wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Forensics and PKI Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Standard Operating Procedures (SOPs) in forensics mainly ensure:

a)

Faster investigations

b)

Repeatability and legal defensibility

c)

Encryption of evidence

d)

Automatic reporting

2.

Why are SOPs important in court proceedings?

a)

They reduce workload

b)

They show investigator experience

c)

They demonstrate standardized methodology

d)

They improve tool performance

3.

Which concern directly relates to privacy in cyber forensics?

a)

Hash length

b)

Disk imaging speed

c)

Scope of data collection

d)

File system type

4.

Accreditation standards in forensic labs mainly ensure:

a)

Use of proprietary tools

b)

Legal compliance and quality assurance

c)

Faster analysis

d)

Lower investigation cost

5.

Which activity must balance forensic needs and privacy rights?

a)

Hash calculation

b)

Evidence storage

c)

Data acquisition

d)

Disk cloning

6.

Which tool suite is commonly used to analyze running Windows systems?

a)

FTK

b)

Sysinternals Suite

c)

Autopsy

d)

Nmap

7.

Which Sysinternals tool is used to view running processes?

a)

Procmon

b)

Autoruns

c)

Process Explorer

d)

PsExec

8.

FTK Imager is primarily used for:

a)

Malware analysis

b)

Network sniffing

c)

Forensic imaging and preview

d)

Password cracking

9.

Which FTK feature allows previewing files without modifying evidence?

a)

Hash engine

b)

Evidence tree

c)

File viewer

d)

Registry parser

10.

Which forensic tool is best suited for registry analysis?

a)

Wireshark

b)

FTK

c)

OpenSSL

d)

CrypTool

11.

Why are write blockers mandatory during forensic acquisition?

a)

Increase speed

b)

Prevent OS-level writes

c)

Encrypt evidence

d)

Compress files

12.

Which forensic task is typically done using Cyber Check Suite?

a)

Packet capture

b)

Disk encryption

c)

Evidence analysis workflow

d)

Live malware execution

13.

Which OS artifact is crucial during Linux forensics?

a)

Windows Registry

b)

Event Viewer

c)

/var/log files

d)

NTUSER.DAT

14.

Which command is commonly used to view running processes on Linux?

a)

ls

b)

grep

c)

ps

d)

chmod

15.

Live forensics is particularly useful for analyzing:

a)

Archived backups

b)

Deleted files

c)

Volatile memory

d)

Optical disks

16.

Which forensic implication arises if evidence is collected beyond scope?

a)

Faster investigation

b)

Violation of privacy laws

c)

Improved accuracy

d)

Better documentation

17.

Which type of investigation often requires legal authorization?

a)

Internal corporate audit

b)

Criminal investigation

c)

Training simulation

d)

Academic research

18.

Why is documentation emphasized in forensic tools usage?

a)

Tool limitation

b)

Legal admissibility

c)

Encryption requirement

d)

Storage optimization

19.

Which forensic tool helps capture memory dumps?

a)

FTK Imager

b)

Process Explorer

c)

Wireshark

d)

CrypTool

20.

Which forensic phase involves interpreting findings?

a)

Identification

b)

Preservation

c)

Analysis

d)

Documentation

21.

Which PKI component binds identity to a public key?

a)

Hash

b)

Digital certificate

c)

Symmetric key

d)

Token

22.

Who is responsible for issuing digital certificates?

a)

RA

b)

CA

c)

OCSP

d)

CRL

23.

What is the primary role of a Registration Authority (RA)?

a)

Encrypt data

b)

Verify identity before certificate issuance

c)

Revoke certificates

d)

Generate hashes

24.

Which trust model is most commonly used in organizations?

a)

Web of Trust

b)

Peer-to-peer

c)

Hierarchical trust

d)

Distributed trust

25.

Which mechanism lists revoked certificates periodically?

a)

CA

b)

OCSP

c)

CRL

d)

PKCS

26.

Which protocol provides real-time certificate status checking?

a)

LDAP

b)

OCSP

c)

CRL

d)

X.509

27.

Why is OCSP preferred over CRL in many environments?

a)

Smaller key size

b)

Real-time verification

c)

Stronger encryption

d)

Offline availability

28.

Which type of certificate is typically used for secure websites?

a)

Email certificate

b)

Code-signing certificate

c)

SSL/TLS certificate

d)

Root certificate

29.

Which certificate is self-signed?

a)

End-entity certificate

b)

Intermediate certificate

c)

Root certificate

d)

Server certificate

30.

Which lab tool is used to create a CA and certificates in PKI labs?

a)

OpenSSL

b)

FTK

c)

XCA

d)

CrypTool

31.

What does PKCS stand for?

a)

Public Key Control Standard

b)

Private Key Cryptographic System

c)

Public Key Cryptography Standards

d)

Protected Key Certificate System

32.

Which standard defines cryptographic module security requirements?

a)

X.509

b)

PKCS#7

c)

FIPS 140-2

d)

SHA-256

33.

Which PKI service ensures proof that a document existed at a certain time?

a)

Digital signature

b)

Hashing

c)

Time-stamping

d)

Encryption

34.

Aadhaar-based e-Sign primarily provides:

a)

Confidentiality

b)

Integrity and authentication

c)

Availability

d)

Compression

35.

Which lab activity involves digitally signing documents?

a)

FTK Imager

b)

Wireshark

c)

XCA

d)

Sysinternals

36.

What happens when a certificate is revoked?

a)

It is deleted permanently

b)

It becomes invalid before expiry

c)

It is reissued automatically

d)

Public key changes

37.

Which PKI element establishes the root of trust?

a)

End-entity certificate

b)

Intermediate CA

c)

Root CA

d)

OCSP responder

38.

Why is certificate revocation critical?

a)

Improves performance

b)

Prevents use of compromised keys

c)

Reduces storage

d)

Speeds encryption

39.

Which PKI failure is most common in real organizations?

a)

Weak cryptography

b)

Certificate lifecycle mismanagement

c)

Hash collision

d)

Large key sizes

40.

Which PKI concept ensures trust flows from root to end entity?

a)

Key exchange

b)

Trust chain

c)

Symmetric encryption

d)

Hashing