

Digital Forensics
Final Exam Questions
Course Introduction
Digital Forensics is a specialized course that introduces students to the principles and practices of collecting, preserving, analyzing, and presenting digital evidence in the context of criminal investigations and legal proceedings. The course covers key concepts such as data acquisition, chain of custody, file system analysis, network forensics, and the recovery of deleted or encrypted data. Students will explore various tools and techniques used to examine digital devices and networks, understand legal and ethical considerations, and learn how to prepare forensic reports for use in court. Hands-on labs and real-world case studies encourage practical skill development, preparing students for professional roles in cybersecurity, law enforcement, and information assurance.
Recommended Textbook
Computer Forensics Principles and Practices 1st Edition by Linda Volonino
Available Study Resources on Quizplus
13 Chapters
600 Verified Questions
600 Flashcards
Source URL: https://quizplus.com/study-set/2159

Page 2

Chapter 1: Forensic Evidence and Crime Investigation
Available Study Resources on Quizplus for this Chatper
33 Verified Questions
33 Flashcards
Source URL: https://quizplus.com/quiz/43035
Sample Questions
Q1) ________ evidence is that type that could incorrectly lead an investigator to believe the evidence is related to the crime.
Answer: Artifact
Q2) In the case of missing Washington,D.C. ,resident ________,e-mail and visited Web sites on a personal laptop were all the police had to go by.
Answer: Chandra Levy
Q3) Military planners,recognizing the need to include cyberwarfare in its defenses,have given this new field the acronym of A)PII
B)C4I
C)P2I
D)P2M
Answer: B
Q4) A(n)________ is considered an offensive act against societal laws. Answer: crime
Q5) Proper collection of evidence and handling procedures must be followed to ensure the evidence is ________.
Answer: admissible
To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Computer Forensics Anddigital Detective Work
Available Study Resources on Quizplus for this Chatper
28 Verified Questions
28 Flashcards
Source URL: https://quizplus.com/quiz/43036
Sample Questions
Q1) One of the more popular theories is that a person could actually commit ________ by changing a patient's medication data.
Answer: murder
Q2) Care,control,and chain of custody are called the ________ of evidence.
Answer: three C's
Q3) ________ is a term generally used to indicate a message is hidden within another file.
Answer: Steganography
Q4) What type of program is available to delete and overwrite data on a computer?
A)File-overwriting software
B)File-deleting software
C)File-wiping software
D)All of the above
Answer: C
Q5) If evidence items are released to auditors or authorities,the ________ should be recorded.
Answer: release dates
Q6) ________ is the blending of accounting,auditing,and investigative skills.
Answer: Forensic accounting
To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Tools, Environments, Equipment, and Certifications
Available Study Resources on Quizplus for this Chatper
48 Verified Questions
48 Flashcards
Source URL: https://quizplus.com/quiz/43037
Sample Questions
Q1) Documentation of the evidence can include which of the following?
A)Name of the suspect's supervisor
B)Status of the computer
C)Name of the investigating officer
D)All the above
Answer: B
Q2) A dead analysis is also referred to as a(n)________ analysis.
Answer: postmortem
Q3) ________ data is data that has been deleted but not erased.
Answer: Residual
Q4) ________,from Paraben Forensics,is a comprehensive tool for investigating the contents of Palm Pocket PCs that run on Windows CE.
Answer: PDA Seizure
Q5) If volatile data must be acquired,you may need to do your analysis in a(n)
A)Trusted environment
B)Postmortem environment
C)Untrusted environment
D)Dead environment
Answer: C
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Policies and Procedures
Available Study Resources on Quizplus for this Chatper
63 Verified Questions
63 Flashcards
Source URL: https://quizplus.com/quiz/43038
Sample Questions
Q1) Summary
A)Uses an algorithm to make readable
B)Needs a word or phrase to unlock the file
C)Data hides in another file
D)Usually mail files
Q2) General case intake form
A) Summarizes the case
B) Avoid contaminating evidence with your fingerprints
C) Write on CDs without damaging them
D) Use to record investigator actions
E) Use to acquire data in the field
Q3) Encrypted files
A)Uses an algorithm to make readable
B)Needs a word or phrase to unlock the file
C)Data hides in another file
D)Usually mail files
Q4) The main reason for file compression is to ________.
Q5) You should ask questions about what types of ________ and ________ are involved because you can save time and mistakes if you take the correct equipment with you.
