NEW
Font size
WorksheetsComputer Forensics Quiz
Total questions: 40
Worksheet time: 20mins
Computer forensics is best described as:
Preventing cyber attacks
Monitoring network traffic
Scientific examination of digital evidence
Recovering deleted files only
Which differentiates computer crime from unauthorized activity?
Use of malware
Internet involvement
Legal violation with intent
Use of encryption
Which is NOT a phase of computer forensics?
Identification
Preservation
Prosecution
Documentation
Why is preservation the first priority in forensics?
To speed investigation
To prevent evidence alteration
To encrypt data
To compress files
Which activity belongs to pre-incident preparation?
Disk imaging
Hash verification
Incident response planning
Evidence analysis
Chain of custody mainly ensures:
Confidentiality
Encryption
Integrity and accountability
Faster acquisition
Which document tracks who handled evidence and when?
Incident response plan
Evidence checkout log
Hash report
Case summary
The first responder should primarily:
Analyze evidence
Present findings in court
Secure and preserve the scene
Prosecute the suspect
Why is analyzing original evidence discouraged?
Slower performance
Legal restriction
Risk of modification
Larger storage
Which is a common forensic mistake?
Using write blockers
Maintaining logs
Analyzing original media
Creating images
Which best describes incident detection?
Evidence examination
Identifying suspicious events
Prosecution of attacker
Data recovery
Which comes under incident response team responsibility?
Court testimony
Evidence encryption
Containment and recovery
Writing laws
What is the primary goal of forensic investigation?
Punish attacker
Recover maximum data
Establish facts legally
Monitor networks
Which activity ensures evidence can be reproduced later?
Encryption
Documentation
Compression
Deletion
Which evidence property ensures it is unaltered?
Availability
Confidentiality
Integrity
Volatility
Which is considered digital evidence?
Printed report
CCTV camera
Log files
Keyboard
Incident response should begin:
After investigation
After court approval
As soon as incident is detected
After disk imaging
Which principle avoids contamination of evidence?
Least privilege
Write protection
Data compression
Encryption
Why is documentation critical in forensics?
Improves speed
Helps hashing
Supports legal admissibility
Reduces storage
Which role decides scope of investigation initially?
Forensic analyst
First responder
Incident manager
Legal counsel
Which CIA triad component ensures data is not altered?
Confidentiality
Availability
Integrity
Authentication
Which is an example of a passive attack?
DoS
Data modification
Eavesdropping
Spoofing
Which encryption uses the same key for both operations?
RSA
ECC
Symmetric
Asymmetric
File encryption mainly protects:
Availability
Integrity
Confidentiality
Authentication
Which algorithm is symmetric?
RSA
AES
ECC
Diffie–Hellman
Which algorithm is asymmetric?
DES
AES
RSA
RC5
Why is asymmetric encryption slower?
Smaller keys
Mathematical complexity
Hashing
Padding
Which is NOT a goal of cryptography?
Confidentiality
Integrity
Non-repudiation
Compression
Which threat targets confidentiality?
DoS
Eavesdropping
Spoofing
Replay
Why are encryption folders used?
Disk formatting
User authentication
Data confidentiality
File recovery
Which tool is commonly used in labs for crypto learning?
Wireshark
Metasploit
CrypTool
Nmap
What does Diffie–Hellman achieve?
Digital signatures
Key exchange
Hashing
Encryption
Which attack targets encryption implementation flaws?
Brute force
Cryptographic attack
DoS
Phishing
Which cryptographic property ensures sender identity?
Confidentiality
Integrity
Authentication
Availability
Which key must remain secret in asymmetric crypto?
Public key
Session key
Private key
Hash key
Which encryption is suitable for bulk data?
RSA
ECC
Symmetric
Asymmetric
Which security attack modifies data?
Passive attack
Active attack
Interception
Traffic analysis
Which mechanism ensures message has not changed?
Encryption
Hashing
Compression
Encoding
Which encryption is typically used for file systems?
Asymmetric
Symmetric
Hash-based
Token-based
Why is encryption alone not sufficient?
Too slow
Does not ensure integrity & authentication
Large keys
Hard to implement
