Browse all practice questions for the Digital Forensics, Investigation, and Response Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Digital Forensics, Investigation, and Response Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What does the OST file extension denote?
  • It is legal for employers to monitor work computers.
  • Once an intrusion into your organization's information system has been detected, which of the following actions should be performed first?
  • Which log is considered the most important from a forensics perspective because it records both successful and unsuccessful login events?
  • What is the file format .edb used with?
  • When a file is deleted on an iPhone, iPad, or iPod, where is the data typically moved to before it is overwritten?
  • Disk forensics primarily involves which activities?
  • In Windows, which component stores metadata about files and directories and can reflect deletions when files are removed?
  • Evidence need not be locked if it is at a police station.
  • Which area does the Sarbanes-Oxley Act of 2002 primarily regulate?
  • Which filesystem type is primarily used for swap space and is not intended to be mounted as a normal filesystem?
  • Preserving what during cataloging digital evidence ensures it can be reliably verified in court?
  • Which application is commonly associated with creating OpenDocument Text files?
  • Network forensics primarily involves which activity?
  • Which of the following file systems cannot be mounted by using the mount command?
  • The Computer Security Act of 1987 requires the establishment of minimum acceptable security practices, creation of computer security plans, and training of system users for which purpose?
  • The Privacy Protection Act of 1980 primarily protects which group from being compelled to turn over work product and documentary materials before publication?
  • AFF file format is used by which forensic software?
  • What type of encryption uses a different key to encrypt the message than it uses to decrypt the message?
  • Which hash algorithm does EnCase calculate to verify the integrity of acquired drives?
  • What does a router use to determine the path to send packets?
  • Which file extension is associated with Lotus Notes databases?
  • Which data structure stores items using last-in, first-out semantics?
  • SQL injection is best described as?
  • Which command line utility is used to display a tree-like view of processes?
  • Which term refers to the unused space between the end of a file and the end of its last data cluster?
  • In Intel-based Mac systems, computers can boot only from drives that use which partitioning scheme?
  • Steganalysis is the process of doing which of the following?
  • The /Users//Library/Preferences folder can provide clues about which of the following?
  • Hiding messages inside another medium is referred to as ________.
  • Which shell is described as the default for the macOS terminal, enabling command input in a Bash-like environment?
  • Which Linux command can be used to generate a hash?
  • What is the purpose of using MD5 in disk examination?
  • Which product is described as recovering Inbox and Outbox data and all contacts data, with a free trial version available?
  • What does a 500 HTTP response indicate?
  • Which of the following is an example of a multialphabet cipher?
  • An improvement on the Caesar cipher that uses more than one shift is called Multialphabet substitution.
  • The /var/log/daily.out file contains data that helps forensic investigators. Which of the following describes its contents?
  • It is important to write-block a phone before doing forensic analysis to make certain data is not copied to the phone.
  • FTK provides tools to search and analyze which Windows data store?
  • Which file extension is used to store Exchange mailbox databases?
  • In Linux, startup scripts responsible for starting and stopping services are traditionally located in which directory?
  • Spyware is legal.
  • What file system does Mac OS use?
  • What category of files is primarily stored in the /etc directory on macOS?
  • Which technique hides a payload in MP3 files?
  • Which statement about stack memory is correct?
  • The Caesar cipher is the oldest known encryption method.
  • Which of the following is explicitly listed as an important consideration regarding logging?
  • What is the minimum number of bitstream copies you should make of a suspect drive?
  • To preserve digital evidence, an investigator should ________.
  • The Electronic Communications Privacy Act of 1986 governs the privacy, disclosure, access, and interception of what aspects of electronic communications?
  • Your roommate can give consent to search your computer.
  • What type of memory do most solid-state drives utilize?
  • Which type of partition space cannot be accessed by the operating system and may contain hidden data?
  • Which act establishes a code of information-handling practices for U.S. federal agencies and defines a system of records retrieved by name or identifier?
  • Which hashing algorithm is most commonly used?
  • Which statement best distinguishes live system forensics from disk forensics?
