4 TH Unit MCQ
4 TH Unit MCQ
4 TH Unit MCQ
1. 1.
Digital forensics is all of them except:
A. Extraction of computer data.
B. Preservation of computer data.
C. Interpretation of computer data.
D. Manipulation of computer data.
5. In the past, the method for expressing an opinion has been to frame a question
based on available factual evidence.
A. Hypothetical
B. Nested
C. Challenging
D. Contradictory
6.More subtle because you are not aware that you are running these macros (the
document opens and the application automatically runs); spread via email
E. The purpose of the copyright
F. The danger of macro viruses
G. Derivative works
H. computer-specific crime
6. There are three c's in computer forensics. Which is one of the three?
A. Control
B. Chance
C. Chains
D. Core
7. What is Digital Forensic?
A. Process of using scientific knowledge in analysis and presentation of evidence in court
B.The application of computer science and investigative procedures for a legal purpose involving
the analysis of digital evidence after proper search authority, the chain of custody, validation with
mathematics, use of validated tools, repeatability, reporting, and possible expert presentation
C. process where we develop and test hypotheses that answer questions about digital events
D. Use of science or technology in the investigation and establishment of the facts or evidence in a court of
law
11. phase includes putting the pieces of a digital puzzle together and developing investigative
hypotheses
A. Preservation phase
B. Survey phase
C. Documentation phase
D. Reconstruction phase
E. Presentation phase
12. phase includes putting the pieces of a digital puzzle together and developing investigative hypotheses
F. Preservation phase
G. Survey phase
H.Documentation phase
I. Reconstruction phase
J. Presentation phase
13. In phase investigator transfers the relevant data from a venue out of physical or administrative control
of the investigator to a controlled location
A.Preservation phase
B.Survey phase
C.Documentation phase
D.Reconstruction phase
E.Presentation phase
14. In phase investigator transfers the relevant data from a venue out of physical or administrative control
of the investigator to a controlled location
A.Preservation phase
B.Survey phase
C.Documentation phase
D.Reconstruction phase
E.Presentation phase
17. To collect and analyze the digital evidence that was obtained from the physical investigation phase, is the
goal of which phase?
A.Physical crime investigation
B.Digital crime investigation.
C.Review phase.
D.Deployment phase.
18. To provide a mechanism to an incident to be detected and confirmed is purpose of which phase?
A.Physical crime investigation
B.Digital crime investigation.
C.Review phase.
D.Deployment phase.
19. Which phase entails a review of the whole investigation and identifies an area of improvement?
A.Physical crime investigation
B.Digital crime investigation.
C.Review phase.
D.Deployment phase
21. _is well established science where various contribution have been made
A.Forensic
B.Crime
C.Cyber Crime
D.Evidence
22. Who proposed End to End Digital Investigation Process (EEDIP)?
A.G. Palmar
B.Stephenson
C.Michael Anderson
D.S.Ciardhuain
D: Evidence
26. is software that blocks unauthorized users from connecting to your computer.
A.Firewall
B.Quick launch
C.OneLogin
D.Centrify
27. Which of the following are general Ethical norms for Investigator?
A.To contribute to society and human beings. B. To avoid harm to others.
C. To be honest and trustworthy. D. All of the above
29. Which of the following is not a general ethical norm for Investigator?
A.To contribute to society and human beings. B. Uphold any relevant Evidence.
C. To be honest and trustworthy. D. To honor confidentially.
30. Which of the following is a not unethical norm for Digital Forensics Investigation?
A.Uphold any relevant evidence.
B.Declare any confidential matters or knowledge.
C.Distort or falsify education, training, credentials.
D.To respect the privacy of others.
31. What is called as the process of creation a duplicate of digital media for purpose of examining it?
A.Acquisition.
B.Steganography.
C.Live analysis
D.Hashing.
32. Which term refers to modifying a computer in a way which was not originally intended to
view Information?
A.Metadata
B.Live analysis
C.Hacking
D.Bit Copy
33. The ability to recover and read deleted or damaged files from a criminal’s
computer is an example of a law enforcement specialty called?
A.Robotics
B.Simulation
C.Computer Forensics
D.Animation
34. What are the important parts of the mobile device which used in Digital forensic?
A.SIM
B.RAM
C.ROM.
D.EMMC chip
35. Using what, data hiding in encrypted images be carried out in digital forensics?
A.Acquisition.
B.Steganography.
C.Live analysis
D.Hashing.
38. is the process of recording as much data as possible to create reports and analysis on
user input.
A.Data mining
B.Data carving
C.Metadata
D.Data Spoofing.
39. searches through raw data on a hard drive without using a file system.
A.Data mining
B.Data carving
C.Metadata
D.Data Spoofing.
40. What is the first step to Handle Retrieving Data from an Encrypted Hard Drive?
A.Formatting disk
B.Storing data
C.Finding configuration files.
D.Deleting Files