

![]()


Digital Forensics is an interdisciplinary course that introduces students to the principles and practices of investigating and analyzing digital evidence from computers, mobile devices, networks, and other electronic media. The course covers methodologies for data acquisition, preservation, examination, and documentation to support legal proceedings and internal investigations. Topics include digital crime scene procedures, file system analysis, recovering deleted or hidden data, network forensics, and the ethical and legal considerations involved in handling digital evidence. Hands-on labs and case studies provide practical experience with leading forensic tools and techniques used by cybersecurity professionals and law enforcement agencies.
Recommended Textbook
Computer Forensics Principles and Practices 1st Edition by Linda Volonino
Available Study Resources on Quizplus
13 Chapters
600 Verified Questions
600 Flashcards
Source URL: https://quizplus.com/study-set/2159 Page 2

Available Study Resources on Quizplus for this Chatper
33 Verified Questions
33 Flashcards
Source URL: https://quizplus.com/quiz/43035
Sample Questions
Q1) A(n)________ is a lesser crime such as careless driving. Answer: misdemeanor
Q2) What piece of legislation makes it a crime to send e-mail using false headers?
A)CAN-SPAM Act
B)CFAA
C)FERPA
D)USA PATRIOT Act
Answer: A
Q3) In the case of missing Washington,D.C. ,resident ________,e-mail and visited Web sites on a personal laptop were all the police had to go by.
Answer: Chandra Levy
Q4) Only ________ evidence supports or helps confirm a given theory. Answer: inculpatory
Q5) Who was arrested as the author of the Lovebug virus?
A)Francisco Antonelli
B)Onel de Guzman
C)Gunter Hanz
D)Ray Chi Chen
Answer: B
To view all questions and flashcards with answers, click on the resource link above. Page 3

Available Study Resources on Quizplus for this Chatper
28 Verified Questions
28 Flashcards
Source URL: https://quizplus.com/quiz/43036
Sample Questions
Q1) One of the more popular theories is that a person could actually commit ________ by changing a patient's medication data.
Answer: murder
Q2) In what manner were e-commerce employees caught making online purchases using clients' credit card numbers?
A)Copies of credit card numbers were found in their desks.
B)Copies of transactions were found at their homes.
C)Saved files were stored in a hidden directory.
D)Credit card numbers,along with the name and address of person who placed order,were found in a hidden HTML coded file.
Answer: D
Q3) Which of the following is NOT considered one of the items e-evidence is currently being used for?
A)To prove intent
B)To imply motive
C)To provide alibis
D)All listed are currently being used
Answer: C
To view all questions and flashcards with answers, click on the resource link above.
4

Available Study Resources on Quizplus for this Chatper
48 Verified Questions
48 Flashcards
Source URL: https://quizplus.com/quiz/43037
Sample Questions
Q1) You may need to do a(n)________ analysis during a hacker attack or other intrusion.
Answer: live
Q2) FTK
A) The universal hexadecimal editor
B) Invaluable for combing through large amounts of data
C) Exclusively for Macs
D) AccessData tool designed for finding and examining evidence
E) Primarily for computer crime investigators
Answer: D
Q3) ________ data can include spreadsheets,databases,and word processing files.
Answer: Active
Q4) If you need to remove a password from files,you could use a program such as
A)Jack the Cracker
B)WinHex
C)MacQuisition
D)John the Ripper
Answer: D
To view all questions and flashcards with answers, click on the resource link above. Page 5

Available Study Resources on Quizplus for this Chatper
63 Verified Questions
63 Flashcards
Source URL: https://quizplus.com/quiz/43038
Sample Questions
Q1) A(n)________ needs to be completed when reviewing a potential case and determining whether to accept it.
Q2) What is the computer environment?
A)Identify the operating system or network topology
B)There may be fingerprints or other trace evidence
C)You would use different tools to locate different items such as photographs or spreadsheets
D)This determines how you will extract the data
E)The more skilled the user, the more likely it is that he can alter or destroy evidence
Q3) Looking for protected files
A)Bottom logical examination layer
B)Second logical examination layer
C)Third logical examination layer
D)Fourth logical examination layer
Q4) With the original evidence safely stored,you should make a(n)________ of the forensic image.
Q5) Your best bet for decrypting a file is to find out what program was used to encrypt it and obtain the ________ for that software.
To view all questions and flashcards with answers, click on the resource link above. Page 6

Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/43039
Sample Questions
Q1) If a PDA has only a single rechargeable battery,the appropriate ________ should be connected to the device if possible.
Q2) To gain access to a protected SIM,you may need to ask the service provider for a(n)________.
Q3) To understand how hardware works,you must understand the ________ of how drives store 0s and 1s.
Q4) ________ media use light from laser or LED sources to determine 0s and 1s.
Q5) Cell Seizure
A)CDMA phones
B)GSM phones
C)Supports GSM and TDMA
D)Palm OS
Q6) One excellent feature of ________ is that this software can crack Palm passwords.
Q7) As further insurance against writing to a hard drive under investigation,an examiner should use a(n)________.
Q8) New cellular phones are basically low-end _______.
Q9) A(n)________ groups the same tracks vertically through a stack of platters.
Q10) ________ is the most widely used hard drive technology.
To view all questions and flashcards with answers, click on the resource link above. Page 7
Available Study Resources on Quizplus for this Chatper
52 Verified Questions
52 Flashcards
Source URL: https://quizplus.com/quiz/43040
Sample Questions
Q1) Network
A)Translates logical to physical addresses
B)Creates and maintains the communications link
C)Performs protocol conversion
D)Transmits raw data
Q2) In data transfer,only the ________ changes from router or switch to the next one in line.
Q3) To interface properly between applications and hardware,operating systems use
Q4) The two main camps in the UNIX world are the ________ and the ________.
Q5) The newest Macintosh systems are based on the
A)UNIX operating system
B)Windows operating system
C)Linux operating system
D)DOS operating system
Q6) Transport
A)Uses IP as its transmission protocol
B)The reliability layer
C)Handles physical aspects of a network
D)Routes packets over a network

8
To view all questions and flashcards with answers, click on the resource link above.
Page 9

Available Study Resources on Quizplus for this Chatper
57 Verified Questions
57 Flashcards
Source URL: https://quizplus.com/quiz/43041
Sample Questions
Q1) In a forensics context,hidden information about files and folders is called
A)Artifact data
B)Metadata
C)Archive data
D)Read-only data
Q2) Dentry object
A)Contain metadata for each file
B)Unit of allocation for storage
C)Created for every file system mounted
D)Contains information about the directory structure
Q3) HKEY_USERS Default
A)Default
B)System
C)SAM
D)Software
Q4) The ________ tracks those actions deemed as events by the software application.
Q5) The process of retrieving image data from unallocated or slack space is called
Q6) A(n)________ is designed as a hierarchical listing of folders and files.
Q7) System data and artifacts are files generated by the ________.
To view all questions and flashcards with answers, click on the resource link above. Page 10

Available Study Resources on Quizplus for this Chatper
47 Verified Questions
47 Flashcards
Source URL: https://quizplus.com/quiz/43042
Sample Questions
Q1) IMAP
A)Dependant upon Internet
B)Accessible from anywhere
C)Special software required
Q2) The tool often used for quick communications without resorting to e-mail is________ .
Q3) Which of the following are NOT considered important when working with RAID systems?
A)Transmission speed
B)Type of controller
C)Size of array
D)Type of hard drive
Q4) Apparently-To
A)Used if sender requests an automated confirmation of the recipient having read the e-mail
B)Easily spoofed by hackers
C)Nonstandard heading sometimes used when encountering a mailing list
D)Deals with non-text items such as photos
Q5) According to many Americans,________ violate their privacy and their First Amendment rights.
11
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
39 Verified Questions
39 Flashcards
Source URL: https://quizplus.com/quiz/43043
Sample Questions
Q1) A(n)________ is the standard operation procedures of the network when it is running normally.
Q2) ________ Software allows you to forensically search for data on your entire network using nothing more than keywords or phrases.
Q3) ________ transmit and receive data via radio frequency in the open.
Q4) Server
A)Where the analysis is performed
B)Contains a large database
C)Modules installed on hosts
Q5) Which type of firewall acts as a mediator between internal hosts and external connections such as the Internet?
A)Network layer firewall
B)Application layer firewall
C)Proxy firewall
D)Internet firewall
Q6) Application layer
A)Permits FTP or HTTP protocols
B)Acts like an IP filter
C)Acts as a mediator
To view all questions and flashcards with answers, click on the resource link above. Page 12

