Practice objective questions
for quick revision and examination
preparation. Try answering each question
before revealing the answer.
π Computer Forensics
π Part 2
π― MCQs
Cyber Forensics MCQs
1
HTTPS is abbreviated as _________
AHypertexts Transfer Protocol Secured
BSecured Hyper Text Transfer Protocol
CHyperlinked Text Transfer Protocol Secured
DHyper Text Transfer Protocol Secure
Correct AnswerSecured Hyper Text Transfer Protocol
2
Which of the following is not a strong security protocol?
ASSL
BHTTPL
CSMTP
DSFTP
Correct AnswerSMTP
3
An attempt to make a computer resource unavailable to its intended users is called _________
ADenial-of-service attack
BVirus attack
CWorms attack
DBotnet process
Correct AnswerDenial-of-service attack
4
You are supposed to maintain three types of records. Which answer is not a record?
AChain of custody
BDocumentation of the crime scene
CSearching the crime scene
DDocument your actions
Correct AnswerSearching the crime scene
5
Volatile data resides in __________________________?
ARegistries
BCache
CRAM
DAll of the above
Correct AnswerAll of the above
6
Who Can Use Computer Forensic Evidence?
ACriminal Prosecutors
BCivil litigations
CLaw enforcement
DAll of them
Correct AnswerAll of them
7
When handling computers for legal purposes, investigators increasingly are faced with four main types of problems, except:
AHow to recover data from computers while preserving evidential integrity
BHow to keep your data and information safe from theft or accidental loss
CHow to securely store and handle recovered data
DHow to find the significant information in a large volume of data
Correct AnswerHow to keep your data and information safe from theft or accidental loss
8
In order for a double tier approach to work it is necessary to have:
AA defined methodology
BCivil control
CA breach of contract
DAsset recovery
Correct AnswerA defined methodology
9
Criteria for equipment in the double tier approach results in the following except:
ASimple to use
BQuick to learn
CTotally reliable
DLegally operable
Correct AnswerLegally operable
10
Computer forensics specialist will take several careful steps to identify and attempt to retrieve possible evidence
AProtect
BDiscover
CRecover
DAll of them
Correct AnswerAll of them
11
A computer forensics professional does more than turn on a computer, make a directory listing, and search through files. Your forensics professionals should be able to successfully perform complex evidence recovery procedures with the skill and expertise that lends credibility to your case. For example, they should be able to perform the following services, except:
AData seizure
BData duplication and preservation
CData recovery
DData dump
Correct AnswerData dump
12
The following are what it really costs to replace a stolen computer, except:
AThe price of the replacement hardware
BThe price of replacing the software
CThe cost of creating data
DThe cost of lost production time or instruction time
Correct AnswerThe cost of creating data
13
Forensic services include but are not limited to the following, except:
ALost password and file recovery
BLocation and retrieval of deleted and hidden files
CFile and email decryption
DEmail non-supervision and non-authentication
Correct AnswerEmail non-supervision and non-authentication
14
Computer evidence is like any other evidence. It must be
AAuthentic
BAccurate
CComplete
DAll of them
Correct AnswerAll of them
15
The legal aspects of a computer forensics investigation center primarily on the following two main issues:
AThe requirements that need to be met in order for evidence to be successfully presented in court and, of course, not considered legally admissible
BThe requirements that need to be met in order for evidence to be successfully presented in court and, of course, considered legally admissible
CThe right of the investigator to avoid the possibility of not incurring legal action against himself or the organization for whom he is conducting the investigation
DThe acceptance of the investigator to avoid the possibility of incurring legal action against himself or the organization for whom he is reviewing the investigation
Correct AnswerThe requirements that need to be met in order for evidence to be successfully presented in court and, of course, considered legally admissible
16
Which of the following is not a type of peer-to-peer cyber-crime?
APhishing
BInjecting Trojans to a target victim
CMiTM
DCredit card details leak in deep web
Correct AnswerCredit card details leak in deep web
17
In terms of digital evidence, the Internet is an example of
AOpen computer systems
BCommunication systems
CEmbedded computer systems
DNone of the above
Correct AnswerCommunication systems
18
In terms of digital evidence, a hard drive is an example of:
AOpen computer systems
BCommunication systems
CEmbedded computer systems
DNone of the above
Correct AnswerOpen computer systems
19
In terms of digital evidence, a Smart Card is an example of
AOpen computer systems
BCommunication systems
CEmbedded computer systems
DNone of the above
Correct AnswerEmbedded computer systems
20
Private networks can be a richer source of evidence than the Internet because:
AThey retain data for longer periods of time.
BOwners of private networks are more cooperative with law enforcement.
CPrivate networks contain a higher concentration of digital evidence.
DAll of the above.
Correct AnswerOwners of private networks are more cooperative with law enforcement.
