Exam (Latest Update 2026/2027)
Questions and Verified Answers | 100%
Correct | Grade A.
1. Which of the following best describes the primary objective of
digital forensics?
A. Prevent malware infections
B. Develop secure software
C. Identify, preserve, analyze, and present digital evidence
D. Configure firewalls
Rationale: Digital forensics focuses on identifying, preserving, collecting,
analyzing, and presenting digital evidence in a manner that maintains
its integrity and allows it to be admissible in legal or organizational
proceedings. Unlike cybersecurity operations, which emphasize
prevention and defense, digital forensics is concerned with investigating
events after they occur while maintaining a documented chain of
custody.
2. What is the first priority when arriving at a digital crime scene?
A. Turn off all systems
,B. Secure the scene and preserve evidence
C. Install forensic software
D. Interview all witnesses
Rationale: The first priority is securing the scene to prevent evidence
tampering, contamination, or loss. Investigators should document the
environment before interacting with devices and follow established
forensic procedures to ensure evidence remains reliable and admissible.
3. Which forensic principle ensures that digital evidence has not
been altered?
A. Redundancy
B. Encryption
C. Integrity
D. Availability
Rationale: Integrity ensures that digital evidence remains unchanged
throughout collection, preservation, examination, and presentation.
Hash values are commonly used to verify integrity by confirming that
evidence remains identical to the original acquisition.
4. Which cryptographic algorithm is commonly used to verify
forensic image integrity?
A. DES
B. AES
,C. SHA-256
D. RC4
Rationale: SHA-256 is a modern cryptographic hash function widely
used to verify evidence integrity. Matching hash values before and after
examination demonstrate that the forensic image has not been
modified during analysis.
5. What is the purpose of maintaining a chain of custody?
A. Increase storage capacity
B. Encrypt evidence
C. Document who handled evidence and when
D. Compress forensic images
Rationale: Chain of custody provides a chronological record
documenting every individual who handled evidence, when it was
transferred, and the reason for each transfer. This documentation helps
establish credibility and admissibility during legal proceedings.
6. Which device prevents accidental modification of storage media
during acquisition?
A. Hub
B. Switch
C. Write blocker
D. Router
, Rationale: A write blocker prevents any write commands from reaching
the evidence drive while allowing read operations. This ensures the
original evidence remains unchanged during forensic acquisition.
7. Which type of data exists only while a system remains powered
on?
A. Archived data
B. Deleted files
C. Volatile data
D. Compressed files
Rationale: Volatile data resides primarily in RAM and disappears when
power is removed. It may contain running processes, encryption keys,
network connections, and other valuable investigative information
requiring immediate collection.
8. Which order of volatility should investigators generally follow?
A. Hard drive before RAM
B. RAM before hard drives
C. Optical media before RAM
D. USB drives before RAM
Rationale: RAM contains the most volatile evidence and should
generally be collected before shutting down a system. Once power is