Unit 3 - Practice Quiz

INT250 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 Which of the following best describes a 'bit-stream' image in digital forensics?

A. A bit-by-bit copy of the source drive, including unallocated space and slack space
B. A file containing only the active files from a hard drive
C. A compressed folder of the user's documents
D. A logical backup of the Windows Registry

2 In the context of the Order of Volatility, which data should be collected first?

A. Archival media (CDs/DVDs)
B. CPU cache, registers, and RAM
C. Disk data (Hard Drive)
D. Temporary file systems

3 Which hardware device is essential during static data acquisition to prevent data alteration on the source drive?

A. Write Blocker
B. Network Tap
C. Hex Editor
D. Packet Sniffer

4 Which file format is considered a 'raw' forensic image format?

A. .E01
B. .ad1
C. .vmdk
D. .dd

5 What is the primary purpose of generating a hash value (MD5 or SHA) immediately after data acquisition?

A. To verify the integrity of the evidence
B. To encrypt the image for security
C. To index the files for searching
D. To compress the image size

6 Which acquisition method is necessary when a computer cannot be shut down due to encryption or critical service availability?

A. Dead Acquisition
B. Static Acquisition
C. Live Acquisition
D. Sparse Acquisition

7 Where is the 'SAM' (Security Account Manager) hive located in a Windows system?

A. C:\Users\Default
B. C:\Program Files\Windows
C. C:\Windows\System
D. C:\Windows\System32\config

8 Which Windows artifact is essentially a snapshot of the contents of RAM saved to the hard drive when a computer is put into hibernation?

A. config.sys
B. hiberfil.sys
C. swapfile.sys
D. pagefile.sys

9 Which Registry hive contains settings specific to the currently logged-in user?

A. HKEY_CLASSES_ROOT
B. HKEY_LOCAL_MACHINE
C. HKEY_USERS
D. HKEY_CURRENT_USER

10 Which Windows artifact allows an investigator to see which applications were recently executed and the frequency of execution?

A. Prefetch files
B. Hosts file
C. SAM hive
D. Cookies

11 In Windows 10/11, where are Windows Event Logs typically stored?

A. C:\ProgramData\Logs
B. C:\Windows\Events
C. C:\Windows\System32\winevt\Logs
D. C:\Windows\Logs

12 Which browser artifact stores a small piece of data sent from a website to remember stateful information (like login status)?

A. History
B. Cookie
C. Bookmark
D. Cache

13 What is the function of the Windows 'Pagefile.sys'?

A. It stores the boot configuration
B. It records all keystrokes
C. It stores printer spooling data
D. It acts as virtual memory, extending physical RAM

14 Which proprietary file format, developed by Guidance Software, is standard for forensic images and supports compression and encryption?

A. ISO
B. AFF
C. E01
D. DD

15 When analyzing the Recycle Bin on Windows 10, which file contains the original filename and deletion date?

A. $R file
B. Desktop.ini
C. $I file
D. INFO2

16 Which Windows Event Log ID is commonly associated with a successful user logon?

A. 6005
B. 1102
C. 4624
D. 4625

17 What is 'Slack Space'?

A. The space on a hard drive reserved for the OS
B. The unused space between the end of a file and the end of the cluster
C. The space used by the Recycle Bin
D. The RAM allocated to the GPU

18 Which registry key is typically analyzed to determine which USB devices have been connected to the system?

A. HKCU\Software\Microsoft\Internet Explorer
B. HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
C. HKLM\SOFTWARE\Microsoft\Windows\Run
D. HKLM\SAM\Domains

19 What does the term 'Logical Acquisition' refer to?

A. Copying only the files and folders visible to the operating system
B. Copying data via a logic analyzer
C. Copying the physical drive bit-by-bit
D. Copying only the RAM

20 Which artifact typically stores the user's browsing history in Google Chrome?

A. index.dat
B. History (SQLite database)
C. places.sqlite
D. WebCache.dat

21 What is the purpose of 'Web Cache' or 'Temporary Internet Files'?

A. To block malicious pop-ups
B. To store user passwords encrypted
C. To record a log of all visited websites
D. To speed up browsing by storing static web content like images locally

22 Which Windows Registry key is known as a 'Run key' used for persistence (starting programs automatically)?

A. Software\Policies\Microsoft\Windows
B. System\CurrentControlSet\Control\Lsa
C. System\Setup\Status
D. Software\Microsoft\Windows\CurrentVersion\Run

23 What is the difference between 'Volatile' and 'Non-volatile' memory?

A. Volatile memory loses data when power is cut; Non-volatile retains it
B. Volatile memory is slower
C. Non-volatile memory cannot be imaged
D. Volatile memory is stored on the hard drive

24 Which file system artifact tracks the date and time a user last accessed a specific folder structure or window preference?

