β˜‘ MCQ PRACTICE

Computer Forensics Part 2

Practice objective questions for quick revision and examination preparation. Try answering each question before revealing the answer.

πŸ“š Computer Forensics
πŸ“– Part 2
🎯 MCQs

Cyber Forensics MCQs

1
HTTPS is abbreviated as _________
AHypertexts Transfer Protocol Secured
BSecured Hyper Text Transfer Protocol
CHyperlinked Text Transfer Protocol Secured
DHyper Text Transfer Protocol Secure
Correct Answer Secured Hyper Text Transfer Protocol
2
Which of the following is not a strong security protocol?
ASSL
BHTTPL
CSMTP
DSFTP
Correct Answer SMTP
3
An attempt to make a computer resource unavailable to its intended users is called _________
ADenial-of-service attack
BVirus attack
CWorms attack
DBotnet process
Correct Answer Denial-of-service attack
4
You are supposed to maintain three types of records. Which answer is not a record?
AChain of custody
BDocumentation of the crime scene
CSearching the crime scene
DDocument your actions
Correct Answer Searching the crime scene
5
Volatile data resides in __________________________?
ARegistries
BCache
CRAM
DAll of the above
Correct Answer All of the above
6
Who Can Use Computer Forensic Evidence?
ACriminal Prosecutors
BCivil litigations
CLaw enforcement
DAll of them
Correct Answer All of them
7
When handling computers for legal purposes, investigators increasingly are faced with four main types of problems, except:
AHow to recover data from computers while preserving evidential integrity
BHow to keep your data and information safe from theft or accidental loss
CHow to securely store and handle recovered data
DHow to find the significant information in a large volume of data
Correct Answer How to keep your data and information safe from theft or accidental loss
8
In order for a double tier approach to work it is necessary to have:
AA defined methodology
BCivil control
CA breach of contract
DAsset recovery
Correct Answer A defined methodology
9
Criteria for equipment in the double tier approach results in the following except:
ASimple to use
BQuick to learn
CTotally reliable
DLegally operable
Correct Answer Legally operable
10
Computer forensics specialist will take several careful steps to identify and attempt to retrieve possible evidence
AProtect
BDiscover
CRecover
DAll of them
Correct Answer All of them
11
A computer forensics professional does more than turn on a computer, make a directory listing, and search through files. Your forensics professionals should be able to successfully perform complex evidence recovery procedures with the skill and expertise that lends credibility to your case. For example, they should be able to perform the following services, except:
AData seizure
BData duplication and preservation
CData recovery
DData dump
Correct Answer Data dump
12
The following are what it really costs to replace a stolen computer, except:
AThe price of the replacement hardware
BThe price of replacing the software
CThe cost of creating data
DThe cost of lost production time or instruction time
Correct Answer The cost of creating data
13
Forensic services include but are not limited to the following, except:
ALost password and file recovery
BLocation and retrieval of deleted and hidden files
CFile and email decryption
DEmail non-supervision and non-authentication
Correct Answer Email non-supervision and non-authentication
14
Computer evidence is like any other evidence. It must be
AAuthentic
BAccurate
CComplete
DAll of them
Correct Answer All of them
15
The legal aspects of a computer forensics investigation center primarily on the following two main issues:
AThe requirements that need to be met in order for evidence to be successfully presented in court and, of course, not considered legally admissible
BThe requirements that need to be met in order for evidence to be successfully presented in court and, of course, considered legally admissible
CThe right of the investigator to avoid the possibility of not incurring legal action against himself or the organization for whom he is conducting the investigation
DThe acceptance of the investigator to avoid the possibility of incurring legal action against himself or the organization for whom he is reviewing the investigation
Correct Answer The requirements that need to be met in order for evidence to be successfully presented in court and, of course, considered legally admissible
16
Which of the following is not a type of peer-to-peer cyber-crime?
APhishing
BInjecting Trojans to a target victim
CMiTM
DCredit card details leak in deep web
Correct Answer Credit card details leak in deep web
17
In terms of digital evidence, the Internet is an example of
AOpen computer systems
BCommunication systems
CEmbedded computer systems
DNone of the above
Correct Answer Communication systems
18
In terms of digital evidence, a hard drive is an example of:
AOpen computer systems
BCommunication systems
CEmbedded computer systems
DNone of the above
Correct Answer Open computer systems
19
In terms of digital evidence, a Smart Card is an example of
AOpen computer systems
BCommunication systems
CEmbedded computer systems
DNone of the above
Correct Answer Embedded computer systems
20
Private networks can be a richer source of evidence than the Internet because:
AThey retain data for longer periods of time.
BOwners of private networks are more cooperative with law enforcement.
CPrivate networks contain a higher concentration of digital evidence.
DAll of the above.
Correct Answer Owners of private networks are more cooperative with law enforcement.
21
Computers can play the following roles in a crime:
ATarget, object, and subject
BEvidence, instrumentality, contraband, or fruit of crime
CObject, evidence, and tool
DSymbol, instrumentality, and source of evidence
Correct Answer Evidence, instrumentality, contraband, or fruit of crime
22
The following specializations exist in digital investigations:
AFirst responder (a.k.a. digital crime scene technician)
BForensic examiner
CDigital investigator
DAll of the above
Correct Answer All of the above
23
A printer used for counterfeiting is an example of:
AHardware as contraband or fruits of crime
BHardware as an instrumentality
CHardware as evidence
DInformation as contraband or fruits of crime
Correct Answer Hardware as an instrumentality
24
Having a member of the search team trained to handle digital evidence:
ACan reduce the number of people who handle the evidence
BCan serve to streamline the presentation of the case
CCan reduce the opportunity for opposing counsel to impugn the integrity of the evidence
DAll of the above
Correct Answer All of the above
25
What can you do to determine the number of sectors on a hard drive larger than 8GB?
AUse a UNIX tool like hdparm
BUse a Windows tools like EnCase
CCheck the drive manufacturer’s website for the specific drive
DAll of the above
Correct Answer All of the above
26
A device that connects network with different protocols
ASwitch
BHub
CGateway
DAll of the above
Correct Answer Gateway
27
A device that is used to connect a number of LANs is
ARouters
BRepeater
CBridge
DAll of these
Correct Answer Routers
28
Because the Internet is built upon the TCP/IP protocol, many hacker attacks will seek to exploit the TCP ports of these servers with public IP addresses. A number of common ports are scanned and attacked, except:
AFTP (21)
BTelnet (23)
CSMTP (25)
DINS (53)
Correct Answer INS (53)
29
There are _______ major ways of stealing email information.
A2
B3
C4
D5
Correct Answer 3
30
Which of them is not a major way of stealing email information?
AStealing cookies
BReverse Engineering
CPassword Phishing
DSocial Engineering
Correct Answer Reverse Engineering
31
Which of them is an example of grabbing email information?
ACookie stealing
BReverse engineering
CPort scanning
DBanner grabbing
Correct Answer Cookie stealing
32
The process of documenting the seizure of digital evidence and, in particular, when that evidence changes hands, is known as:
AChain of custody
BField notes
CInterim report
DNone of the above
Correct Answer Chain of custody
33
A network sniffer program is an example of:
AHardware as contraband or fruits of crime
BHardware as an instrumentality
CInformation as an instrumentality
DInformation as evidence
Correct Answer Information as an instrumentality
34
HDD,CD/DVD media, backup tapes, USB drive, biometric scanner, digital camera, smart phone, smart card, PDA etc. are ________________________________________.
APhysical evidence
BElectronic evidence
CIllustrative evidence.
DDocumented evidence
Correct Answer Electronic evidence
35
Which of the following is not a type of volatile evidence?
ARouting tables
BMain memory
CLog files
DCached data
Correct Answer Log files
36
Private networks can be a richer source of evidence than the Internet because:
AThey retain data for longer periods of time.
BOwners of private networks are more cooperative with law enforcement.
CPrivate networks contain a higher concentration of digital evidence.
DAll of the above.
Correct Answer Private networks contain a higher concentration of digital evidence.
37
___________________ the first task in computer forensics investigation.
AAcquisition
BValidation and discrimination
CExtraction
DReconstruction
Correct Answer Acquisition
38
Validating data is done by obtaining
ABinary values
BHex values
CHash values
DNone of the above
Correct Answer Hash values
39
_____________________ laptop computer with a built-in LCD monitor and almost as many bays and peripherals as a stationary workstation
ALightweight workstation
BPortable workstation
CAdvanced Stationary workstation
DNone of the above
Correct Answer Portable workstation
40
___________________publishes articles, provides tools, and creates procedures for testing and validating computer forensics software.
AIIT
BMIT
CNIST
Dboth B & C
Correct Answer NIST
41
______________________ e-mail system is specific to a company, used only by its employees.
ALocalhost
BIntranet
CInternet
DNone of the above
Correct Answer Intranet
42
What is the disadvantage of circular logging?
AIt saves server space
BCan’t recover a log after it’s overwritten
CIt records traffic in the Mon.log file
DNone of the above
Correct Answer Can’t recover a log after it’s overwritten
43
E-mail logs generally identifies:
AE-mail contents
BIP address
CSystem-specific information
DAll of the above
Correct Answer All of the above
44
What are some tools that can be used to recover e-mail files?
AProDiscover Basic and Access Data FTK
BFINAL e MAIL for Outlook Express and Eudora
CSawmill-GroupWise for log analysis office_agent.html
DAll of the above
Correct Answer All of the above
45
What is the search criteria used to find log files?
A.log
B.db
C.pst
D.ost
Correct Answer .log
46
What is one of the most challenging tasks in digital forensics?
AInvestigating cell phones and mobile devices
BInvestigating laptops and desktops
CInvestigating servers and databases
DInvestigating networks and routers
Correct Answer Investigating cell phones and mobile devices
47
What is a SIM card reader?
AA software device
BA hardware device
CA combination hardware/software device
DNone of these
Correct Answer A combination hardware/software device
48
What is the first tool used for computer investigations?
ANorton Disk Edit
BFTK Imager
CMS-DOS
DNone of the above
Correct Answer Norton Disk Edit
49
What is the most challenging task in a computing investigation?
AData viewing
BKeyword searching
CDecompressing
DRecovery task
Correct Answer Recovery task
50
What is the primary purpose of data discrimination?
ATo remove good data from suspicious data
BTo remove suspicious data from good data
CTo remove all data from the disk
DTo remove all files from the disk
Correct Answer To remove good data from suspicious data
51
What is the first task in computer forensics investigations?
ACopying the original drive
BAnalyzing the data
CPreserving the original drive
DAcquiring an image
Correct Answer Copying the original drive
52
What are software forensics tools used for?
ATo analyze image files
BTo copy data from a suspect’s drive to an image file
CTo read all structures in an image file though image were original drive.
DBoth B and C
Correct Answer To copy data from a suspect’s drive to an image file
53
What is the purpose of GUI acquisition tools?
ATo analyze image files
BTo copy data from a suspect’s drive to an image file
CTo read all structures in an image file as though the image were the original drive.
DAll the above
Correct Answer To read all structures in an image file as though the image were the original drive.
54
What are some analysis tools used for analyzing image files?
AProDiscover and En Case
BFTK and X-Ways Forensics
CILook
DAll of the above
Correct Answer All of the above
55
Software Forensics Tools Software forensics tools are grouped into
ACommand-line applications
BGUI applications
CBoth A & B
DNone of the Above
Correct Answer Both A & B
56
What is the function of validation and discrimination?
ATo refine data analysis and recovery
BTo acquire data from a device
CTo extract data from a device
DNone of the above
Correct Answer To refine data analysis and recovery
57
____________________powerful Windows tool available at Sysinternals
ARegMon
Bfilemon
Chandle
DAll the above
Correct Answer All the above
58
______________________ tool display who logged on locally
APsLoggedOn
BPsKill
CPsPasswd
DPsList
Correct Answer PsLoggedOn
59
_________________ Kills processes by name or process ID
APsExec
BPsGetSid
CPsKill
DPsList
Correct Answer PsKill
60
_______________ tool allows you to change account password
APsService
BPsPasswd
CPsShutdown
DPsSuspend
Correct Answer PsPasswd
61
_______ tool lists detailed information about processes
APsGetSid
BPsKill
CPsList
DPsLoggedOn
Correct Answer PsList
62
_______ tool shuts down and optionally restarts a computer
APsSuspend
BPsPasswd
CPsService
DPsShutdown
Correct Answer PsShutdown

