AND NETWORK INTRUSION 350 UNIQUE
MULTIPLE‑CHOICE QUESTIONS WITH
CORRECT ANSWERS & DETAILED
RATIONALES
DOMAIN 1: DIGITAL FORENSICS FUNDAMENTALS (Qs 1–75)
Question 1
What is the primary goal of computer forensics?
A) To recover deleted files for personal data recovery
B) To identify, preserve, analyze, and present digital evidence in a legally
admissible manner
C) To monitor network traffic for active intrusions
D) To install security software on compromised systems
Correct Answer: B – To identify, preserve, analyze, and present digital evidence in
a legally admissible manner.
Rationale: Computer forensics is a structured investigation process with the
ultimate goal of ensuring findings are acceptable in a court of law. This involves a
methodological approach to handling evidence, distinguishing it from general data
recovery or network monitoring.
1
,---
Question 2
According to Locard's Exchange Principle, what occurs when someone enters a
crime scene?
A) The scene remains completely unchanged by the person's presence
B) Only physical trace evidence is transferred, never digital evidence
C) The person takes something from the scene and leaves something of themselves
behind
D) Nothing is transferred if the person is wearing protective gear
Correct Answer: C – The person takes something from the scene and leaves
something of themselves behind.
Rationale: Locard's principle is fundamental to forensics, stating that every contact
leaves a trace. In digital forensics, this translates to artifacts like log entries, file
modifications, and network connections left by an intruder.
---
Question 3
Which type of investigation involves a dispute between two parties, typically
resulting in monetary damages?
A) Criminal investigation
B) Civil investigation
C) Administrative investigation
D) Regulatory investigation
2
,Correct Answer: B – Civil investigation.
Rationale: Civil cases are non‑criminal disputes, such as contract violations or
lawsuits, where the outcome usually involves financial penalties for the liable
party, not imprisonment. Criminal cases involve government prosecution for
violations of law.
---
Question 4
An organization is investigating an employee for violating the company's
acceptable use policy. What type of investigation is this?
A) Criminal case
B) Civil case
C) Administrative case
D) Class‑action lawsuit
Correct Answer: C – Administrative case.
Rationale: Administrative cases are internal investigations focused on whether
employees are following organizational rules and policies. They are non‑criminal
in nature and do not involve law enforcement.
---
Question 5
What is the very first step a first responder must take upon arriving at a digital
crime scene?
A) Begin imaging the hard drives immediately
B) Interview all potential witnesses
3
, C) Secure and isolate the scene to prevent contamination of evidence
D) Power on all computers to check their status
Correct Answer: C – Secure and isolate the scene to prevent contamination of
evidence.
Rationale: The priority for a first responder is to secure the scene and preserve
evidence integrity. This prevents unauthorized access, alteration, or destruction of
volatile digital evidence.
---
Question 6
What is the main purpose of a hardware write blocker?
A) To prevent any data writes to the original evidence, preserving its integrity
B) To accelerate the data acquisition process
C) To decrypt encrypted files on the suspect drive
D) To create a backup of the operating system
Correct Answer: A – To prevent any data writes to the original evidence,
preserving its integrity.
Rationale: A hardware write blocker sits between the source drive and the forensic
workstation, intercepting and blocking any write commands. This ensures the
original evidence remains unaltered and forensically sound.
---
Question 7
4