Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Computer Forensics and Security Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which phase of computer forensics ensures evidence can be legally defended later?

a)

Identification

b)

Preservation

c)

Documentation

d)

Extraction

2.

Which of the following best defines unauthorized activity?

a)

Any illegal digital action

b)

Activity violating policy but not necessarily law

c)

Cybercrime involving intent

d)

Malware execution only

3.

Which principle ensures minimal handling of original evidence?

a)

Chain of custody

b)

Write protection

c)

Least privilege

d)

SOP

4.

Which forensic process step involves deciding what evidence is relevant?

a)

Identification

b)

Preservation

c)

Examination

d)

Interpretation

5.

Why is an incident response plan created before incidents occur?

a)

To collect evidence

b)

To reduce investigation time

c)

To ensure coordinated and lawful response

d)

To avoid forensic duplication

6.

Which member of the incident response team decides containment strategy?

a)

First responder

b)

Incident manager

c)

Forensic analyst

d)

Legal advisor

7.

What is the primary purpose of an evidence checkout log?

a)

Encrypt evidence

b)

Track evidence access

c)

Verify hash values

d)

Store case notes

8.

Which situation requires forensic duplication instead of logical copying?

a)

Email investigation

b)

File recovery case

c)

Slack space analysis

d)

Log analysis

9.

Which of the following is a forensic sound action?

a)

Booting suspect OS to check files

b)

Viewing files using original disk

c)

Imaging disk using write blocker

d)

Editing timestamps for clarity

10.

Why is hexadecimal used in forensic analysis?

a)

It hides data

b)

It compresses files

c)

It represents binary efficiently

d)

It encrypts content

11.

How many bits are represented by one hexadecimal digit?

a)

2

b)

4

c)

8

d)

16

12.

Which file attribute is most affected if system time is incorrect?

a)

File content

b)

File permissions

c)

Timestamps

d)

File size

13.

Which best explains hashing in forensics?

a)

Encrypting evidence

b)

Authenticating users

c)

Verifying evidence integrity

d)

Compressing files

14.

What does a hash collision indicate?

a)

Hashing failure

b)

Same input, different hash

c)

Different input, same hash

d)

Bit rot

15.

Which issue occurs due to aging storage media?

a)

Hash chaining

b)

Bit rot

c)

Encryption failure

d)

Key reuse

16.

Why are SOPs critical in forensic investigations?

a)

Tool standardization

b)

Legal defensibility

c)

Faster acquisition

d)

Reduced storage

17.

Which forensic concern arises if scope exceeds authorization?

a)

Data loss

b)

Privacy violation

c)

Hash mismatch

d)

Evidence duplication

18.

Which forensic tool category helps analyze running systems?

a)

Disk imaging tools

b)

Live response tools

c)

Hash calculators

d)

Backup tools

19.

Which artifact is most volatile?

a)

Disk data

b)

Registry hive

c)

RAM contents

d)

Log files

20.

Which area does mobile forensics mainly address?

a)

Network routing

b)

Embedded and handheld devices

c)

Server logs

d)

Cloud storage

21.

Which security goal ensures data is not altered?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Authentication

22.

Which attack is classified as passive?

a)

DoS

b)

Replay

c)

Eavesdropping

d)

Spoofing

23.

DES uses a key size of:

a)

56 bits

b)

64 bits

c)

128 bits

d)

256 bits

24.

AES supports which key sizes?

a)

64, 128, 256

b)

56, 112, 168

c)

128, 192, 256

d)

160, 224, 384

25.

How many main rounds does AES-128 use?

a)

8

b)

10

c)

12

d)

14

26.

Which is NOT an AES transformation step?

a)

SubBytes

b)

ShiftRows

c)

MixColumns

d)

PermuteKeys

27.

Which algorithm is best suited for bulk data encryption?

a)

RSA

b)

ECC

c)

Symmetric encryption

d)

Hashing

28.

Which algorithm is based on integer factorization?

a)

AES

b)

RSA

c)

ECC

d)

SHA-256

29.

What is the main weakness of Diffie–Hellman if unauthenticated?

a)

Weak encryption

b)

MITM vulnerability

c)

Small key size

d)

Hash collision

30.

Which cryptographic function provides integrity only?

a)

Encryption

b)

Hashing

c)

Digital signature

d)

Key exchange

31.

HMAC differs from hashing because it:

a)

Encrypts data

b)

Uses public keys

c)

Uses a secret key

d)

Produces larger output

32.

Which PKI component issues certificates?

a)

RA

b)

CA

c)

OCSP

d)

CRL

33.

Which component verifies certificate status in real time?

a)

CA

b)

CRL

c)

OCSP

d)

PKCS

34.

Which certificate forms the root of trust?

a)

End-entity certificate

b)

Server certificate

c)

Root CA certificate

d)

Intermediate certificate

35.

What happens when a certificate is revoked?

a)

It is deleted

b)

It expires immediately

c)

It becomes invalid before expiry

d)

Public key changes

36.

Which PKI standard defines cryptographic module security?

a)

X.509

b)

PKCS#12

c)

FIPS 140-2

d)

SHA-2

37.

Which authentication uses something you are?

a)

Password

b)

OTP

c)

Fingerprint

d)

Smart card

38.

OAuth is mainly used for:

a)

Authentication

b)

Authorization delegation

c)

Encryption

d)

Digital signatures

39.

Which protocol secures emails using PKI?

a)

TLS

b)

SSL

c)

PGP

d)

IPSec

40.

Which is the most common real-world PKI failure?

a)

Weak algorithms

b)

Certificate lifecycle mismanagement

c)

Hash collision

d)

Large key sizes