MARYLAND CYBERCRIME INVESTIGATOR CERTIFICATION
EXAM PRACTICE – 2026/2027 COMPLETE (150) CURRENT
TESTING QUESTIONS AND CORRECT ANSWERS WITH
DETAILED RATIONALES.
CYBERCRIME
Prepare effectively for the Maryland Cybercrime Investigator Certification Exam with
this focused practice resource. It supports review of cybercrime investigation
principles, digital evidence, investigative procedures, legal considerations,
documentation, and professional responsibilities. Use the material to reinforce your
knowledge, review key topics, and identify areas that may require additional study.
This resource is suited for cybercrime investigators, law enforcement professionals,
digital forensics learners, and candidates preparing for Maryland certification
examinations.
MULTIPLE CHOICE.
SECTION 1: DIGITAL FORENSICS FUNDAMENTALS (Questions 1–25)
1. What is the primary goal of a cybercrime investigator?
• A. Repair damaged computers
• B. Identify, preserve, and analyze digital evidence
• C. Develop antivirus software
• D. Monitor internet usage for entertainment
Correct Answer: B
Rationale: Cybercrime investigators focus on evidence handling and
analysis, not system repair or software development. Their primary role is
to identify, preserve, and analyze digital evidence for legal proceedings.
2. In the context of cybercrime investigations, which of the following best
describes the principle of "Locard's Exchange Principle" as applied to
digital evidence?
, Page 2 of 58
• A. Data cannot be duplicated without detection
• B. All cybercrimes involve physical evidence
• C. Every interaction with a digital system leaves a trace
• D. Encryption prevents evidence collection
Correct Answer: C
Rationale: Locard's Exchange Principle states that every contact leaves a
trace. In digital forensics, this translates to the idea that interactions with
systems produce artifacts such as logs, metadata, and residual data.
3. What is the first step when arriving at a cybercrime scene?
• A. Immediately power off all devices
• B. Begin data extraction
• C. Secure and preserve the scene
• D. Interview suspects
Correct Answer: C
Rationale: Securing the scene prevents evidence contamination. This is
the foundational step in any forensic investigation.
4. What does "chain of custody" ensure?
• A. Device performance optimization
• B. Legal ownership of hardware
• C. Integrity and documentation of evidence handling
• D. Faster forensic analysis
Correct Answer: C
Rationale: Chain of custody tracks evidence handling for court
admissibility. It documents every person who handled the evidence,
when, and for what purpose.
, Page 3 of 58
5. Which tool is commonly used for disk imaging?
• A. Wireshark
• B. FTK Imager
• C. Metasploit
• D. Notepad
Correct Answer: B
Rationale: FTK Imager creates forensic disk images. It is a widely used
tool for acquiring forensic copies of digital media.
6. What is digital evidence?
• A. Printed documents only
• B. Any data stored or transmitted digitally
• C. Physical fingerprints
• D. Oral testimony
Correct Answer: B
Rationale: Digital evidence includes emails, logs, files, metadata, and any
other data stored or transmitted in digital form.
7. During a forensic acquisition, what is the primary purpose of creating a
hash value of digital evidence?
• A. To compress data
• B. To encrypt evidence
• C. To verify data integrity
• D. To store evidence securely
, Page 4 of 58
Correct Answer: C
Rationale: Hash values serve as digital fingerprints, ensuring that
evidence has not been altered during acquisition or analysis.
8. Which of the following best describes "phishing"?
• A. Intercepting encrypted communications
• B. Sending fraudulent emails to obtain sensitive information
• C. Installing malware on a system
• D. Overwhelming a network with traffic
Correct Answer: B
Rationale: Phishing is a social engineering attack where attackers send
fraudulent communications (often emails) that appear to come from a
reputable source to trick victims into revealing sensitive information.
9. What type of malware disguises itself as legitimate software?
• A. Worm
• B. Trojan horse
• C. Ransomware
• D. Spyware
Correct Answer: B
Rationale: Trojan horses appear as legitimate programs but contain
hidden malicious functions.
10. Which of the following is a key characteristic of ransomware?
• A. Data theft without detection
• B. System monitoring