wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

389-493

Total questions: 103

Worksheet time: 52mins

Name
Class
Date
1.

Which of the following data structures stores attributes of a process, as well as pointers to other attributes and data structures?

a)

RegEdit

b)

Lsproc

c)

EProcess

d)

DumpChk

2.

How will you categorize a cybercrime that took place within a CSP's cloud environment?

a)

Cloud as a Subject

b)

Cloud as an Audit

c)

Cloud as an Object

d)

Cloud as a Tool

3.

Which of the following reports are delivered under oath to a board of directors/managers/panel of the jury?

a)

Written Informal Report

b)

Verbal Informal Report

c)

Verbal Formal Report

d)

Written Formal Report

4.

The process of restarting a computer that is already turned on through the operating system is called?

a)

Warm boot

b)

Ice boot

c)

Cold boot

d)

Hot Boot

5.

Amber, a black hat hacker, has embedded a malware into a small enticing advertisement and posted it on a popular ad-network that displays across various websites. What is she doing?

a)

Compromising a legitimate site

b)

Malvertising

c)

Click-jacking

d)

Spearphishing

6.

Sectors are pie-shaped regions on a hard disk that store data. Which of the following parts of a hard disk do not contribute in determining the addresses of data?

a)

Heads

b)

Cylinder

c)

Interface

d)

Sectors

7.

Netstat is a tool for collecting information regarding network connections. It provides a simple view of TCP and UDP connections, and their state and network traffic statistics. Which of the following commands shows you the TCP and UDP network connections, listening ports, and the identifiers?

a)

netstat -b

b)

netstat -ano

c)

netstat -r

d)

netstat -s

8.

Billy, a computer forensics expert, has recovered a large number of DBX files during the forensic investigation of a laptop. Which of the following email clients can he use to analyze the DBX files?

a)

Microsoft Outlook

b)

Microsoft Outlook Express

c)

Eudora

d)

Mozilla Thunderbird

9.

Which network attack is described by the following statement? "At least five Russian major banks came under a continuous hacker attack, although online client services were not disrupted. The attack came from a wide-scale botnet involving at least 24,000 computers, located in 30 countries."

a)

DDoS

b)

Buffer Overflow

c)

Sniffer Attack

d)

Man-in-the-Middle Attack

10.

Which of the following is NOT a part of pre-investigation phase?

a)

Gathering information about the incident

b)

Gathering evidence data

c)

Creating an investigation team

d)

Building forensics workstation

11.

To which phase of the Computer Forensics Investigation Process does the Planning and Budgeting of a Forensics Lab belong?

a)

Investigation Phase

b)

Post-investigation Phase

c)

Reporting Phase

d)

Pre-investigation Phase

12.

Which tool does the investigator use to extract artifacts left by Google Drive on the system?

a)

PEBrowse Professional

b)

RegScanner

c)

RAM Capturer

d)

Dependency Walker

13.

BMP (Bitmap) is a standard file format for computers running the Windows operating system. BMP images can range from black and white (1 bit per pixel) up to 24 bit color (16.7 million colors). Each bitmap file contains a header, the RGBQUAD array, information header, and image data. Which of the following element specifies the dimensions, compression type, and color format for the bitmap?

a)

Information header

b)

Image data

c)

The RGBQUAD array

d)

Header

14.

Identify the file system that uses $BitMap file to keep track of all used and unused clusters on a volume.

a)

EXT

b)

FAT

c)

NTFS

15.

An investigator has acquired packed software and needed to analyze it for the presence of malice. Which of the following tools can help in finding the packaging software used?

a)

PEiD

b)

Comodo Programs Manager

c)

Dependency Walker

d)

SysAnalyzer

16.

Korey, a data mining specialist in a knowledge processing firm DataHub.com, reported his CISO that he has lost certain sensitive data stored on his laptop. The CISO wants his forensics investigation team to find if the data loss was accident or intentional. In which of the following category this case will fall?

a)

Civil Investigation

b)

Administrative Investigation

c)

Both Civil and Criminal Investigations

d)

Criminal Investigation

17.