6
To view all questions and flashcards with answers, click on the resource link above.

Chapter 5: Data, PDA, and Cell Phone Forensics
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/43039
Sample Questions
Q1) PDA Seizure
A)Can do Blackberry devices
B)Completely emulates Palm
C)Cannot generate a hash of the Palm OS
D)Doesn't support Linux
Q2) pdd
A)Can do Blackberry devices
B)Completely emulates Palm
C)Cannot generate a hash of the Palm OS
D)Doesn't support Linux
Q3) EIDE
A)Allows up to four ATA devices
B)Allows a CD to use ATA connections
C)The umbrella standard
D)The standard is no longer used
Q4) Cellular phones can typically carry what size processor?
A)200MHz
B)1GHz
C)300MHz
D)900MHz
To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Operating Systems and Data Transmission
Basics for Digital Investigations
Available Study Resources on Quizplus for this Chatper
52 Verified Questions
52 Flashcards
Source URL: https://quizplus.com/quiz/43040
Sample Questions
Q1) In data transfer,only the ________ changes from router or switch to the next one in line.
Q2) Memory management deals with
A)Saving and archiving data
B)Task scheduling
C)Temporary storage or use of applications and data
D)All of the above
Q3) One approach Apple took in designing the Macintosh was to make ________ a standard feature from the beginning.
Q4) Which of the following is considered to be the first stable GUI operating system?
A)Windows 3.0
B)Windows 3.1
C)Windows 3.11
D)Windows 95
Q5) One of Linux's strongest points is that you can ________ it for a specific computer.
Q6) For an examiner to understand how data may be captured,one must know that data traverses a network in ________.
Q7) The user interface is also known as a(n)________.
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Investigating Windows, linux, and Graphic Files
Available Study Resources on Quizplus for this Chatper
57 Verified Questions
57 Flashcards
Source URL: https://quizplus.com/quiz/43041
Sample Questions
Q1) Which of the following is one of the default directories created when installing Linux?
A)/setup
B)/default
C)/bin
D)/swap
Q2) /tmp
A)Where files with no names are placed
B)Contains information on printers, log files, and transient data
C)Could be a rich source of evidence if not recently cleaned
D)Library files
E)Contains shadow password files
Q3) Which of the following is the primary default folder in Windows 2000 and XP?
A)Documents and Settings
B)My Documents
C)User Root
D)My Computer
Q4) A(n)________ is designed as a hierarchical listing of folders and files.
Q5) Windows NT and higher changed the registry to a mixture of several files referred to as ________.
To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: E-Mail and Webmail Forensics
Available Study Resources on Quizplus for this Chatper
47 Verified Questions
47 Flashcards
Source URL: https://quizplus.com/quiz/43042
Sample Questions
Q1) Attachments are normally handled using a(n)_______ binary-to-text encoding scheme.
Q2) .mbx
A)OE fax page
B)Lotus Notes mailbox
C)Eudora message base
D)AOL organizer file
Q3) Working with mail servers can be a challenge for all of the following reasons EXCEPT A)These programs service hundreds or even thousands of accounts
B)It may not be possible to get forensic access to the accounts
C)Servers are particularly hard to access in small companies
D)Companies may have policies in place to limit the time data is retained
Q4) A person using webmail may be able to use a program such as ________ to connect to the server and thus download messages to work with offline.
Q5) ________ uses two or more hard drives accessed in parallel to create a pool of storage.
Q6) The ________ comes before the @ sign in an e-mail address
Q7) The tool often used for quick communications without resorting to e-mail is________ .
Page 10
To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Internet and Network Forensics and Intrusion Detection
Available Study Resources on Quizplus for this Chatper
39 Verified Questions
39 Flashcards
Source URL: https://quizplus.com/quiz/43043
Sample Questions
Q1) ________ transmit and receive data via radio frequency in the open.
Q2) Software clients called ________ installed on network devices are designed to collect information from the host.
Q3) The newest NFAT systems are a combination of
A)IDS and application software
B)IDS and forensic software
C)Agents and application software
D)DHCP servers and IDSs
Q4) Network layer
A)Permits FTP or HTTP protocols
B)Acts like an IP filter
C)Acts as a mediator
Q5) A(n)________ repeats all data received on any port to the remaining ports;it is gradually being replaced by switches and SPAN systems.
