Browse all practice questions for the Cengage Computer Forensics Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Cengage Computer Forensics Practice Test 2026 - Free Computer Forensics Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which of the following is NOT a commonly used hash algorithm for verifying forensic images?
  • Which concept describes the data collection priority based on how quickly data can disappear from a system?
  • What is the primary purpose of the chain of custody in digital forensics?
  • To help determine which computer forensics tool to purchase, a comparison table of functions, subfunctions, and vendor products is useful.
  • Which artifact is commonly recovered from memory to aid digital investigations?
  • Which hash algorithms are commonly used to verify forensic images, and why are they important?
  • What is the role of exactly matching time stamps and time zones in investigations?
  • Which Linux command is used to create the raw data format?
  • What is the primary hash algorithm used by the NIST project created to collect all known hash values for commercial software and OS files?
  • One way to examine a partition's physical level is to use a disk editor such as WinHex or Hex Workshop.
  • What is Microsoft's SkyDrive now called?
  • Which activity focuses on setting acceptable levels of risk for operational processes?
  • What is used to verify evidence integrity?
  • Data carving in disk forensics often yields recoverable remnants from which region of the disk?
  • Which type of forensics can help you determine whether a system is truly under attack or a user has inadvertently installed an untested patch or custom program?
  • Which DNS and DHCP artifacts are valuable for investigations?
  • In mobile forensics, what is the difference between logical extraction and physical/complete extraction?
  • What is the primary purpose of maintaining chain of custody in a digital forensics investigation?
  • Which document is sworn to under oath in legal proceedings?
  • Which artifact stores local copies of mailbox data for an email client?
  • Which artifacts are commonly sought on iOS devices?
  • What is triage imaging and when is it typically performed?
  • Which tool is commonly used for memory forensics to extract artifacts from RAM dumps?
  • Which term best describes the published guidance that establishes who is empowered to conduct internal investigations within an organization?
  • Which tool enables the investigator to acquire the forensic image and process it in the same step?
  • Drive slack is composed of RAM slack and file slack.
  • Which browser artifacts are typically recovered in a forensic examination?
  • Which agency introduced training on software for forensics investigations by the early 1990s?
  • During opening statements, both attorneys provide an overview of the case, with the plaintiff's attorney going last.
  • What is the Master File Table (MFT) in NTFS, and why is it important?
  • Differentiate between live data acquisition and static/disk imaging.
  • Which stage of the standard digital forensics process involves documenting the results and preparing a final report?
  • Which group often works as part of a team to secure an organization's computers and networks?
  • Which browser artifact provides a record of visited URLs and timestamps?
  • Which practice helps ensure the integrity of evidence across custody?
  • Which statement best describes the APA's Ethics Code in relation to forensic activities?
  • The HFS and HFS+ file systems have four descriptors for the end of a file (EOF).
  • What is data carving and when is it used?
  • Describe common anti-forensic techniques and how investigators mitigate them.
  • Why is hash verification critical when handling forensic evidence?
  • In Firefox, which data store holds the history of visited pages?
  • What imaging technique captures a sector-by-sector copy of a storage device, including slack space?
  • Which document offers comprehensive guidance for psychologists, with an entire section devoted to forensics activities?
  • In the context of data changes, which log records changes to a data store in a messaging server?
  • Which of the following best describes an essential step in maintaining an admissible digital evidence during collection?
  • Because digital forensics tools have limitations in performing hashing, what tools should be used to ensure data integrity?
  • What type of location data artifacts are commonly sought on iOS devices?
  • When serving as an expert witness or a fact witness, you should be professional and polite when presenting yourself to any attorney or the court.
  • Which option best describes the purpose of chain-of-custody documentation?
  • Are virtual machines commonly used for both personal and business use?
  • What does timeline visualization help present in forensic findings?
  • Which stage directly follows Examination in the standard digital forensics process model?
  • Where are Windows MRU lists and Jump Lists stored?
  • What metadata category is commonly found in image files that can reveal camera settings and GPS data?
  • What is the role of an incident response playbook in digital forensics?
  • According to the material, virtual machines are common in which domains?
  • Type 1 hypervisors are usually the ones you find loaded on a suspect machine.
  • Which RAID configuration is a combination of RAID 1 and RAID 0, also called mirrored striping?