Which of the following Windows-based tool displays who is logged onto a computer, either locally or remotely?

a)

Tokenmon

b)

Process Monitor

c)

PSLoggedon

d)

TCPView

18.

A forensic examiner is examining a Windows system seized from a crime scene. During the examination of a suspect file, he discovered that the file is password protected. He tried guessing the password using the suspect's available information but without any success. Which of the following tool can help the investigator to solve this issue?

a)

Colasoft's Capsa

b)

Xplico

c)

Cain & Abel

d)

Recuva

19.

Which of the following Android libraries are used to render 2D (SGL) or 3D (OpenGL/ES) graphics content to the screen?

a)

Media framework

b)

Surface Manager

c)

WebKit

d)

OpenGL/ES and SGL

20.

Report writing is a crucial stage in the outcome of an investigation. Which information should not be included in the report section?

a)

Speculation or opinion as to the cause of the incident

b)

Purpose of the report

c)

Author of the report

d)

Incident summary

21.

You are assigned a task to examine the log files pertaining to MyISAM storage engine. While examining, you are asked to perform a recovery operation on a MyISAM log file. Which among the following MySQL Utilities allow you to do so?

a)

mysqlbinlog

b)

mysqldump

c)

mysqlshow

d)

mysqlcheck

22.

Andie, a network administrator, suspects unusual network services running on a Windows system. Which of the following commands should he use to verify unusual network services started on a Windows system?

a)

net start

b)

lusrmgr

c)

netmgr

d)

net serv

23.

Randy has extracted data from an old version of a Windows-based system and discovered info file Dc5.txt in the system recycle bin. What does the file name denote?

a)

A text file deleted from C drive in sixth sequential order

b)

A text file deleted from C drive in fifth sequential order

c)

A text file copied from D drive to C drive in fifth sequential order

d)

A text file copied from C drive to D drive in fifth sequential order

24.

Sheila is a forensics trainee and is searching for hidden image files on a hard disk. She used a forensic investigation tool to view the media in hexadecimal code for simplifying the search process. Which of the following hex codes should she look for to identify image files?

a)

50 41 03 04

b)

d0 0f 11 e0

c)

25 50 44 46

d)

ff d8 ff

25.

Shane, a forensic specialist, is investigating an ongoing attack on a MySQL database server hosted on a Windows machine with SID `WIN-ABCDE12345F.` Which of the following log files will help Shane in tracking all the client connections and activities performed on the database server?

a)

WIN-ABCDE12345F-bin.n

b)

WIN-ABCDE12345F.pid

c)

WIN-ABCDE12345F.err

d)

WIN-ABCDE12345F.log

26.

What must an attorney do first before you are called to testify as an expert?

a)

Qualify you as an expert witness

b)

Read your curriculum vitae to the jury

c)

Engage in damage control

d)

Prove that the tools you used to conduct your examination are perfect

27.

Gary is checking for the devices connected to USB ports of a suspect system during an investigation. Select the appropriate tool that will help him document all the connected devices.

a)

Reg.exe

b)

fsutil

c)

Devcon

d)

DevScan

28.

Which of the following is NOT a physical evidence?

a)

Removable media

b)

Cables

c)

Image file on a hard disk

d)

Publications

29.

During forensics investigations, investigators collect the system time and compare it with UTC. What does the abbreviation UTC stand for?

a)

Universal Time for Computers

b)

Universal Computer Time

c)

Coordinated Universal Time

d)

Correlated Universal Time

30.

Buffer overflow vulnerability occurs when a web application allows writing beyond a buffer’s maximum size, overwriting the ________.

a)

Adjacent string locations

b)

Adjacent memory locations

c)

Adjacent bit blocks

d)

Adjacent buffer locations

31.

Which of the following is a part of a Solid-State Drive (SSD)?

a)

Head

b)

Spindle

c)

Cylinder

d)

NAND-based flash memory

32.