Additional Questions

63 _________________is chronological documentation of electronic evidence.
Correct Answer Chain of custody
64 The aim of a forensic examination is to prove with certainty what occurred (True/False)?
Correct Answer False
65 Even digital investigations that do not result in legal action can benefit from principles of forensic science. (True/False)?
Correct Answer True
66 Forensic science is the application of science to investigation and prosecution of crime or to the just resolution of conflict. (True/False)?
Correct Answer True
67 When a file is deleted from a hard drive, it can often be recovered. (True/False)?
Correct Answer True
68 NSA stands for ___________________________________________
Correct Answer National Security Agency
69 _______________________ is the strategy developed by the National Security Agency.
Correct Answer Defence in Depth (Di
70 Three modes of protection in DiD are ___________________________________.
Correct Answer People, Technology, Operations
71 IDS stand for _______________________________
Correct Answer Intrusion Detection Systems
72 How long a piece of information lasts on a system is known as ________________________
Correct Answer Order of Volatility.
73 ________________ is a collection of free tools for examining Windows products.
Correct Answer Sysinternals
74 DDL stands for _______________________________
Correct Answer Dynamic Link Libraries
75 ___________________ tool shows all Registry data in real time.
Correct Answer RegMon
76 __________________________ enables you to view and control services.
Correct Answer PsService
← Back to All MCQs