  • You are performing a forensic analysis on a cell phone. You have tried entering the PUK 6 times, all incorrectly. What does this mean for John's investigation?
  • Which act protects journalists from being compelled to turn over work product and documentary materials before publication?
  • In memory forensics, what does a Volatility profile define?
  • Which description best defines a bitstream copy?
  • What assesses potential loss that could be caused by a disaster?
  • It takes ___________ occurrence(s) of overextending yourself during testimony to ruin your reputation.
  • Multialphabet substitution is a type of which cipher family?
  • Business Continuity Plan development depends most on:
  • How many hives are in the Windows Registry?
  • Moore's law concerns which of the following?
  • EnCase is a proprietary format defined by which company?
  • A common steganalysis indicator for potential LSB steganography is what pattern in close-color pairs?
  • If a computer is on when you arrive at a scene, what does the Secret Service recommend you do?
  • What best describes volume slack?
  • Which statement best reflects the material about monitoring work computers?
  • In steganography, what is the payload?
  • The Windows Registry contains information Windows references during operation. Which of the following is described as being stored there?
  • Which statement accurately reflects Moore's law in terms of chip progress?
  • Volatility is used to analyze which type of data in digital forensics?
  • In steganography, what is the carrier?
  • Rainbow tables are best described as which of the following?
  • Which term best describes an overarching plan to keep essential business operations operating during and after a disruptive event?
  • Which method stores data in the least significant bit of each byte in steganography?
  • How many rounds does DES have?
  • What is the primary purpose of the /proc filesystem in Linux?
  • How would you connect to a smart TV using ADB?
  • Which term best describes the practice of concealing the existence of a secret message?
  • The Windows swap file serves to augment RAM by temporarily storing memory contents on disk. Which scenario best describes when it is used?
  • Which type of mass emails are not covered by the CAN-SPAM Act?
  • Which folder syncs with iCloud and contains items saved to iCloud?
  • What is the recommended handling of the original evidence after creating copies and hashes?
  • Is it acceptable, when you have evidence in a vehicle, to stop for a meal if the vehicle is locked?
  • Cell-phone forensics includes which aspects?
  • Which of the following is the Linux equivalent of a shortcut?
  • What single shell command will tell you the home directory, current user, and current history size?
  • Which standard governs the admissibility of forensic techniques based on acceptance by the scientific community?
  • Which storage technology uses NAND?
  • Where are the startup scripts defined in many Unix-like systems?
  • The Electronic Communications Privacy Act of 1986 governs privacy, disclosure, access, and interception of content and traffic data related to electronic communications.
  • What partition type is used to boot Intel-based Apple machines?
  • The payload in a steganographic system is the data that is intended to be covertly communicated.
  • Which of the following statements correctly characterizes SQL injection?
  • XRY is a forensic tool mentioned for which capability related to iPhones?
  • In the Advanced Forensic Format variations, which variation stores all data and metadata in a single file?
  • Where would you look for configuration files on an Apple computer?
  • ________ is a commonly used name for a command-line utility that provides disk partitioning functions in an operating system. It can list the partitions on a Linux system.
  • Which of the following is a 4G standard?
  • APFS was designed to correct issues with which earlier Apple filesystem?
  • The MD5 message-digest algorithm is used to ____________.
  • CA LEA was enacted as a federal wiretap law for traditional wired telephony and was expanded in 2004 to include which technologies?
  • The dmesg command provides access to which type of messages?
  • What is the key length used for DES?
  • Which statement is false about evidence handling at a police station according to the provided guidelines?
  • What file system does Windows 10 use?
  • Where would you seek evidence that Ophcrack had been used on a Windows Server 2008 machine?
  • Cryptographic hashes are used to store passwords in many systems. What exactly is stored?
  • Which word processor is specifically associated with creating OpenDocument Text (.odt) files in the source material?
  • Which file system is associated with Mac OS according to the material?
  • An ODT file is an OpenDocument text document created by which word processor?
  • Which of the following might contain data that was live in memory and not stored on the hard drive?
  • What is the aim of internet forensics?
  • FTK is produced by which company?
  • You can undelete files in Mac OS.
