NEW
Font size
WorksheetsComputer Forensics Quiz
Total questions: 40
Worksheet time: 20mins
Which of the following best differentiates computer crime from unauthorized activity?
Computer crime always involves the Internet
Unauthorized activity is always accidental
Computer crime violates law, unauthorized activity may violate policy
Unauthorized activity cannot be investigated
Which phase of computer forensics ensures evidence remains legally admissible?
Detection
Preservation
Interpretation
Reporting
Which document tracks who handled evidence, when, and why?
Incident response plan
Evidence checkout log
Forensic report
Investigation summary
The primary objective of a first responder at a digital crime scene is to:
Analyze the evidence immediately
Power off all systems
Preserve volatile and non-volatile evidence
Prepare the charge sheet
Which action can destroy volatile evidence?
Disk imaging
Pulling the power cable
Photographing the screen
Using write blocker
Which of the following is volatile evidence?
Browser history
Registry hives
RAM contents
Disk slack
What is the correct order of a forensic process?
Identification → Preservation → Collection → Examination → Analysis → Reporting
Collection → Identification → Analysis → Reporting → Preservation
Detection → Examination → Collection → Reporting
Identification → Analysis → Preservation → Reporting
Why is hashing performed immediately after forensic duplication?
To compress the image
To encrypt the evidence
To verify evidence integrity
To identify file types
Which hash property is critical in forensics?
Reversibility
Collision resistance
Encryption strength
Key length
Which statement about MD5 is correct in forensics?
It encrypts files
It guarantees collision-free hashes
It is used for integrity verification
It stores file metadata
What does bit-stream imaging ensure?
Only active files are copied
Exact sector-by-sector copy
Faster acquisition
Compression of evidence
Which file system is commonly found on legacy floppy disks?
NTFS
FAT32
FAT16
FAT12
When a file is deleted in a FAT file system:
Data is immediately overwritten
File becomes unrecoverable
Directory entry is marked deleted
Cluster is encrypted
Which tool is best suited for viewing raw file headers?
FTK
Hex Editor
Registry Viewer
Sysinternals
Hexadecimal is preferred in forensics because it:
Is human readable
Maps directly to binary values
Encrypts data
Reduces storage size
Which encoding is commonly used in email transmission?
ASCII
MIME
UTF-16
Base32
Which encryption ensures confidentiality but not integrity by default?
Hashing
Symmetric encryption
Digital signature
Steganography
Which SOP ensures repeatability and legal defensibility?
Informal procedures
Tool-specific manuals
Standard Operating Procedures
Investigator experience
Which Windows artifact helps determine USB device usage?
Event Viewer
Registry
Pagefile
Prefetch
Which Sysinternals tool shows active processes and DLLs?
Autoruns
Procmon
Process Explorer
TCPView
FTK Imager is primarily used for:
Malware detection
Disk imaging and preview
Password cracking
Network capture
Which mistake can invalidate forensic evidence?
Using certified tools
Incomplete chain of custody
Hash verification
Write blocking
Live forensics is preferred when:
System is powered off
Evidence is purely archival
Volatile data is critical
Disk space is limited
Which Linux command is useful for keyword searching during analysis?
grep
ls
ps
chmod
Which artifact can prove website access even after history deletion?
Cookies
RAM dump
Swap file
All of the above
What does write blocker prevent?
Read access
Hashing
Data modification
Disk imaging
Which evidence supports user activity timeline reconstruction?
File slack
MAC timestamps
Disk geometry
Boot sector
Which file system structure stores file metadata in Linux?
Superblock
Inode
Journal
Boot loader
Which is a common forensic mistake?
Imaging before analysis
Documenting every step
Working on original evidence
Verifying hashes
Which component is essential in an incident response team?
Only technical staff
Legal and management members
External hackers
Media personnel only
Which forensic principle ensures objectivity?
Investigator intuition
Tool popularity
Evidence-based conclusion
Speed of analysis
Which technique hides data inside another file?
Encryption
Hashing
Steganography
Encoding
Which tool is best for memory analysis?
FTK Imager
Volatility
Sysmon
Autoruns
Which log helps in email forensics?
Web server log
Mail header
DNS cache
Firewall ACL
Which ensures time consistency across multiple systems?
SNMP
NTP
FTP
SMTP
Which evidence proves exculpatory nature?
Evidence proving guilt
Evidence proving innocence
Evidence not documented
Evidence with weak hashes
Which attack floods a system to make it unavailable?
Phishing
DoS
Spoofing
Sniffing
Which Windows artifact records application execution?
Event logs
Prefetch
Pagefile
SAM
Which factor most affects forensic credibility in court?
Tool brand
Investigator experience
Procedure adherence
Report formatting
What is the most critical legal issue in cyber forensics?
Speed of investigation
Evidence admissibility
Tool licensing
Storage capacity