  • What does the Windows "Shellbag" artifact indicate?
  • What NTFS artifact tracks all changes to files over time, enabling timeline reconstruction?
  • Why is physical segregation of evidence important in a forensic lab?
  • What is the purpose of file signatures (magic numbers) in forensic analysis?
  • What is BitLocker and how does it impact forensic analysis?
  • What term refers to Linux ISO images that can be burned to a CD or DVD?
  • Which type of log is most associated with potential loss of essential network activity records during abrupt power loss?
  • What is a PCAP file and why is it central to network forensics?
  • Which type of digital network divides a radio frequency into time slots?
  • What APFS feature provides point-in-time copies of the filesystem for backups and recovery?
  • What is the forensic value of an APFS snapshot on macOS?
  • Slack space in disk forensics refers to which of the following?
  • What is metadata in documents and why is it valuable to investigations?
  • In which log does Exchange log information about changes to its data?
  • Which file system feature provides encryption on a per-file basis in Windows NTFS?
  • What material is recommended for secure storage containers and cabinets?
  • What NTFS metadata file contains details about files and directories, and how is it used in forensics?
  • Which file system was used before OS X to store files in nested directories?
  • What is the most common and flexible data-acquisition method?
  • Which description defines a static acquisition?
  • Network logs record traffic in and out of a network.
  • Before OS X, the Hierarchical File System (HFS) was used; are files stored in nested directories?
  • Why is hashing RAM dumps important in live memory forensics?
  • Which of the following is most appropriate for validating that two copies of evidence are identical?
  • Which type of tool can be used to compare results and verify a new tool by viewing data in its raw format?
  • What are key legal considerations in mobile device forensics?
  • Which term refers to unused space at the end of allocated clusters that can contain remnants of deleted data?
  • Evidence artifacts vary depending on the social media channel and the device.
  • Which option best describes Linux Live CDs?
  • What Windows artifact tracks file system changes and is useful for reconstructing activity over time?
  • Which NTFS component records changes to files over time, aiding timeline reconstruction?
  • Which material is recommended for secure storage containers and cabinets due to durability?
  • Which motion provides a written list of objections to certain testimony or exhibits?
  • What cloud application offers a variety of cloud services, including automation and CRM, cloud application development, and Web site marketing?
  • A technician is trying to recover information on a computer that has been hidden or deleted on purpose in order to hide evidence of a crime. Which type of task is the technician performing?
  • Which Windows event log records operating system events such as driver failures and shutdowns?
  • The first 5 bytes (characters) for all MFT records are FILE.
  • Which of the following is a correct listing of some stages in the standard digital forensics process model?
  • In 1999, Salesforce.com developed a customer relationship management (CRM) Web service that applied digital marketing research to business subscribers so that they could do their own market analysis; this service eventually led the way to the cloud.
  • What is a primary legal challenge in cloud forensics?
  • In the context of network malware analysis, what is a beacon?
  • What type of acquisition is used for most remote acquisitions?
  • What resource might attorneys use to search for information on expert witnesses?
  • Which artifact helps determine USB device usage history beyond a single session?
  • Which type of hypervisor is typically found loaded on a suspect machine?
  • Which analysis technique aligns events from multiple artifacts into a chronological sequence?
  • Volatile memory preserves which types of data?
  • What is the Daubert standard and how does it apply to forensic evidence?
  • Which tool enables acquiring a forensic image and processing it in one step?
  • Which space is targeted during file carving to recover data when metadata is missing?
  • The lab manager is responsible for setting up processes for managing cases and reviewing them regularly.
  • Research on wearable computers has been conducted at MIT labs for more than a decade, and these computers are now moving into working reality.
  • What entity created the Interim Standards used in mobile communications?
  • What should you use to verify evidence and thus ensure its integrity?
  • Differentiate volatile and non-volatile data in digital forensics.
  • Which phase focuses on ensuring data is not altered during collection?
  • Corporate investigators always have the authority to seize all computer equipment during a corporate investigation.
  • Which access method is used by GSM where multiple devices share a channel in time slots?
  • Which Windows feature records recently opened files for a program and supports quick access?
  • Which Windows registry hives commonly hold user activity, settings, and system configuration data?
