Section A (Multiple Choice)
[30 marks]
1. Graphics files stored on a computer can't be recovered after they are delete
A. True
B. False
2. Areal density refers to which of the following?
A. Number of bits per disk
B. Number of bits per partition
C. Number of bits per square inch of a disk platter
D. Number of bits per platter
3. Hashing, filtering, and file header analysis make up which function of digital forensics tools?
A. Validation and verification
B. Acquisition
C. Extraction
D. Reconstruction
4. The reconstruction function is needed for which of the following purposes? (Choose three.)
A. Re-create a suspect drive to show what happened
B. Create a copy of a drive for other investigators.
C. Recover file headers.
D. Re-create a drive compromised by malware.
5. Hash values are used for which of the following purposes? (Choose two)
A. Determining file size
B. Filtering known good files from potentially suspicious data
C. Reconstructing file fragments
D. Validating that the original data hasn't changed
6. The verification function does which of the following?
A. Proves that a tool performs as intended
B. Creates segmented files
C. Proves that two sets of data are identical via hash values
D. Verifies hex editors
7. Which of the following is true of most drive-imaging tools? (Choose two.)
A. They perform the same function as a backup.
B. They ensure that the original drive doesn't become corrupt and damage the digital
evidence.
C. They create a copy of the original drive.
D. They must be run from the command line.
8. A log report in forensics tools does which of the following?
A. Tracks file types
B. Monitors network intrusion attempts
C. Records an investigator's actions in examining a case
D. Lists known good files
Page 11