Forensics and Evidence Collection Quiz
Quiz covering Incident Response Planning
Forensics and Evidence Collection Quiz
5 questions | Pass: 70% | Earn 25 points
Questions in this quiz
A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.
- 1
Which of the following is the primary goal of the 'Order of Volatility' when collecting digital evidence?
- 2
When performing a forensic image of a hard drive, why is it critical to calculate a cryptographic hash (e.g., SHA-256) of the original drive and the resulting image?
- 3
You are documenting the chain of custody for a seized laptop. What information is LEAST important to include in the log?
- 4
In a live memory acquisition scenario, why is it generally preferred to use a tool that runs from an external, trusted drive rather than installing software on the target system?
- 5
A forensic analyst is examining a server and discovers that the system time is offset by 15 minutes compared to the actual time. What is the most critical step the analyst must take during documentation?
- Amazon GuardDuty Configuration
- Amazon GuardDuty Configuration Quiz5q
- GuardDuty Runtime Monitoring
- GuardDuty Runtime Monitoring Quiz5q
- Security Hub Aggregation
- Security Hub Aggregation Quiz5q
- AWS Security Finding Format (ASFF)
- AWS Security Finding Format (ASFF) Quiz5q
- Amazon Inspector Scanning
- Amazon Inspector Scanning Quiz5q
Enjoying the courses?
Everything stays free. Pro shows fewer ads, doubles the points you earn on every lesson and quiz so you progress twice as fast, unlocks half of every practice exam — plus full case studies — with the Learn & Exam study modes, and lets you read each lesson on one page.
- ✓ Fewer advertisements
- ✓ 2× points per lesson & quiz
- ✓ 50% of every exam unlocked
- ✓ Learn & Exam modes
- ✓ Distraction-free lessons