The forensic process generally follows three phases: pre-investigation (preparation), investigation (analysis), and post-investigation (reporting).
Incorrect! Try again.
19Which activity typically occurs during the pre-investigation phase?
Understand the pre-investigation phase
Easy
A.Setting up a forensics lab and obtaining authorization
B.Writing the final court report
C.Closing the investigation case
D.Destroying all collected evidence
Correct Answer: Setting up a forensics lab and obtaining authorization
Explanation:
The pre-investigation phase involves preparation tasks like setting up the lab, getting proper authorization, and assembling tools.
Incorrect! Try again.
20What is a key priority during the first response at a crime scene?
Understand first response
Easy
A.Deleting suspicious files immediately
B.Installing new software on devices
C.Rebooting all systems right away
D.Securing the scene and preserving volatile evidence
Correct Answer: Securing the scene and preserving volatile evidence
Explanation:
First responders must secure the scene and preserve fragile, volatile evidence (like RAM data) before it is lost or altered.
Incorrect! Try again.
21An investigator applies scientific methods to preserve, identify, extract, and document digital evidence so it can be presented in court. Which principle is being followed when the original evidence is never altered during analysis?
Understand the fundamentals of computer forensics
Medium
A.Chain of custody
B.Order of volatility
C.Data acquisition integrity
D.Least privilege
Correct Answer: Data acquisition integrity
Explanation:
Preserving the original evidence unchanged and analyzing only verified copies maintains data acquisition integrity, a core forensic principle. Chain of custody tracks handling, not alteration itself.
Incorrect! Try again.
22A company detects that an attacker used a compromised employee account to transfer funds. Which classification best describes this cyber crime?
Understand cyber crimes and their investigation procedures
Medium
A.Crime where the computer is the target
B.Crime where the computer is the tool
C.Crime incidental to another offense
D.Crime with no digital component
Correct Answer: Crime where the computer is the tool
Explanation:
The computer/account is used as an instrument to commit financial fraud, so it is the tool of the crime rather than the target being attacked directly.
Incorrect! Try again.
23During an investigation, which type of digital evidence should be collected first based on the order of volatility?
Understand digital evidence
Medium
A.Logs on a remote server
B.Contents of system RAM and cache
C.Archived backup tapes
D.Data stored on a hard disk
Correct Answer: Contents of system RAM and cache
Explanation:
The order of volatility dictates collecting the most volatile data first. RAM and cache are lost when power is removed, so they take priority over disk and archived data.
Incorrect! Try again.
24An investigator hashes an evidence file at seizure and again after imaging, and both hashes match. What does this primarily demonstrate?
Understand digital evidence
Medium
A.The evidence is relevant to the case
B.The evidence is legally admissible
C.The evidence has not been modified
D.The evidence was legally obtained
Correct Answer: The evidence has not been modified
Explanation:
Matching hash values before and after imaging prove data integrity, confirming the evidence was not altered. Admissibility, relevance, and legality are separate legal considerations.
Incorrect! Try again.
25An organization pre-configures centralized logging, evidence-handling policies, and trained staff before any incident occurs. This proactive capability is best termed:
Understand forensic readiness
Medium
A.Incident containment
B.Disaster recovery
C.Forensic readiness
D.Business continuity
Correct Answer: Forensic readiness
Explanation:
Forensic readiness is the ability to collect and preserve evidence proactively, minimizing investigation cost and time when an incident happens.
Incorrect! Try again.
26Which of the following is the primary business benefit of establishing forensic readiness?
Understand forensic readiness
Medium
A.Reducing the cost and time of investigations
B.Removing the need for legal counsel
C.Eliminating all future security breaches
D.Guaranteeing conviction of attackers
Correct Answer: Reducing the cost and time of investigations
Explanation:
Forensic readiness ensures evidence is already available and properly handled, lowering the effort, cost, and disruption of investigations. It cannot eliminate breaches or guarantee convictions.
Incorrect! Try again.
