Unit 1: Computer Forensics and Investigation Process - Practice Quiz

CSC303 — Digital Forensics 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the primary goal of computer forensics?

Understand the fundamentals of computer forensics Easy
A. Identifying, collecting, and preserving digital evidence for legal use
B. Improving website loading speed
C. Developing new antivirus software
D. Designing faster computer networks

2 Which term describes the process of using scientific methods to examine digital devices for evidence?

Understand the fundamentals of computer forensics Easy
A. Digital forensics
B. Data mining
C. Software testing
D. Cloud computing

3 Which of the following is an example of a cyber crime?

Understand cyber crimes and their investigation procedures Easy
A. Backing up files to a hard drive
B. Updating an operating system
C. Phishing to steal login credentials
D. Installing a printer driver

4 Cyber crimes are generally classified into which two broad categories?

Understand cyber crimes and their investigation procedures Easy
A. Fast and slow attacks
B. Hardware and paper attacks
C. Internal (insider) and external attacks
D. Legal and illegal attacks

5 Which of the following is the best example of digital evidence?

Understand digital evidence Easy
A. A handwritten paper note
B. A printed newspaper article
C. A physical fingerprint on glass
D. An email log stored on a server

6 Which property of digital evidence means it can be easily altered or deleted?

Understand digital evidence Easy
A. Fragility (volatility)
B. Durability
C. Rigidity
D. Permanence

7 What is used to ensure the integrity of digital evidence remains unchanged?

Understand digital evidence Easy
A. The device battery level
B. A cryptographic hash value
C. A file's color code
D. The screen resolution

8 What does forensic readiness primarily aim to achieve for an organization?

Understand forensic readiness Easy
A. Cheaper hardware purchases
B. Faster internet connectivity
C. Ability to collect and preserve evidence efficiently before an incident occurs
D. Reduced electricity consumption

9 A key benefit of forensic readiness is that it helps reduce which of the following?

Understand forensic readiness Easy
A. The cost and time of an investigation
B. The size of the office building
C. The number of employees needed
D. The speed of the CPU

10 What does the abbreviation SOC stand for in cybersecurity?

Incident response and the role of SOC (security operations center) in computer forensics Easy
A. Server Online Control
B. Security Operations Center
C. Software Optimization Cell
D. System Operating Console

11 What is the main purpose of an incident response process?

Incident response and the role of SOC (security operations center) in computer forensics Easy
A. To detect, contain, and recover from security incidents
B. To manage employee payroll
C. To increase advertising revenue
D. To design new company logos

12 Which is a core responsibility of a forensic investigator?

Identify the roles and responsibilities of a forensic investigator Easy
A. Managing company social media
B. Preserving the integrity of evidence during collection
C. Selling computer hardware
D. Writing marketing content

13 A forensic investigator may be required to do which of the following in a legal case?

Identify the roles and responsibilities of a forensic investigator Easy
A. Approve the company budget
B. Testify as an expert witness in court
C. Design the courtroom furniture
D. Set the trial date

14 Which of the following is a common challenge in investigating cyber crimes?

Understand the challenges faced in investigating cyber crimes Easy
A. Too few computers in the world
B. Lack of paper documents
C. Use of encryption and anti-forensic techniques by criminals
D. Excessive sunlight in offices

15 Why does the cross-border nature of cyber crime create investigation difficulties?

Understand the challenges faced in investigating cyber crimes Easy
A. The internet is slower internationally
B. Computers stop working across borders
C. Different countries have different laws and jurisdictions
D. Evidence becomes physically heavier

16 Why is legal compliance important in computer forensics?

Understand legal compliance in computer forensics Easy
A. It ensures evidence is admissible in court
B. It improves screen brightness
C. It makes computers run faster
D. It reduces the price of software

17 Which document tracks the handling and movement of evidence from collection to court?

Understand legal compliance in computer forensics Easy
A. Sales invoice
B. User manual
C. Chain of custody
D. Warranty card

18 What is the correct high-level order of the forensic investigation process?

Understand the forensic investigation process and its importance Easy
A. Post-investigation, investigation, pre-investigation
B. Pre-investigation, investigation, post-investigation
C. Investigation, pre-investigation, post-investigation
D. Investigation only, no other phases

19 Which activity typically occurs during the pre-investigation phase?

Understand the pre-investigation phase Easy
A. Setting up a forensics lab and obtaining authorization
B. Writing the final court report
C. Closing the investigation case
D. Destroying all collected evidence

20 What is a key priority during the first response at a crime scene?

Understand first response Easy
A. Deleting suspicious files immediately
B. Installing new software on devices
C. Rebooting all systems right away
D. Securing the scene and preserving volatile evidence

21 An investigator applies scientific methods to preserve, identify, extract, and document digital evidence so it can be presented in court. Which principle is being followed when the original evidence is never altered during analysis?

Understand the fundamentals of computer forensics Medium
A. Chain of custody
B. Order of volatility
C. Data acquisition integrity
D. Least privilege

22 A company detects that an attacker used a compromised employee account to transfer funds. Which classification best describes this cyber crime?

Understand cyber crimes and their investigation procedures Medium
A. Crime where the computer is the target
B. Crime where the computer is the tool
C. Crime incidental to another offense
D. Crime with no digital component

23 During an investigation, which type of digital evidence should be collected first based on the order of volatility?

Understand digital evidence Medium
A. Logs on a remote server
B. Contents of system RAM and cache
C. Archived backup tapes
D. Data stored on a hard disk

24 An investigator hashes an evidence file at seizure and again after imaging, and both hashes match. What does this primarily demonstrate?

Understand digital evidence Medium
A. The evidence is relevant to the case
B. The evidence is legally admissible
C. The evidence has not been modified
D. The evidence was legally obtained

25 An organization pre-configures centralized logging, evidence-handling policies, and trained staff before any incident occurs. This proactive capability is best termed:

Understand forensic readiness Medium
A. Incident containment
B. Disaster recovery
C. Forensic readiness
D. Business continuity

26 Which of the following is the primary business benefit of establishing forensic readiness?

Understand forensic readiness Medium
A. Reducing the cost and time of investigations
B. Removing the need for legal counsel
C. Eliminating all future security breaches
D. Guaranteeing conviction of attackers

27 A SOC analyst detects suspicious lateral movement and escalates it. Within incident response, this activity primarily supports which phase?

Incident response and the role of SOC (security operations center) in computer forensics Medium
A. Post-incident recovery
B. Preparation
C. Detection and analysis
D. Legal prosecution

28 Why is coordination between the SOC and the forensic team important during an active incident?

Incident response and the role of SOC (security operations center) in computer forensics Medium
A. To immediately reinstall affected systems
B. To disable all logging quickly
C. To publicly disclose the breach at once
D. To preserve volatile evidence before containment destroys it

29 A forensic investigator is asked to draw legal conclusions about a suspect's guilt in their report. What is the correct response?

Identify the roles and responsibilities of a forensic investigator Medium
A. Provide guilt conclusions to help the court
B. Delete evidence that suggests innocence
C. Refuse to write any report
D. Report only technical findings without legal verdicts

30 Which responsibility most distinguishes a forensic investigator from a general IT administrator?

Identify the roles and responsibilities of a forensic investigator Medium
A. Installing software patches
B. Maintaining evidence integrity and chain of custody
C. Managing user email accounts
D. Configuring network routers

31 An attacker routes traffic through servers in multiple countries before reaching the victim. Which investigation challenge does this most directly create?

Understand the challenges faced in investigating cyber crimes Medium
A. Jurisdictional and cross-border complexity
B. Weak password policies
C. Data volume overload
D. Lack of antivirus software

32 Investigators find that suspect files are encrypted with a strong algorithm and no key is available. This situation best illustrates which challenge?

Understand the challenges faced in investigating cyber crimes Medium
A. Excessive logging
B. Anti-forensic techniques
C. Improper documentation
D. Chain of custody failure

33 An investigator seizes a personal laptop without a warrant or consent. What is the most likely legal consequence?

Understand legal compliance in computer forensics Medium
A. The evidence gets automatically verified
B. The evidence may be ruled inadmissible
C. The chain of custody improves
D. The investigation speeds up

34 Which document primarily authorizes investigators to search and seize specific digital evidence at a location?

Understand legal compliance in computer forensics Medium
A. Incident report
B. Chain of custody form
C. Search warrant
D. Acceptable use policy

35 Why is following a standardized forensic investigation methodology critical?

Understand the forensic investigation process and its importance Medium
A. It guarantees the suspect confesses
B. It ensures results are repeatable and defensible in court
C. It removes the need for documentation
D. It makes investigations faster than any tool

36 Setting up a forensic lab, acquiring validated tools, and obtaining authorization all occur in which phase?

Understand the pre-investigation phase Medium
A. Post-investigation phase
B. Investigation phase
C. First response phase
D. Pre-investigation phase

37 Why should forensic tools be validated before an investigation begins?

Understand the pre-investigation phase Medium
A. To speed up suspect interviews
B. To avoid buying licenses
C. To ensure tool outputs are reliable and court-defensible
D. To reduce electricity usage

38 A first responder arrives at a scene with a running computer suspected of holding volatile evidence. What is the most appropriate initial action?

Understand first response Medium
A. Unplug the power cable at once
B. Install analysis software on it
C. Document the state and capture volatile data before powering off
D. Immediately shut it down normally

39 Which action by a first responder would most likely compromise the integrity of digital evidence?

Understand first response Medium
A. Noting connected devices
B. Browsing files on the suspect system directly
C. Recording the system time
D. Photographing the screen state

40 During the investigation phase, an examiner works on a forensic image rather than the original drive. What is the main reason?

Understand the investigation phase Medium
A. To preserve the original evidence unaltered
B. Images are cheaper to store
C. Originals cannot be hashed
D. Images run analysis tools faster

41 An investigator recovers a file whose logical size is 4,096 bytes but whose allocated cluster size is 8,192 bytes. Which forensic principle explains why the remaining 4,096 bytes may still contain evidentiary value?

Understand the fundamentals of computer forensics Hard
A. Slack space may retain fragments of previously deleted data
B. File carving always overwrites unallocated clusters
C. The MFT compresses unused bytes to zero automatically
D. Journaling erases residual data on every write cycle

42 During acquisition, an investigator computes an MD5 hash of a drive as a1b2... and later a SHA-256 hash as f9e8.... On re-verification months later, MD5 matches but SHA-256 differs. What is the MOST defensible conclusion?

Understand digital evidence Hard
A. Both hashes are invalid and the evidence must be discarded
B. An MD5 collision proves the drive is intact
C. MD5 is authoritative because it was computed first
D. The image was altered; SHA-256 collision resistance makes the mismatch the reliable indicator

43 Before seizing systems at a corporate site, the lead examiner insists on documenting the network topology and establishing a chain-of-custody template. Which pre-investigation objective does this BEST serve?

Understand the pre-investigation phase Hard
A. Ensuring evidence admissibility and scoping the investigation boundaries
B. Guaranteeing that no volatile data is ever collected
C. Accelerating the imaging speed of target drives
D. Reducing the number of forensic tools required

44 A first responder arrives at a running server suspected of active data exfiltration. Applying the order of volatility, which action should occur FIRST?

Understand first response Hard
A. Photograph the server rack and label cables
B. Power off the server to freeze the disk state
C. Image the hard disk with a write blocker
D. Capture RAM contents and active network connections

45 An organization wants to minimize the cost of future investigations while maximizing evidence usability. Which forensic readiness measure aligns BEST with this goal?

Understand forensic readiness Hard
A. Deleting logs weekly to comply with privacy defaults
B. Pre-defining logging policies and secure log retention aligned to legal needs
C. Encrypting logs so only executives can read them
D. Disabling all logging to reduce storage overhead

46 During incident response, a SOC analyst isolates an infected host but preserves its memory and disk before reimaging. Which tension is this workflow primarily balancing?

Incident response and the role of SOC (security operations center) in computer forensics Hard
A. Rapid containment against evidence preservation for later forensics
B. Password complexity against user convenience
C. Firewall throughput against VPN latency
D. Cost reduction against employee productivity

47 An examiner in the U.S. accesses a suspect's personal cloud account using credentials found on a seized laptop, without a specific warrant covering the cloud provider. What is the MOST likely legal consequence?

Understand legal compliance in computer forensics Hard
A. Cloud data is exempt from warrant requirements
B. Evidence is automatically admissible because the credentials were lawfully seized
C. Evidence may be excluded as it exceeds the scope of the original warrant
D. The examiner gains ownership of the account data

48 An attacker used a chain of proxies across multiple jurisdictions and full-disk encryption on the endpoint. Which combined challenge does this scenario MOST directly illustrate?

Understand the challenges faced in investigating cyber crimes Hard
A. Insufficient RAM capacity on the analysis workstation
B. Attribution difficulty compounded by anti-forensic encryption
C. Lack of a documented incident response plan
D. Absence of a forensic imaging tool

49 A forensic investigator discovers evidence that could exonerate the accused, but the client (prosecution) prefers it be omitted from the report. What is the investigator's correct professional obligation?

