Digital Forensics in
Cybersecurity
LATEST FA REVIEW
Q&S
©2024/2025
,1. Which of the following digital forensic tools is primarily used
for network forensics?
- A) EnCase
- B) FTK (Forensic Toolkit)
- C) Wireshark
- D) Cellebrite
- Correct ANS: C) Wireshark
2. In digital forensics, the primary function of a hash algorithm
is to:
- A) Compress file sizes
- B) Encrypt data
- C) Ensure data integrity
- D) Decode binary data
- Correct ANS: C) Ensure data integrity
3. Which file system is known for supporting large files and is
often a consideration in digital forensic examinations on Windows
systems?
©2024/2025
, - A) FAT32
- B) NTFS
- C) ext4
- D) HFS+
- Correct ANS: B) NTFS
4. Which of the following best describes the purpose of a write
blocker in digital forensics?
- A) To decode encrypted files
- B) To prevent unauthorized access
- C) To prevent any writing to the original storage media during
analysis
- D) To accelerate data recovery process
- Correct ANS: C) To prevent any writing to the original
storage media during analysis
### Fill-in-the-Blank Questions
5. The principle of maintaining the integrity of digital evidence
from collection through analysis to presentation in court is known
as the __________.
- Correct ANS: Chain of custody
©2024/2025