27A SOC analyst detects suspicious lateral movement and escalates it. Within incident response, this activity primarily supports which phase?
Incident response and the role of SOC (security operations center) in computer forensics
Medium
A.Post-incident recovery
B.Preparation
C.Detection and analysis
D.Legal prosecution
Correct Answer: Detection and analysis
Explanation:
Monitoring, detecting anomalies, and escalating alerts are core SOC functions that map to the detection and analysis phase of incident response.
Incorrect! Try again.
28Why is coordination between the SOC and the forensic team important during an active incident?
Incident response and the role of SOC (security operations center) in computer forensics
Medium
A.To immediately reinstall affected systems
B.To disable all logging quickly
C.To publicly disclose the breach at once
D.To preserve volatile evidence before containment destroys it
Correct Answer: To preserve volatile evidence before containment destroys it
Explanation:
Containment actions like isolating or rebooting hosts can destroy volatile evidence. Coordination ensures forensically sound preservation before such actions occur.
Incorrect! Try again.
29A forensic investigator is asked to draw legal conclusions about a suspect's guilt in their report. What is the correct response?
Identify the roles and responsibilities of a forensic investigator
Medium
A.Provide guilt conclusions to help the court
B.Delete evidence that suggests innocence
C.Refuse to write any report
D.Report only technical findings without legal verdicts
Correct Answer: Report only technical findings without legal verdicts
Explanation:
The investigator documents objective technical findings. Determining guilt is the role of the court, not the forensic examiner.
Incorrect! Try again.
30Which responsibility most distinguishes a forensic investigator from a general IT administrator?
Identify the roles and responsibilities of a forensic investigator
Medium
A.Installing software patches
B.Maintaining evidence integrity and chain of custody
C.Managing user email accounts
D.Configuring network routers
Correct Answer: Maintaining evidence integrity and chain of custody
Explanation:
Forensic investigators are uniquely responsible for legally sound evidence handling, including preserving integrity and documenting the chain of custody.
Incorrect! Try again.
31An attacker routes traffic through servers in multiple countries before reaching the victim. Which investigation challenge does this most directly create?
Understand the challenges faced in investigating cyber crimes
Medium
A.Jurisdictional and cross-border complexity
B.Weak password policies
C.Data volume overload
D.Lack of antivirus software
Correct Answer: Jurisdictional and cross-border complexity
Explanation:
Evidence spread across multiple legal jurisdictions complicates warrants, cooperation, and prosecution, a major challenge in cyber crime investigations.
Incorrect! Try again.
32Investigators find that suspect files are encrypted with a strong algorithm and no key is available. This situation best illustrates which challenge?
Understand the challenges faced in investigating cyber crimes
Medium
A.Excessive logging
B.Anti-forensic techniques
C.Improper documentation
D.Chain of custody failure
Correct Answer: Anti-forensic techniques
Explanation:
Encryption used to hinder analysis is an anti-forensic technique deliberately designed to obstruct evidence recovery.
Incorrect! Try again.
33An investigator seizes a personal laptop without a warrant or consent. What is the most likely legal consequence?
Understand legal compliance in computer forensics
Medium
A.The evidence gets automatically verified
B.The evidence may be ruled inadmissible
C.The chain of custody improves
D.The investigation speeds up
Correct Answer: The evidence may be ruled inadmissible
Explanation:
Evidence obtained without proper legal authority (warrant/consent) can be excluded in court, regardless of its technical value.
Incorrect! Try again.
34Which document primarily authorizes investigators to search and seize specific digital evidence at a location?
Understand legal compliance in computer forensics
Medium
A.Incident report
B.Chain of custody form
C.Search warrant
D.Acceptable use policy
Correct Answer: Search warrant
Explanation:
A search warrant grants legal authority to search and seize specified evidence. The other documents track or govern handling but do not grant seizure authority.
Incorrect! Try again.
35Why is following a standardized forensic investigation methodology critical?
