Unit 1: Computer Forensics and Investigation Process - Subjective Questions

INT250 — Digital Evidence Analysis • Practice Questions with Detailed Answers

20 questions

1

Define computer forensics and explain its major objectives.

2

Explain the fundamental principles that make a computer forensic investigation reliable and legally defensible.

3

Classify common types of cybercrime and describe an appropriate investigation procedure for each major category.

4

Define digital evidence and explain its major characteristics with suitable examples.

5

Distinguish between volatile evidence and non-volatile evidence. Why is the order of collection important?

6

Explain the requirements that digital evidence should satisfy to be considered admissible and credible.

7

Describe the purpose of forensic imaging, write blockers, and cryptographic hash values in preserving digital evidence.

8

What is forensic readiness? Explain the main elements of an effective forensic-readiness program.

9

Explain the relationship between incident response and computer forensics.

10

Describe the phases of the incident-response life cycle and identify the forensic activities performed in each phase.

11

Explain the role of a Security Operations Center (SOC) in computer forensic investigations.

12

Compare the responsibilities of a SOC analyst, an incident responder, and a forensic investigator during a cyber incident.

13

Describe the roles, responsibilities, and ethical duties of a forensic investigator.

14

Explain the complete forensic investigation process and discuss why each stage is important.

15

What activities are carried out during the pre-investigation phase of a computer forensic investigation?

16

Describe the duties of a first responder at a digital crime scene.

17

A suspected employee computer is powered on, connected to the network, and displaying an encrypted volume. Explain how a first responder should approach this situation.

18

Explain the activities performed during the investigation phase, from forensic examination to the presentation of findings.

19

Define chain of custody and describe how it should be maintained for digital evidence.

20

Compare live acquisition and dead acquisition. State their advantages, limitations, and suitable use cases.