Unit 4: Linux, Mac and Network Forensics - Subjective Questions

CSC303 — Digital Forensics • Practice Questions with Detailed Answers

20 questions

1

Distinguish between volatile and non-volatile data in a Linux system. Give examples of each and explain why the order of volatility matters during evidence acquisition.

2

Explain The Sleuth Kit (TSK) and describe how it is used to analyze filesystem images. Mention at least four key command-line tools with their functions.

3

Describe the process of memory forensics using the Volatility framework. Explain the importance of memory profiles and list five commonly used plugins.

4

What is PhotoRec? Explain how it performs file carving and how it differs from traditional file recovery methods.

5

Explain the key aspects of Mac forensics. Discuss important artifacts, filesystems, and challenges an investigator faces on macOS.

6

Define network forensics. Explain its objectives and describe the two common approaches: "catch-it-as-you-can" and "stop-look-and-listen".

7

Discuss logging fundamentals and the concept of network forensic readiness. Why is forensic readiness important for an organization?

8

Summarize the concept of event correlation in digital forensics. Explain different types of correlation techniques.

9

What are Indicators of Compromise (IoCs)? Explain how IoCs can be identified from network logs, giving examples.

10

Explain the process of investigating network traffic. Describe the role of tools like Wireshark and tcpdump in this process.

11

What is a SIEM tool? Explain how SIEM helps in incident detection and examination, and describe its core capabilities.

12

Describe common wireless network attacks and explain how they can be monitored and detected.

13

Explain how volatile data can be collected from a live Linux system. List the important commands and the artifacts they capture.

14

Compare HFS+ and APFS filesystems used in macOS from a forensic perspective.

15

Explain the concept of file signature (magic number) based carving. Illustrate with the header and footer signatures of common file types.

16

Describe the different types of logs that are important in network forensics and explain what forensic value each provides.

17

Explain the incident response lifecycle and how digital and network forensics fit into each phase.

18

Distinguish between Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), and explain signature-based vs anomaly-based detection.

19

Explain the steps involved in performing memory forensics on a Linux system, from acquisition to analysis using Volatility.

20

Describe how an investigator would analyze a captured network traffic file (.pcap) to detect a data exfiltration incident. Explain the indicators to look for and the analysis steps.