  • Who is responsible for establishing and reviewing case management processes in a forensic lab?
  • What is a key concern in cloud forensics regarding data storage?
  • What is a write blocker and when should it be used?
  • Why are cryptographic hashes calculated for forensic images?
  • EDGE is associated with data services for which generation of mobile networks?
  • At what hard link count is a file effectively deleted?
  • A separate manual validation is recommended for all raw acquisitions at the time of analysis.
  • By the early 1990s, which agency had introduced training on software for forensics investigations?
  • What Windows artifact reveals program startup information and helps reconstruct execution flow?
  • What does file carving involve in data recovery?
  • In IT terminology, the person who uses a computer for routine tasks and doesn't perform administration is called the End User.
  • Which Windows logs commonly provide evidence of user logins and authentication events?
  • What is the name of the optional built-in encryption that Microsoft added to NTFS when Windows 2000 was introduced?
  • If a corrupted file shows no evidence of a virus and no evidence of intentional alteration, what conclusion can be offered?
  • Which practice is recommended for all raw acquisitions at the time of analysis?
  • Which network protocol analyzer can be programmed to examine TCP headers to find the SYN flag?
  • What is volatile memory forensics and what type of data does it preserve?
  • A verbal report is more structured than a written report.
  • What should a forensic report include to be court-ready?
  • What is the main goal of disk imaging in digital forensics?
  • Software forensics tools typically copy data from a suspect's disk drive into which type of file?
  • The police blotter provides a record of clues to crimes that have been committed previously.
  • What is the significance of the /var/log directory in Linux systems for forensics?
  • The pipe (|) character redirects the output of the command preceding it.
  • What do published company policies provide for a business that enables internal investigations?
  • Which data structure in many file systems contains file and directory metadata and links to data blocks?
  • How does cloud forensics differ from on-prem forensics?
  • Which task is described as recovering information hidden or deleted to hide evidence?
  • What information do Windows Jump Lists provide that can aid investigators?
  • Drive slack includes RAM slack (found mainly in older Microsoft OSs) and file slack.
  • In forensic investigations, which type of acquisition is typically performed on a computer seized during a police raid?
  • Name common forensic imaging formats and their characteristics.
  • What type of acquisition is performed when the computer has an encrypted drive and the password or passphrase is available?
  • Which metadata in image files is commonly used to reveal camera settings and geographic information?
  • The 1999 Salesforce.com CRM Web service contributed to the early development of cloud computing.
  • What is a sandbox in malware analysis?
  • Investigations involving email are different from other computer abuse investigations.
  • In cloud forensics, what is a primary concern when dealing with data across providers and regions?
  • Which cloud application offers automation and CRM, cloud application development, and web site marketing?
  • Investigations of email policy violations are generally the same as other computer abuse investigations.
  • Is the decimal numbering system frequently used when writing pleadings?
  • What is an APFS snapshot and its forensic value on macOS?
  • Computing systems in a forensics lab should be able to process typical cases in a timely manner.
  • Which data is typically collected during a live data acquisition?
  • In BYOD environments, investigators should consider separating employees' personal data from case evidence.
  • Which artifact records USB device usage on Windows hosts?
  • What type of cards, consisting of a microprocessor and internal memory, are usually found in GSM devices?
  • The Enhanced Data GSM Environment (EDGE) standard was developed specifically for which type of service?
  • Name a common forensic disk image format associated with EnCase.
  • Deposition banks are resources used by attorneys to search for information on which of the following?
  • Which cloud platform is known for offering automation, CRM, development, and marketing capabilities?
  • The chain of custody of evidence supports the integrity of your evidence.
  • Which artifact documents the origins of downloaded files and their sources?
  • Which algorithm is the standard widely used for disk encryption in modern systems?
  • What artifacts are commonly found in email forensics, and how do PST/OST files relate?
  • From a network forensics standpoint, are there potential issues related to using virtual machines?
  • What type of files might lose essential network activity records if power is terminated without a proper shutdown?
  • Which material is recommended for secure storage containers and cabinets due to durability?
  • To retrieve e-mail headers in Microsoft Outlook, after selecting an e-mail, which option should be clicked?
  • Expert opinions cannot be presented without stating the underlying factual basis.
  • Which acquisition is typically used on a powered-down system to preserve evidence and avoid altering data?