Understand the forensic investigation process and its importance
Medium
A.It guarantees the suspect confesses
B.It ensures results are repeatable and defensible in court
C.It removes the need for documentation
D.It makes investigations faster than any tool
Correct Answer: It ensures results are repeatable and defensible in court
Explanation:
A standardized process produces reproducible, verifiable results that withstand legal scrutiny, which is the core reason methodology matters.
Incorrect! Try again.
36Setting up a forensic lab, acquiring validated tools, and obtaining authorization all occur in which phase?
Understand the pre-investigation phase
Medium
A.Post-investigation phase
B.Investigation phase
C.First response phase
D.Pre-investigation phase
Correct Answer: Pre-investigation phase
Explanation:
Preparation activities such as building the lab, validating tools, and securing legal authorization belong to the pre-investigation phase, before evidence handling begins.
Incorrect! Try again.
37Why should forensic tools be validated before an investigation begins?
Understand the pre-investigation phase
Medium
A.To speed up suspect interviews
B.To avoid buying licenses
C.To ensure tool outputs are reliable and court-defensible
D.To reduce electricity usage
Correct Answer: To ensure tool outputs are reliable and court-defensible
Explanation:
Validated tools produce trusted, consistent results that can be defended in court, which is essential before they are used on real evidence.
Incorrect! Try again.
38A first responder arrives at a scene with a running computer suspected of holding volatile evidence. What is the most appropriate initial action?
Understand first response
Medium
A.Unplug the power cable at once
B.Install analysis software on it
C.Document the state and capture volatile data before powering off
D.Immediately shut it down normally
Correct Answer: Document the state and capture volatile data before powering off
Explanation:
Documenting the scene and capturing volatile data (RAM, network connections) first prevents loss of evidence that disappears when the system is powered off.
Incorrect! Try again.
39Which action by a first responder would most likely compromise the integrity of digital evidence?
Understand first response
Medium
A.Noting connected devices
B.Browsing files on the suspect system directly
C.Recording the system time
D.Photographing the screen state
Correct Answer: Browsing files on the suspect system directly
Explanation:
Opening or browsing files alters timestamps and metadata on the original system. Photographing, recording time, and noting devices are non-intrusive.
Incorrect! Try again.
40During the investigation phase, an examiner works on a forensic image rather than the original drive. What is the main reason?
Understand the investigation phase
Medium
A.To preserve the original evidence unaltered
B.Images are cheaper to store
C.Originals cannot be hashed
D.Images run analysis tools faster
Correct Answer: To preserve the original evidence unaltered
Explanation:
Analyzing a verified bit-stream copy protects the original from any modification, keeping it intact and admissible.
Incorrect! Try again.
41An investigator recovers a file whose logical size is 4,096 bytes but whose allocated cluster size is 8,192 bytes. Which forensic principle explains why the remaining 4,096 bytes may still contain evidentiary value?
Understand the fundamentals of computer forensics
Hard
A.Slack space may retain fragments of previously deleted data
C.The MFT compresses unused bytes to zero automatically
D.Journaling erases residual data on every write cycle
Correct Answer: Slack space may retain fragments of previously deleted data
Explanation:
The gap between a file's logical size and its allocated cluster is file slack, which can retain remnants of older data not yet overwritten, making it a valuable source of evidence.
Incorrect! Try again.
42During acquisition, an investigator computes an MD5 hash of a drive as a1b2... and later a SHA-256 hash as f9e8.... On re-verification months later, MD5 matches but SHA-256 differs. What is the MOST defensible conclusion?
Understand digital evidence
Hard
A.Both hashes are invalid and the evidence must be discarded
B.An MD5 collision proves the drive is intact
C.MD5 is authoritative because it was computed first
D.The image was altered; SHA-256 collision resistance makes the mismatch the reliable indicator
Correct Answer: The image was altered; SHA-256 collision resistance makes the mismatch the reliable indicator
Explanation:
A SHA-256 mismatch indicates the data changed. Because MD5 is vulnerable to collisions, a matching MD5 alone cannot guarantee integrity, so the stronger algorithm's mismatch governs.
