Skip to main content

Digital Forensics Final Exam Questions - 600 Verified Questions

Page 1


Digital Forensics

Final Exam Questions

Course Introduction

Digital Forensics is a specialized course that introduces students to the principles and practices of collecting, preserving, analyzing, and presenting digital evidence in the context of criminal investigations and legal proceedings. The course covers key concepts such as data acquisition, chain of custody, file system analysis, network forensics, and the recovery of deleted or encrypted data. Students will explore various tools and techniques used to examine digital devices and networks, understand legal and ethical considerations, and learn how to prepare forensic reports for use in court. Hands-on labs and real-world case studies encourage practical skill development, preparing students for professional roles in cybersecurity, law enforcement, and information assurance.

Recommended Textbook

Computer Forensics Principles and Practices 1st Edition by Linda Volonino

Available Study Resources on Quizplus

13 Chapters

600 Verified Questions

600 Flashcards

Source URL: https://quizplus.com/study-set/2159

Page 2

Chapter 1: Forensic Evidence and Crime Investigation

Available Study Resources on Quizplus for this Chatper

33 Verified Questions

33 Flashcards

Source URL: https://quizplus.com/quiz/43035

Sample Questions

Q1) ________ evidence is that type that could incorrectly lead an investigator to believe the evidence is related to the crime.

Answer: Artifact

Q2) In the case of missing Washington,D.C. ,resident ________,e-mail and visited Web sites on a personal laptop were all the police had to go by.

Answer: Chandra Levy

Q3) Military planners,recognizing the need to include cyberwarfare in its defenses,have given this new field the acronym of A)PII

B)C4I

C)P2I

D)P2M

Answer: B

Q4) A(n)________ is considered an offensive act against societal laws. Answer: crime

Q5) Proper collection of evidence and handling procedures must be followed to ensure the evidence is ________.

Answer: admissible

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Computer Forensics Anddigital Detective Work

Available Study Resources on Quizplus for this Chatper

28 Verified Questions

28 Flashcards

Source URL: https://quizplus.com/quiz/43036

Sample Questions

Q1) One of the more popular theories is that a person could actually commit ________ by changing a patient's medication data.

Answer: murder

Q2) Care,control,and chain of custody are called the ________ of evidence.

Answer: three C's

Q3) ________ is a term generally used to indicate a message is hidden within another file.

Answer: Steganography

Q4) What type of program is available to delete and overwrite data on a computer?

A)File-overwriting software

B)File-deleting software

C)File-wiping software

D)All of the above

Answer: C

Q5) If evidence items are released to auditors or authorities,the ________ should be recorded.

Answer: release dates

Q6) ________ is the blending of accounting,auditing,and investigative skills.

Answer: Forensic accounting

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Tools, Environments, Equipment, and Certifications

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/43037

Sample Questions

Q1) Documentation of the evidence can include which of the following?

A)Name of the suspect's supervisor

B)Status of the computer

C)Name of the investigating officer

D)All the above

Answer: B

Q2) A dead analysis is also referred to as a(n)________ analysis.

Answer: postmortem

Q3) ________ data is data that has been deleted but not erased.

Answer: Residual

Q4) ________,from Paraben Forensics,is a comprehensive tool for investigating the contents of Palm Pocket PCs that run on Windows CE.

Answer: PDA Seizure

Q5) If volatile data must be acquired,you may need to do your analysis in a(n)

A)Trusted environment

B)Postmortem environment

C)Untrusted environment

D)Dead environment

Answer: C

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Policies and Procedures

Available Study Resources on Quizplus for this Chatper

63 Verified Questions

63 Flashcards

Source URL: https://quizplus.com/quiz/43038

Sample Questions

Q1) Summary

A)Uses an algorithm to make readable

B)Needs a word or phrase to unlock the file

C)Data hides in another file

D)Usually mail files

Q2) General case intake form

A) Summarizes the case

B) Avoid contaminating evidence with your fingerprints

C) Write on CDs without damaging them

D) Use to record investigator actions

E) Use to acquire data in the field

Q3) Encrypted files

A)Uses an algorithm to make readable

B)Needs a word or phrase to unlock the file

C)Data hides in another file

D)Usually mail files

Q4) The main reason for file compression is to ________.

Q5) You should ask questions about what types of ________ and ________ are involved because you can save time and mistakes if you take the correct equipment with you.

6

To view all questions and flashcards with answers, click on the resource link above.

Chapter 5: Data, PDA, and Cell Phone Forensics

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/43039

Sample Questions

Q1) PDA Seizure

A)Can do Blackberry devices

B)Completely emulates Palm

C)Cannot generate a hash of the Palm OS

D)Doesn't support Linux

Q2) pdd

A)Can do Blackberry devices

B)Completely emulates Palm

C)Cannot generate a hash of the Palm OS

D)Doesn't support Linux

Q3) EIDE

A)Allows up to four ATA devices

B)Allows a CD to use ATA connections

C)The umbrella standard

D)The standard is no longer used

Q4) Cellular phones can typically carry what size processor?

A)200MHz

B)1GHz

C)300MHz

D)900MHz

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Operating Systems and Data Transmission

Basics for Digital Investigations

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/43040

Sample Questions

Q1) In data transfer,only the ________ changes from router or switch to the next one in line.

Q2) Memory management deals with

A)Saving and archiving data

B)Task scheduling

C)Temporary storage or use of applications and data

D)All of the above

Q3) One approach Apple took in designing the Macintosh was to make ________ a standard feature from the beginning.

Q4) Which of the following is considered to be the first stable GUI operating system?

A)Windows 3.0

B)Windows 3.1

C)Windows 3.11

D)Windows 95

Q5) One of Linux's strongest points is that you can ________ it for a specific computer.

Q6) For an examiner to understand how data may be captured,one must know that data traverses a network in ________.

Q7) The user interface is also known as a(n)________.

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Investigating Windows, linux, and Graphic Files

Available Study Resources on Quizplus for this Chatper

57 Verified Questions

57 Flashcards

Source URL: https://quizplus.com/quiz/43041

Sample Questions

Q1) Which of the following is one of the default directories created when installing Linux?

A)/setup

B)/default

C)/bin

D)/swap

Q2) /tmp

A)Where files with no names are placed

B)Contains information on printers, log files, and transient data

C)Could be a rich source of evidence if not recently cleaned

D)Library files

E)Contains shadow password files

Q3) Which of the following is the primary default folder in Windows 2000 and XP?

A)Documents and Settings

B)My Documents

C)User Root

D)My Computer

Q4) A(n)________ is designed as a hierarchical listing of folders and files.

Q5) Windows NT and higher changed the registry to a mixture of several files referred to as ________.

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: E-Mail and Webmail Forensics

Available Study Resources on Quizplus for this Chatper

47 Verified Questions

47 Flashcards

Source URL: https://quizplus.com/quiz/43042

Sample Questions

Q1) Attachments are normally handled using a(n)_______ binary-to-text encoding scheme.

Q2) .mbx

A)OE fax page

B)Lotus Notes mailbox

C)Eudora message base

D)AOL organizer file

Q3) Working with mail servers can be a challenge for all of the following reasons EXCEPT A)These programs service hundreds or even thousands of accounts

B)It may not be possible to get forensic access to the accounts

C)Servers are particularly hard to access in small companies

D)Companies may have policies in place to limit the time data is retained

Q4) A person using webmail may be able to use a program such as ________ to connect to the server and thus download messages to work with offline.

Q5) ________ uses two or more hard drives accessed in parallel to create a pool of storage.

Q6) The ________ comes before the @ sign in an e-mail address

Q7) The tool often used for quick communications without resorting to e-mail is________ .

Page 10

To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Internet and Network Forensics and Intrusion Detection

Available Study Resources on Quizplus for this Chatper

39 Verified Questions

39 Flashcards

Source URL: https://quizplus.com/quiz/43043

Sample Questions

Q1) ________ transmit and receive data via radio frequency in the open.

Q2) Software clients called ________ installed on network devices are designed to collect information from the host.

Q3) The newest NFAT systems are a combination of

A)IDS and application software

B)IDS and forensic software

C)Agents and application software

D)DHCP servers and IDSs

Q4) Network layer

A)Permits FTP or HTTP protocols

B)Acts like an IP filter

C)Acts as a mediator

Q5) A(n)________ repeats all data received on any port to the remaining ports;it is gradually being replaced by switches and SPAN systems.

Q6) Which of the following is considered the BEST answer in defining DHCP?

A)They dynamically assign IP addresses.

B)They dynamically assign IP addresses to servers.

C)They dynamically assign IP addresses to computers.

D)They dynamically assign IP addresses to computers on a network.

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Tracking Down Those Who Intend to Do Harm

on a Large Scale

Available Study Resources on Quizplus for this Chatper

39 Verified Questions

39 Flashcards

Source URL: https://quizplus.com/quiz/43044

Sample Questions

Q1) Nachi and friends

A)\( \$ 3.2 \) billion

B)\( \$ 1.15 \) billion

C)\( \$ 2.62 \) billion

D)\( \$ 635 \) million

Q2) ________ logs help track down criminals because they hold evidence that a crime has been committed and where the intrusion occurred.

Q3) Based on verified e-evidence,it was concluded that Aaron Caffrey

A)Did indeed launch an attack against the Port of Houston

B)Did not launch an attack against the Port of Houston

C)Was able to prove he was an unwilling accomplice

D)Was exonerated of all charges

Q4) One of the original motives of many hackers was

A)Stealing bandwidth

B)Political activism

C)Creating bot networks

D)Organized criminal activities

Q5) Anonymity,control resources,and many other features make the ________ the criminals' conduit for coordinating and carrying out an agenda.

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Fraud and Forensic Accounting Investigation

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/43045

Sample Questions

Q1) Which of the following weaknesses in an organization can create an opportunity for fraud?

A)Questionable hiring practices

B)Lack of an audit trail

C)Allowing personnel to work unsupervised

D)Pressure from management

Q2) The law of ________ holds that some information is protected by law from being released.

Q3) Something is ________ if it is relevant and significant to the situation.

Q4) With a forensic accounting investigation,there is a presumption of ________.

Q5) Opportunity

A)Destroying documents prior to an investigation

B)Showing perp had a chance to commit crime

C)Is a strong circumstantial element

D)Finding multiple events of the same error

Q6) Repetitive acts

A)Destroying documents prior to an investigation

B)Showing perp had a chance to commit crime

C)Is a strong circumstantial element

D)Finding multiple events of the same error

Page 13

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Federal Rules and Criminal Codes

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43046

Sample Questions

Q1) Privilege

A)Qualified experts may testify though not eyewitnesses

B)The evidence is valuable to an issue of the case

C)Keeps private attorney-client communications

D)The evidence is what it claims to be

E)Ruling against "out of court" statements

Q2) Digital Millennium Copyright Act

A)Requires that recordings be handed over to a judge

B)Forces ISPs to turn over names of suspected music pirates upon subpoena

C)Includes new guidance relating to computer crime and eevidence

D)Permits an ISP to look through stored e-mail messages

Q3) Rule 104(a)

A)Even if relevant, evidence may be excluded if it misleads the jury

B)Preliminary questions concerning qualifications of an expert witness

C)Evidence is admissible unless ruled on by an Act of Congress

D. A qualified expert may testify if based upon sufficient facts

Q4) The ________ is a mechanical device that can be attached to a specific telephone line at a telephone office.

Q5) Real-time interception of computer information in transit falls under the ________ Statute.

Page 14

To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Ethical and Professional Responsibility in Testimony

Available Study Resources on Quizplus for this Chatper

30 Verified Questions

30 Flashcards

Source URL: https://quizplus.com/quiz/43047

Sample Questions

Q1) A common trap used by lawyers is to ask you to offer opinions outside ________.

Q2) Preparation for testifying in court can include

A)Preparation of data

B)Personal training

C)Phone calls

D)All may be included

Q3) You can ensure the best reception of your evidence by maintaining a(n)________ demeanor at all times.

Q4) Which of the following is NOT considered a part of an expert witness report?

A)Description of the facts

B)Materials not available for review

C)Findings

D)Background

Q5) The _______ was designed to encourage witnesses to testify freely and honestly without fear of lawsuits arising from their testimony.

Q6) Jurors should begin a case

A)Knowing all the facts that may be presented

B)With a clear opinion about the guilt or innocence of the defendant

Page 15

C)With a clear understanding of the laws at issue in the case

D)In a state of ignorance

To view all questions and flashcards with answers, click on the resource link above.

Page 16

Turn static files into dynamic content formats.

Create a flipbook
Digital Forensics Final Exam Questions - 600 Verified Questions by Quizplus - Issuu