  • The law of search and seizure protects the rights of all people, excluding people suspected of crimes.
  • Which tool can reveal hidden network sockets on a suspect machine?
  • Which option best describes the difference between a forensic image and a simple copy?
  • What is a major challenge when examining encrypted devices in a forensic investigation?
  • Which statement is accurate regarding a disk editor's capabilities for forensic testing?
  • Which practice helps ensure that an evidence image remains trustworthy after transfer and analysis?
  • Which cloud storage service did SkyDrive evolve into?
  • Which type of forensics examines network activity to determine if an intrusion occurred or if an untested patch was installed?
  • In mobile forensics, which extraction type is typically faster and less intrusive but may not recover deleted data?
  • If a graphics file cannot be opened in an image viewer, what should the next step be?
  • Which practice supports the integrity of evidence?
  • Which Windows artifact is primarily used to record authentication events for security auditing?
  • In a Unix-like file system, which structure stores metadata and pointers to data blocks?
  • In Windows forensics, which artifact is most commonly used to identify files that were executed on the system?
  • What is PCAP data and how is it used in network forensics?
  • Which devices have largely been replaced by iPods, iPads, and other mobile devices for personal use?
  • What is the purpose of a write blocker in the imaging process?
  • TDMA is a method used in digital networks to:
  • Which artifact documents downloaded files and their origins?
  • What is the Volatility framework used for in memory forensics?
  • Which symbol is used to redirect the output of the preceding command to another destination?
  • In mobile forensics, what data types are typically retrieved via a logical extraction?
  • Which Windows artifact lists the most recently opened documents and programs?
  • Which symmetric encryption standard is widely used for disk encryption on modern systems?
  • MRU lists in Windows primarily help investigators understand which of the following?
  • Why is physical segregation of evidence, work, and suspect devices essential in a forensic lab?
  • What determines how long a piece of information lasts on a system?
  • Which document is sworn to under oath and penalty of perjury, or a comparable false swearing statute?
  • Which statement correctly describes the purpose of timeline visualization in court preparation?
  • Which filesystem central to macOS supports snapshots and strong encryption?
  • Which Windows artifacts help reconstruct user activity around Explorer use and Office documents?
  • Which open-source toolkit is commonly used for Unix-like forensic analysis and includes a GUI called Autopsy?
  • Differentiate between slack space and unallocated space and explain why both matter in forensics.
  • Which statement best defines steganography in the context of anti-forensics?
  • What types of evidence sources are important in cloud forensics?
  • Which devices have been replaced by mobile technology such as iPods and iPads for personal use?
  • Which activity involves determining how much risk is acceptable for any process or operation?
  • What is the main information being sought when examining e-mail headers?
  • In Linux forensics, what does the /proc filesystem provide access to?
  • Which statement describes static malware analysis?
  • Which registry key is commonly used to configure startup programs for all users in Windows?
  • Name typical Android artifacts collected during investigations.
  • What is a bit-for-bit forensic image and why is it essential?
  • Which type of format acquisition leaves the investigator unable to share an image between different vendors' forensic tools?
  • To verify a new forensic tool by viewing a disk's data in its unprocessed form, which type of tool is appropriate?
  • Which type of disk space often contains recoverable remnants of deleted files, making data carving possible?
  • How does data carving differ from traditional file recovery?
  • Which term describes a question that contains multiple questions within a single prompt?
  • In memory forensics, which sensitive data may be recovered because it is often stored in RAM during operation?
  • As an expert witness, you can't testify if you weren't present when the event occurred.
  • The police blotter documents clues to crimes that have been committed previously.
  • In live memory forensics, hashing the memory image primarily serves to verify what?
  • Is the following statement true: macOS volume fragmentation is kept to a minimum by removing clumps from larger files?
  • What is the purpose of timeline analysis in digital forensics?
  • Besides presenting facts, reports can communicate expert opinion.
  • A good practice is to use less powerful workstations for mundane tasks and reserve multipurpose workstations for resource-heavy analysis.
  • Which statement best describes volatile data in memory forensics?
  • Why is including slack space in a disk image sometimes important for investigations?
  • What is FileVault and its forensic implications?
  • Which term refers to a person using a computer to perform routine tasks other than systems administration?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy