WorksheetsForensics and PKI Quiz
Total questions: 40
Worksheet time: 20mins
Standard Operating Procedures (SOPs) in forensics mainly ensure:
Faster investigations
Repeatability and legal defensibility
Encryption of evidence
Automatic reporting
Why are SOPs important in court proceedings?
They reduce workload
They show investigator experience
They demonstrate standardized methodology
They improve tool performance
Which concern directly relates to privacy in cyber forensics?
Hash length
Disk imaging speed
Scope of data collection
File system type
Accreditation standards in forensic labs mainly ensure:
Use of proprietary tools
Legal compliance and quality assurance
Faster analysis
Lower investigation cost
Which activity must balance forensic needs and privacy rights?
Hash calculation
Evidence storage
Data acquisition
Disk cloning
Which tool suite is commonly used to analyze running Windows systems?
FTK
Sysinternals Suite
Autopsy
Nmap
Which Sysinternals tool is used to view running processes?
Procmon
Autoruns
Process Explorer
PsExec
FTK Imager is primarily used for:
Malware analysis
Network sniffing
Forensic imaging and preview
Password cracking
Which FTK feature allows previewing files without modifying evidence?
Hash engine
Evidence tree
File viewer
Registry parser
Which forensic tool is best suited for registry analysis?
Wireshark
FTK
OpenSSL
CrypTool
Why are write blockers mandatory during forensic acquisition?
Increase speed
Prevent OS-level writes
Encrypt evidence
Compress files
Which forensic task is typically done using Cyber Check Suite?
Packet capture
Disk encryption
Evidence analysis workflow
Live malware execution
Which OS artifact is crucial during Linux forensics?
Windows Registry
Event Viewer
/var/log files
NTUSER.DAT
Which command is commonly used to view running processes on Linux?
ls
grep
ps
chmod
Live forensics is particularly useful for analyzing:
Archived backups
Deleted files
Volatile memory
Optical disks
Which forensic implication arises if evidence is collected beyond scope?
Faster investigation
Violation of privacy laws
Improved accuracy
Better documentation
Which type of investigation often requires legal authorization?
Internal corporate audit
Criminal investigation
Training simulation
Academic research
Why is documentation emphasized in forensic tools usage?
Tool limitation
Legal admissibility
Encryption requirement
Storage optimization
Which forensic tool helps capture memory dumps?
FTK Imager
Process Explorer
Wireshark
CrypTool
Which forensic phase involves interpreting findings?
Identification
Preservation
Analysis
Documentation
Which PKI component binds identity to a public key?
Hash
Digital certificate
Symmetric key
Token
Who is responsible for issuing digital certificates?
RA
CA
OCSP
CRL
What is the primary role of a Registration Authority (RA)?
Encrypt data
Verify identity before certificate issuance
Revoke certificates
Generate hashes
Which trust model is most commonly used in organizations?
Web of Trust
Peer-to-peer
Hierarchical trust
Distributed trust
Which mechanism lists revoked certificates periodically?
CA
OCSP
CRL
PKCS
Which protocol provides real-time certificate status checking?
LDAP
OCSP
CRL
X.509
Why is OCSP preferred over CRL in many environments?
Smaller key size
Real-time verification
Stronger encryption
Offline availability
Which type of certificate is typically used for secure websites?
Email certificate
Code-signing certificate
SSL/TLS certificate
Root certificate
Which certificate is self-signed?
End-entity certificate
Intermediate certificate
Root certificate
Server certificate
Which lab tool is used to create a CA and certificates in PKI labs?
OpenSSL
FTK
XCA
CrypTool
What does PKCS stand for?
Public Key Control Standard
Private Key Cryptographic System
Public Key Cryptography Standards
Protected Key Certificate System
Which standard defines cryptographic module security requirements?
X.509
PKCS#7
FIPS 140-2
SHA-256
Which PKI service ensures proof that a document existed at a certain time?
Digital signature
Hashing
Time-stamping
Encryption
Aadhaar-based e-Sign primarily provides:
Confidentiality
Integrity and authentication
Availability
Compression
Which lab activity involves digitally signing documents?
FTK Imager
Wireshark
XCA
Sysinternals
What happens when a certificate is revoked?
It is deleted permanently
It becomes invalid before expiry
It is reissued automatically
Public key changes
Which PKI element establishes the root of trust?
End-entity certificate
Intermediate CA
Root CA
OCSP responder
Why is certificate revocation critical?
Improves performance
Prevents use of compromised keys
Reduces storage
Speeds encryption
Which PKI failure is most common in real organizations?
Weak cryptography
Certificate lifecycle mismanagement
Hash collision
Large key sizes
Which PKI concept ensures trust flows from root to end entity?
Key exchange
Trust chain
Symmetric encryption
Hashing
