Unit 3: Anti-Forensics Techniques and Windows Forensics - Subjective Questions

CSC303 — Digital Forensics • Practice Questions with Detailed Answers

20 questions

1

Define anti-forensics and explain its main goals. Describe at least four broad categories of anti-forensics techniques used by attackers.

2

Explain how data deletion works in Windows and describe the role of the Recycle Bin in forensic investigations. What artifacts can be recovered from the Recycle Bin?

3

Illustrate the concept of file carving. Explain the difference between header/footer-based carving and file structure-based carving, and discuss the challenges involved.

4

Explore the common password cracking and bypassing techniques used in digital forensics. Compare their approaches and effectiveness.

5

What is steganography? Describe various methods used to hide data and explain the techniques (steganalysis) used to detect it.

6

Explain how data can be hidden within file system structures. Discuss slack space, alternate data streams, and hidden partitions with examples.

7

Discuss trail obfuscation as an anti-forensic technique. Explain timestamp manipulation (timestomping) and log manipulation with their forensic countermeasures.

8

Understand artifact wiping. Explain the difference between file wiping, disk wiping, and the detection of overwritten data and metadata.

9

Explain encryption as an anti-forensic technique. Distinguish between full disk encryption and file-level encryption, and describe how investigators handle encrypted evidence.

10

Describe program packers and footprint-minimizing techniques. How are packed executables detected during forensic analysis?

11

Understand anti-forensics countermeasures. Discuss in detail the strategies and best practices investigators adopt to counter various anti-forensic techniques.

12

Distinguish between volatile and non-volatile information in the context of digital forensics. Explain the order of volatility and why it matters during evidence collection.

13

Explain the process of Windows memory (RAM) analysis in digital forensics. Discuss acquisition methods and the types of artifacts recoverable from memory. [10 marks]

14

Describe the structure of the Windows Registry and explain its importance in forensic analysis. List key registry locations and the evidence they provide. [10 marks]

15

Examine the forensic significance of web browser artifacts. Explain how cache, cookies, and browsing history can be analyzed as evidence.

16

Explain the significance of Windows files and metadata in forensic examination. Discuss prefetch files, thumbnail cache, and file metadata as sources of evidence.

17

Understand ShellBags. Explain what ShellBags are, where they are stored, and their forensic value.

18

Explain LNK files and Jump Lists in Windows forensics. How do they help establish user activity and access to files?

19

Distinguish between text-based logs and Windows Event Logs. Explain their formats, storage, and forensic importance. [10 marks]

20

Describe the complete procedure for collecting volatile and non-volatile information from a suspect Windows system, following forensic best practices. [10 marks]