Unit 1: Computer Forensics and Investigation Process - Practice Quiz

INT250 — Digital Evidence Analysis 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 What is the primary definition of computer forensics?

A. The application of computer investigation and analysis techniques in the interest of determining potential legal evidence
B. The process of hacking into computer systems to test security
C. The repair of damaged computer hardware to recover lost data
D. The monitoring of network traffic for marketing purposes

2 Which legal principle states that evidence must be gathered in a way that allows the court to verify its origin and integrity?

A. Chain of Custody
B. Miranda Rights
C. Double Jeopardy
D. Hearsay Rule

3 In the context of cybercrimes, what distinguishes a 'computer as a target' crime from a 'computer as a tool' crime?

A. There is no difference; they are legal synonyms
B. Target crimes involve theft of hardware; tool crimes involve software piracy
C. Target crimes attack the system's integrity (e.g., DDoS); tool crimes use the computer to commit other offenses (e.g., fraud)
D. Target crimes are civil; tool crimes are criminal

4 Which of the following best describes 'Forensic Readiness'?

A. Keeping all servers offline to prevent attacks
B. The process of training all employees to be forensic investigators
C. The ability of an organization to maximize its potential to use digital evidence while minimizing the costs of an investigation
D. Buying the most expensive forensic software available

5 What is the primary role of a Security Operations Center (SOC) in relation to computer forensics?

A. To write legislation regarding cybercrime
B. To repair broken hardware in the office
C. To conduct full legal prosecutions
D. To monitor, detect, and respond to security incidents, often providing the initial data for forensic analysis

6 According to the Order of Volatility, which data should be collected first?

A. Temporary file systems
B. Archival media (Backup tapes)
C. Hard disk drive data
D. CPU registers and cache

7 What is the primary purpose of a hardware Write Blocker?

A. To speed up the data transfer process
B. To encrypt the data being copied
C. To compress the evidence files
D. To prevent the forensic workstation from modifying data on the suspect drive

8 What does Locard's Exchange Principle state in the context of digital forensics?

A. Anyone entering a digital scene leaves a trace, and takes something with them
B. Data can never be fully deleted
C. All evidence must be printed on paper
D. Encryption is impossible to break without a key

9 Which phase of the investigation involves obtaining a search warrant?

A. Analysis Phase
B. Post-investigation Phase
C. Reporting Phase
D. Pre-investigation Phase

10 What is a 'Bit-stream image'?

A. A compressed zip folder of the My Documents folder
B. A copy of only the active files on a disk
C. A sector-by-sector copy of the hard drive, including hidden and deleted data
D. A screenshot of the desktop

11 Who is typically the 'First Responder' in a computer forensic scenario?

A. The CEO of the company
B. The first person to arrive at the crime scene and assess the situation
C. The suspect
D. The lead judge on the case

12 What is the cardinal rule of computer forensics regarding original evidence?

A. Send the original evidence to the suspect for verification
B. Never work on the original evidence; always work on a forensic copy
C. Modify the original evidence to fix security holes
D. Always work on the original evidence to save time

13 What is the function of a cryptographic hash (like MD5 or SHA-256) in forensics?

A. To formatting the drive for reuse
B. To encrypt the drive so no one can read it
C. To organize files alphabetically
D. To act as a digital fingerprint to verify data integrity

14 Which of the following is a characteristic of 'Civil' investigations compared to 'Criminal' ones?

A. They are always conducted by law enforcement
B. They result in jail time for the offender
C. They typically involve disputes between individuals or companies regarding contracts or intellectual property
D. The standard of proof is 'Beyond a reasonable doubt'

15 What is 'Slack Space'?

A. The space on a desk where the computer sits
B. The unused space in a disk cluster when a file does not fill the entire cluster
C. The space taken up by the operating system
D. The RAM memory used by the web browser

16 In the context of First Response, what should be done if a computer is found powered OFF?

A. Leave it off and secure it
B. Turn it on to install forensic software
C. Turn it on to see what is on the screen
D. Turn it on and immediately copy the My Documents folder

17 What is the primary responsibility of a Forensic Investigator regarding bias?

A. To remain objective and report facts regardless of whom they help or hurt
B. To support the client who is paying them
C. To prove the suspect is guilty at all costs
D. To prove the suspect is innocent

18 What defines 'Digital Evidence'?

A. Verbal testimony given by a computer user
B. The physical hardware of a laptop only
C. Information of probative value that is stored or transmitted in binary form
D. Any printed document found near a computer

19 Which of the following is considered 'Volatile Memory'?

A. CD-ROM
B. Hard Disk Drive
C. RAM (Random Access Memory)
D. USB Flash Drive

20 What is the purpose of 'Bag and Tag'?

A. To organize cables neatly
B. To throw away useless hardware
C. To identifying, seizing, and securing evidence in appropriate containers to preserve integrity
D. To sell the computer equipment

21 What is the difference between Incident Response (IR) and Computer Forensics?

A. IR is for hardware; Forensics is for software
B. IR happens in court; Forensics happens in the lab
C. There is no difference
D. IR focuses on containment and recovery; Forensics focuses on analysis and legal evidence

22 Which tool is used to block radio signals from reaching a mobile device after seizure?

A. Write Blocker
B. Faraday Bag
C. Anti-static wrist strap
D. Hashing Algorithm

23 What is 'Steganography'?

A. A type of computer virus
B. The practice of hiding data within other files (like images or audio)
C. The process of deleting files permanently
D. The study of dinosaur bones

24 During the Pre-investigation phase, what is the importance of risk assessment?

A. To guess who the suspect is
B. To identify potential hazards (biological, electrical, chemical) at the crime scene
C. To check the weather forecast
D. To determine how much to charge the client

25 What is 'Live Acquisition'?

A. Interviewing a suspect live
B. Streaming the investigation on social media
C. Acquiring data from a computer that is powered on and running
D. Acquiring data from a dead drive

26 Which file system artifact allows an investigator to see which programs were recently executed?

A. Prefetch Files
B. The Printer Spool
C. The Recycle Bin
D. The Hosts file

27 What is the 'Best Evidence Rule'?

A. Evidence found by the police is always best
B. Evidence found on a server is better than a laptop
C. Courts prefer the original evidence (or an accurate duplicate) rather than a copy or oral testimony
D. The most expensive evidence is the best

28 What is the final phase of the Computer Forensics Investigation Process?

A. Identification
B. Reporting
C. Analysis
D. Acquisition

29 Why is 'documentation' critical throughout the investigation process?

A. To increase the billable hours
B. To improve typing speed
C. To share with the press
D. To ensure the investigation can be repeated and validated by a third party

30 What does a SIEM (Security Information and Event Management) system do in a SOC?

A. It is an email client
B. It aggregates and analyzes log data from various sources to detect security threats
C. It is used to physically lock doors
D. It acts as a backup generator

31 Which of the following is an example of 'Metadata'?

A. The text content of a Word document
B. The pixels in an image
C. The date created, date modified, and author of a file
D. The sound waves in an MP3

32 When photographing a crime scene, what is the best practice?

A. Selfies with the evidence
B. Take one photo of the room and leave
C. Photograph the computer screen only
D. Take photos of the entire scene, including connections, cable positions, and serial numbers

33 What is 'Anti-forensics'?

A. The study of law
B. A group of people against technology
C. Tools or techniques used to frustrate or prevent forensic analysis (e.g., data wiping, encryption)
D. Old school investigation methods

34 In a criminal investigation, who carries the 'Burden of Proof'?

A. The Defense
B. The Suspect
C. The Jury
D. The Prosecution

35 What is the definition of 'Unallocated Space'?

A. Broken sectors on a hard drive
B. Disk space that is currently not flagged as in use by the file system, but may contain deleted data
C. The space occupied by the Operating System
D. Space on the hard drive that has never been used

36 Which organization typically creates the 'Search Warrant'?

A. Law Enforcement / The Court
B. The Victim
C. The Forensic Investigator
D. The Internet Service Provider

37 What is the primary risk of pulling the plug (abrupt shutdown) on a server?

A. It alerts the hacker
B. It might corrupt the file system and result in loss of volatile data (RAM)
C. It saves too much data
D. It uses too much electricity

38 What role does an 'Expert Witness' play in court?

A. They assist the judge/jury in understanding complex technical evidence through their specialized knowledge
B. They decide the verdict
C. They defend the accused
D. They prosecute the accused

39 Which of the following is a key component of a Forensic Report?

A. Executive Summary, Methodology, Findings, and Conclusion
B. Marketing material for the forensic firm
C. Personal opinions about the suspect's character
D. A list of the investigator's favorite software

40 What is 'Data Wiping'?

A. Overwriting data multiple times to make it unrecoverable
B. Cleaning the computer screen with a cloth
C. Formatting a disk
D. Deleting a file to the Recycle Bin

41 What is the role of the 'Evidence Custodian'?

A. To analyze the evidence
B. To repair the evidence
C. To arrest the suspect
D. To manage the secure storage and log the entry/exit of evidence in the storage facility

42 Why is 'Timeline Analysis' important?

A. It predicts future crimes
B. It sorts files by file size
C. It reconstructs events in chronological order to understand the sequence of the attack
D. It tells the investigator when to take a lunch break

43 What is the difference between 'Static' and 'Dynamic' analysis?

A. Static is for Windows; Dynamic is for Linux
B. Static is fast; Dynamic is slow
C. Static uses electricity; Dynamic does not
D. Static analyzes the system at rest (off); Dynamic analyzes the system while running (behavior)

44 Which of the following describes an 'Internal Threat'?

A. A disgruntled employee misusing their access privileges
B. A hacker from another country
C. A virus from a website
D. A lightning strike

45 What is 'Logical Acquisition'?

A. Copying the entire physical drive bit-by-bit
B. Guessing the password logically
C. Drawing a picture of the drive
D. Extracting specific files and objects (like photos or chats) accessible by the file system

46 In the context of SOC, what is 'Triage'?

A. Fixing the computer completely
B. Deleting all infected files immediately
C. The initial assessment to prioritize incidents based on severity and potential impact
D. Calling the police

47 What should an investigator do if they accidentally alter the evidence?

A. Quit the investigation
B. Blame the software
C. Hide the mistake
D. Document the alteration and explain how and why it happened

48 What does the term 'Admissibility' refer to?

A. Whether the evidence meets legal standards to be presented in court
B. The cost of the investigation
C. Whether the investigator is hired
D. The speed of the computer

49 Which is a common challenge in Cloud Forensics compared to traditional Computer Forensics?

A. Physical access to the storage hardware is often impossible or restricted
B. Cloud data is always unencrypted
C. There is no difference
D. Cloud computers are too slow

50 What is the purpose of 'Keyword Searching' in the Analysis phase?

A. To locate specific terms (e.g., names, credit card numbers) within the massive amount of data
B. To find the investigator's keys
C. To rename files
D. To unlock encrypted files