Incorrect! Try again.
43Before seizing systems at a corporate site, the lead examiner insists on documenting the network topology and establishing a chain-of-custody template. Which pre-investigation objective does this BEST serve?
Understand the pre-investigation phase
Hard
A.Ensuring evidence admissibility and scoping the investigation boundaries
B.Guaranteeing that no volatile data is ever collected
C.Accelerating the imaging speed of target drives
D.Reducing the number of forensic tools required
Correct Answer: Ensuring evidence admissibility and scoping the investigation boundaries
Explanation:
The pre-investigation phase establishes scope, authorization, and chain-of-custody procedures so evidence collected later remains admissible and the investigation stays within legal limits.
Incorrect! Try again.
44A first responder arrives at a running server suspected of active data exfiltration. Applying the order of volatility, which action should occur FIRST?
Understand first response
Hard
A.Photograph the server rack and label cables
B.Power off the server to freeze the disk state
C.Image the hard disk with a write blocker
D.Capture RAM contents and active network connections
Correct Answer: Capture RAM contents and active network connections
Explanation:
The order of volatility prioritizes the most transient data first. RAM and live network connections vanish on shutdown, so they are captured before disk imaging or powering down.
Incorrect! Try again.
45An organization wants to minimize the cost of future investigations while maximizing evidence usability. Which forensic readiness measure aligns BEST with this goal?
Understand forensic readiness
Hard
A.Deleting logs weekly to comply with privacy defaults
B.Pre-defining logging policies and secure log retention aligned to legal needs
C.Encrypting logs so only executives can read them
D.Disabling all logging to reduce storage overhead
Correct Answer: Pre-defining logging policies and secure log retention aligned to legal needs
Explanation:
Forensic readiness means preparing in advance so evidence can be gathered cost-effectively. Defining what to log, for how long, and how to protect it ensures usable, admissible evidence when needed.
Incorrect! Try again.
46During incident response, a SOC analyst isolates an infected host but preserves its memory and disk before reimaging. Which tension is this workflow primarily balancing?
Incident response and the role of SOC (security operations center) in computer forensics
Hard
A.Rapid containment against evidence preservation for later forensics
B.Password complexity against user convenience
C.Firewall throughput against VPN latency
D.Cost reduction against employee productivity
Correct Answer: Rapid containment against evidence preservation for later forensics
Explanation:
SOC-driven incident response must stop ongoing harm (containment) while retaining forensic artifacts. Preserving memory and disk before reimaging balances speed with the integrity of future evidence.
Incorrect! Try again.
47An examiner in the U.S. accesses a suspect's personal cloud account using credentials found on a seized laptop, without a specific warrant covering the cloud provider. What is the MOST likely legal consequence?
Understand legal compliance in computer forensics
Hard
A.Cloud data is exempt from warrant requirements
B.Evidence is automatically admissible because the credentials were lawfully seized
C.Evidence may be excluded as it exceeds the scope of the original warrant
D.The examiner gains ownership of the account data
Correct Answer: Evidence may be excluded as it exceeds the scope of the original warrant
Explanation:
A warrant defines the lawful scope of search. Accessing separately stored cloud data typically requires its own authorization; exceeding scope risks suppression of the evidence.
Incorrect! Try again.
48An attacker used a chain of proxies across multiple jurisdictions and full-disk encryption on the endpoint. Which combined challenge does this scenario MOST directly illustrate?
Understand the challenges faced in investigating cyber crimes
Hard
A.Insufficient RAM capacity on the analysis workstation
B.Attribution difficulty compounded by anti-forensic encryption
C.Lack of a documented incident response plan
D.Absence of a forensic imaging tool
Correct Answer: Attribution difficulty compounded by anti-forensic encryption
Explanation:
Proxy chains obscure the true origin (attribution problem), while full-disk encryption is an anti-forensic barrier to data access. Together they represent core cybercrime investigation challenges.