Identify the roles and responsibilities of a forensic investigator Hard
A. Report only findings that support the retaining party
B. Omit exculpatory data since it weakens the case
C. Follow the client's request to protect the engagement
D. Report all findings objectively regardless of which party they favor

50 An examiner must analyze a 2 TB image but only has read-only access and limited time. Which analysis strategy BEST preserves integrity while improving efficiency?

Understand the investigation phase Hard
A. Delete unallocated space before beginning analysis
B. Boot the original drive to browse it interactively
C. Modify the original evidence to remove irrelevant files
D. Work on a verified forensic copy using targeted keyword and hash-set filtering

51 In the post-investigation phase, why is a detailed, reproducible report considered more important than the raw tool output alone?

Understand the post-investigation phase Hard
A. It allows the tools to be uninstalled afterward
B. It reduces the storage needed for the evidence image
C. It enables independent verification and withstands cross-examination in court
D. It replaces the need to maintain chain of custody

52 Investigators classify an insider who copied trade secrets to a USB drive as committing which category, and what investigative focus follows?

Understand cyber crimes and their investigation procedures Hard
A. A ransomware event, focusing on backup restoration times
B. A phishing campaign, focusing on email gateway spam scores
C. An internal attack, focusing on endpoint logs, USB history, and access rights
D. An external DDoS, focusing on firewall throughput graphs

53 Why does skipping the identification/assessment step and jumping directly to acquisition often undermine an entire investigation?

Understand the forensic investigation process and its importance Hard
A. Hashing becomes mathematically impossible
B. Without scoping, relevant volatile or remote evidence may be missed or spoiled
C. Acquisition tools cannot function without a court order
D. The disk image size cannot be calculated

54 A defense attorney challenges a memory dump because the acquisition tool itself ran on the target and altered a few KB of RAM. Which principle best frames the appropriate response?

Understand digital evidence Hard
A. Only disk-based evidence can be authenticated
B. Locard-style trade-offs are documented; minimal, disclosed impact can still be admissible
C. RAM is never considered digital evidence
D. Any alteration renders all evidence permanently inadmissible

55 An organization implements NTP synchronization across all servers as part of forensic readiness. Which investigative benefit does this MOST directly enable?

Understand forensic readiness Hard
A. Reliable correlation of events across systems via consistent timestamps
B. Automatic encryption of all stored evidence
C. Elimination of the need for write blockers
D. Guaranteed recovery of deleted files

56 A multinational investigation must collect data stored on servers in the EU concerning EU residents. Which compliance consideration MOST directly constrains the collection?

Understand legal compliance in computer forensics Hard
A. GDPR data-protection and lawful-basis requirements for personal data
B. PCI-DSS card-storage rules exclusively
C. Export controls on cryptographic software only
D. The DMCA safe-harbor provisions for hosting providers

57 A first responder finds a locked, running workstation displaying a chat window with incriminating text. Pulling the plug would clear RAM. What is the BEST immediate action?

Understand first response Hard
A. Reboot the machine to capture startup logs
B. Immediately unplug to prevent remote wiping
C. Photograph the screen and perform live RAM acquisition before any shutdown
D. Log in with guessed credentials to save the chat

58 An examiner encounters timestamps that appear deliberately backdated using a timestomping tool. Which cross-verification approach BEST detects the manipulation?

Understand the challenges faced in investigating cyber crimes Hard
A. Trust the file's visible modified time in the OS
B. Rely solely on the recycle bin deletion time
C. Compare $STANDARD_INFORMATION and $FILE_NAME MFT timestamps for inconsistencies
D. Assume all timestamps are correct if hashes match

59 A SOC's SIEM raises a high-severity alert, but responders eradicate the threat before collecting artifacts. From a forensic standpoint, what is the primary loss?

Incident response and the role of SOC (security operations center) in computer forensics Hard
A. The SIEM's license validity period
B. Firewall bandwidth during the cleanup
C. Root-cause and attribution evidence needed for legal or full-scope analysis
D. The ability to update antivirus signatures

60 Which statement BEST captures the relationship between the Daubert standard and forensic methodology in court?

Understand the fundamentals of computer forensics Hard
A. Only open-source tools satisfy legal scrutiny
B. Any tool marketed as forensic is automatically admissible
C. Methods must be testable, peer-reviewed, and have a known error rate to be admissible
D. Admissibility depends solely on the examiner's certifications