wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Computer Forensics Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which of the following best differentiates computer crime from unauthorized activity?

a)

Computer crime always involves the Internet

b)

Unauthorized activity is always accidental

c)

Computer crime violates law, unauthorized activity may violate policy

d)

Unauthorized activity cannot be investigated

2.

Which phase of computer forensics ensures evidence remains legally admissible?

a)

Detection

b)

Preservation

c)

Interpretation

d)

Reporting

3.

Which document tracks who handled evidence, when, and why?

a)

Incident response plan

b)

Evidence checkout log

c)

Forensic report

d)

Investigation summary

4.

The primary objective of a first responder at a digital crime scene is to:

a)

Analyze the evidence immediately

b)

Power off all systems

c)

Preserve volatile and non-volatile evidence

d)

Prepare the charge sheet

5.

Which action can destroy volatile evidence?

a)

Disk imaging

b)

Pulling the power cable

c)

Photographing the screen

d)

Using write blocker

6.

Which of the following is volatile evidence?

a)

Browser history

b)

Registry hives

c)

RAM contents

d)

Disk slack

7.

What is the correct order of a forensic process?

a)

Identification → Preservation → Collection → Examination → Analysis → Reporting

b)

Collection → Identification → Analysis → Reporting → Preservation

c)

Detection → Examination → Collection → Reporting

d)

Identification → Analysis → Preservation → Reporting

8.

Why is hashing performed immediately after forensic duplication?

a)

To compress the image

b)

To encrypt the evidence

c)

To verify evidence integrity

d)

To identify file types

9.

Which hash property is critical in forensics?

a)

Reversibility

b)

Collision resistance

c)

Encryption strength

d)

Key length

10.

Which statement about MD5 is correct in forensics?

a)

It encrypts files

b)

It guarantees collision-free hashes

c)

It is used for integrity verification

d)

It stores file metadata

11.

What does bit-stream imaging ensure?

a)

Only active files are copied

b)

Exact sector-by-sector copy

c)

Faster acquisition

d)

Compression of evidence

12.

Which file system is commonly found on legacy floppy disks?

a)

NTFS

b)

FAT32

c)

FAT16

d)

FAT12

13.

When a file is deleted in a FAT file system:

a)

Data is immediately overwritten

b)

File becomes unrecoverable

c)

Directory entry is marked deleted

d)

Cluster is encrypted

14.

Which tool is best suited for viewing raw file headers?

a)

FTK

b)

Hex Editor

c)

Registry Viewer

d)

Sysinternals

15.

Hexadecimal is preferred in forensics because it:

a)

Is human readable

b)

Maps directly to binary values

c)

Encrypts data

d)

Reduces storage size

16.

Which encoding is commonly used in email transmission?

a)

ASCII

b)

MIME

c)

UTF-16

d)

Base32

17.

Which encryption ensures confidentiality but not integrity by default?

a)

Hashing

b)

Symmetric encryption

c)

Digital signature

d)

Steganography

18.

Which SOP ensures repeatability and legal defensibility?

a)

Informal procedures

b)

Tool-specific manuals

c)

Standard Operating Procedures

d)

Investigator experience

19.

Which Windows artifact helps determine USB device usage?

a)

Event Viewer

b)

Registry

c)

Pagefile

d)

Prefetch

20.

Which Sysinternals tool shows active processes and DLLs?

a)

Autoruns

b)

Procmon

c)

Process Explorer

d)

TCPView

21.

FTK Imager is primarily used for:

a)

Malware detection

b)

Disk imaging and preview

c)

Password cracking

d)

Network capture

22.

Which mistake can invalidate forensic evidence?

a)

Using certified tools

b)

Incomplete chain of custody

c)

Hash verification

d)

Write blocking

23.

Live forensics is preferred when:

a)

System is powered off

b)

Evidence is purely archival

c)

Volatile data is critical

d)

Disk space is limited

24.

Which Linux command is useful for keyword searching during analysis?

a)

grep

b)

ls

c)

ps

d)

chmod

25.

Which artifact can prove website access even after history deletion?

a)

Cookies

b)

RAM dump

c)

Swap file

d)

All of the above

26.

What does write blocker prevent?

a)

Read access

b)

Hashing

c)

Data modification

d)

Disk imaging

27.

Which evidence supports user activity timeline reconstruction?

a)

File slack

b)

MAC timestamps

c)

Disk geometry

d)

Boot sector

28.

Which file system structure stores file metadata in Linux?

a)

Superblock

b)

Inode

c)

Journal

d)

Boot loader

29.

Which is a common forensic mistake?

a)

Imaging before analysis

b)

Documenting every step

c)

Working on original evidence

d)

Verifying hashes

30.

Which component is essential in an incident response team?

a)

Only technical staff

b)

Legal and management members

c)

External hackers

d)

Media personnel only

31.

Which forensic principle ensures objectivity?

a)

Investigator intuition

b)

Tool popularity

c)

Evidence-based conclusion

d)

Speed of analysis

32.

Which technique hides data inside another file?

a)

Encryption

b)

Hashing

c)

Steganography

d)

Encoding

33.

Which tool is best for memory analysis?

a)

FTK Imager

b)

Volatility

c)

Sysmon

d)

Autoruns

34.

Which log helps in email forensics?

a)

Web server log

b)

Mail header

c)

DNS cache

d)

Firewall ACL

35.

Which ensures time consistency across multiple systems?

a)

SNMP

b)

NTP

c)

FTP

d)

SMTP

36.

Which evidence proves exculpatory nature?

a)

Evidence proving guilt

b)

Evidence proving innocence

c)

Evidence not documented

d)

Evidence with weak hashes

37.

Which attack floods a system to make it unavailable?

a)

Phishing

b)

DoS

c)

Spoofing

d)

Sniffing

38.

Which Windows artifact records application execution?

a)

Event logs

b)

Prefetch

c)

Pagefile

d)

SAM

39.

Which factor most affects forensic credibility in court?

a)

Tool brand

b)

Investigator experience

c)

Procedure adherence

d)

Report formatting

40.

What is the most critical legal issue in cyber forensics?

a)

Speed of investigation

b)

Evidence admissibility

c)

Tool licensing

d)

Storage capacity