Incorrect! Try again.
49A forensic investigator discovers evidence that could exonerate the accused, but the client (prosecution) prefers it be omitted from the report. What is the investigator's correct professional obligation?
Identify the roles and responsibilities of a forensic investigator
Hard
A.Report only findings that support the retaining party
B.Omit exculpatory data since it weakens the case
C.Follow the client's request to protect the engagement
D.Report all findings objectively regardless of which party they favor
Correct Answer: Report all findings objectively regardless of which party they favor
Explanation:
A forensic investigator's duty is to objectivity and the truth, not to a party. Suppressing exculpatory evidence violates ethical and legal obligations and undermines admissibility.
Incorrect! Try again.
50An examiner must analyze a 2 TB image but only has read-only access and limited time. Which analysis strategy BEST preserves integrity while improving efficiency?
Understand the investigation phase
Hard
A.Delete unallocated space before beginning analysis
B.Boot the original drive to browse it interactively
C.Modify the original evidence to remove irrelevant files
D.Work on a verified forensic copy using targeted keyword and hash-set filtering
Correct Answer: Work on a verified forensic copy using targeted keyword and hash-set filtering
Explanation:
Analysis is always performed on a verified copy, never the original. Hash-set (known-file) filtering and keyword searches reduce the data volume to examine while preserving integrity.
Incorrect! Try again.
51In the post-investigation phase, why is a detailed, reproducible report considered more important than the raw tool output alone?
Understand the post-investigation phase
Hard
A.It allows the tools to be uninstalled afterward
B.It reduces the storage needed for the evidence image
C.It enables independent verification and withstands cross-examination in court
D.It replaces the need to maintain chain of custody
Correct Answer: It enables independent verification and withstands cross-examination in court
Explanation:
The report documents methodology and findings so another expert can reproduce results and the examiner can defend conclusions under cross-examination—raw output alone lacks this context.
Incorrect! Try again.
52Investigators classify an insider who copied trade secrets to a USB drive as committing which category, and what investigative focus follows?
Understand cyber crimes and their investigation procedures
Hard
A.A ransomware event, focusing on backup restoration times
B.A phishing campaign, focusing on email gateway spam scores
C.An internal attack, focusing on endpoint logs, USB history, and access rights
D.An external DDoS, focusing on firewall throughput graphs
Correct Answer: An internal attack, focusing on endpoint logs, USB history, and access rights
Explanation:
Data theft by a trusted user is an internal (insider) attack. Investigation centers on endpoint artifacts—USB device history, file access logs, and the user's authorized privileges.
Incorrect! Try again.
53Why does skipping the identification/assessment step and jumping directly to acquisition often undermine an entire investigation?
Understand the forensic investigation process and its importance
Hard
A.Hashing becomes mathematically impossible
B.Without scoping, relevant volatile or remote evidence may be missed or spoiled
C.Acquisition tools cannot function without a court order
D.The disk image size cannot be calculated
Correct Answer: Without scoping, relevant volatile or remote evidence may be missed or spoiled
Explanation:
Proper identification determines what and where evidence exists, including volatile and remote sources. Skipping it risks losing time-sensitive data and collecting the wrong systems.
Incorrect! Try again.
54A defense attorney challenges a memory dump because the acquisition tool itself ran on the target and altered a few KB of RAM. Which principle best frames the appropriate response?
Understand digital evidence
Hard
A.Only disk-based evidence can be authenticated
B.Locard-style trade-offs are documented; minimal, disclosed impact can still be admissible
C.RAM is never considered digital evidence
D.Any alteration renders all evidence permanently inadmissible
Correct Answer: Locard-style trade-offs are documented; minimal, disclosed impact can still be admissible
Explanation:
Live memory acquisition inherently perturbs RAM. When the impact is minimal, unavoidable, and fully documented, courts generally accept the evidence; transparency preserves admissibility.
Incorrect! Try again.
