Skip to main content

Digital Forensics Midterm Exam - 600 Verified Questions

Page 1


Digital Forensics

Midterm Exam

Course Introduction

Digital Forensics is an interdisciplinary course that introduces students to the principles and practices of investigating and analyzing digital evidence from computers, mobile devices, networks, and other electronic media. The course covers methodologies for data acquisition, preservation, examination, and documentation to support legal proceedings and internal investigations. Topics include digital crime scene procedures, file system analysis, recovering deleted or hidden data, network forensics, and the ethical and legal considerations involved in handling digital evidence. Hands-on labs and case studies provide practical experience with leading forensic tools and techniques used by cybersecurity professionals and law enforcement agencies.

Recommended Textbook

Computer Forensics Principles and Practices 1st Edition by Linda Volonino

Available Study Resources on Quizplus

13 Chapters

600 Verified Questions

600 Flashcards

Source URL: https://quizplus.com/study-set/2159 Page 2

Chapter 1: Forensic Evidence and Crime Investigation

Available Study Resources on Quizplus for this Chatper

33 Verified Questions

33 Flashcards

Source URL: https://quizplus.com/quiz/43035

Sample Questions

Q1) A(n)________ is a lesser crime such as careless driving. Answer: misdemeanor

Q2) What piece of legislation makes it a crime to send e-mail using false headers?

A)CAN-SPAM Act

B)CFAA

C)FERPA

D)USA PATRIOT Act

Answer: A

Q3) In the case of missing Washington,D.C. ,resident ________,e-mail and visited Web sites on a personal laptop were all the police had to go by.

Answer: Chandra Levy

Q4) Only ________ evidence supports or helps confirm a given theory. Answer: inculpatory

Q5) Who was arrested as the author of the Lovebug virus?

A)Francisco Antonelli

B)Onel de Guzman

C)Gunter Hanz

D)Ray Chi Chen

Answer: B

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Computer Forensics Anddigital Detective Work

Available Study Resources on Quizplus for this Chatper

28 Verified Questions

28 Flashcards

Source URL: https://quizplus.com/quiz/43036

Sample Questions

Q1) One of the more popular theories is that a person could actually commit ________ by changing a patient's medication data.

Answer: murder

Q2) In what manner were e-commerce employees caught making online purchases using clients' credit card numbers?

A)Copies of credit card numbers were found in their desks.

B)Copies of transactions were found at their homes.

C)Saved files were stored in a hidden directory.

D)Credit card numbers,along with the name and address of person who placed order,were found in a hidden HTML coded file.

Answer: D

Q3) Which of the following is NOT considered one of the items e-evidence is currently being used for?

A)To prove intent

B)To imply motive

C)To provide alibis

D)All listed are currently being used

Answer: C

To view all questions and flashcards with answers, click on the resource link above.

4

Chapter 3: Tools, Environments, Equipment, and Certifications

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/43037

Sample Questions

Q1) You may need to do a(n)________ analysis during a hacker attack or other intrusion.

Answer: live

Q2) FTK

A) The universal hexadecimal editor

B) Invaluable for combing through large amounts of data

C) Exclusively for Macs

D) AccessData tool designed for finding and examining evidence

E) Primarily for computer crime investigators

Answer: D

Q3) ________ data can include spreadsheets,databases,and word processing files.

Answer: Active

Q4) If you need to remove a password from files,you could use a program such as

A)Jack the Cracker

B)WinHex

C)MacQuisition

D)John the Ripper

Answer: D

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Policies and Procedures

Available Study Resources on Quizplus for this Chatper

63 Verified Questions

63 Flashcards

Source URL: https://quizplus.com/quiz/43038

Sample Questions

Q1) A(n)________ needs to be completed when reviewing a potential case and determining whether to accept it.

Q2) What is the computer environment?

A)Identify the operating system or network topology

B)There may be fingerprints or other trace evidence

C)You would use different tools to locate different items such as photographs or spreadsheets

D)This determines how you will extract the data

E)The more skilled the user, the more likely it is that he can alter or destroy evidence

Q3) Looking for protected files

A)Bottom logical examination layer

B)Second logical examination layer

C)Third logical examination layer

D)Fourth logical examination layer

Q4) With the original evidence safely stored,you should make a(n)________ of the forensic image.

