Exam Questions with Correct
Answers (VERIFIED)
The most common computer hard drives today are __________.—ANSWER--SATA
A __________ is used to send a test packet, or echo packet, to a machine to determine if the
machine is reachable and how long the packet takes to reach the machine.—ANSWER--ping
Suspects often overwhelm forensic analysts with false positives and false leads. This is
referred to as__________.—ANSWER--data fabrication
Which of the following is the definition of the Daubert Standard?—ANSWER--The Daubert
Standard dictates that only methods and tools widely accepted in the scientific community
can be used in court.
The __________ protects journalists from being required to turn over to law enforcement
any work product and documentary material, including sources, before it is disseminated to
the public.—ANSWER--Privacy Protection Act of 1980
It has been claimed that __________ of all computers connected to the Internet have
spyware.—ANSWER--80%
__________ is/are the cyber-equivalent of vandalism.—ANSWER--DoS attacks
, Which of the following is the definition of logic bomb?—ANSWER--malware that executes
damage when a specific condition is met
Rules of evidence can be defined as __________.—ANSWER--rules that govern whether,
when, how, and why proof of a legal case can be placed before a judge or jury
Use of __________ tools enables an investigator to reconstruct file fragments if files have
been deleted or overwritten.—ANSWER--bit-level
Identification, preservation, collection, examination, analysis, and presentation are six
classes in the matrix of __________.—ANSWER--the DFRWS framework
What is meant by file slack?—ANSWER--the unused space between the logical end of file
and the physical end of file
Information that has been processed and assembled so that it is relevant to an investigation
and supports a specific finding or determination is the definition of __________.—ANSWER-
-digital evidence
__________ is a Linux Live CD that you use to boot a system and then use the tools. It is a
free Linux distribution, making it extremely attractive to schools teaching forensics or
laboratories on a strict budget.—ANSWER--BackTrack
What name is given to data that an operating system creates and overwrites without the
computer user taking a direct action to save this data?—ANSWER--temporary data
__________ is offline analysis conducted on an evidence disk or forensic duplicate after
booting from a CD or another system.—ANSWER--Physical analysis
© 2026 Copyright. All Rights Reserved. This document is
protected by copyright law, Copyrighted By Brittie Donald