Practice objective questions
for quick revision and examination
preparation. Try answering each question
before revealing the answer.
π Computer Forensics
π Part 1
π― MCQs
Computer Forensics - Unit-1
1
Computer forensics also known as?
Adigital forensic science
Bcomputer crime
Ccomputer forensic science
Dcomputer forensics investigations
Correct Answercomputer forensic science
2
Which one option is not a type of cybercrime?
AData theft
BForgery
CDamage to data and systems
DInstalling antivirus for protection
Correct AnswerInstalling antivirus for protection
3
CCFP stands for?
ACyber Certified Forensics Professional
BCertified Cyber Forensics Professional
CCertified Cyber Forensics Program
DCertified Cyber Forensics Product
Correct AnswerCertified Cyber Forensics Professional
4
______________ involves the preservation, identification, extraction, and documentation of computer evidence stored as data or magnetically encoded information.
ADigital Forensics
BLive Data Collection
CIncident Response Methodology
DForensic Duplication
Correct AnswerDigital Forensics
5
_______________ recording the system time and date.
Als
Bdate and time
Crdate
Dw
Correct Answerdate and time
6
How many c's in computer forensics?
A1
B2
C3
D4
Correct Answer3
7
You are supposed to maintain three types of records. Which answer is not a record?
AChain of custody
BDocumentation of the crime scene
CSearching the crime scene
DDocument your actions
Correct AnswerSearching the crime scene
8
The first computer virus is βββ
AVirus Bomb
BBlaster
CSasser
DCreeper
Correct AnswerCreeper
9
_______________data that is stored in memory, or exists in transit, that will be lost when the computer loses power or is turned off.
AVolatile
BNon Volatile
CBoth
DNone of the above
Correct AnswerVolatile
10
Expand DoS Attacks __________________________
ADenial of Service
BDisk operating System
CDuplication of Service
DNone of the above
Correct AnswerDenial of Service
11
What category of software is designed to cause detriment to your computer?
ASystem software
BNetwork snakes
CMalware
DBugs
Correct AnswerMalware
12
Rules of Digital Forensic βAn examination should never be performed on the original media.β Is true of false? ________________________
Atrue
Bfalse
Cboth
DNone of the above
Correct Answertrue
13
Expand CSIRT____________________________________
AComputer Security Incident Request Team
BComputer Security Incident Response Team
CCyber Security Incident Response Team
DNone of the above
Correct AnswerComputer Security Incident Response Team
14
Which of the following describes malicious computer programs such as viruses, worms, and Trojan horses?
ASoftware piracy
BMalware
CLarceny
DArson
Correct AnswerMalware
15
Choose the process model whose goal is to completely describe the flow of information in a digital investigation.
AThe Physical Model
BThe Staircase Model
CThe Evidence Flow Model
DThe Subphase Model
Correct AnswerThe Evidence Flow Model
16
Write any two components of Incident Response Methodology ___________ and _____________
APreparation, Identification
BContainment, Eradication
CRecovery, Lessons learned
DAny of the above
Correct AnswerAny of the above
17
After An Incident Responder Identifies That A Security Incident Is In Progress, What Is The Next Step In The Incident Response Process?
APreparation
BRecovery
CEradication
DContainment
Correct AnswerContainment
18
Which of the following are not the Types of Cybercrimes?
ADenial-of-Service Attacks
BMonkey Attacks
CCyber Pornography
DSoftware Piracy
Correct AnswerMonkey Attacks
19
Which of the following have the capability of spreading itself? It doesnβt require the host and human support to sprea
AVirus
BTrojan
CWorm
DBug
Correct AnswerWorm
20
Minimizing the number of incidents is a function of which of the following?
AIncident response testing
BForensic analysis
CRisk management
DSecurity investments
Correct AnswerRisk management
21
Which of the following attack types best describes a targeted attack that successfully obstructs functionality?
ASpam attack
BMalware attack
CDDoS attack
DKiller attack
Correct AnswerDDoS attack
22
Which of the following belong to Categories of Cybercrimes
ACybercrimes against People
BCybercrimes against Property
CCybercrimes against Government
DAll the above
Correct AnswerAll the above
23
What is the command use to indentify the running processes
Anbtstart
Bps
Cnetstat
Dquery user
Correct Answerps
24
Which tool is not a Qualified Forensic Duplicate of a Hard Drive
ASafeBack
BEnCase
CFTK Imager
DNone of the above
Correct AnswerNone of the above
25
How Many Rules in Digital forensic
A12
B19
C10
D6
Correct Answer6
26
In Computer intrusions the attacker will be leave multiple traces of their presence in:
AFile System
BRegistry
CSystem Logs
DAll of the Above
Correct AnswerAll of the Above
27
What is an grey hat hacker
ABlack Hat Hacker
BWhite Hat Hacker
CCombination of White and black hat hackers
DNone
Correct AnswerCombination of White and black hat hackers
28
To crack the password you need cracking tool such as:
ALC4
BJohn The Ripper
Cpwdump
DAll of the above
Correct AnswerAll of the above
29
Which of the following belong to Categories of Cybercrimes?
ACybercrimes against People
BCybercrimes against Property
CCybercrimes against Government
DAll the above
Correct AnswerAll the above
30
___________ is a crime committed when someone uses the internet and other technologies to harass or stalk another person online
ACyber Bullying
BCyber stalking
CIdentity Theft
DNone
Correct AnswerCyber stalking
31
Volatile data resides in ?
Aregistries
Bcache
CRAM
DAll of the above
Correct AnswerAll of the above
32
The term cybercrime refers to _________________________________
AAny criminal activity carried out over the internet
BAny criminal activity carried out over computer
CAny criminal activity carried out without the internet
DAny criminal activity carried out over computer with the internet
Correct AnswerAny criminal activity carried out over computer with the internet
33
The virus does not have the capability of spreading itself. It requires the host and human support to sprea.β Is true of falseβ? ________________
Atrue
Bfalse
Cboth
DNone of the above
Correct Answertrue
34
Which of the following techniques are used during computer forensics investigations?
ACross-drive analysis
BLive analysis
CDeleted files
DAll of the above
Correct AnswerAll of the above
35
Which one of the following is used for encrypted data transfer?
Anetstat
Bcryptcat
Cmd5sum
Dnetcat
Correct Answercryptcat
36
Which command is used to record all users who currently logged on
Anbtstart
BPsLoggedOn
Cnetstat
Dquery user
Correct AnswerPsLoggedOn
37
Which command used to list the open ports
Anbtstart
BFport
Cnetstat
Drasusers
Correct Answernetstat
38
Choose the command that shows all Registry data in real time on a Windows computer.
APsReg
BRegMon
CRegExplorer
DRegHandle
Correct AnswerRegMon
39
Choose the term which describes Digital forensics.
AScience of collecting and analyzing evidence
Bprocess of Chasing the criminal
CProcess of punishing the culprit
Dpreservation filtering and organization of evidence
Correct AnswerScience of collecting and analyzing evidence
40
Which tool is used for analysis of forensic image?
AFTK Imager
BFlawfinder
CNessus
DOpenstego
Correct AnswerFTK Imager
41
Which of the following is not a Forensic Image Formats?
AComplete Disk Image
BPartition Image
COEM Image
DLogical Image
Correct AnswerOEM Image
42
____________is a broad phrase that encompasses a wide range of cyber attacks such as Trojans, viruses, and worms
AMalware
BComputer Crime
CPhishing
DNone
Correct AnswerMalware
43
What is the command used to display command history taken during initial response
Anbtstart
Bdoskey
Cnetstat
Dquery user
Correct Answerdoskey
44
Digital Evidence in the form of the:
AOffice File
BE-mail Messages
CEither A or B
DBoth A and B
Correct AnswerBoth A and B
45
________________is the process of dealing with a data breach or cyber attack, including how an organization attempts to control the consequences of such an incident.
ADigital Forensics
BLive Data Collection
CIncident Response Methodology
DForensic Duplication
Correct AnswerIncident Response Methodology
46
Computer forensics also is used in civil proceedings.
AYes
BNo
CCan be yes or no
DCannot say
Correct AnswerYes
47
Which of the following techniques are used during computer forensics investigations?
ACross-drive analysis
BLive analysis
CDeleted files
DAll of the above
Correct AnswerAll of the above
48
Deleted files are a common technique used in computer forensics is the recovery of deleted files.
ATRUE
BFALSE
CCan be true or false
DCannot say
Correct AnswerTRUE
49
You are supposed to maintain three types of records. Which answer is not a record?
AChain of custody
BDocumentation of the crime scene
CSearching the crime scene
DDocument your actions
Correct AnswerSearching the crime scene
50
Which of the following actions compromise cyber security?
AVulnerability
BAttack
CThreat
DExploit
Correct AnswerThreat
Artificial Intelligence - Search Strategies
1
What is Artificial Intelligence (AI)?
AA branch of computer science dealing with hardware
BA field focused on creating machines that can perform tasks requiring human intelligence
CA type of software used for graphic design
DA programming language
Correct AnswerA field focused on creating machines that can perform tasks requiring human intelligence
2
An intelligent agent is:
AA robot that can walk
BA system that perceives its environment and takes actions to achieve goals
CA type of database
DA computer virus
Correct AnswerA system that perceives its environment and takes actions to achieve goals
3
Problem-solving agents are designed to:
APlay games only
BSolve specific problems by searching for solutions
CManage computer networks
DCreate animations
Correct AnswerSolve specific problems by searching for solutions
4
Which of the following is an uninformed search strategy?