Unit 5: Dark Web, Email, and Web Attacks - Subjective Questions

INT250 — Digital Evidence Analysis • Practice Questions with Detailed Answers

20 questions

1

Define the Surface Web, Deep Web, and Dark Web. Distinguish between them with suitable examples.

2

Explain how anonymity is provided on the Dark Web and discuss the forensic challenges created by such anonymity.

3

Describe a systematic procedure for investigating a suspected crime conducted through the Dark Web.

4

Discuss the major legal, ethical, and evidentiary issues associated with Dark Web investigations.

5

Explain the basic architecture of an email system and the roles of the major components involved in sending and receiving email.

6

Describe the logical structure of an email message. Why are email headers important in digital evidence analysis?

7

Compare SMTP, POP3, and IMAP with respect to purpose, operation, and forensic relevance.

8

Explain how an investigator analyzes a complete email header to determine the probable route and origin of a suspicious message.

9

Identify and explain common forms of email-related crime.

10

Describe the complete steps involved in an email crime investigation, from complaint reception to presentation of findings.

11

Explain how email evidence should be preserved and acquired while maintaining authenticity and chain of custody.

12

How can spoofed and phishing emails be identified through technical and content-based indicators?

13

Describe a safe forensic approach for examining suspicious email attachments and embedded URLs.

14

Define an Intrusion Detection System and explain its major types based on placement and data source.

15

Differentiate between signature-based and anomaly-based intrusion detection. State the advantages and limitations of each.

16

What is an Intrusion Prevention System? Compare its operation with that of an Intrusion Detection System.

17

Explain the purpose, placement, and main functions of a Web Application Firewall.

18

Compare IDS, IPS, and WAF, and explain how they can be combined to create defense in depth.

19

Explain the working principles and security impact of major attacks on web applications, including SQL injection, cross-site scripting, cross-site request forgery, path traversal, and malicious file upload.

20

Describe a forensic workflow for investigating a suspected web application attack using WAF, IDS, web-server, application, and database logs.