Which standard represents a legal precedent set in 1993 by the U.S. Supreme Court regarding the admissibility of expert witnesses’ testimony during federal legal proceedings?

a)

Daubert

b)

IOCE

c)

SWGDE & SWGIT

d)

Frye

33.

Which statement is incorrect when preserving digital evidence?

a)

Document the actions and changes that you observe in the monitor, computer, printer, or in

b)

Remove the plug from the power router or modem

c)

Turn on the computer and extract Windows event viewer log files

d)

Verify if the monitor is in on, off, or in sleep mode

34.

Which ISO standard defines file systems and protocol for exchanging data between optical disks?

a)

ISO 9660

b)

IEC 3490

c)

ISO/IEC 13940

d)

ISO 9060

35.

In computer forensics, Heap Buffer Overflow is categorized under which broader vulnerability class?

a)

Race condition errors

b)

Authentication bypass issues

c)

Privilege escalation flaws

d)

Buffer overflow vulnerabilities

36.

What value of the Boot Record Signature is used to indicate that the boot-loader exists?

a)

AA00

b)

00AA

c)

A100

d)

AA55

37.

Which of the following is a MAC-based File Recovery Tool?

a)

Cisdem DataRecovery 3

b)

Smart Undeleter

c)

GetDataBack

d)

VirtualLab

38.

Smith wants to find all values typed into the Run box in the Start menu during a Windows forensic analysis. Which registry key should he check?

a)

RunMRU key

b)

UserAssist key

c)

MountedDevices key

d)

TypedURLs key

39.

When analyzing logs, clocks of all network devices must be synchronized. Which protocol helps in synchronizing these clocks?

a)

NTP

b)

UTC

c)

PTP

d)

Time Protocol

40.

The first eight digits of an IMEI that provide information about the model and origin of a mobile device are known as:

a)

Device Origin Code (DOC)

b)

Integrated Circuit Code (ICC)

c)

Type Allocation Code (TAC)

d)

Manufacturer Identification Code (MIC)

41.

Which of the following is NOT an anti-forensics technique?

a)

Encryption

b)

Password Protection

c)

Steganography

d)

Data Deduplication

42.

A computer forensics apprentice uses the command nbtstat -c to analyze a suspect system. What information is he looking for?

a)

Contents of the network routing table

b)

Status of the network carrier

c)

Contents of the NetBIOS name cache

d)

Network connections

43.

Tasklist command displays a list of applications and services with their Process ID (PID) for all tasks running on either a local or a remote computer. Which of the following tasklist commands provides information about the listed processes, including the image name, PID, name, and number of the session for the process?

a)

tasklist /s

b)

tasklist /v

c)

tasklist /u

d)

tasklist /p

44.

Which part of Metasploit framework helps users to hide the data related to a previously deleted file or currently unused by the allocated file.

a)

FragFS

b)

Slacker

c)

RuneFS

d)

Waffen FS

45.

Which one of the following is not a first response procedure?

a)

Crack passwords

b)

Take photos

c)

Fill forms

d)

Preserve volatile data

46.

Graphics Interchange Format (GIF) is a ____ RGB bitmap image format for images with up to 256 distinct colors per frame.

a)

32-bit

b)

8-bit

c)

16-bit

d)

24-bit

47.

Hard disk data addressing is a method of allotting addresses to each ______ of data on a hard disk.

a)

Logical block

b)

Hard disk block

c)

Operating system block

d)

Physical block

48.

Which of the following standard represents a legal precedent regarding the admissibility of scientific examinations or experiments in legal cases?

a)

IOCE

b)

SWGDE & SWGIT

c)

Daubert

d)

Frye

49.

Event correlation is the process of finding relevance between the events that produce a final result. What type of correlation will help an organization to correlate events across a set of servers, systems, routers and network?

a)

Same-platform correlation

b)

Network-platform correlation

c)

Cross-platform correlation

d)

Multiple-platform correlation

50.

In Apache error logs, which entry type typically records server-side issues such as missing modules, script failures, or permission problems?

a)

Audit entries

b)

Rewrite entries

c)

Error entries

d)

Access entries

51.