  • Which statement about The Sleuth Kit is true?
  • In steganography, the ________ is the data to be covertly communicated. In other words, it is the message you want to hide.
  • What is Pwnage primarily used to do in the context of iPods or iPhones?
  • What was the most important forensic feature in OSX 10.10?
  • APFS is explicitly optimized to work with which storage technologies?
  • Which statement about forensic copying tools is accurate?
  • Which Volatility plug-in is specifically used to reveal processes that may be hidden in a memory image?
  • Which group is most commonly associated with logic bombs?
  • Use the ________ command to see running processes as a tree.
  • Which crime is most likely to leave email evidence?
  • Which forensic software family is known to work with the AFF file format?
  • What is the central principle of chain of custody in forensics?
  • OST files are used by which application to store offline mail data?
  • The ________ is memory that programs can allocate as needed.
  • Public-key cryptography is exemplified by which algorithm mentioned in the material?
  • Which type of drive would be least susceptible to damage when dropped?
  • What is The Sleuth Kit primarily described as?
  • Which header would have the sender's MAC address?
  • Which statement about email forensics is accurate?
  • When seeking evidence of Ophcrack usage on a Windows Server 2008, which artifact is most likely to indicate its use?
  • The Computer Security Act of 1987 was enacted to improve the security and privacy of sensitive information in which systems?
  • What is the starting point for investigating denial-of-service attacks?
  • From which URL is the Data Doctor product available, according to the material?
  • Which directory is commonly used to store configuration files on Unix-like systems?
  • The Foreign Intelligence Surveillance Act of 1978 allows for the collection of foreign intelligence information using which process?
  • Which Linux command can wipe a target drive?
  • Email forensics includes which tasks?
  • Ophcrack is typically very successful at cracking Windows local machine passwords and depends on which of the following?
  • GUID Partition Table is used primarily with computers that have which type of processor?
  • Which statement best describes the role of the /var/log folder in the context of the provided material?
  • Logic bombs are often perpetrated by _________.
  • Which act is a federal wiretap statute originally covering traditional wired telephony and expanded to wireless and other forms of electronic communications?
  • FTK is particularly effective at cracking passwords for which file types?
  • Unlawful Access to Stored Communications: 18 U.S.C. § 2701 covers access to a facility through which electronic communications are provided, exceeding the access that was authorized. What is the penalty for the first offense?
  • What type of artifacts are found in the /var/vm app profile subfolder, such as lists of recently opened applications?
  • What is the .ost file format used for?
  • What is the most obvious utility included in The Sleuth Kit?
  • To locate the web server logs on a Linux system, which directory should be checked?
  • What is the purpose of hashing a copy of a suspect drive?
  • Lotus Notes uses the following file format.
  • The most common way steganography is accomplished is via ________.
  • Which term best describes devices that are in an early stage after manufacture?
  • Which AFF variation stores data and metadata in separate files?
  • What is the purpose of creating more than one bitstream copy of a suspect drive?
  • Hash comparison between the original and its copy can reveal alterations if the values do not match. Which option reflects this correctly?
  • Which of the following focuses on sustaining an organization's business functions during and after a disruption?
  • The .mbx extension is associated with which email client?
  • Which network component stores roaming subscriber data for devices currently in a visited network?
  • Which of the following is an asymmetric cryptography algorithm invented by three mathematicians in the 1970s?
  • All devices are in the following state when received from the manufacturer.
  • What is the recommended practice to minimize changes to the system?
  • IMAP uses port 143.
  • Which term describes the formal process of evaluating potential losses and prioritizing resources to mitigate risk in an organization?
  • What is the primary reason to take cyberstalking seriously?
  • Why can you undelete files in Windows 7?
  • Outlook Express mailbox data can be stored in which extensions?
  • Which port is IMAP commonly associated with by default?
  • What is a notable characteristic of the /private/var/audit Logs?
  • Which characteristic describes the main benefit of cloud computing over traditional on-premises systems?
  • Which file extension is associated with Outlook data storage?
  • Why is it important to interact with the suspect system as little as possible?
