CB3601 Cyber Forensic
UNIT III – ANALYSIS AND VALIDATION (MCQs)
Validating Forensics Data
1. The PRIMARY purpose of validating forensic data is to ensure:
A. Faster analysis
B. Legal compliance
C. Accuracy and integrity of evidence
D. Data compression
Answer: C
2. Hash values are mainly used to:
A. Encrypt evidence
B. Authenticate investigators
C. Verify evidence integrity
D. Compress data
Answer: C
3. Which situation indicates evidence tampering?
A. Matching hash values
B. Duplicate copies
C. Hash mismatch
D. Read-only access
Answer: C
4. Validation must be performed:
A. Only before court presentation
B. Only after analysis
C. Before and after acquisition
D. Only during seizure
Answer: C
5. Which principle ensures forensic soundness?
A. Confidentiality
B. Repeatability
C. Encryption
D. Compression
Answer: B
Data Hiding Techniques
6. Steganography is BEST defined as:
A. Encrypting data
B. Compressing files
C. Hiding data within another file
D. Deleting evidence
Answer: C
7. Which medium is MOST commonly used for steganography?
A. Text files
B. Image files
C. Executable files
D. Log files
Answer: B
8. Difference between encryption and steganography is that steganography:
A. Makes data unreadable
B. Removes metadata
C. Hides the existence of data
D. Uses public keys
Answer: C
9. Which technique hides data in unused disk areas?
A. File compression
B. Slack space hiding
C. Encryption
D. Hashing
Answer: B
10. Detecting hidden data generally requires:
A. Antivirus tools
B. Steganalysis
C. Firewalls
D. Proxy servers
Answer: B
Performing Remote Acquisition
11. Remote acquisition is performed when:
A. Devices are powered off
B. Physical access is impossible
C. Data is encrypted
D. Evidence is deleted
Answer: B
12. A major challenge of remote acquisition is:
A. File system incompatibility
B. Network latency and data alteration
C. Device power failure
D. Excess storage
Answer: B
13. Remote acquisition must ensure:
A. Faster download
B. Minimal bandwidth usage
C. Secure transmission and integrity
D. Data compression
Answer: C
14. Which protocol is preferred for secure remote acquisition?
A. FTP
B. Telnet
C. SSH
D. HTTP
Answer: C
15. Remote acquisition is MOST suitable for:
A. RAM analysis
B. Cloud-hosted evidence
C. Optical disks
D. Offline systems
Answer: B
Network Forensics
16. Network forensics focuses on:
A. File recovery
B. Monitoring and analyzing network traffic
C. Password cracking
D. Disk imaging
Answer: B
17. Packet capture is essential for:
A. Disk forensics
B. Memory forensics
C. Network forensics
D. Mobile forensics
Answer: C
18. Which tool is commonly used for packet analysis?
A. Autopsy
B. EnCase
C. Wireshark
D. FTK
Answer: C
19. Logs from firewalls and IDS are examples of:
A. Volatile data
B. Network evidence
C. Hidden artifacts
D. Metadata
Answer: B
20. Network forensics is MOST useful in investigating:
A. Insider threats
B. DDoS attacks
C. File corruption
D. Hardware failures
Answer: B
Email Investigations
21. Email headers are useful to identify:
A. Email content
B. Sender routing path
C. Attachment size
D. Passwords
Answer: B
22. Which field helps trace the origin of an email?
A. To
B. Subject
C. Received
D. CC
Answer: C
23. Spoofed emails primarily manipulate:
A. Message body
B. Header information
C. Attachments
D. Encryption keys
Answer: B
24. Email investigations often involve examining:
A. Registry keys only
B. Mail servers and logs
C. BIOS settings
D. Disk partitions
Answer: B
25. Which protocol is MOST associated with email transmission?
A. FTP
B. SMTP
C. SNMP
D. POP
Answer: B
Cell Phone and Mobile Devices Forensics
26. Mobile forensics deals with:
A. Network traffic only
B. Disk imaging only
C. Data extraction from mobile devices
D. Cloud security
Answer: C
27. SIM card forensics can reveal:
A. Browser cache
B. Subscriber identity and contacts
C. Application logs
D. System files
Answer: B
28. Which acquisition method extracts limited user data?
A. Physical acquisition
B. Logical acquisition
C. Chip-off
D. JTAG
Answer: B
29. Airplane mode is enabled during seizure to:
A. Save battery
B. Prevent remote wiping
C. Improve performance
D. Enable encryption
Answer: B
30. Deleted SMS messages may still exist in:
A. RAM only
B. Unallocated space
C. Cloud backups only
D. BIOS
Answer: B
Analysis of Digital Evidence
31. Evidence analysis involves:
A. Data deletion
B. Data interpretation and correlation
C. Evidence seizure
D. Data encryption
Answer: B
32. Timeline analysis helps in:
A. Hash generation
B. Establishing event sequences
C. Password recovery
D. Malware creation
Answer: B
33. Correlating multiple artifacts helps to:
A. Reduce storage
B. Increase admissibility
C. Strengthen conclusions
D. Encrypt data
Answer: C
34. Which factor is CRITICAL during evidence analysis?
A. Speed
B. Tool popularity
C. Objectivity
D. Cost
Answer: C
35. Analysis should always be:
A. Hypothesis-driven
B. Investigator-biased
C. Random
D. Automated only
Answer: A
Admissibility of Evidence
36. Digital evidence is admissible if it is:
A. Large in size
B. Properly documented and reliable
C. Encrypted
D. Open-source
Answer: B
37. Failure in chain of custody affects:
A. Data compression
B. Evidence admissibility
C. File size
D. Encryption
Answer: B
38. Courts require digital evidence to be:
A. Easy to understand
B. Scientifically obtained
C. Cheap to collect
D. Visually appealing
Answer: B
Cyber Laws in India
39. The primary cyber law governing digital evidence in India is the:
A. IPC
B. CrPC
C. Information Technology Act
D. Companies Act
Answer: C
40. Section 65B of Indian law relates to:
A. Cyber terrorism
B. Electronic evidence admissibility
C. Privacy protection
D. Data encryption
Answer: B
41. Digital signatures are legally recognized under:
A. IPC
B. IT Act
C. Evidence Act only
D. Copyright Act
Answer: B
42. Which authority handles cybercrime investigation in India?
A. RBI
B. CERT-In
C. CBI / State Cyber Cells
D. TRAI
Answer: C
Case Studies
43. Case studies in cyber forensics mainly help to:
A. Learn programming
B. Understand real-world application
C. Reduce crime
D. Encrypt evidence
Answer: B
44. A phishing case study would MOST involve:
A. Disk formatting
B. Email analysis
C. BIOS inspection
D. Hardware repair
Answer: B
45. Ransomware case analysis focuses on:
A. Image steganography
B. Encryption behavior and logs
C. Hardware faults
D. File compression
Answer: B
46. Case studies enhance investigator skills by improving:
A. Tool dependency
B. Critical thinking
C. Storage usage
D. Automation
Answer: B
47. Legal outcome analysis in case studies helps in understanding:
A. Programming errors
B. Judicial reasoning
C. Network protocols
D. Hardware design
Answer: B
Integrated Concepts
48. Combining network and email forensics is MOST useful in:
A. Hardware theft
B. Phishing attacks
C. Disk corruption
D. Power failure
Answer: B
49. Mobile forensics combined with network logs helps trace:
A. Device model
B. User behavior and location
C. Screen resolution
D. Battery health
Answer: B
50. The FINAL objective of analysis and validation is to:
A. Speed up investigations
B. Present reliable and admissible evidence
C. Recover all files
D. Prevent cybercrime
Answer: B