Unit 3: Data Acquisition and Windows Forensics - Subjective Questions

INT250 — Digital Evidence Analysis • Practice Questions with Detailed Answers

20 questions

1

Define data acquisition in digital forensics. Explain the fundamental principles that must be followed while acquiring digital evidence.

2

Compare physical acquisition, logical acquisition, and sparse or targeted acquisition. Discuss their advantages, limitations, and suitable use cases.

3

Describe a systematic data acquisition methodology from initial authorization to secure evidence storage.

4

Explain the role of write blockers, cryptographic hashing, and chain of custody in maintaining the integrity and admissibility of acquired evidence.

5

What steps should an examiner follow when preparing a forensic image for examination?

6

Define volatile information and describe the recommended order of volatility for collecting evidence from a running Windows system.

7

Describe the collection of non-volatile information from a Windows computer and identify the major artifacts that should be preserved.

8

Distinguish between live acquisition and dead-box acquisition. Under what circumstances should each method be selected?

9

Explain the objectives and major stages of Windows memory analysis. What forensic artifacts can be recovered from a RAM image?

10

How can an examiner use Windows memory analysis to identify process injection, hidden processes, and suspicious network activity?

11

Describe the structure of the Windows Registry and explain the forensic significance of major registry hives.

12

Explain how Windows Registry artifacts can be used to reconstruct user activity, program execution, connected devices, and persistence mechanisms.

13

Distinguish among browser cache, cookies, and browsing history and state the forensic value of each artifact.

14

Describe a forensic methodology for examining cache, cookies, history, downloads, and private-browsing remnants in Windows web browsers.

15

Explain the forensic importance of Windows files and NTFS metadata, including the Master File Table and other relevant file-system structures.

16

Discuss Windows file timestamps and metadata. How can an examiner detect possible timestomping or metadata manipulation?

17

Describe methods for examining deleted files, file slack, unallocated space, and alternate data streams on a Windows storage image.

18

What are text-based logs? Explain how they should be collected, validated, normalized, and analyzed during a Windows forensic investigation.

19

Explain the structure and forensic significance of Windows Event Logs. How can event records be used to reconstruct security incidents?

20

A running Windows workstation is suspected of malware infection and unauthorized web activity. Develop an integrated forensic plan covering acquisition, memory, registry, browser, file metadata, and log analysis.