WorksheetsComputer Forensics Quiz
Total questions: 40
Worksheet time: 20mins
Which best describes Computer Forensics?
Preventing cyber attacks
Recovering lost data only
Scientific examination of digital evidence
Monitoring live networks
Which of the following differentiates computer crime from unauthorized activity?
Presence of malware
Use of the internet
Legal violation and intent
Use of encryption
Which is NOT one of the six phases of computer forensics?
Identification
Preservation
Prosecution
Documentation
Why is evidence preservation critical in forensics?
To speed investigation
To prevent modification of evidence
To encrypt data
To reduce storage usage
Which activity comes under pre-incident preparation?
Hash comparison
Evidence analysis
Incident response planning
Disk imaging
The chain of custody ensures:
Encryption of evidence
Confidentiality of data
Integrity and accountability of evidence
Faster investigation
Which document records movement and handling of evidence?
Incident response plan
Evidence checkout log
Hash report
Case summary
What is the role of a first responder in digital forensics?
Perform deep analysis
Present evidence in court
Secure and preserve the scene
Prosecute the suspect
Why is forensic duplication preferred over direct analysis?
Faster access
Lower cost
Avoids altering original evidence
Improves encryption
Which is a common forensic mistake?
Using write blockers
Imaging disks
Analyzing original media
Documenting steps
Hexadecimal notation is mainly used because it:
Is easier to memorize
Maps directly to binary data
Encrypts data
Compresses files
Which tool is most suitable for file header analysis?
Network sniffer
Hash calculator
Hex editor
Packet analyzer
Hashing in forensics is mainly used to:
Encrypt files
Reduce file size
Verify integrity
Detect malware
What does MD5 hash collision imply?
Faster hashing
Same hash for different inputs
Encrypted output
Key reuse
What is bit rot?
Disk encryption failure
Gradual data corruption over time
Malware infection
Hash collision
Standard Operating Procedures (SOPs) ensure:
Faster tools
Legal consistency and repeatability
Higher encryption
Automatic evidence collection
Why are write blockers used during acquisition?
Speed up imaging
Encrypt evidence
Prevent modification of source media
Compress disk data
Which forensic concern directly impacts privacy?
Hash calculation
Evidence storage
Scope of data collection
Disk imaging speed
Live system forensics is required when investigating:
Formatted disks
Powered-off systems
Volatile memory artifacts
Archived backups
Which area does mobile forensics mainly deal with?
Network traffic
Desktop applications
Smartphones and embedded devices
Servers only
Which element of the CIA triad ensures data is not altered?
Confidentiality
Availability
Integrity
Authentication
Which attack exploits weak key management?
Brute force
Man-in-the-middle
Replay
Side-channel
Which encryption uses the same key for encryption and decryption?
RSA
ECC
Symmetric encryption
Asymmetric encryption
Which algorithm is asymmetric?
AES
DES
RSA
RC5
Why is AES preferred over DES?
Simpler structure
Larger key size and stronger security
Uses public keys
Faster hashing
The primary purpose of Diffie–Hellman is:
Encrypt data
Exchange keys securely
Generate hashes
Create digital certificates
Which cryptographic attack exploits repeated ciphertext patterns?
Frequency analysis
Replay attack
Collision attack
Oracle attack
HMAC provides:
Confidentiality only
Integrity and authentication
Non-repudiation
Encryption
Which PKI component issues digital certificates?
RA
CA
OCSP
CRL
Which trust model is commonly used in enterprises?
Web of Trust
Peer-to-Peer
Hierarchical Trust
Mesh Trust
What is the purpose of CRL?
Encrypt certificates
Revoke compromised certificates
Issue new certificates
Verify identities
Which protocol checks certificate status in real time?
CA
LDAP
OCSP
PKCS
Digital signatures primarily provide:
Confidentiality
Integrity and non-repudiation
Availability
Compression
Why is time-stamping important in PKI?
Improves encryption
Reduces key size
Supports legal validity
Prevents brute force
Which standard defines cryptographic module security?
X.509
PKCS#12
FIPS 140-2
SHA-256
Why is ECC preferred in mobile devices?
Easier math
Smaller keys with strong security
No certificates needed
Faster hashing
Which authentication uses something you are?
Password
Smart card
Fingerprint
OTP
Which model follows “never trust, always verify”?
Kerberos
SSO
Zero Trust
LDAP
Which protocol secures emails using public-key cryptography?
TLS
SSL
PGP
IPSec
Which is the most common real-world PKI failure?
Weak algorithms
Certificate lifecycle mismanagement
Hash collision
Large key sizes
