Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

494-593

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

What is the purpose of using Obfuscator in malware?

a)

Avoid encryption while passing through a VPN

b)

Avoid detection by security mechanisms

c)

Propagate malware to other connected devices

d)

Execute malicious code in the system

2.

Which of the following commands shows you the username and IP address used to access the system via a remote login session and the type of client from which they are accessing the system?

a)

Net share

b)

Net config

c)

Net sessions

d)

Net stat

3.

Which of the following is a federal law enacted in the US to control the ways that financial institutions deal with the private information of individuals?

a)

PCI DSS

b)

GLBA

c)

HIPAA 1996

d)

SOX

4.

UEFI is a specification that defines a software interface between an OS and platform firmware. Where does this interface store information about files present on a disk?

a)

BIOS-MBR

b)

BIOS Parameter Block

c)

GUID Partition Table (GPT)

d)

Master Boot Record (MBR)

5.

You are working as an independent computer forensics investigator and received a call from a systems administrator for a local school system requesting your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer Lab. When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a 'simple backup copy' of the hard drive in the PC and put it on this drive and requests that you examine the drive for evidence of the suspected images. You inform him that a 'simple backup copy' will not provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future proceeding?

a)

Robust copy

b)

Bit-stream copy

c)

Incremental backup copy

d)

Full backup copy

6.

Which of the following network attacks refers to sending huge volumes of email to an address in an attempt to overflow the mailbox or overwhelm the server where the email address is hosted so as to cause a denial-of-service attack?

a)

Email spoofing

b)

Mail bombing

c)

Phishing

d)

Email spamming

7.

Gill is a computer forensics investigator who has been called upon to examine a seized computer. This computer, according to the police, was used by a hacker who gained access to numerous banking institutions to steal customer information. After preliminary investigations, Gill finds in the computer’s log files that the hacker was able to gain access to these banks through the use of Trojan horses. The hacker then used these Trojan horses to obtain remote access to the companies’ domain controllers. From this point, Gill found that the hacker pulled off the SAM files from the domain controllers to then attempt and crack network passwords. What is the most likely password cracking technique used by this hacker to break the user passwords from the SAM files?

a)

Hybrid attack

b)

Dictionary attack

c)

Brute force attack

d)

Syllable attack

8.

An attacker has compromised a cloud environment of a company and used the employee information to perform an identity theft attack. Which type of attack is this?

a)

Cloud as a service

b)

Cloud as an object

c)

Cloud as a tool

d)

Cloud as a subject

9.

In which implementation of RAID will the image of a Hardware RAID volume be different from the image taken separately from the disks?

a)

RAID 0

b)

The images will always be identical because data is mirrored for redundancy

c)

It will always be different

d)

RAID 1

10.

One technique for hiding information is to change the file extension from the correct one to the one that might not be noticed by an investigator. For example, [1] extension?

a)

The sector map

b)

The file header

c)

The File Allocation Table

d)

The file footer

11.

An investigator enters the command sqlcmd -S WIN-CQQMK62867E -e -s", -E as part of collecting the primary data file and logs from a database. What does the "WIN-CQQMK62867E" represent?

a)

Name of SQL Server

b)

Network credentials of the database

c)

Operating system of the system

d)

Name of the Database

12.

During the trial, an investigator observes that one of the principal witnesses is severely ill and cannot be present for the hearing. He decides to record the evidence and present it to the court. Under which rule should he present such evidence?

a)

Locard's Principle

b)

Rule 1003: Admissibility of Duplicates

c)

Hearsay

d)

Limited admissibility

13.

What is cold boot (hard boot)?

a)

It is the process of shutting down a computer from a powered-on or on state

b)

It is the process of restarting a computer that is already in sleep mode

c)

It is the process of starting a computer from a powered-down or off state

d)

It is the process of restarting a computer that is already turned on through the operating system

14.

Which of the following malware analysis involves executing the malware code to know how the code interacts with the host system and its impact on the system?

a)

Dynamic Malware Analysis

b)

Static Malware Analysis

c)

Secondary Malware Analysis

d)

Primary Malware Analysis

15.

Which among the following laws emphasizes the need for each Federal agency to develop, document, and implement an organization-wide program to provide information security for the information systems that support its operations and assets?

a)

SOX

b)

GLBA

c)

HIPAA

d)

FISMA

16.

Which of the following techniques delete the files permanently?

a)

Trail obfuscation

b)

Artifact Wiping

c)

Steganography

d)

Data Hiding

17.

What is an investigator looking for in the rp.log file stored in a system running on Windows 10 operating system?

a)

Restore point functions

b)

System CheckPoints required for restoring

c)

Restore point interval

d)

Automatically created restore points

18.

Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive. Which of the following statements is correct while dealing with local archives?

a)

Server storage archives are the server information and settings stored on a local system, whereas the local archives are the local email client information stored on the mail server

b)

It is difficult to deal with the webmail as there is no offline archive in most cases. So consult your counsel on the case as to the best way to approach and gain access to the required data on servers

c)

Local archives should be stored together with the server storage archives in order to be admissible in a court of law

d)

Local archives do not have evidentiary value as the email client may alter the message data

19.

Which of the following tool is used to locate IP addresses?

a)

Towelroot

b)

XRY LOGICAL

c)

SmartWhois

d)

Deep Log Analyzer

20.

Which of the following protocols allows non-ASCII files, such as video, graphics, and audio, to be sent through the email messages?

a)

BINHEX

b)

MIME

c)

UT-16

d)

UUCODE

21.

What is the framework used for application development for iOS-based mobile devices?

a)

Zygote

b)

Dalvik

c)

Cocoa Touch

d)

AirPlay

22.

Chong-lee, a forensics executive, suspects that a malware is continuously making copies of files and folders on a victim system to consume the available disk space. What type of test would confirm his claim?

a)

Static analysis

b)

Identifying file obfuscation

c)

File fingerprinting

d)

Dynamic analysis

23.

Which of the following tools is not a data acquisition hardware tool?

a)

UltraKit

b)

Atola Insight Forensic

c)

F-Response Imager

d)

Triage-Responder

24.

The given image displays information about date and time of installation of the OS along with service packs, patches, and sub-directories. What command or tool did the investigator use to view this output?

a)

dir /o:d

b)

dir /o:s

c)

dir /o:e

d)

dir /o:n

25.

Which list contains the most recent actions performed by a Windows User?

a)

Activity

b)

Windows Error Log

c)

MRU

d)

Recents

26.

Joshua is analyzing an MSSQL database for finding the attack evidence and other details, where should he look for the database logs?

a)

Model.txt

b)

Model.log

c)

Model.ldf

d)

Model.lgf

27.

What is the name of the first reserved sector in File allocation table?

a)

Master Boot Record

b)

Partition Boot Sector

c)

Volume Boot Record

d)

BIOS Parameter Block

28.

What does the command 'C:\>wevtutil gl ' display?

a)

Configuration information of a specific Event Log

b)

Event logs are saved in .xml format

c)

Event log record structure

d)

List of available Event Logs

29.

An investigator is analyzing a checkpoint firewall log and comes across symbols. What type of log is he looking at?

a)

Connection rejected

b)

An email marked as potential spam

c)

Security event was monitored but not stopped

d)

Malicious URL detected

30.

For what purpose do the investigators use tools like iPhoneBrowser, iFunBox, OpenSSHSSH, and iMazing?

a)

Rooting iPhone

b)

Debugging iPhone

c)

Copying contents of iPhone

d)

Bypassing iPhone passcode

31.

In a computer that has Dropbox client installed, which of the following files related to the Dropbox client store information about local Dropbox installation and the Dropbox user account, along with email IDs linked with the account?

a)

filecache.db

b)

config.db

c)

install.db

d)

sigstore.db

32.

Robert is a regional manager working in a reputed organization. One day, he suspected malware attack after unwanted programs started to popup after logging into his computer. The network administrator was called upon to trace out any intrusion on the computer and he/she finds that suspicious activity has taken place within Autostart locations. In this situation, which of the following tools is used by the network administrator to detect any intrusion on a system?

a)

Process Monitor

b)

Report Viewer

c)

Internet Evidence Finder

d)

Hex Editor

33.

What do you call the process of studying the changes that have taken place across a system or a machine after a series of actions or incidents?

a)

Host integrity Monitoring

b)

Windows Services Monitoring

c)

Start-up Programs Monitoring

d)

System Baselining

34.

Self-Monitoring, Analysis, and Reporting Technology (SMART) is built into the hard drives to monitor and report system activity. Which of the following is included in the report generated by SMART?

a)

List of running processes

b)

All the states (running and discontinued) associated with the OS

c)

Logs of high temperatures the drive has reached

d)

Power Off time

35.

Data Files contain Multiple Data Pages, which are further divided into Page Header, Data Rows, and Offset Table. Which of the following is true for Data Rows?

a)

Data Rows store the actual data

b)

Data Rows spreads data across multiple databases

c)

Data Rows point to the location of actual data

d)

Data Rows present Page type, Page ID, and so on

36.

In Windows, prefetching is done to improve system performance. There are two types of prefetching: boot prefetching and application prefetching. During boot prefetching, what does the Cache Manager do?

a)

Determines the data associated with value EnablePrefetcher

b)

Checks hard page faults and soft page faults

c)

Monitors the first 10 seconds after the process is started

d)

Checks whether the data is processed

37.

The MAC attributes are timestamps that refer to a time at which the file was last modified or last accessed or originally created. Which of the following file systems store MAC attributes in Coordinated Universal Time (UTC) format?

a)

Hierarchical File System (HFS)

b)

File Allocation Table (FAT)

c)

New Technology File System (NTFS)

d)

Global File System (GFS)

38.

Robert, a cloud architect, received a huge bill from the cloud service provider, which usually doesn't happen. After analyzing the bill, he found that the cloud resource consumption was very high. He then examined the cloud server and discovered that a malicious code was running on the server, which was generating huge but harmless traffic from the server. This means that the server has been compromised by an attacker with the sole intention to hurt the cloud customer financially. Which attack is described in the above scenario?

a)

XSS Attack

b)

DDoS Attack (Distributed Denial of Service)

c)

Man-in-the-cloud Attack

d)

EDoS Attack (Economic Denial of Service)

39.

What is the role of Alloc.c in Apache core?

a)

It handles server start-ups and timeouts

b)

It handles allocation of resource pools

c)

It is useful for reading and handling of the configuration files

d)

It takes care of all the data exchange and socket connections between the client and the server

40.

Which of the following statements is true regarding SMTP Server?

a)

SMTP Server breaks the recipient's address into Recipient's name and his/her designation before passing it to the DNS Server

b)

SMTP Server breaks the recipient's address into Recipient's name and recipient's address before passing it to the DNS Server

c)

SMTP Server breaks the recipient's address into Recipient's name and domain name before passing it to the DNS Server

d)

SMTP Server breaks the recipient's address into Recipient's name and his/her initial before passing it to the DNS Server

41.

Which ISO Standard enables laboratories to demonstrate that they comply with quality assurance and provide valid results?

a)

ISO/IEC 17025

b)

ISO/IEC 19025

c)

ISO/IEC 18025

d)

ISO/IEC 16025

42.

Which type of attack is possible when attackers know some credible information about the victim's password, such as the password length, algorithms involved, or the strings and characters used in its creation?

a)

Dictionary Attack

b)

Brute-Forcing Attack

c)

Hybrid Password Guessing Attack

d)

Rule-Based Attack

43.

In which of these attacks will a steganalyst use a random message to generate a stego-object by using some steganography tool, to find the steganography algorithm used to hide the information?

a)

Known-message attack

b)

Known-cover attack

c)

Chosen-message attack

d)

Known-stego attack

44.

Which of these Windows utility help you to repair logical file system errors?

a)

Resource Monitor

b)

Disk cleanup

c)

Disk defragmenter

d)

CHKDSK

45.

Identify the term that refers to individuals who, by virtue of their knowledge and expertise, express an independent opinion on a matter related to a case based on the information that is provided.

a)

Defense Witness

b)

Forensic Examiner

c)

Evidence Examiner

d)

Expert Witness

46.

Steve, a forensic investigator, was asked to investigate an email incident in his organization. The organization has Microsoft Exchange Server deployed for email communications. Which among the following files will Steve check to analyze message headers, message text, and standard attachments?

a)

PUB.STM

b)

PRIV.STM

c)

PUB.EDB

d)

PRIV.EDB

47.

Which of the following information is displayed when Netstat is used with -ano switch?

a)

Details of routing table

b)

Details of TCP and UDP connections

c)

Ethernet statistics

d)

Contents of IP routing table

48.

While collecting Active Transaction Logs using SQL Server Management Studio, the query Select * from ::fn_dblog(NULL, NULL) displays the active portion of the transaction log file. Here, assigning NULL values implies?

a)

Start and end points for log files are specified

b)

Start and end points for log files are not specified

c)

Start and end points for log sequence numbers are specified

d)

Start and end points for log sequence numbers are not specified

49.

Which of the following statements is TRUE with respect to the Registry settings in the user startup folder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\

a)

All the values in this subkey run when specific user logs on, as this setting is user-specific

b)

The string specified in the value run executes when user logs on

c)

All values in this subkey run when specific user logs on and then the values are deleted

d)

All the values in this key are executed at system start-up

50.

Which cloud model allows an investigator to acquire the instance of a virtual machine and initiate the forensics examination process?

a)

IaaS model

b)

PaaS model

c)

SaaS model

d)

SecaaS model

51.

An attacker successfully gained access to a remote Windows system and plans to install persistent backdoors on it. Before that, to avoid getting detected in future, he wants to cover his tracks by disabling the last-accessed timestamps of the machine. What would he do to achieve this?

a)

Run the command fsutil behavior set disablelastaccess 0

b)

Run the command fsutil behavior set enablelastaccess 0

c)

Set the registry value of HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 0

d)

Set the registry value of HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate to 1

52.

Which of the following web browser uses the Extensible Storage Engine (ESE) database format to store browsing records, including history, cache, and cookies?

a)

Microsoft Edge

b)

Mozilla Firefox

c)

Safari

d)

Google Chrome

53.

Which U.S. law sets the rules for sending emails for commercial purposes, establishes the minimum requirements for commercial messaging, gives the recipients of emails the right to ask the senders to stop emailing them, and spells out the penalties in case the above said rules are violated?

a)

NO-SPAM Act

b)

American: DoD 5220.22-M

c)

American: NAVSO P-5239-26 (RLL)

d)

CAN-SPAM Act

54.

Which of the following statements is TRUE about SQL Server error logs?

a)

Trace files record, user-defined events, and specific system events

b)

Error logs contain IP address of SQL Server client connections

c)

Forensic investigator uses SQL Server Profiler to view error log files

d)

SQL Server error logs record all the events occurred on the SQL Server and its databases

55.

Which among the following tools can help a forensic investigator to access the registry files during postmortem analysis?

a)

RegistryChangesView

b)

RegRipper

c)

RegDllView

d)

ProDiscover

56.

Consider that you are investigating a machine running an Windows OS released prior to Windows Vista. You are trying to gather information about the deleted files by examining the master database file named INFO2 located at C:\Recycler\\. You read an entry named "Dd5.exe". What does Dd5.exe mean?

a)

D drive, fifth file deleted, a .exe file

b)

D drive, fourth file deleted, a .exe file

c)

D drive, fourth file restored, a .exe file

d)

D drive, sixth file deleted, a .exe file

57.

Which Linux command when executed displays kernel ring buffers or information about device drivers loaded into the kernel?

a)

fsck

b)

dmesg

c)

pgrep

d)

grep

58.

A section of your forensics lab houses several electrical and electronic equipment. Which type of fire extinguisher you must install in this area to contain any fire incident?

a)

Class A

b)

Class B

c)

Class D

d)

Class C

59.

Checkpoint Firewall logs can be viewed through a Check Point Log viewer that uses icons and colors in the log table to represent different security events and their severity. What does the icon in the checkpoint logs represent?

a)

The firewall rejected a connection

b)

An email was marked as potential spam

c)

A virus was detected in an email

d)

The firewall dropped a connection

60.

In which cloud crime do attackers try to compromise the security of the cloud environment in order to steal data or inject a malware?

a)

Cloud as an Object

b)

Cloud as a Tool

c)

Cloud as an Application

d)

Cloud as a Subject

61.

POP3 is an Internet protocol used to retrieve emails from a mail server. Through which port does an email client connect with a POP3 server?

a)

993

b)

25

c)

143

d)

110

62.

James identifies a website vulnerability. He visits the login page, notes the session ID, appends it to the login URL, and shares the link. When the victim logs in using the shared URL, James reloads the page and can browse the victim’s active session. Which attack did James execute?

a)

Session Fixation Attack

b)

Parameter Tampering

c)

Cookie Tampering

d)

Cross Site Request Forgery

63.

Which Android architecture component is responsible for displaying windows owned by different applications?

a)

Application Framework

b)

Media Framework

c)

Surface Manager

d)

Resource Manager

64.

Which web application threat results when developers expose internal implementation objects such as files, directories, database records, or key-through references?

a)

Insecure Direct Object References

b)

Cross Site Request Forgery

c)

Remote File Inclusion

d)

Cross Site Scripting

65.

What does Locard’s Exchange Principle state?

a)

Probative digital information must be disclosed

b)

Digital evidence must have court characteristics

c)

Entering a scene takes something and leaves something

d)

Forensics faces many digital investigation challenges

66.

A company begins a network vulnerability assessment. What is the first step the team should take to create the assessment plan?

a)

Make a hypothesis of final findings

b)

Create an initial Executive report

c)

Analyze currently gathered company data

d)

Acquire documents and review security policies

67.

What is the location of a Protective MBR in a GPT disk layout?

a)

Logical Block Address (LBA) 2

b)

Logical Block Address (LBA) 0

c)

Logical Block Address (LBA) 1

d)

Logical Block Address (LBA) 3

68.

In Linux, what information can investigators obtain from the log file /var/log/dmesg?

a)

Kernel ring buffer information

b)

All mail server message logs

c)

Global system messages

d)

Debugging log messages

69.

Which Windows registry hive contains configuration information related to the application type used to open various files on the system?

a)

HKEY_LOCAL MACHINE

b)

HKEY_CLASSES_ROOT

c)

HKEY_CURRENT_CONFIG

d)

HKEY_CURRENT_USER

70.

Which ISO standard defines the file system for optical storage media such as CD-ROM?

a)

ISO 9660

b)

ISO 27001

c)

ISO 15408

d)

ISO 8859-1

71.

Which of the following Linux command searches through the current processes and lists the process IDs those match the selection criteria to stdout?

a)

grep

b)

ps

c)

pgrep

d)

pstree

72.

Which forensic investigation methodology believes that criminals commit crimes solely to benefit their criminal enterprises?

a)

Enterprise Theory of Investigation

b)

Daubert Standard

c)

Scientific Working Group on Digital Evidence

d)

Fyre Standard

73.

Which of these rootkit detection techniques function by comparing a snapshot of the file system, boot records, or memory with a known and trusted baseline?

a)

Heuristic/Behavior-Based Detection

b)

Cross View-Based Detection

c)

Integrity-Based Detection

d)

Signature-Based Detection

74.

Which program uses different techniques to conceal a malware's code, thereby making it difficult for security mechanisms to detect or remove it?

a)

Dropper

b)

Packer

c)

Obfuscator

d)

Injector

75.

What do the bytes 0x0B-0x53 represent in the boot sector of NTFS volume on Windows 2000?

a)

Jump instruction and the OEM ID

b)

BIOS Parameter Block (BPB) and the OEM ID

c)

BIOS Parameter Block (BPB) and the extended BPB

d)

Bootstrap code and the end of the sector marker

76.

What does the Rule 101 of Federal Rules of Evidence states?

a)

Purpose of the Rules

b)

Limited Admissibility of the Evidence

c)

Scope of the Rules, where they can be applied

d)

Rulings on Evidence

77.

What document does the screenshot represent?

a)

Evidence collection form

b)

Chain of custody form

c)

Search warrant form

d)

Expert witness form

78.

You are asked to build a forensic lab and your manager has specifically informed you to use copper for lining the walls, ceilings, and floor. What is the main purpose of lining the walls, ceilings, and floor with copper?

a)

To make the lab sound proof

b)

To avoid electromagnetic emanations

c)

To strengthen the walls, ceilings, and floor

d)

To control the room temperature

79.

James is dealing with a case regarding a cybercrime that has taken place in Arizona, USA. James needs to lawfully seize the evidence from an electronic device without affecting the user's anonymity. Which of the following law should he comply with, before retrieving the evidence?

a)

Third Amendment of the U.S. Constitution

b)

Fourth Amendment of the U.S. Constitution

c)

First Amendment of the U.S. Constitution

d)

Fifth Amendment of the U.S. Constitution

80.

Which of the following stand true for BIOS Parameter Block?

a)

Is the first sector of a data storage device

b)

Always refers to the 512-byte boot sector

c)

Describes the physical layout of a data storage volume

d)

Length remains the same across all file systems

81.

Which Event Correlation approach assumes and predicts what an attacker can do next after the attack by studying statistics and probability?

a)

Heuristic Profiling

b)

Temporal Sequencing

c)

Bayesian Correlation

d)

Signature Matching

82.

MAC filtering is a security access control methodology, where a __________ is assigned to each network card to determine access to the network.

a)

24-bit address

b)

32-bit address

c)

48-bit address

d)

16-bit address

83.

Which of the following files store the MySQL database data permanently, including data that had been deleted, helping investigation?

a)

mysql-bin

b)

mysql-log

c)

iblog

d)

ibdata1

84.

Which tool allows dumping the contents of process memory without stopping the process?

a)

psdump.exe

b)

pmdump.exe

c)

processdump.exe

d)

pdump.exe

85.

Which component in the hard disk moves over the platter to read and write information?

a)

Head

b)

Actuator

c)

Spindle

d)

Actuator Axis

86.

A log entry reads 192.168.0.1 - - [18/Jan/2020:12:42:29 +0000] "GET / HTTP/1.1" 200 1861. Which log format does it belong to?

a)

The common log format of Apache access log

b)

IIS log

c)

The combined log format of Apache access log

d)

Apache error log

87.

In a Filesystem Hierarchy Standard (FHS), which directory contains the binary files required for working?

a)

/mnt

b)

/sbin

c)

/proc

d)

/media

88.

A computer has a failed OS install and damaged MBR/partition sector. Which tool can find and restore files and information on the disk?

a)

R-Studio

b)

Helix

c)

Wireshark

d)

NetCat

89.

There is a file named myfile.txt on C: that contains hidden data streams. Which command displays the contents of a data stream?

a)

echo text > program:source_file

b)

myfile.dat:stream1

c)

C:\>ECHO text_message > myfile.txt:stream1

d)

C:\>MORE < myfile.txt:stream1

90.

Cybercriminals use compromised computers to commit other crimes and may prevent a company from providing a service to its customers. Which type of cybercrime does this describe?

a)

Ransomware attack

b)

Malware attack

c)

Phishing

d)

Denial-of-Service attack

91.

A MySQL server on Windows named WIN-DTRAI83202X was attacked. To retrieve information on changes made to the database, which file should be examined?

a)

WIN-DTRAI83202Xslow.log

b)

relay-log.info

c)

mysql.ini

d)

WIN-DTRAI83202X-bin.nnnnnn

92.

Which OWASP IoT vulnerability talks about security flaws such as lack of firmware validation, lack of secure delivery, and lack of anti-rollback mechanisms on IoT devices?

a)

Insecure default settings

b)

Use of insecure or outdated components

c)

Lack of secure update mechanism

d)

Insecure data transfer and storage

93.

Which of the following malware targets Android mobile devices and installs a backdoor that remotely installs applications from an attacker-controlled server?

a)

xHelper

b)

Unflod

c)

Felix

d)

XcodeGhost

94.

Which of the following tools is used to dump the memory of a running process, either immediately or when an error condition occurs?

a)

CacheInf

b)

FATKit

c)

Belkasoft Live RAM Capturer

d)

Coreography

95.

Which Federal Rule of Evidence speaks about the Hearsay exception where the availability of the declarant is immaterial and certain characteristics of the declarant such as present sense impression, excited utterance, and recorded recollection are also observed while giving their testimony?

a)

Rule 801

b)

Rule 802

c)

Rule 803

d)

Rule 804

96.

Williamson is a forensic investigator. While investigating a case of data breach at a company, he is maintaining a document that records details such as the forensic processes applied on the collected evidence, particulars of people handling it, the dates and times when it is being handled, and the place of storage of the evidence. What do you call this document?

a)

Consent form

b)

Authorization form

c)

Chain of custody

d)

Log book

97.

Which of the following is a requirement for senders as per the CAN-SPAM act?

a)

Senders must use deceptive subject lines

b)

Emails must not contain information regarding how to stop receiving emails from the sender in future

c)

Senders should never share their physical postal address in the email

d)

Senders cannot use misleading or false header information

98.

Donald made an OS disk snapshot of a compromised Azure VM under a resource group used by the affected company as a part of forensic analysis process. He then created a vhd file out of the snapshot and stored it in a file share and as a page blob as backup in a storage account under different region. What is the next thing he should do as a security measure?

a)

Create another VM by using the snapshot

b)

Delete the snapshot from the source resource group

c)

Delete the OS disk of the affected VM altogether

d)

Recommend changing the access policies followed by the company

99.

Identify the location of Recycle Bin on a Windows 7 machine that uses NTFS file system to store and retrieve files on the hard disk.

a)

C:\RECYCLED

b)

Drive:\$Recycle.Bin

c)

Drive:\RECYCLED

d)

Drive:\RECYCLEr

100.

Which "Standards and Criteria" under SWDGE states that "the agency must use hardware and software that are appropriate and effective for the seizure or examination procedure"?

a)

Standards and Criteria 1.6

b)

Standards and Criteria 1.5

c)

Standards and Criteria 1.7

d)

Standards and Criteria 1.4