WorksheetsComputer Forensics and Security Quiz
Total questions: 40
Worksheet time: 20mins
Which phase of computer forensics ensures evidence can be legally defended later?
Identification
Preservation
Documentation
Extraction
Which of the following best defines unauthorized activity?
Any illegal digital action
Activity violating policy but not necessarily law
Cybercrime involving intent
Malware execution only
Which principle ensures minimal handling of original evidence?
Chain of custody
Write protection
Least privilege
SOP
Which forensic process step involves deciding what evidence is relevant?
Identification
Preservation
Examination
Interpretation
Why is an incident response plan created before incidents occur?
To collect evidence
To reduce investigation time
To ensure coordinated and lawful response
To avoid forensic duplication
Which member of the incident response team decides containment strategy?
First responder
Incident manager
Forensic analyst
Legal advisor
What is the primary purpose of an evidence checkout log?
Encrypt evidence
Track evidence access
Verify hash values
Store case notes
Which situation requires forensic duplication instead of logical copying?
Email investigation
File recovery case
Slack space analysis
Log analysis
Which of the following is a forensic sound action?
Booting suspect OS to check files
Viewing files using original disk
Imaging disk using write blocker
Editing timestamps for clarity
Why is hexadecimal used in forensic analysis?
It hides data
It compresses files
It represents binary efficiently
It encrypts content
How many bits are represented by one hexadecimal digit?
2
4
8
16
Which file attribute is most affected if system time is incorrect?
File content
File permissions
Timestamps
File size
Which best explains hashing in forensics?
Encrypting evidence
Authenticating users
Verifying evidence integrity
Compressing files
What does a hash collision indicate?
Hashing failure
Same input, different hash
Different input, same hash
Bit rot
Which issue occurs due to aging storage media?
Hash chaining
Bit rot
Encryption failure
Key reuse
Why are SOPs critical in forensic investigations?
Tool standardization
Legal defensibility
Faster acquisition
Reduced storage
Which forensic concern arises if scope exceeds authorization?
Data loss
Privacy violation
Hash mismatch
Evidence duplication
Which forensic tool category helps analyze running systems?
Disk imaging tools
Live response tools
Hash calculators
Backup tools
Which artifact is most volatile?
Disk data
Registry hive
RAM contents
Log files
Which area does mobile forensics mainly address?
Network routing
Embedded and handheld devices
Server logs
Cloud storage
Which security goal ensures data is not altered?
Confidentiality
Availability
Integrity
Authentication
Which attack is classified as passive?
DoS
Replay
Eavesdropping
Spoofing
DES uses a key size of:
56 bits
64 bits
128 bits
256 bits
AES supports which key sizes?
64, 128, 256
56, 112, 168
128, 192, 256
160, 224, 384
How many main rounds does AES-128 use?
8
10
12
14
Which is NOT an AES transformation step?
SubBytes
ShiftRows
MixColumns
PermuteKeys
Which algorithm is best suited for bulk data encryption?
RSA
ECC
Symmetric encryption
Hashing
Which algorithm is based on integer factorization?
AES
RSA
ECC
SHA-256
What is the main weakness of Diffie–Hellman if unauthenticated?
Weak encryption
MITM vulnerability
Small key size
Hash collision
Which cryptographic function provides integrity only?
Encryption
Hashing
Digital signature
Key exchange
HMAC differs from hashing because it:
Encrypts data
Uses public keys
Uses a secret key
Produces larger output
Which PKI component issues certificates?
RA
CA
OCSP
CRL
Which component verifies certificate status in real time?
CA
CRL
OCSP
PKCS
Which certificate forms the root of trust?
End-entity certificate
Server certificate
Root CA certificate
Intermediate certificate
What happens when a certificate is revoked?
It is deleted
It expires immediately
It becomes invalid before expiry
Public key changes
Which PKI standard defines cryptographic module security?
X.509
PKCS#12
FIPS 140-2
SHA-2
Which authentication uses something you are?
Password
OTP
Fingerprint
Smart card
OAuth is mainly used for:
Authentication
Authorization delegation
Encryption
Digital signatures
Which protocol secures emails using PKI?
TLS
SSL
PGP
IPSec
Which is the most common real-world PKI failure?
Weak algorithms
Certificate lifecycle mismanagement
Hash collision
Large key sizes
