Unit 5: Dark Web, Email, and Web Attacks - Practice Quiz

INT250 — Digital Evidence Analysis 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the dark web?

Dark Web Easy
A. A public collection of ordinary search engine results
B. A private folder stored on a local computer
C. A wireless network protected by a password
D. A hidden part of the internet requiring special software

2 Which software is commonly used to access websites on the Tor dark web?

Dark Web Easy
A. Tor Browser
B. Media Player
C. Text Editor
D. File Explorer

3 Which statement correctly distinguishes the dark web from the deep web?

Dark Web Easy
A. The dark web is an intentionally hidden part of the deep web
B. The deep web contains only illegal online marketplaces
C. The deep web can be accessed only through Tor Browser
D. The dark web includes every password-protected web page

4 Which email field identifies the main recipient of a message?

Email Basics Easy
A. From
B. Subject
C. To
D. Date

5 Which protocol is commonly used to send email messages?

Email Basics Easy
A. SMTP
B. SSH
C. FTP
D. DNS

6 What is an email attachment?

Email Basics Easy
A. A password used to open an inbox
B. A server that delivers email messages
C. A folder that stores deleted messages
D. A file sent with an email message

7 What should an investigator do first with a potentially important email?

Email Crime Investigation and Its Steps Easy
A. Preserve it without altering its contents
B. Forward it to several personal accounts
C. Delete it after taking a screenshot
D. Edit its subject to describe the case

8 Which part of an email can show the servers through which the message traveled?

Email Crime Investigation and Its Steps Easy
A. Email subject
B. Email header
C. Email greeting
D. Email signature

9 Why is a hash value calculated for collected email evidence?

Email Crime Investigation and Its Steps Easy
A. To verify that the evidence remains unchanged
B. To remove unwanted messages from the inbox
C. To deliver the message to another recipient
D. To translate the message into another language

10 What is the primary purpose of an Intrusion Detection System (IDS)?

Intrusion Detection System Easy
A. To design web pages and database tables
B. To create user accounts and email addresses
C. To detect suspicious activity and generate alerts
D. To compress files and reduce storage use

11 What does a network-based IDS mainly monitor?

Intrusion Detection System Easy
A. Documents stored in an office cabinet
B. Traffic moving across a computer network
C. Images displayed on a computer screen
D. Passwords written in a paper notebook

12 What does an IDS commonly produce when it identifies suspicious behavior?

Intrusion Detection System Easy
A. A user profile
B. A software license
C. A security alert
D. A backup archive

13 What is the main purpose of an Intrusion Prevention System (IPS)?

Intrusion Prevention System Easy
A. To detect and block malicious network activity
B. To improve the quality of digital images
C. To organize and rename personal documents
D. To create and format spreadsheet reports

14 What is a basic difference between an IDS and an IPS?

Intrusion Prevention System Easy
A. An IDS blocks attacks, while an IPS stores passwords
B. An IDS encrypts files, while an IPS deletes backups
C. An IPS can block attacks, while an IDS mainly alerts
D. An IPS sends email, while an IDS hosts websites

15 Why is an IPS commonly placed inline with network traffic?

Intrusion Prevention System Easy
A. So it can inspect and block traffic directly
B. So it can create employee email accounts
C. So it can increase the size of stored files
D. So it can print incident reports automatically

16 What does a Web Application Firewall (WAF) primarily protect?

Web Application Firewall Easy
A. Mobile batteries from excessive power use
B. Web applications from malicious web requests
C. Printed documents from physical damage
D. Desktop files from accidental name changes

17 Which type of traffic is commonly inspected by a WAF?

Web Application Firewall Easy
A. Keyboard lighting signals
B. Bluetooth audio traffic
C. Printer cartridge data
D. HTTP and HTTPS traffic

18 Which web attack attempts to insert malicious database commands into an input field?

Attacks on Web Applications Easy
A. Password hashing
B. SQL injection
C. Data compression
D. Digital signing

19 Which attack injects malicious scripts into web pages viewed by other users?

Attacks on Web Applications Easy
A. Port forwarding
B. Disk fragmentation
C. Cross-site scripting
D. File compression

20 What does a Cross-Site Request Forgery (CSRF) attack attempt to do?

Attacks on Web Applications Easy
A. Trick a logged-in user into sending an unwanted request
B. Insert a harmful script into a displayed web page
C. Flood a server with a large amount of traffic
D. Guess a database password through repeated login attempts

21 A dark-web vendor consistently signs marketplace announcements with the same PGP key. Which artifact found on a suspect's seized laptop would most strongly link the suspect to that vendor identity?