Available Study Resources on Quizplus for this Chatper
39 Verified Questions
39 Flashcards
Source URL: https://quizplus.com/quiz/43044
Sample Questions
Q1) Which of the following was NOT e-evidence used to track the creator of the Melissa virus?
A)Hardware ID
B)Operating system event log
C)AOL return address
D)Key signature in e-mails from the perpetrator
Q2) Investigations into hackers can be difficult because even with a full audit trail showing that a user came from a particular account on a particular ISP,
A)ISPs almost never release the necessary information
B)The hacker may use more than one ISP
C)Often only billing information is available,which does not prove identity
D)All of the above
Q3) Anonymity,control resources,and many other features make the ________ the criminals' conduit for coordinating and carrying out an agenda.
Q4) alneda.com
A)Alleged to have flashed pictures of persecuted Muslims
B)Designed to teach users to conduct attacks
C)Used by jihad in Afghanistan
D)Featured international news on al Qaeda
To view all questions and flashcards with answers, click on the resource link above. Page 13

Available Study Resources on Quizplus for this Chatper
40 Verified Questions
40 Flashcards
Source URL: https://quizplus.com/quiz/43045
Sample Questions
Q1) Motive
A)Destroying documents prior to an investigation
B)Showing perp had a chance to commit crime
C)Is a strong circumstantial element
D)Finding multiple events of the same error
Q2) Which of the following is NOT one of the ways that fraud investigations originate?
A)From internal audits
B)From anonymous tips
C)From the FBI
D)From complaints by customers or vendors
Q3) The term ________ means mental state or "guilty mind."
Q4) Adelphia
A)Admitted to "loaning" $ 2.3 billion to the Rigas family
B)Insiders sell over $ 1.5 billion of inflated stock
C)CEO and CFO charged with multiple counts of fraud
Q5) Fraud is more likely to occur when someone feels ________ to commit fraud.
Q6) ________ is also referred to as forensic financial investigation.
Q7) Refusing to testify in court on the basis that the testimony may be self-incriminating is called ________.
Page 14
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/43046
Sample Questions
Q1) Under the Federal Rules of Civil Procedure,which two rules regulate the production of evidence?
A)Rules 26 and 35
B)Rules 34 and 23
C)Rules 26 and 34
D)Rules 25 and 33
Q2) Digital Millennium Copyright Act
A)Requires that recordings be handed over to a judge
B)Forces ISPs to turn over names of suspected music pirates upon subpoena
C)Includes new guidance relating to computer crime and eevidence
D)Permits an ISP to look through stored e-mail messages
Q3) What amendment must a law enforcement office check before seizing hardware or computers?
A)The Fourth Amendment
B)The Sixth Amendment
C)The Eighth Amendment
D)The Tenth Amendment
Q4) The Frye test that Rule 702 relied upon was replaced with the ________ test.
Q5) The same circumstantial evidence the courts use to authenticate physical documents applies to ________ as well.
15
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
30 Verified Questions
30 Flashcards
Source URL: https://quizplus.com/quiz/43047
Sample Questions
Q1) Which of the following is NOT considered a part of the work product?
A)Your conclusions
B)Your notes
C)Your opinions
D)Your colleague's opinion
Q2) Who may write the expert report?
A)The lawyer handling the case
B)The lawyer's secretary
C)The expert's secretary
D)Only the expert investigating the case
Q3) Everyone involved in the courts has a(n)________ to protect the legal system and the Constitution.
Q4) Before accepting a case,a good investigator will check
A)That there is enough money to make it worthwhile
B)That there are enough witnesses
C)That there are no physical dangers involved
D)That there is no conflict of interest
Q5) ________ is also used to examine jurors to make sure they are fair and impartial.
Q6) ________ are done out of court but under the same oath as in court.
To view all questions and flashcards with answers, click on the resource link above. Page 16