Forensics and Evidence Collection Quiz

5 questions Pass: 70% +25 pts

Quiz covering Incident Response Planning

Forensics and Evidence Collection Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which of the following is the primary goal of the 'Order of Volatility' when collecting digital evidence?

  2. 2

    When performing a forensic image of a hard drive, why is it critical to calculate a cryptographic hash (e.g., SHA-256) of the original drive and the resulting image?

  3. 3

    You are documenting the chain of custody for a seized laptop. What information is LEAST important to include in the log?

  4. 4

    In a live memory acquisition scenario, why is it generally preferred to use a tool that runs from an external, trusted drive rather than installing software on the target system?

  5. 5

    A forensic analyst is examining a server and discovers that the system time is offset by 15 minutes compared to the actual time. What is the most critical step the analyst must take during documentation?