Dark Web Medium
A. A text file containing the marketplace's onion address
B. A browser bookmark pointing to the vendor's marketplace profile
C. The private PGP key corresponding to the vendor's public key
D. A screenshot showing the vendor's public PGP key

22 An investigator must preserve a dark-web listing that may soon disappear. Which approach provides the strongest evidentiary record?

Dark Web Medium
A. Take screenshots, rename them by date, and place them in a case folder
B. Bookmark the page, record its title, and revisit it after obtaining approval
C. Copy the listing text, translate it, and paste it into an investigation report
D. Capture page source and assets, record UTC time, and hash the files

23 When examining an email's Received headers, how should an investigator usually identify the earliest documented mail server in the route?

Email Basics Medium
A. Select the entry with the newest local timestamp
B. Select the entry containing the visible sender address
C. Read the trusted Received entries from top to bottom
D. Read the trusted Received entries from bottom to top

24 A recipient received an email through Bcc, but their address does not appear in the message headers. Which source is most likely to confirm that the server delivered the message to that address?

Email Basics Medium
A. The SMTP transaction logs
B. The message's subject header
C. The email client's signature block
D. The sender's display-name field

25 An email has a valid DKIM result for news.example. What does this result establish most directly?

Email Basics Medium
A. The recipient personally knows the human author
B. The message was delivered without passing through relays
C. The signed content remained intact after domain signing
D. The sending computer was free of malicious software

26 An investigator receives a suspicious email as an .eml file. What should be done before opening attachments or modifying the evidence?

Email Crime Investigation and Its Steps Medium
A. Remove duplicate headers to simplify later examination
B. Rename each attachment according to its apparent type
C. Calculate and record a hash of the original file
D. Forward the message to a personal analysis account

27 An email displays From: security@bank.example, but SPF passes only for bounce.attacker.example, and no DKIM signature is present. What is the best interpretation?

Email Crime Investigation and Its Steps Medium
A. SPF passed, but the visible sender domain is not aligned
B. SPF proves that bank.example authorized the visible sender
C. SPF validates the attachment but not the sender's domain
D. SPF confirms that both domains use the same mail provider

28 A suspicious email contains a password-protected document. Which initial examination method best reduces risk while preserving useful evidence?

Email Crime Investigation and Its Steps Medium
A. Open the document directly on the investigator's workstation
B. Upload the original document to a public conversion website
C. Analyze a verified copy in an isolated forensic sandbox
D. Remove the password and overwrite the original attachment

29 Email headers, firewall logs, and authentication logs use different time zones. What should an investigator do before correlating the events?

Email Crime Investigation and Its Steps Medium
A. Remove timestamps that include daylight-saving-time information
B. Sort the events alphabetically by the systems that recorded them
C. Use only the timestamps recorded by the recipient's email client
D. Convert all timestamps to a common time standard such as UTC

30 A network IDS detects command-and-control traffic and generates an alert, but the connection continues. Which characteristic best explains this behavior?

Intrusion Detection System Medium
A. The IDS can inspect traffic only after the connection is closed
B. The IDS records attacks but cannot generate real-time notifications
C. The IDS monitors traffic passively rather than blocking it inline
D. The IDS blocks traffic only when a firewall is completely disabled

31 An anomaly-based IDS begins alerting on a newly deployed backup service because the service transfers unusually large amounts of data at night. What is the most appropriate response?

Intrusion Detection System Medium
A. Replace anomaly detection with packet capture only
B. Update the behavioral baseline for the authorized service
C. Classify every large transfer as confirmed data theft
D. Disable all nighttime monitoring for the affected network

32 Network traffic to a server is encrypted with TLS, limiting a network IDS's visibility. Which deployment would provide better evidence of malicious activity after decryption?

Intrusion Detection System Medium
A. A DNS resolver placed on an isolated management segment
B. A network IDS placed upstream of the internet router
C. A passive hub connected outside the network perimeter
D. A host-based IDS installed on the destination server

33 Where should an IPS be positioned if it must automatically stop malicious packets before they reach an internal web server?

Intrusion Prevention System Medium
A. On a passive mirror port beside the web server
B. Inside an offline forensic analysis workstation
C. Inline along the traffic path to the web server
D. Behind the server on a disconnected monitoring segment

34 A new IPS signature may block a legitimate business application. Which rollout strategy best balances protection and availability?

Intrusion Prevention System Medium
A. Enable blocking immediately and suppress all resulting logs
B. Disable the business application until the signature becomes outdated
C. Run the signature in alert mode, validate it, then enable blocking
D. Apply the signature only after removing all existing IPS policies

35 A WAF is placed in front of an HTTPS application, but TLS terminates only on the application server. Why might the WAF fail to detect SQL injection in request bodies?

Web Application Firewall Medium
A. The WAF ignores every request containing standard HTTP headers
B. The WAF cannot inspect application data that remains encrypted
C. The WAF requires the application to use UDP instead of TCP
D. The WAF can inspect only responses returned by database servers

36 A critical web framework vulnerability has been disclosed, but the application cannot be patched until the next maintenance window. What can a WAF provide temporarily?

Web Application Firewall Medium
A. A database backup that removes the vulnerable application component
B. A replacement certificate that permanently corrects the software defect
C. A source-code patch automatically inserted into the vulnerable framework
D. A virtual patch that blocks requests matching the exploit pattern

37 A login query is constructed by concatenating user input into SELECT * FROM users WHERE name='...'. Which change most directly prevents SQL injection?

Attacks on Web Applications Medium
A. Store the database on the same host as the application
B. Use parameterized queries with separately bound input values
C. Rename the login fields to values that attackers cannot predict
D. Encode the database response before displaying it to users

38 A forum stores a malicious script in a comment. The script executes whenever another user views the discussion. Which attack occurred?

Attacks on Web Applications Medium
A. Server-side request forgery
B. Stored cross-site scripting
C. Cross-site request forgery
D. Reflected cross-site scripting

39 A logged-in user visits a malicious page that silently submits a request to change the user's email address on another site. Which control most directly prevents this attack?

Attacks on Web Applications Medium
A. A database index created for the user-account table
B. An output-encoding function applied to every displayed email address
C. A unique anti-CSRF token validated with each state-changing request
D. A longer TLS certificate installed on the destination server

40 A web application fetches images from URLs supplied by users. An attacker submits http://169.254.169.254/latest/meta-data/ and obtains cloud credentials. Which vulnerability was exploited?

Attacks on Web Applications Medium
A. Cross-site request forgery
B. Directory path traversal
C. Server-side request forgery
D. Reflected cross-site scripting

41 Investigators suspect that two Tor onion marketplaces are operated by the same person. Which evidence most strongly supports this attribution while still requiring corroboration?

Dark Web Hard
A. Both sites are reachable through Tor and accept privacy-focused cryptocurrency
B. Both sites use dark themes and experience downtime during similar periods
C. Both sites reuse a unique PGP key and announce synchronized changes signed by it
D. Both sites sell similar prohibited products and use comparable category names

42 A live server hosting an onion service is seized under valid legal authority. Which acquisition strategy best preserves evidence that may disappear when the system is powered off?

Dark Web Hard
A. Browse the service from the console, export its pages, and then copy database files
B. Disconnect power immediately, image each disk, and reconstruct memory from swap files
C. Restart into trusted media, acquire the disks, and inspect active network connections
D. Document the system, capture volatile memory, and then create verified forensic images

43 A cryptocurrency withdrawal from a dark-web market enters a CoinJoin transaction and later reaches a regulated exchange. What is the most defensible forensic conclusion?

Dark Web Hard
A. The market operator directly controlled the output deposited at the regulated exchange
B. The transaction creates an investigative lead whose attribution needs independent evidence
C. The CoinJoin mathematically proves that the deposited funds originated outside the market
D. The exchange account owns every input that participated in the CoinJoin transaction

44 An email is forwarded by a conventional mailing list. SPF fails because the forwarding server is not authorized by the original envelope sender, but an aligned DKIM signature remains valid. Under ordinary DMARC evaluation, what is the expected result?

Email Basics Hard
A. DMARC passes because one aligned authentication mechanism passes
B. DMARC passes only if both SPF and DKIM produce aligned results
C. DMARC fails because SPF failure overrides every valid DKIM result
D. DMARC fails because forwarding necessarily invalidates identifier alignment

45 A suspicious message contains five Received: fields, including two attacker-supplied fields below the entry added by the recipient's secure email gateway. Which method best identifies the earliest trustworthy transport hop?

Email Basics Hard
A. Select the lowest Received: field because headers are always appended at the bottom
B. Average timestamps from all Received: fields and choose the host nearest that time
C. Select the highest Received: field because it necessarily records the original sender
D. Start at the gateway-added field and validate downward only to the established trust boundary

46 A message is signed using DKIM with relaxed header and relaxed body canonicalization. Which modification is most likely to preserve signature validity?

Email Basics Hard
A. Changing a signed subject word while retaining the original header length
B. Rewrapping body text by inserting line breaks at different character positions
C. Compressing header whitespace and removing trailing whitespace from body lines
D. Replacing an attachment while preserving its MIME type and original filename

47 Investigators obtain a running laptop and a provider-hosted mailbox in an email-extortion case. Which sequence best supports forensic integrity and completeness?

Email Crime Investigation and Its Steps Hard
A. Open messages, print relevant threads, reset credentials, and image the laptop afterward
B. Shut down the laptop, forward messages to investigators, and analyze them in personal mailboxes
C. Confirm authority, document state, capture volatile data, acquire originals, hash, and analyze copies
D. Export screenshots, remove malicious messages, image user folders, and calculate one final hash

48 A business email compromise used a malicious OAuth application rather than a stolen password. Which evidence set is most likely to establish the access mechanism and subsequent mailbox activity?

Email Crime Investigation and Its Steps Hard
A. Email screenshots, local browser history, public DNS records, and attachment filenames
B. SPF records, DKIM public keys, message themes, and the recipient's contact directory
C. Antivirus detections, printer logs, DHCP leases, and deleted desktop shortcut files
D. Consent records, token-related sign-ins, mailbox audit events, and forwarding-rule changes

49 An email's Date: field shows 09:15 with a -0500 offset, the receiving gateway logs 14:17 UTC, and the suspect computer clock was seven minutes fast. What is the soundest timeline practice?

Email Crime Investigation and Its Steps Hard
A. Subtract seven minutes from every server timestamp in the entire investigation
B. Discard the email timestamp because a two-minute transport delay proves manipulation
C. Normalize timestamps to UTC and document each source's offset, drift, and trust level
D. Treat 09:15 as authoritative because the sender creates the Date: field

50 A MIME attachment's Base64 text has one hash, while the decoded executable has another. Which reporting approach is forensically correct?

Email Crime Investigation and Its Steps Hard
A. Record both hashes and document the deterministic decoding process connecting the artifacts
B. Record only the executable hash because transfer-encoded bytes have no evidentiary value
C. Record only the Base64 hash because decoded content is necessarily derivative evidence
D. Replace the original MIME section with decoded bytes so all tools calculate one hash

51 An IDS examines events of which are truly malicious. Its true-positive rate is , and its false-positive rate is . Approximately what proportion of alerts represent real attacks?

Intrusion Detection System Hard
A.
B.
C.
D.

52 TLS inspection is unavailable, but defenders must detect possible command-and-control traffic in encrypted sessions. Which IDS strategy is most appropriate?