Q6) Which of the following is considered the BEST answer in defining DHCP?
A)They dynamically assign IP addresses.
B)They dynamically assign IP addresses to servers.
C)They dynamically assign IP addresses to computers.
D)They dynamically assign IP addresses to computers on a network.
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Tracking Down Those Who Intend to Do Harm
on a Large Scale
Available Study Resources on Quizplus for this Chatper
39 Verified Questions
39 Flashcards
Source URL: https://quizplus.com/quiz/43044
Sample Questions
Q1) Nachi and friends
A)\( \$ 3.2 \) billion
B)\( \$ 1.15 \) billion
C)\( \$ 2.62 \) billion
D)\( \$ 635 \) million
Q2) ________ logs help track down criminals because they hold evidence that a crime has been committed and where the intrusion occurred.
Q3) Based on verified e-evidence,it was concluded that Aaron Caffrey
A)Did indeed launch an attack against the Port of Houston
B)Did not launch an attack against the Port of Houston
C)Was able to prove he was an unwilling accomplice
D)Was exonerated of all charges
Q4) One of the original motives of many hackers was
A)Stealing bandwidth
B)Political activism
C)Creating bot networks
D)Organized criminal activities
Q5) Anonymity,control resources,and many other features make the ________ the criminals' conduit for coordinating and carrying out an agenda.
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Fraud and Forensic Accounting Investigation
Available Study Resources on Quizplus for this Chatper
40 Verified Questions
40 Flashcards
Source URL: https://quizplus.com/quiz/43045
Sample Questions
Q1) Which of the following weaknesses in an organization can create an opportunity for fraud?
A)Questionable hiring practices
B)Lack of an audit trail
C)Allowing personnel to work unsupervised
D)Pressure from management
Q2) The law of ________ holds that some information is protected by law from being released.
Q3) Something is ________ if it is relevant and significant to the situation.
Q4) With a forensic accounting investigation,there is a presumption of ________.
Q5) Opportunity
A)Destroying documents prior to an investigation
B)Showing perp had a chance to commit crime
C)Is a strong circumstantial element
D)Finding multiple events of the same error
Q6) Repetitive acts
A)Destroying documents prior to an investigation
B)Showing perp had a chance to commit crime
C)Is a strong circumstantial element
D)Finding multiple events of the same error
Page 13
To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Federal Rules and Criminal Codes
Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/43046
Sample Questions
Q1) Privilege
A)Qualified experts may testify though not eyewitnesses
B)The evidence is valuable to an issue of the case
C)Keeps private attorney-client communications
D)The evidence is what it claims to be
E)Ruling against "out of court" statements
Q2) Digital Millennium Copyright Act
A)Requires that recordings be handed over to a judge
B)Forces ISPs to turn over names of suspected music pirates upon subpoena
C)Includes new guidance relating to computer crime and eevidence
D)Permits an ISP to look through stored e-mail messages
Q3) Rule 104(a)
A)Even if relevant, evidence may be excluded if it misleads the jury
B)Preliminary questions concerning qualifications of an expert witness
C)Evidence is admissible unless ruled on by an Act of Congress
D. A qualified expert may testify if based upon sufficient facts
Q4) The ________ is a mechanical device that can be attached to a specific telephone line at a telephone office.
Q5) Real-time interception of computer information in transit falls under the ________ Statute.
Page 14
To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Ethical and Professional Responsibility in Testimony
Available Study Resources on Quizplus for this Chatper
30 Verified Questions
30 Flashcards
Source URL: https://quizplus.com/quiz/43047
Sample Questions
Q1) A common trap used by lawyers is to ask you to offer opinions outside ________.
Q2) Preparation for testifying in court can include
A)Preparation of data
B)Personal training
C)Phone calls
D)All may be included
Q3) You can ensure the best reception of your evidence by maintaining a(n)________ demeanor at all times.
Q4) Which of the following is NOT considered a part of an expert witness report?
A)Description of the facts
B)Materials not available for review
C)Findings
D)Background
Q5) The _______ was designed to encourage witnesses to testify freely and honestly without fear of lawsuits arising from their testimony.
Q6) Jurors should begin a case
A)Knowing all the facts that may be presented
B)With a clear opinion about the guilt or innocence of the defendant
Page 15
C)With a clear understanding of the laws at issue in the case
D)In a state of ignorance
To view all questions and flashcards with answers, click on the resource link above.
Page 16