Q5) Your best bet for decrypting a file is to find out what program was used to encrypt it and obtain the ________ for that software.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Data, PDA, and Cell Phone Forensics

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/43039

Sample Questions

Q1) If a PDA has only a single rechargeable battery,the appropriate ________ should be connected to the device if possible.

Q2) To gain access to a protected SIM,you may need to ask the service provider for a(n)________.

Q3) To understand how hardware works,you must understand the ________ of how drives store 0s and 1s.

Q4) ________ media use light from laser or LED sources to determine 0s and 1s.

Q5) Cell Seizure

A)CDMA phones

B)GSM phones

C)Supports GSM and TDMA

D)Palm OS

Q6) One excellent feature of ________ is that this software can crack Palm passwords.

Q7) As further insurance against writing to a hard drive under investigation,an examiner should use a(n)________.

Q8) New cellular phones are basically low-end _______.

Q9) A(n)________ groups the same tracks vertically through a stack of platters.

Q10) ________ is the most widely used hard drive technology.

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Operating Systems and Data Transmission

Basics for Digital Investigations

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/43040

Sample Questions

Q1) Network

A)Translates logical to physical addresses

B)Creates and maintains the communications link

C)Performs protocol conversion

D)Transmits raw data

Q2) In data transfer,only the ________ changes from router or switch to the next one in line.

Q3) To interface properly between applications and hardware,operating systems use

Q4) The two main camps in the UNIX world are the ________ and the ________.

Q5) The newest Macintosh systems are based on the

A)UNIX operating system

B)Windows operating system

C)Linux operating system

D)DOS operating system

Q6) Transport

A)Uses IP as its transmission protocol

B)The reliability layer

C)Handles physical aspects of a network

D)Routes packets over a network

8

To view all questions and flashcards with answers, click on the resource link above.

Page 9

Chapter 7: Investigating Windows, linux, and Graphic Files

Available Study Resources on Quizplus for this Chatper

57 Verified Questions

57 Flashcards

Source URL: https://quizplus.com/quiz/43041

Sample Questions

Q1) In a forensics context,hidden information about files and folders is called

A)Artifact data

B)Metadata

C)Archive data

D)Read-only data

Q2) Dentry object

A)Contain metadata for each file

B)Unit of allocation for storage

C)Created for every file system mounted

D)Contains information about the directory structure

Q3) HKEY_USERS Default

A)Default

B)System

C)SAM

D)Software

Q4) The ________ tracks those actions deemed as events by the software application.

Q5) The process of retrieving image data from unallocated or slack space is called

Q6) A(n)________ is designed as a hierarchical listing of folders and files.

Q7) System data and artifacts are files generated by the ________.

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 8: E-Mail and Webmail Forensics

Available Study Resources on Quizplus for this Chatper

47 Verified Questions

47 Flashcards

Source URL: https://quizplus.com/quiz/43042

Sample Questions

Q1) IMAP

A)Dependant upon Internet

B)Accessible from anywhere

C)Special software required

Q2) The tool often used for quick communications without resorting to e-mail is________ .

Q3) Which of the following are NOT considered important when working with RAID systems?

A)Transmission speed

B)Type of controller

C)Size of array

D)Type of hard drive

Q4) Apparently-To

A)Used if sender requests an automated confirmation of the recipient having read the e-mail

B)Easily spoofed by hackers

C)Nonstandard heading sometimes used when encountering a mailing list

D)Deals with non-text items such as photos

Q5) According to many Americans,________ violate their privacy and their First Amendment rights.

11

To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Internet and Network Forensics and Intrusion

Detection

Available Study Resources on Quizplus for this Chatper

39 Verified Questions

39 Flashcards

Source URL: https://quizplus.com/quiz/43043

Sample Questions

Q1) A(n)________ is the standard operation procedures of the network when it is running normally.

Q2) ________ Software allows you to forensically search for data on your entire network using nothing more than keywords or phrases.

Q3) ________ transmit and receive data via radio frequency in the open.

Q4) Server

A)Where the analysis is performed

B)Contains a large database

C)Modules installed on hosts

Q5) Which type of firewall acts as a mediator between internal hosts and external connections such as the Internet?

