Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Computer Forensics Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which best describes Computer Forensics?

a)

Preventing cyber attacks

b)

Recovering lost data only

c)

Scientific examination of digital evidence

d)

Monitoring live networks

2.

Which of the following differentiates computer crime from unauthorized activity?

a)

Presence of malware

b)

Use of the internet

c)

Legal violation and intent

d)

Use of encryption

3.

Which is NOT one of the six phases of computer forensics?

a)

Identification

b)

Preservation

c)

Prosecution

d)

Documentation

4.

Why is evidence preservation critical in forensics?

a)

To speed investigation

b)

To prevent modification of evidence

c)

To encrypt data

d)

To reduce storage usage

5.

Which activity comes under pre-incident preparation?

a)

Hash comparison

b)

Evidence analysis

c)

Incident response planning

d)

Disk imaging

6.

The chain of custody ensures:

a)

Encryption of evidence

b)

Confidentiality of data

c)

Integrity and accountability of evidence

d)

Faster investigation

7.

Which document records movement and handling of evidence?

a)

Incident response plan

b)

Evidence checkout log

c)

Hash report

d)

Case summary

8.

What is the role of a first responder in digital forensics?

a)

Perform deep analysis

b)

Present evidence in court

c)

Secure and preserve the scene

d)

Prosecute the suspect

9.

Why is forensic duplication preferred over direct analysis?

a)

Faster access

b)

Lower cost

c)

Avoids altering original evidence

d)

Improves encryption

10.

Which is a common forensic mistake?

a)

Using write blockers

b)

Imaging disks

c)

Analyzing original media

d)

Documenting steps

11.

Hexadecimal notation is mainly used because it:

a)

Is easier to memorize

b)

Maps directly to binary data

c)

Encrypts data

d)

Compresses files

12.

Which tool is most suitable for file header analysis?

a)

Network sniffer

b)

Hash calculator

c)

Hex editor

d)

Packet analyzer

13.

Hashing in forensics is mainly used to:

a)

Encrypt files

b)

Reduce file size

c)

Verify integrity

d)

Detect malware

14.

What does MD5 hash collision imply?

a)

Faster hashing

b)

Same hash for different inputs

c)

Encrypted output

d)

Key reuse

15.

What is bit rot?

a)

Disk encryption failure

b)

Gradual data corruption over time

c)

Malware infection

d)

Hash collision

16.

Standard Operating Procedures (SOPs) ensure:

a)

Faster tools

b)

Legal consistency and repeatability

c)

Higher encryption

d)

Automatic evidence collection

17.

Why are write blockers used during acquisition?

a)

Speed up imaging

b)

Encrypt evidence

c)

Prevent modification of source media

d)

Compress disk data

18.

Which forensic concern directly impacts privacy?

a)

Hash calculation

b)

Evidence storage

c)

Scope of data collection

d)

Disk imaging speed

19.

Live system forensics is required when investigating:

a)

Formatted disks

b)

Powered-off systems

c)

Volatile memory artifacts

d)

Archived backups

20.

Which area does mobile forensics mainly deal with?

a)

Network traffic

b)

Desktop applications

c)

Smartphones and embedded devices

d)

Servers only

21.

Which element of the CIA triad ensures data is not altered?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Authentication

22.

Which attack exploits weak key management?

a)

Brute force

b)

Man-in-the-middle

c)

Replay

d)

Side-channel

23.

Which encryption uses the same key for encryption and decryption?

a)

RSA

b)

ECC

c)

Symmetric encryption

d)

Asymmetric encryption

24.

Which algorithm is asymmetric?

a)

AES

b)

DES

c)

RSA

d)

RC5

25.

Why is AES preferred over DES?

a)

Simpler structure

b)

Larger key size and stronger security

c)

Uses public keys

d)

Faster hashing

26.

The primary purpose of Diffie–Hellman is:

a)

Encrypt data

b)

Exchange keys securely

c)

Generate hashes

d)

Create digital certificates

27.

Which cryptographic attack exploits repeated ciphertext patterns?

a)

Frequency analysis

b)

Replay attack

c)

Collision attack

d)

Oracle attack

28.

HMAC provides:

a)

Confidentiality only

b)

Integrity and authentication

c)

Non-repudiation

d)

Encryption

29.

Which PKI component issues digital certificates?

a)

RA

b)

CA

c)

OCSP

d)

CRL

30.

Which trust model is commonly used in enterprises?

a)

Web of Trust

b)

Peer-to-Peer

c)

Hierarchical Trust

d)

Mesh Trust

31.

What is the purpose of CRL?

a)

Encrypt certificates

b)

Revoke compromised certificates

c)

Issue new certificates

d)

Verify identities

32.

Which protocol checks certificate status in real time?

a)

CA

b)

LDAP

c)

OCSP

d)

PKCS

33.

Digital signatures primarily provide:

a)

Confidentiality

b)

Integrity and non-repudiation

c)

Availability

d)

Compression

34.

Why is time-stamping important in PKI?

a)

Improves encryption

b)

Reduces key size

c)

Supports legal validity

d)

Prevents brute force

35.

Which standard defines cryptographic module security?

a)

X.509

b)

PKCS#12

c)

FIPS 140-2

d)

SHA-256

36.

Why is ECC preferred in mobile devices?

a)

Easier math

b)

Smaller keys with strong security

c)

No certificates needed

d)

Faster hashing

37.

Which authentication uses something you are?

a)

Password

b)

Smart card

c)

Fingerprint

d)

OTP

38.

Which model follows “never trust, always verify”?

a)

Kerberos

b)

SSO

c)

Zero Trust

d)

LDAP

39.

Which protocol secures emails using public-key cryptography?

a)

TLS

b)

SSL

c)

PGP

d)

IPSec

40.

Which is the most common real-world PKI failure?

a)

Weak algorithms

b)

Certificate lifecycle mismanagement

c)

Hash collision

d)

Large key sizes