A. Jump Lists
B. Thumbcache
C. Shellbags
D. Amcache

25 What is an LNK file?

A. A locked file in the registry
B. A system link file for network drivers
C. A log file for kernel errors
D. A Windows shortcut file that links to an application or file

26 Which command line tool is built into Windows and can be used to query the registry?

A. ipconfig
B. grep
C. netstat
D. reg query

27 Which of the following is considered 'metadata' of a file?

A. The pixel data of an image
B. The actual content of a Word document
C. The text inside a text file
D. The creation, modification, and access timestamps

28 Why is 'Incognito' or 'Private' browsing mode a challenge for forensics?

A. It routes traffic through the Dark Web
B. It does not save history, cookies, or cache to the hard drive upon closing
C. It prevents the ISP from seeing traffic
D. It encrypts the internet connection

29 What is the 'Master File Table' (MFT)?

A. A partition table for the hard drive
B. A log of all master users
C. A backup of the BIOS
D. A database in NTFS that stores information about every file and directory

30 Which registry hive corresponds to the file 'NTUSER.DAT'?

A. HKEY_USERS
B. HKEY_LOCAL_MACHINE
C. HKEY_CURRENT_USER
D. HKEY_CURRENT_CONFIG

31 In a live acquisition, which tool is commonly used to capture RAM?

A. RegEdit
B. FTK Imager
C. Wireshark
D. Photoshop

32 What is a 'Sparse Copy'?

A. A copy of only the registry
B. A copy containing only allocated data and ignoring unallocated space
C. A copy made using a write blocker
D. A copy of data spread across multiple disks

33 Which text-based log file is generated by the IIS (Internet Information Services) web server?

A. Event Viewer Log
B. Kernel Log
C. W3C Extended Log
D. Syslog

34 The 'UserAssist' registry key provides information about:

A. Installed USB devices
B. GUI-based programs run by the user
C. User passwords
D. Network connections

35 What is 'Alternate Data Stream' (ADS) in Windows NTFS?

A. A method for streaming video
B. A backup stream for internet data
C. A corrupt file segment
D. A feature allowing data to be hidden behind a file without changing the file size

36 Which artifact lists files that were present on the system before a reboot or shutdown, often used to identify malware execution upon boot?

A. Thumb.db
B. Recycle Bin
C. ShimCache (AppCompatCache)
D. Jump Lists

37 What does Event ID 4625 represent in the Windows Security Log?

A. An account was locked out
B. Successful Logon
C. An account failed to log on
D. System shutdown

38 In the context of browser forensics, what is 'Form Data'?

A. The structure of the HTML page
B. The encryption key for SSL
C. The digital signature of the browser
D. Information entered by the user into web fields (names, addresses, search terms)

39 Which system file contains the mapping of IP addresses to hostnames, often modified by malware to redirect users?

A. protocol
B. services.exe
C. hosts
D. networks

40 What is the primary difference between Copy and Bit-stream Image?

A. Copy captures only active file content; Image captures the exact state of the drive
B. Copy is compressed; Image is not
C. Copy is faster; Image is slower
D. There is no difference

41 Which tool is commonly used to analyze Windows Registry hives?

A. Paint
B. Notepad
C. Registry Viewer
D. Wireshark

42 What is the function of the 'SYSTEM' hive?

A. Stores user settings
B. Stores internet history
C. Stores file extensions
D. Stores system configuration, driver settings, and hardware profiles

43 Which metadata standard is commonly found in image files (JPEG) containing camera model and GPS coordinates?

A. ASCII
B. EXIF
C. FAT
D. NTFS

44 When preparing a drive for an image, what should be done to the destination drive?

A. It should contain the operating system
B. It should be defragmented
C. It should be forensically wiped (sterilized)
D. It should be smaller than the source drive

45 What is 'Unallocated Space'?

A. Space that is damaged
B. Space reserved for the system
C. Space on the drive not currently assigned to any active file by the file system
D. Space used by hidden files

46 Which artifact is created when a user right-clicks the taskbar icon of an application to see recent files?

A. Jumplist
B. Logfile
C. Prefetch
D. Shortcut

47 In Windows Event Logs, what does the 'System' log record?

A. Events logged by Windows system components (drivers, boot errors)
B. Security audits like logins
C. Events logged by applications
D. Internet history

48 Why is 'Time Zone' information critical during analysis?

A. To decrypt files
B. To convert UTC timestamps in artifacts to the local time of the suspect
C. To determine the language of the OS
D. To calculate the internet speed

49 Which registry value controls the time zone information of the system?

A. ControlSet
B. TimeZoneInformation
C. HardwareProfiles
D. CurrentVersion

50 Which of the following describes a 'Static Acquisition'?

A. Acquisition of RAM only
B. Acquisition performed on a system that is powered off
C. Acquisition performed while the user is typing
D. Acquisition via a network connection