55An organization implements NTP synchronization across all servers as part of forensic readiness. Which investigative benefit does this MOST directly enable?
Understand forensic readiness
Hard
A.Reliable correlation of events across systems via consistent timestamps
B.Automatic encryption of all stored evidence
C.Elimination of the need for write blockers
D.Guaranteed recovery of deleted files
Correct Answer: Reliable correlation of events across systems via consistent timestamps
Explanation:
Synchronized clocks let investigators build accurate cross-system timelines. Without consistent time sources, correlating logs across hosts becomes unreliable and disputable.
Incorrect! Try again.
56A multinational investigation must collect data stored on servers in the EU concerning EU residents. Which compliance consideration MOST directly constrains the collection?
Understand legal compliance in computer forensics
Hard
A.GDPR data-protection and lawful-basis requirements for personal data
B.PCI-DSS card-storage rules exclusively
C.Export controls on cryptographic software only
D.The DMCA safe-harbor provisions for hosting providers
Correct Answer: GDPR data-protection and lawful-basis requirements for personal data
Explanation:
Collecting personal data of EU residents triggers GDPR, which requires a lawful basis and safeguards. Investigators must reconcile forensic needs with data-protection obligations.
Incorrect! Try again.
57A first responder finds a locked, running workstation displaying a chat window with incriminating text. Pulling the plug would clear RAM. What is the BEST immediate action?
Understand first response
Hard
A.Reboot the machine to capture startup logs
B.Immediately unplug to prevent remote wiping
C.Photograph the screen and perform live RAM acquisition before any shutdown
D.Log in with guessed credentials to save the chat
Correct Answer: Photograph the screen and perform live RAM acquisition before any shutdown
Explanation:
Screen contents and RAM are volatile. Documenting the visible state photographically and capturing memory preserves the on-screen evidence and live artifacts before power is removed.
Incorrect! Try again.
58An examiner encounters timestamps that appear deliberately backdated using a timestomping tool. Which cross-verification approach BEST detects the manipulation?
Understand the challenges faced in investigating cyber crimes
Hard
A.Trust the file's visible modified time in the OS
B.Rely solely on the recycle bin deletion time
C.Compare $STANDARD_INFORMATION and $FILE_NAME MFT timestamps for inconsistencies
D.Assume all timestamps are correct if hashes match
Correct Answer: Compare $STANDARD_INFORMATION and $FILE_NAME MFT timestamps for inconsistencies
Explanation:
Many timestomping tools alter only $STANDARD_INFORMATION times, leaving $FILE_NAME (MFT) times untouched. Discrepancies between the two attribute sets reveal manipulation.
Incorrect! Try again.
59A SOC's SIEM raises a high-severity alert, but responders eradicate the threat before collecting artifacts. From a forensic standpoint, what is the primary loss?
Incident response and the role of SOC (security operations center) in computer forensics
Hard
A.The SIEM's license validity period
B.Firewall bandwidth during the cleanup
C.Root-cause and attribution evidence needed for legal or full-scope analysis
D.The ability to update antivirus signatures
Correct Answer: Root-cause and attribution evidence needed for legal or full-scope analysis
Explanation:
Eradicating before preserving destroys artifacts required to determine root cause, scope, and attribution—critical for legal action and preventing recurrence. Preservation should precede eradication.
Incorrect! Try again.
60Which statement BEST captures the relationship between the Daubert standard and forensic methodology in court?
Understand the fundamentals of computer forensics
Hard
A.Only open-source tools satisfy legal scrutiny
B.Any tool marketed as forensic is automatically admissible
C.Methods must be testable, peer-reviewed, and have a known error rate to be admissible
D.Admissibility depends solely on the examiner's certifications
Correct Answer: Methods must be testable, peer-reviewed, and have a known error rate to be admissible
Explanation:
The Daubert standard evaluates scientific evidence by testability, peer review, known error rates, and general acceptance—forensic methods must meet these criteria, not merely be branded 'forensic.'
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →