Unit 1: Computer Forensics and Investigation Process - Subjective Questions

CSC303 — Digital Forensics • Practice Questions with Detailed Answers

20 questions

1

Define computer forensics and explain its fundamental objectives in the context of a digital investigation.

2

Explain the different types of cyber crimes and briefly describe the general procedure followed in their investigation.

3

What is digital evidence? Discuss its characteristics and the various types of digital evidence.

4

Define forensic readiness. Explain its importance and list the key goals an organization should achieve to be forensically ready.

5

Explain the concept of Incident Response and describe the role of the Security Operations Center (SOC) in computer forensics.

6

Identify and describe the key roles and responsibilities of a forensic investigator.

7

Discuss the various challenges faced in investigating cyber crimes.

8

Explain the importance of legal compliance in computer forensics. What are the consequences of non-compliance?

9

Describe the forensic investigation process and explain why a systematic process is important.

10

Explain in detail the pre-investigation phase of a forensic investigation, including the setup of a forensic lab.

11

What is first response in a forensic investigation? Describe the responsibilities of a first responder and the steps involved.

12

Explain the investigation phase of the forensic process, focusing on evidence acquisition and analysis.

13

Describe the post-investigation phase and explain the importance of the forensic report.

14

Distinguish between volatile and non-volatile digital evidence with suitable examples.

15

What is the chain of custody? Explain its significance and the information it must contain.

16

Compare internal (insider) attacks and external attacks in the context of cyber crime investigation.

17

Explain the rules of evidence that digital evidence must satisfy to be admissible in a court of law.

18

Discuss the various forensic tools and techniques used in computer forensics, categorizing them appropriately.

19

Explain the importance of hashing in digital forensics. How is data integrity verified using hash values? Illustrate with an example.

20

Describe the fundamentals of computer forensics and explain how it differs from general data recovery.