Forensics and Evidence Collection Quiz

5 questions Pass: 70% +25 pts

Quiz covering Incident Response Planning

Forensics and Evidence Collection Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    In the context of digital forensics, what is the primary purpose of maintaining a 'Chain of Custody'?

  2. 2

    When collecting digital evidence from a live system, which of the following should be collected FIRST according to the Order of Volatility?

  3. 3

    Why is it standard practice to create a cryptographic hash (e.g., SHA-256) of a disk image immediately after acquisition?

  4. 4

    You are performing a forensic investigation and need to analyze a hard drive. What is the most important tool to use when connecting the suspect drive to your forensic workstation?

  5. 5

    During a memory dump analysis, you discover a suspicious process residing in a memory address space that is not associated with any loaded executable file on the disk. This is a primary indicator of what type of malicious activity?