You are investigating events from Windows servers, Linux routers, and a SIEM. Which approach best helps you sequence and relate these events to detect a multi-stage attack?

a)

Protocol-only analysis

b)

Unfiltered log aggregation

c)

Single-source timelines

d)

Cross-platform correlation

52.

What malware analysis operation can the investigator perform using the jv16 tool?

a)

Files and Folder Monitor

b)

Network Traffic Monitoring/Analysis

c)

Installation Monitor

d)

Registry Analysis/Monitoring

53.

Which email header specifies an address for mailer-generated errors, like "no such user" bounces, to go to instead of the sender's address?

a)

Mime-Version header

b)

Content-Type header

c)

Errors-To header

d)

Content-Transfer-Encoding header

54.

A computer forensics investigator with extensive experience is called as a qualified witness to testify to the accuracy and integrity of technical log files gathered in a fraud investigation. What is the term for this testimony?

a)

Authentication

b)

Reiteration

c)

Justification

d)

Certification

55.

When a user deletes a file, the system creates an SI file to store its details. What detail does the SI file not contain?

a)

File origin and modification

b)

File Size

c)

File Name

d)

Time and date of deletion

56.

Raw data acquisition format creates ________ of a data set or suspect drive.

a)

Segmented image files

b)

Simple sequential flat files

c)

Compressed image files

d)

Segmented files

57.

Under the CAN-SPAM Act, which requirement applies to commercial email senders?

a)

Don't use true header information

b)

Don't identify the message as an ad

c)

Don't use deceptive subject lines

d)

Don't tell recipients where you are located

58.

Which registry hive provides configuration information about which application was used to open various files on the system?

a)

HKEY_LOCAL_MACHINE

b)

HKEY_USERS

c)

HKEY_CLASSES_ROOT

d)

HKEY_CURRENT_CONFIG

59.

Select the tool appropriate for examining the dynamically linked libraries of an application or process.

a)

Wireshark

b)

Dependency Walker

c)

RegShot

d)

Netstat

60.

Which U.S. federal law requires financial institutions that offer consumers financial products or services to protect their customers' private information?

a)

Health Insurance Portability and Accountability Act

b)

Payment Card Industry Data Security Standard

c)

Federal Information Security Management Act

d)

Gramm-Leach-Bliley Act

61.

Which application password-cracking tool can discover all password-protected items on a computer and decrypt them?

a)

Passware Kit Forensic

b)

R-Studio

c)

Windows Password Recovery Bootdisk

d)

TestDisk for Windows

62.

After analyzing a mobile device, what identifier can reveal the manufacturer information?

a)

Equipment Identity Register

b)

Electronic Serial Number

c)

International mobile subscriber identity

d)

Integrated circuit card identifier

63.

Which command-line tool is used to determine active network connections?

a)

netstat

b)

nslookup

c)

nbstat

d)

netsh

64.

Which process is part of dynamic malware analysis?

a)

Process monitoring

b)

Malware disassembly

c)

File fingerprinting

d)

Searching for strings

65.

Investigators use the Type Allocation Code (TAC) to find the model and origin of a mobile device. Where is TAC located on mobile devices?

a)

International Mobile Equipment Identifier

b)

Integrated circuit card identifier

c)

International mobile subscriber identity

d)

Equipment Identity Register

66.

What is the process where a magnetic field is used over a digital media device to delete previously stored data?

a)

Disk wiping

b)

Disk deletion

c)

Disk cleaning

d)

Disk degaussing

67.

Which of the following tool can reverse machine code to assembly language?

a)

RAM Capturer

b)

PEiD

c)

IDA Pro

d)

Deep Log Analyzer

68.

Which of the following file formats allows the user to compress the acquired data as well as keep it randomly accessible?

a)

Advanced Forensics Format (AFF)

b)

Advanced Forensic Framework 4

c)

Proprietary Format

d)

Generic Forensic Zip (gfzip)

69.

What is the investigator trying to view by issuing the command displayed in the following screenshot?

a)

List of services installed

b)

List of services stopped

c)

List of services closed recently

d)

List of services recently started

70.

Which layer of iOS architecture should a forensics investigator evaluate to analyze services such as Threading, File Access, Preferences, Networking and high-level features?

a)

Core OS

b)

Cocoa Touch

c)

Core Services

d)

Media services

71.

Which command can provide the investigators with details of all the loaded modules on a Linux-based system?

a)

plist mod -a

b)

list modules -a

c)

lsmod

d)

lsof -m

72.

In a Linux-based system, what does the command 'last -F' display?

a)

Last run processes

b)

Login and logout times and dates of the system

c)

Recently opened files

d)

Last functions performed

73.

Which of the following examinations refers to the process of providing the opposing side in a trial the opportunity to question a witness?

a)

Witness Examination

b)

Direct Examination

c)

Indirect Examination

d)

Cross Examination

74.

Pick the statement which does not belong to the Rule 804 Hearsay Exceptions; Declarant

a)

Statement against interest by unavailable declarant

b)

Former testimony of an unavailable witness

c)

Excited utterance regardless of availability

d)

Statement of personal or family history

75.

Which of the following is a responsibility of the first responder?

a)

Determine the severity of the incident

b)

Document the findings

c)

Collect as much information about the incident as possible

d)

Share the collected information to determine the root cause

76.

NTFS sets a flag for the file once you encrypt it and creates an EFS attribute where it stores Data Decryption Field (DDF) and Data Recovery Field (DDR). Which of the following is not a part of DDF?

a)

Container Name

b)

Encrypted FEK

c)

Checksum

d)

EFS Certificate Hash

77.

If the partition size is 4 GB, each cluster will be 32 K. Even if a file needs only 10 K, the entire 32 K will be allocated, resulting in 22 K of ________.

a)

Slack space

b)

Sector space

c)

Deleted space

d)

Cluster space

78.

After suspecting a change in MS-Exchange Server storage archive, the investigator has analyzed it. Which of the following components is not an actual part of the archive?

a)

PRIV.STM

b)

PUB.EDB

c)

PUB.STM

d)

PRIV.EDB

79.

Which of the following is a non-zero data that an application allocates on a hard disk cluster in systems running on Windows OS?

a)

Slack Space

b)

Meta Block Group

c)

Master File Table

d)

Sparse File

80.

Which of the following is a tool to reset Windows admin password?

a)

Windows Data Recovery Software

b)

Windows Password Recovery Bootdisk

c)

TestDisk for Windows

d)

R-Studio

81.

Ron, a computer forensics expert, needs to recover the IMEI number of a Nokia phone left ON. Which key combination can he use to recover the IMEI number?

a)

#*06*#

b)

#*06#

c)

#.06#

d)

*IMEI#

82.

Select the data that a virtual memory would store in a Windows-based system.

a)

Information or metadata of the files

b)

Application data

c)

Documents and other files

d)

Running processes

83.

Which principle states that anyone or anything entering a crime scene takes something of the scene with them, and leaves something of themselves behind?

a)

Locard's Exchange Principle

b)

Enterprise Theory of Investigation

c)

Locard's Evidence Principle

d)

Evidence Theory of Investigation

84.

During an investigation, Noel found a SIM card from a suspect's mobile. What does the code 89 44 represent on the card?

a)

TAC and Industry Identifier

b)

Individual Account Identification Number and Country Code

c)

Industry Identifier and Country code

d)

Issuer Identifier Number and TAC

85.

Which file system uses the Master File Table (MFT) database to store information about every file and directory on a volume?

a)

NTFS File System

b)

exFAT

c)

ReFS

d)

FAT File System

86.

A forensic expert needs detailed transaction log information from a SQL Server database named Transfers, including AllocUnitId, page id, and slot id. Which DBCC LOG command should be executed?

a)

DBCC LOG(Transfers, 2)

b)

DBCC LOG(Transfers, 1)

c)

DBCC LOG(Transfers, 3)

d)

DBCC LOG(Transfers, 0)

87.

%3cscript%3ealert('XXXXXXXX')%3c/script%3e is a script obtained from a Cross-Site Scripting attack. What type of encoding has been employed?

a)

Unicode

b)

Hex encoding

c)

Base64

d)

Double encoding

88.

Which of the following is a device monitoring tool?

a)

Capsa

b)

Regshot

c)

Driver Detective

d)

RAM Capturer

89.

What system details can an investigator obtain from the NetBIOS name table cache?

a)

List of files opened on other systems

b)

List of the system present on a router

c)

List of connections made to other systems

d)

List of files shared between the connected systems

90.

While analyzing a hard disk, the investigator finds that the file system does not use UEFI-based interface. Which of the following operating systems is present on the hard disk?

a)

Windows 8.1

b)

Windows 7

c)

Windows 8

d)

Windows 10

91.

In which registry does the system store the Microsoft security IDs?

a)

HKEY_CURRENT_CONFIG (HKCC)

b)

HKEY_CURRENT_USER (HKCU)

c)

HKEY_CLASSES_ROOT (HKCR)

d)

HKEY_LOCAL_MACHINE (HKLM)

92.

An investigator has extracted the device descriptor for a 1GB thumb drive that looks like: Disk&Ven_Best_Buy&Prod_Geek_Squad_U3&Rev_6.15. What does the 'Geek_Squad' part represent?

a)

Developer description

b)

Manufacturer Details

c)

Software or OS used

d)

Product description

93.

Which of the following Perl scripts will help an investigator to access the executable image of a process?

a)

Lspi.pl

b)

Lspd.pl

c)

Lpsi.pl

d)

Lspm.pl

94.

Which of the following attack uses HTML tags like ?

a)

XSS attack

b)

Phishing

c)

SQL injection

d)

Spam

95.

Examination of a computer by a technically unauthorized person will almost always result in:

a)

Rendering any evidence found admissible in a court of law

b)

The chain of custody being fully maintained

c)

Completely accurate results of the examination

d)

Rendering any evidence found inadmissible in a court of law

96.

Adam, a forensic analyst, is preparing VMs for analyzing a malware. Which of the following is NOT a best practice?

a)

Enabling shared folders

b)

Using network simulation tools

c)

Installing malware analysis tools

d)

Isolating the host device

97.

Which log file records details of files deleted from the Windows Recycle Bin?

a)

LOGINFO2

b)

LOGINFO1

c)

INFO2

d)

INFO1

98.

During an investigation of an XSS attack, the investigator comes across the term '[a-zA-Z0-9%]+' in analyzed evidence details. What is the expression used for?

a)

Checks for forward slash used in HTML closing tags, its hex or double-encoded hex equivalent

b)

Checks for upper and lower-case alphanumeric string inside the tag, or its hex representation

c)

Checks for opening angle bracket, hex or double-encoded hex equivalent

d)

Checks for closing angle bracket, hex or double-encoded hex equivalent

99.

Which among the following search warrants allows the first responder to search and seize the victim's computer components such as hardware, software, storage devices, and documentation?

a)

Service Provider Search Warrant

b)

Electronic Storage Device Search Warrant

c)

Citizen Informant Search Warrant

d)

John Doe Search Warrant

100.

Centralized binary logging is a process in which many websites write binary and unformatted log data to a single log file. What extension should the investigator look to find its log file?

a)

.cbl

b)

.log

c)

.ibl

d)

.txt

101.

Where should the investigator look for the Edge browser's browsing records, including history, cache, and cookies?

a)

Sparse files

b)

Slack Space

c)

ESE Database

d)

Virtual Memory

102.

Which of the following setups should a tester choose to analyze malware behavior?

a)

A normal system with internet connection

b)

A normal system without internet connect

c)

A virtual system with internet connection

d)

A virtual system with network simulation for internet connection

103.

A Linux system is undergoing investigation. In which directory should the investigators look for its current state data if the system is in powered on state?

a)

/auth

b)

/var/spool/cron/

c)

/proc

d)

/var/log/debug