Intrusion Detection System Hard
A. Correlate flow timing, destination reputation, certificate metadata, and endpoint telemetry
B. Match plaintext command strings directly inside every encrypted application record
C. Disable network monitoring and rely exclusively on server-side application error logs
D. Treat all long-lived TLS sessions as confirmed command-and-control communications

53 An attacker sends overlapping IP fragments that the IDS and protected server reassemble differently. Which defense most directly addresses this evasion technique?

Intrusion Detection System Hard
A. Reduce alert retention so duplicate fragment events cannot overwhelm the analyst queue
B. Increase signature length so every fragment contains the complete malicious pattern
C. Normalize or reject ambiguous fragments before applying detection to reassembled traffic
D. Move detection behind DNS resolution so fragments can be associated with hostnames

54 An inline IPS is configured to fail open if its inspection engine crashes. Which statement most accurately describes the resulting risk trade-off?

Intrusion Prevention System Hard
A. Detection accuracy increases, but encrypted traffic is automatically converted to plaintext
B. Evidence integrity improves, but packet timing is permanently removed from all captures
C. Availability is preserved, but malicious traffic may bypass inspection during failure
D. Confidentiality is preserved, but legitimate traffic is blocked until inspection resumes

55 A critical exploit is active, but a new IPS signature may block legitimate requests sharing similar byte patterns. Which deployment plan best balances rapid protection and operational safety?

Intrusion Prevention System Hard
A. Disable all related signatures until the vulnerable application receives its next upgrade
B. Enable blocking globally without logging so attackers cannot infer the signature's behavior
C. Block every connection to the application and treat resulting outages as false positives
D. Test in detection mode, scope the rule, validate traffic, and then enable monitored blocking

56 A reverse proxy decodes a URL once, the WAF inspects that result, and the application decodes it again. An attacker exploits double encoding to bypass a traversal rule. Which remediation is strongest?

Web Application Firewall Hard
A. Canonicalize consistently, reject ambiguous encodings, and align inspection with application parsing
B. Decode repeatedly until the value stops changing and permit every resulting normalized path
C. Add signatures for several known encoded traversal strings and retain both decoding stages
D. Inspect only the undecoded URL because transformations always destroy reliable attack indicators

57 A retail API validates each purchase request, but attackers send concurrent requests that collectively buy more limited-stock items than exist. Why is a WAF alone unlikely to solve the defect?

Web Application Firewall Hard
A. The attack relies on invalid TLS certificates that only endpoint antivirus can evaluate
B. The attack abuses transaction-level business logic requiring atomic application-side controls
C. The attack modifies DNS responses after the WAF has completed signature verification
D. The attack requires fragmented packets that every reverse proxy automatically discards

58 An application uses prepared statements for values but concatenates a user-controlled sort parameter into an SQL ORDER BY clause. What is the safest correction?

Attacks on Web Applications Hard
A. Bind the column identifier as a normal string parameter in the prepared statement
B. Map accepted parameter values to a server-side allowlist of fixed column expressions
C. Escape quotation marks in the parameter and concatenate the resulting identifier
D. Encode the parameter with Base64 before appending it to the SQL statement

59 A front-end proxy honors Content-Length, while a back-end server prioritizes Transfer-Encoding: chunked. What attack can arise from this parser disagreement, and what is the best primary mitigation?

Attacks on Web Applications Hard
A. Cross-site request forgery; rotate session cookies and disable all persistent HTTP connections
B. HTTP request smuggling; enforce consistent framing and reject ambiguous requests at every hop
C. XML external entity injection; remove document type declarations from JSON request bodies
D. DNS cache poisoning; randomize resolver ports and validate authoritative response signatures

60 A server-side URL fetcher blocks literal private IP addresses but follows redirects and performs fresh DNS lookups. Which control set best mitigates SSRF, including DNS rebinding?

Attacks on Web Applications Hard
A. Validate only the submitted hostname and trust all addresses returned during later connections
B. Resolve and validate each destination, restrict egress, and recheck every redirect and connection
C. Block uncommon URL extensions and allow redirects whenever the first response uses HTTPS
D. Require Base64-encoded URLs and reject requests whose original strings contain decimal digits