypt encrypted mobile device data

b)

To identify physical evidence at a crime scene

c)

To recover deleted files from a hard drive

d)

To trace the origin and path of an email message

2.

The cloud services Dropbox, Google Drive, and OneDrive have no Registry entries.

a)

True

b)

False

3.

Evidence of cloud access found on a smartphone usually means that PaaS cloud service level was in use.

a)

True

b)

False

4.

At the investigation scene, determine whether the device is on or off. If it’s off, turn it on.

a)

True

b)

False

5.

E-mail services on both the Internet and an intranet use a client/server architecture, but they differ in how server accounts are assigned, used, and managed and in how users access their e-mail.

a)

True

b)

False

6.

Which email protocol is commonly used by forensic investigators to retrieve messages from a mail server during an investigation?

a)

HTTP

b)

IMAP

c)

FTP

d)

SSH

7.

When acquiring a mobile device at an investigation scene, you should leave it connected to a laptop or tablet so that you can observe synchronization as it takes place.

a)

True

b)

False

8.

Google was an early provider of Web-based services that eventually developed into the cloud concept.

a)

True

b)

False

9.

In Web-based e-mail, messages are displayed and saved as Web pages in the PC cache memory.

a)

True

b)

False

10.

Using wireless connection to extract information from a mobile device is a Leavesical extraction.

a)

True

b)

False

11.

For digital investigators, tracking intranet e-mail is easier because accounts use nonstandard names the administrator establishes.

a)

True

b)

False

12.

Which of the following is a common challenge when collecting evidence from mobile devices during a digital forensic investigation?

a)

Encryption of device data

b)

Unlimited battery life

c)

Absence of any operating system

d)

Lack of physical access to the Internet

13.

Which of the following is a key challenge when collecting digital evidence from cloud storage services?

a)

Cloud services never keep logs

b)

Lack of any user authentication

c)

Cloud data is always unencrypted

d)

Jurisdictional issues due to data stored in multiple countries

14.

A mobile station has 3 parts: GSM, SIM card, and Mobile Equipment.

a)

True

b)

False

15.

Which of the following is a primary method used to preserve data integrity when collecting evidence from a mobile device?

a)

Deleting unnecessary files

b)

Resetting the device to factory settings

c)

Enabling airplane mode on the device

d)

Installing new applications