21
Computers can play the following roles in a crime:
ATarget, object, and subject
BEvidence, instrumentality, contraband, or fruit of crime
CObject, evidence, and tool
DSymbol, instrumentality, and source of evidence
Correct AnswerEvidence, instrumentality, contraband, or fruit of crime
22
The following specializations exist in digital investigations:
AFirst responder (a.k.a. digital crime scene technician)
BForensic examiner
CDigital investigator
DAll of the above
Correct AnswerAll of the above
23
A printer used for counterfeiting is an example of:
AHardware as contraband or fruits of crime
BHardware as an instrumentality
CHardware as evidence
DInformation as contraband or fruits of crime
Correct AnswerHardware as an instrumentality
24
Having a member of the search team trained to handle digital evidence:
ACan reduce the number of people who handle the evidence
BCan serve to streamline the presentation of the case
CCan reduce the opportunity for opposing counsel to impugn the integrity of the evidence
DAll of the above
Correct AnswerAll of the above
25
What can you do to determine the number of sectors on a hard drive larger than 8GB?
AUse a UNIX tool like hdparm
BUse a Windows tools like EnCase
CCheck the drive manufacturerβs website for the specific drive
DAll of the above
Correct AnswerAll of the above
26
A device that connects network with different protocols
ASwitch
BHub
CGateway
DAll of the above
Correct AnswerGateway
27
A device that is used to connect a number of LANs is
ARouters
BRepeater
CBridge
DAll of these
Correct AnswerRouters
28
Because the Internet is built upon the TCP/IP protocol, many hacker attacks will seek to exploit the TCP ports of these servers with public IP addresses. A number of common ports are scanned and attacked, except:
AFTP (21)
BTelnet (23)
CSMTP (25)
DINS (53)
Correct AnswerINS (53)
29
There are _______ major ways of stealing email information.
A2
B3
C4
D5
Correct Answer3
30
Which of them is not a major way of stealing email information?
AStealing cookies
BReverse Engineering
CPassword Phishing
DSocial Engineering
Correct AnswerReverse Engineering
31
Which of them is an example of grabbing email information?
ACookie stealing
BReverse engineering
CPort scanning
DBanner grabbing
Correct AnswerCookie stealing
32
The process of documenting the seizure of digital evidence and, in particular, when that evidence changes hands, is known as:
AChain of custody
BField notes
CInterim report
DNone of the above
Correct AnswerChain of custody
33
A network sniffer program is an example of:
AHardware as contraband or fruits of crime
BHardware as an instrumentality
CInformation as an instrumentality
DInformation as evidence
Correct AnswerInformation as an instrumentality
34
HDD,CD/DVD media, backup tapes, USB drive, biometric scanner, digital camera, smart phone, smart card, PDA etc. are ________________________________________.
APhysical evidence
BElectronic evidence
CIllustrative evidence.
DDocumented evidence
Correct AnswerElectronic evidence
35
Which of the following is not a type of volatile evidence?
ARouting tables
BMain memory
CLog files
DCached data
Correct AnswerLog files
36
Private networks can be a richer source of evidence than the Internet because:
AThey retain data for longer periods of time.
BOwners of private networks are more cooperative with law enforcement.
CPrivate networks contain a higher concentration of digital evidence.
DAll of the above.
Correct AnswerPrivate networks contain a higher concentration of digital evidence.
37
___________________ the first task in computer forensics investigation.
AAcquisition
BValidation and discrimination
CExtraction
DReconstruction
Correct AnswerAcquisition
38
Validating data is done by obtaining
ABinary values
BHex values
CHash values
DNone of the above
Correct AnswerHash values
39
_____________________ laptop computer with a built-in LCD monitor and almost as many bays and peripherals as a stationary workstation
ALightweight workstation
BPortable workstation
CAdvanced Stationary workstation
DNone of the above
Correct AnswerPortable workstation
40
___________________publishes articles, provides tools, and creates procedures for testing and validating computer forensics software.
AIIT
BMIT
CNIST
Dboth B & C
Correct AnswerNIST
41
______________________ e-mail system is specific to a company, used only by its employees.
ALocalhost
BIntranet
CInternet
DNone of the above
Correct AnswerIntranet
42
What is the disadvantage of circular logging?
AIt saves server space
BCanβt recover a log after itβs overwritten
CIt records traffic in the Mon.log file
DNone of the above
Correct AnswerCanβt recover a log after itβs overwritten
43
E-mail logs generally identifies:
AE-mail contents
BIP address
CSystem-specific information
DAll of the above
Correct AnswerAll of the above
44
What are some tools that can be used to recover e-mail files?
AProDiscover Basic and Access Data FTK
BFINAL e MAIL for Outlook Express and Eudora
CSawmill-GroupWise for log analysis office_agent.html
DAll of the above
Correct AnswerAll of the above
45
What is the search criteria used to find log files?
A.log
B.db
C.pst
D.ost
Correct Answer.log
46
What is one of the most challenging tasks in digital forensics?
AInvestigating cell phones and mobile devices
BInvestigating laptops and desktops
CInvestigating servers and databases
DInvestigating networks and routers
Correct AnswerInvestigating cell phones and mobile devices