A)Network layer firewall

B)Application layer firewall

C)Proxy firewall

D)Internet firewall

Q6) Application layer

A)Permits FTP or HTTP protocols

B)Acts like an IP filter

C)Acts as a mediator

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Tracking Down Those Who Intend to Do Harm

on a Large Scale

Available Study Resources on Quizplus for this Chatper

39 Verified Questions

39 Flashcards

Source URL: https://quizplus.com/quiz/43044

Sample Questions

Q1) Which of the following was NOT e-evidence used to track the creator of the Melissa virus?

A)Hardware ID

B)Operating system event log

C)AOL return address

D)Key signature in e-mails from the perpetrator

Q2) Investigations into hackers can be difficult because even with a full audit trail showing that a user came from a particular account on a particular ISP,

A)ISPs almost never release the necessary information

B)The hacker may use more than one ISP

C)Often only billing information is available,which does not prove identity

D)All of the above

Q3) Anonymity,control resources,and many other features make the ________ the criminals' conduit for coordinating and carrying out an agenda.

Q4) alneda.com

A)Alleged to have flashed pictures of persecuted Muslims

B)Designed to teach users to conduct attacks

C)Used by jihad in Afghanistan

D)Featured international news on al Qaeda

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 11: Fraud and Forensic Accounting Investigation

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/43045

Sample Questions

Q1) Motive

A)Destroying documents prior to an investigation

B)Showing perp had a chance to commit crime

C)Is a strong circumstantial element

D)Finding multiple events of the same error

Q2) Which of the following is NOT one of the ways that fraud investigations originate?

A)From internal audits

B)From anonymous tips

C)From the FBI

D)From complaints by customers or vendors

Q3) The term ________ means mental state or "guilty mind."

Q4) Adelphia

A)Admitted to "loaning" $ 2.3 billion to the Rigas family

B)Insiders sell over $ 1.5 billion of inflated stock

C)CEO and CFO charged with multiple counts of fraud

Q5) Fraud is more likely to occur when someone feels ________ to commit fraud.

Q6) ________ is also referred to as forensic financial investigation.

Q7) Refusing to testify in court on the basis that the testimony may be self-incriminating is called ________.

Page 14

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Federal Rules and Criminal Codes

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43046

Sample Questions

Q1) Under the Federal Rules of Civil Procedure,which two rules regulate the production of evidence?

A)Rules 26 and 35

B)Rules 34 and 23

C)Rules 26 and 34

D)Rules 25 and 33

Q2) Digital Millennium Copyright Act

A)Requires that recordings be handed over to a judge

B)Forces ISPs to turn over names of suspected music pirates upon subpoena

C)Includes new guidance relating to computer crime and eevidence

D)Permits an ISP to look through stored e-mail messages

Q3) What amendment must a law enforcement office check before seizing hardware or computers?

A)The Fourth Amendment

B)The Sixth Amendment

C)The Eighth Amendment

D)The Tenth Amendment

Q4) The Frye test that Rule 702 relied upon was replaced with the ________ test.

Q5) The same circumstantial evidence the courts use to authenticate physical documents applies to ________ as well.

15

To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Ethical and Professional Responsibility in Testimony

Available Study Resources on Quizplus for this Chatper

30 Verified Questions

30 Flashcards

Source URL: https://quizplus.com/quiz/43047

Sample Questions

Q1) Which of the following is NOT considered a part of the work product?

A)Your conclusions

B)Your notes

C)Your opinions

D)Your colleague's opinion

Q2) Who may write the expert report?

A)The lawyer handling the case

B)The lawyer's secretary

C)The expert's secretary

D)Only the expert investigating the case

Q3) Everyone involved in the courts has a(n)________ to protect the legal system and the Constitution.

Q4) Before accepting a case,a good investigator will check

A)That there is enough money to make it worthwhile

B)That there are enough witnesses

C)That there are no physical dangers involved

D)That there is no conflict of interest

Q5) ________ is also used to examine jurors to make sure they are fair and impartial.

Q6) ________ are done out of court but under the same oath as in court.

To view all questions and flashcards with answers, click on the resource link above. Page 16

Turn static files into dynamic content formats.

Create a flipbook
Digital Forensics Midterm Exam - 600 Verified Questions by Quizplus - Issuu