  • CAN-SPAM Act does not cover which type of emails?
  • What file system is used in most modern Mac OS systems?
  • Which of the following is NOT listed as a drive connection type for magnetic or solid-state drives?
  • Which concept involves hiding information inside another object for covert communication, commonly using little change to cover media?
  • When investigating a virus, what is the first step?
  • Steganography is defined as which of the following?
  • Which file extensions are used for Outlook Express mailbox storage?
  • What is a Volatility profile for?
  • APFS was first announced at the Apple Developer Conference in 2016. Which choice best states the year?
  • Which type of firewall is most likely to prevent SYN floods?
  • In steganography, the ________ is the stream or file into which the data is hidden.
  • Which Volatility plug-in is commonly used to identify processes that may be hidden from standard process listings?
  • What does live system forensics involve?
  • Which best describes DLL injection?
  • Daubert standard is used by a trial judge to determine whether an expert's reasoning or methodology is scientifically valid and can be applied to the facts.
  • Why would you not turn off a router before examining it for evidence?
  • Which of the following encryption algorithms uses three key ciphers in a block system and uses the Rijndael algorithm?
  • RAID 4 should be acquired as individual disks. True or False?
  • Which statement best describes symmetric encryption?
  • Why is the /etc directory often examined during a forensic investigation?
  • The GUID Partition Table is associated with a compatibility requirement on Mac systems. Which statement is true?
  • Under the Federal Privacy Act, a system of records is a group of records under agency control from which information is retrieved by the name of the individual or by some identifier assigned to the individual.
  • Which of the following represents a data type explicitly recoverable by the Data Doctor product, as mentioned in the material?
  • Why should you note all cable connections for a computer you intend to seize as evidence?
  • Which file extension is associated with the OST file used by Microsoft Outlook for offline storage?
  • In Windows 10, the swap file ends with what extension?
  • In steganography, which statement best describes a channel?
  • What is the main advantage of cloud computing?
  • In the Bash history log, which command would indicate an attempt to create a disk image of the drive?
  • Which file system provides system statistics and does not contain real files but provides an interface to run-time information?
  • It is not ideal to rely on a simple DOS copy for copying files because:
  • What type of document is the OpenDocument Text (.odt) format?
  • The Children's Online Privacy Protection Act of 1998 protects children of what age from the collection and use of their personal information by websites?
  • The Foreign Intelligence Surveillance Act of 1978 allows for collection of foreign intelligence information using physical and electronic surveillance with a warrant issued by which court?
  • Which of the following is important to the investigator regarding logging?
  • Which HTTP status code category corresponds to server-side errors?
  • Which Windows operating system first supported FAT32?
  • How many possible combinations does a six-digit iPhone passcode have?
  • When cataloging digital evidence, what is the primary goal?
  • What is the most important reason you should not touch the original evidence more than necessary?
  • Which acts might intersect with cell-phone forensics in the United States?
  • In binary, changing the first bit of 11111111 from 1 to 0 yields 01111111, which equals 127. Which bit was changed?
  • Which folder stores information about printed documents on Apple devices, including the document name and the user who printed?
  • The .mbx extension is used by which email client?
  • Which command can be used to view the Linux boot messages?
  • What is the essence of the Daubert standard?
  • In a computer forensics investigation, what describes the route that evidence takes from the time you find it until the case is closed or goes to court?
  • Where is the data for roaming phones stored?
  • What is a primary method to verify the integrity of a forensic image during acquisition?
  • Under the Wireless Communications and Public Safety Act of 1999, what type of data is described as 'empty' communications and may be collected?
  • What is a key limitation of using a DOS copy for evidence transfer?
  • What information does the /Library/Receipts folder primarily contain?
  • What should be documented in an investigation to support admissibility?
  • Which statement best describes the status of evidence handling if the computer is on arrival and the procedure is followed?
  • MS-DOS stands for which of the following?
  • What term describes 'empty' communications such as GPS information that may be collected under the act?
  • What maps virtual addresses to physical addresses?
  • When performing forensic analysis on devices from diverse jurisdictions, the proper approach is to:
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy