Exam Containing 214 Questions with
Definitive Solutions 2024-2025.
Which of the following is true regarding computer forensics? - ANS: Computer forensics deals with the process of finding evidence related to a digital crime to find the culprits and initiate legal action against them
Which of the following is NOT a objective of computer forensics? - ANS: Document vulnerabilities allowing further loss of intellectual property, finances, and reputation during an attack.
1 | P a g e Which of the following is true regarding Enterprise Theory of Investigation (ETI)? - ANS: It adopts a holistic approach toward any criminal activity as a criminal operation rather as a single criminal act.
Forensic readiness refers to: - ANS: An organization's ability to make optimal use of digital evidence in a limited time period and with minimal investigation costs.
Which of the following is NOT a element of cybercrime? - ANS: Evidence smaller in
size.
Which of the following is true of cybercrimes? - ANS: Investigators, with a warrant, have the authority to forcibly seize the computing devices.
Which of the following is true of cybercrimes? - ANS: The initial reporting of the evidence is usually informal.
Which of the following is NOT a consideration during a cybercrime investigation? - ANS: Value or cost to the victim.
Which of the following is a user-created source of potential evidence? - ANS: Address book.
Which of the following is a computer-created source of potential evidence? - ANS:
Swap file.
2 | P a g e Which of the following is NOT where potential evidence may be located? - ANS: Processor.
Under which of the following conditions will duplicate evidence NOT suffice? - ANS: When original evidence is in possession of the originator.
Which of the following Federal Rules of Evidence governs proceedings in the courts of the United States? - ANS: Rule 101.
Which of the following Federal Rules of Evidence ensures that the truth may be ascertained and the proceedings justly determined? - ANS: Rule 102.
Which of the following Federal Rules of Evidence contains rulings on evidence? - ANS: Rule 103
Which of the following Federal Rules of Evidence states that the court shall restrict
the evidence to its proper scope and instruct the jury accordingly? - ANS: Rule 105
Which of the following refers to a set of methodological procedures and techniques to identify, gather, preserve, extract, interpret, document, and present evidence from computing equipment in such a manner that the discovered evidence is acceptable during a legal and/or administrative proceeding in a court of law? - ANS: Computer Forensics.
3 | P a g e