0% found this document useful (0 votes)
6 views96 pages

Overview of Cyber Crimes and Protections

The document outlines key concepts, classifications, and processes related to Cyber Crimes, Computer Insecurity, and Incident Management. It details the definitions and motivations behind cyber crimes, various attack methods, and the importance of information security controls. Additionally, it discusses the roles of hackers, incident management processes, and relevant Indian legislation pertaining to cyber crime and fraud management.

Uploaded by

sarathannameti1
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views96 pages

Overview of Cyber Crimes and Protections

The document outlines key concepts, classifications, and processes related to Cyber Crimes, Computer Insecurity, and Incident Management. It details the definitions and motivations behind cyber crimes, various attack methods, and the importance of information security controls. Additionally, it discusses the roles of hackers, incident management processes, and relevant Indian legislation pertaining to cyber crime and fraud management.

Uploaded by

sarathannameti1
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

This summary covers the essential concepts, classifications, and processes detailed

across the provided chapters on Cyber Crimes, Computer Insecurity, Computer


Fraud Protection, and Incident Management.

I. Fundamentals of Cyber Crime (CH 1)

Cyber crime is defined as any illegal activity or crime committed with the help of
a computer or an electronic gadget. The fundamental difference between a cyber
crime and a conventional crime is the use of an electronic device.

 Mens Rea and Fraud Triangle: The essence of fraud is the criminal intent
(mens rea), which drives activities done fraudulently with intent to deceive.
Crime, including cyber crime, is commonly associated with the Fraud
Triangle: Pressure/Need, Opportunity, and Rationalization.
 Classification and Motives: Cyber crimes can be classified based on
victims (targeting individuals, physical assets, or groups/nations, like cyber
terrorism). Motivations for cyber criminals often include demonstrating
technological supremacy or financial greed. Cyber criminals are classified
into categories like Script Kiddies (lacking thorough technical knowledge)
and APT Agents (highly skilled, often state-sponsored).

II. Channels and Methods of Cyber Crimes (CH 2 & CH 3)

The channels of cyber crime are the means through which an attack materializes,
and the investigation requires understanding the Threat Vector (path of attack)
and the Threat Landscape (overall overview).

Cyber Crime Methods (CH 3)

 Phishing and Vishing (3.11): Phishing is the technique of soliciting


information (like passwords) on a fake website. Vishing is phishing
combined with a voice call where the fraudster pretends to be a bank
employee to gain confidential data.
 Hacking, Extortion, and Cheating (3.7, 3.8): Cyber Extortion involves
obtaining something by threatening force in a digital world (punishable
under IPC Sections 383 to 389). Cyber Cheating involves deceit using a
computer resource (punishable under IT Act Section 66D).
 Domain Name Misuse (3.5, 3.6): Cyber Squatting is registering a domain
name with the illegal intention of using someone else’s trademark. Domain
name disputes are often handled internationally by ICANN or in India by
INDRP.
 Cyber Warfare and Terrorism (3.9, 3.10): Cyber Warfare attacks
nations or organizations and often targets critical SCADA (Supervisory
Control and Data Acquisition) systems. Cyber Terrorism is specifically
addressed in Section 66F of the IT Amendment Act 2008, punishable by life
imprisonment.
 Network Technologies: Criminals use IP Spoofing (changing the sending
system's IP address dynamically) and Fast Flux (rapidly changing IP
addresses to hide the sender's details) to conceal their location.

III. Computer Insecurity and Protection (CH 4 & CH 6)

Information Security and Controls (CH 4 & CH 6)

Information security relies on four main pillars, chiefly the CIA Triad:

1. Confidentiality: Keeping data secret and disclosing it only to authorized


persons.
2. Integrity: Data remaining in the same format without unauthorized
tampering.
3. Availability: Data being accessible at all times. Other attributes include
Non-Repudiation (preventing the sender from denying transmission),
Authentication (confirming identity, often via 2FA), and Authorization
(granting specific access rights).

Controls are safeguards deployed to mitigate risk and the impact of attacks.

 Types of Controls (CH 6):


o Hardware and Physical Controls: Related to the physical asset,
often managed using tools like Bar-coding and RFID tags for
identification and inventory. Intrusion prevention involves physical
security measures like smart cards or biometric devices.
o Software and Logical Controls: Include Application Controls
(managing input validation checks and output security, such as
printouts) and Database Controls (managing the database structure
using DDL/DML and controlling access to the schema).
o Network Controls (CH 4): Involve using VLAN equipment,
firewalls, and UTM (Unified Threat Management) servers to monitor
network traffic.
 Functional Controls (CH 6):
o Prevention Controls: Aim to prevent an attack (e.g., strong password
policies). Techniques like Tailgating (following an authorized person
through a secured door) and Masquerading (using a fictitious user
ID) exploit weaknesses in physical/logical entry controls.
o Detection Controls: Post-incident controls focused on Fault
Detection, Isolation, and Recovery. This includes reconciliation and
logs management.
o Mitigation Controls (Compensating Controls): Minimize damage,
such as Cyber Risk Insurance (a form of risk transfer) and ensuring
proper segregation of duties.
 Encryption (CH 6): A time-tested methodology to enhance data security by
coding messages. Symmetric encryption uses a single key, while
Asymmetric encryption uses a public/private key pair and hash values for
digital signatures.

Malware and User Failures (CH 4)

 Malware: Malicious software intended to cause a malicious impact. This


includes Viruses, Worms, Trojans (like Zeus), Bots, and Zombies
(compromised computers controlled remotely). CAPTCHA is a control used
to confirm human access versus bot access.
 User Failures: These are a major cause of internet crimes, often
unintentional, and include not keeping passwords secret, clicking untrusted
links, and indiscriminately downloading apps.

IV. Computer Hackers (CH 5)

Hacking is the activity of accessing information or resources without the owner's


knowledge. Accessing the database directly via non-logged means is known as
Back-end Access, which is a severe security risk.

 Hacker Types (5.5):


o White Hat Hackers: Find vulnerabilities with the owner's permission
(Ethical Hackers).
o Black Hat Hackers: Access systems illegally for unlawful purposes.
o Grey Hat Hackers: Look for vulnerabilities without permission but
offer to help the owner fix them for a fee.
o Script Kiddies: Youngsters without technical knowledge who use
tools developed by others.
o The word Cracking is often used to denote hacking done for illegal or
unethical purposes.
 Criminality: Section 66 of the IT Act 2008 describes hacking as a criminal
activity. International gangs, sometimes loosely known as Anonymous,
operate in the area of hacking and exchange information.
 Banking Threat: Major threats include DoS, Zeus/GameOver attacks,
session hijacking, and new variants like Smishing (SMS phishing).

V. Incident Management (CH 7)

An Incident is an unwelcome event that diminishes the value of an asset or


contravenes the law. Incident Management deals with the entire process from
reporting to review.

 Cyber Crime Incident (7.2): Unlike physical crime, there is no "place of


crime" or physical scene in a cyber crime incident, as it is trans-border.
 Incident Management Life Cycle (7.9): The process is continuous (like the
PDCA cycle) and comprises four stages: Reporting (often via "Incident
Ticketing"), Classification/Escalation, Action (creating forensic logs), and
Verification/Review.
 Investigation (7.6, 7.7): Requires a systematic examination to find the root
cause of the incident. Investigation involves analyzing volatile logs
(memory that is destroyed when the system is shut down). Network-based
investigations use protocols like NTP (Network Time Protocol) to determine
communication time.
 Digital Evidence (7.10, 7.11): Any information stored or transmitted
electronically that is used for investigation or judicial process. Digital
evidence is easily duplicated and volatile. The process of collecting evidence
must follow Locard's principle (the perpetrator always leaves a trail).
 Evidence Collection and Chain of Custody (7.13): Mobile tower records
like CDR (Call Detail Records) and device identifiers like IMEI
(International Mobile Equipment Identity) and IMSI are crucial evidence.
The Chain of Custody is the essential chronological documentation
required to maintain the evidence's non-tamperability until it is produced in
a court of law.
 Cyber Forensics (7.12): The science of identification, seizure, acquisition,
analysis, documentation, and preservation of digital evidence. Organizations
like C-DAC (Centre for Development of Advanced Computing) are engaged
in this field in India.
 Risk Management (7.14): Incident management plays a role in identifying
risk (threats, vulnerabilities, and impact) associated with cyber crimes,
which include financial losses, downtime, and loss of intellectual property.
The sources provide references to several key years, sections, and legislative acts
relevant to cyber crime and fraud management, primarily within the context of
Indian law.

Here is a compilation of all years mentioned in conjunction with specific sections


and acts:

Indian Legislation and Legal References

Act and Specific


Year Context
Section(s)
An ancient treatise that discussed sending
Kautilya's communication (encryption/decryption) that was
BCE 350
Arthashastra intelligible only to the receiver, demonstrating that
cryptography has been practiced for centuries.
Punishments for offenses in India are dealt with
elaborately in the I.T. Act, which is sometimes read
Indian Penal
1860 with the relevant sections of the IPC,. The IPC
Code (IPC)
covers offenses like cheating and dishonesty, and
punishments for offences,.
Indian Contract Defines fraud, though the word 'fraud' per se is not
1872
Act, Section 17 defined in the IPC,.
Information
This Act is the principal legislation related to cyber
2000 Technology (IT)
crimes and digital records in India,,.
Act, 2000
IT Amendment This amendment is frequently read along with the
2008
Act (IT Act 2008) original IT Act for trials and convictions,.
Describes the activity of hacking as a criminal
2008 IT Amendment
activity,. This section deals with penalties for
(Section Act 2008, Section
computer-related offenses, including hacking and
66) 66
causing damage to a computer resource,.
2008 I.T. Amendment Deals with offenses punishable by imprisonment
(Section Act 2008, Section for sending offensive messages through a
66A) 66A communication service,.
2008 IT Amendment Deals specifically with the issue of Cyber
(Section Act 2008, Section Terrorism, calling it an offense affecting the
66F) 66F (effective 27 sovereignty of the nation and stipulating life
Oct) imprisonment as punishment,,,. The I.T.
Amendment Act of 2008, Section 66F, also deals
exclusively with cyber terrorism in India,
especially in the aftermath of the Taj Hotel
Mumbai attack of 26 Nov 2008,.
Clearly addresses punishment for cheating by
(Section I.T. Act, Section personation using a computer resource, which
66D) 66-D extends to three years of imprisonment and a fine
of up to one lakh rupees,.
Indian Penal
(Section
Code (IPC), Discusses cheating in detail,.
415)
Section 415
Indian Penal
(Section Relates to personation, used in the context of cyber
Code (IPC),
416) cheating.
Section 416
Indian Penal This is a section referred to for "Nigerian fraud"
(Section
Code (IPC), where a billionnaire died intestate, leading to a
420)
Section 420 fraud of crores of rupees,.
Indian Penal
(Section Pertains to criminal intimidation, used in the
Code (IPC),
506) context of cyber stalking, along with Section 284,.
Section 506
Indian Penal
(Sections Use the words 'dishonestly' and 'fraudulently' in a
Code (IPC),
24, 25) definitive manner,.
Sections 24 and 25
Indian Penal
(Sections Cyber extortion is stipulated as a crime under these
Code (IPC),
383 to sections, which deal with extortion using various
Sections 383 to
389) degrees of threat,.
389
Bankers' Books
Evidence Act and These acts were also amended along with the IT
(Various
the 160-year old Act, 2000 to grant legal recognition to digital
Acts)
Indian Penal records,.
Code

Other Specific Dates


 2011: The regulator RBI spoke about withdrawing Cyber Risk Insurance in
India, though the practice did not materialize,.
 December 2014: A major attack occurred in the US resulting in the theft,
stealing, and releasing of public data from the Sony systems, known as the
Sony data breach,.
 September 2015: The U.S. and China signed an agreement with a view to
discouraging corporate stealing of data and as a hacking preventing
measure,.
 March 2015: The Supreme Court of India delivered a significant judgment
regarding cyber stalking, which affected the interpretation of this offense,.

The sources contain numerous abbreviations and acronyms related to information


security, cyber crime methodologies, and digital forensics. Below is an explanation
of these terms, grouped by category for clarity.

I. Information Security and Controls

Source
Abbreviation Explanation
Context
Two-Factor Authentication. This is the process of
authentication that involves a process other than the
2FA
standard username and password. It may be implemented
using a card and a PIN.
Advanced Persistent Threat. Refers to highly skilled,
APT often state-sponsored groups, responsible for targeted
attacks and possessing technical skills.
Bring Your Own Device. A concept where an officer or
BYOD employee is permitted to work using their personal
device.
Completely Automated Public Turing Test to Tell
Computers and Humans Apart. This is a challenge-
CAPTCHA
response test used to confirm that the system is being
accessed only by human beings and not by a robot.
Intrusion Detection System. A security appliance
IDS
available for network security checks.
Intrusion Prevention System. A security appliance
IPS
available for network security checks.
Point of Sales. Used in the context of authentication,
PoS
such as a PoS terminal where a debit card is swiped.
Security Information and Event Management. An
SIEM approach to security management that provides a
complete view of the IT Security of the organization.
Unified Threat Management. Refers to servers or boxes
containing comprehensive security features like anti-
UTM
virus, web filtering, and URL filtering, often used in
banking networks.
Virtual Private Networks. Used in the context of
VPNs
network security appliances.

II. Network, Database, and Cyber Crime Techniques

Source
Abbreviation Explanation
Context
Automated Teller Machine. Used as an example of a
ATM device requiring two factors (card and PIN) for
authentication.
Country Code Top Level Domain. Used in domain
ccTLD
name registration (e.g., ".in" for India).
Data Definition Language. A statement used to
DDL
CREATE, ALTER, or DROP objects in a database.
Data Manipulation Language. A language used to
DML
insert, modify, or delete data within the database.
Domain Name System. Mentioned in the context of
DNS
assigning blocks of regional Internet addresses.
Denial of Service. An attack type that makes a system
DoS
unavailable to users.
Distributed Denial of Service. A type of Denial of
DDoS
Service attack.
Internet Corporation for Assigned Names and
Numbers. The international agency based in the US
ICANN
responsible for IP address space and domain name
methodologies.
Internationalized Domain Names. Domain names that
IDN
are represented using characters in local languages.
Internet of Things. Technology that connects various
IoT gadgets in a network, including computer systems and
devices with chips and storage.
Internet Protocol Address. The address of a system on
IP Address the Internet, normally consisting of four parts separated
by dots.
Man-in-the-Middle. A kind of network attack where the
MiTM criminal or attacker intercepts messages between two
systems.
One Time Password. Used in banking fraud scenarios
OTP
where a victim is tricked into revealing this password.
Programmable Logic Controllers. Systems similar to
PLC
SCADA which are targets for cyber terrorism.
Relational Database Management System. The
RDBMS specific database system architecture mentioned in
relation to Database Controls.
Supervisory Control and Data Acquisition. Critical
SCADA systems, such as gas supply and metro rail, that rely
heavily upon automation and control.
Structured Query Language. Used for accessing or
SQL
modifying the database (e.g., using an update command).
Unmanned Aerial Vehicle. The generic word used to
UAV
refer to a Drone.
Uniform Resource Locator. Mentioned in the context of
URL
URL filtering (a feature of UTM).
Virtual Local Area Network. Equipment used for
VLAN
managing network security and monitoring traffic.
Voice over Internet Protocol. A communication method
VoIP
mentioned in the context of forensic evidence collection.

III. Legal, Regulatory, and Investigatory

Source
Abbreviation Explanation
Context
Call Detail Records. Logs generated by mobile towers
CDR containing valuable data such as time, duration,
completion status, and the route taken by the call.
Centre for Development of Advanced Computing. An
R&D wing of the Department of Electronics in India
C-DAC
engaged in cyber forensics and associated technology
development.
Central Forensic Science Laboratory. The Government
CFSL of India’s Digital Forensic Laboratory located in
Hyderabad.
Directorate General of Civil Aviation. The regulatory
DGCA body in India responsible for setting guidelines for
developing and importing Drones/UAVs.
Information Technology Act. Refers generally to the
I.T. Act
Indian I.T. Act 2000 and the IT Amendment Act 2008.
Internet Addiction Disorder. Sometimes referred to as
IAD a possible consequence of the excessive use of computers
and the Internet.
Integrated Circuit. Used in the context of the chips
IC
embedded in Drones/UAVs.
International Mobile Equipment Identity. The unique
IMEI 15-digit number for the mobile handset, used for
identification.
International Mobile Subscriber Identity. The unique
IMSI identifier belonging to a subscriber, stored in the SIM
card.
inRegistry Dispute Resolution Policy. The agency in
INDRP India that settles disputes related to cyber squatting for
.in domain names.
Indian Penal Code. Relevant sections of this act are
IPC sometimes read along with the I.T. Act for criminal trial
processes.
Network Time Protocol. A protocol used to determine
NT P the exact time of communication, especially in
international incidents.
Reserve Bank of India. The regulator responsible for
RBI guiding public awareness and notifications regarding
banking frauds and phishing.
Subscriber Identity Module. The card in mobile
SIM
handsets that stores valuable subscriber information.
Uniform Domain Name Dispute Resolution Policy. An
UDRP internationally adopted policy for settling disputes related
to domain names.
Uninterruptible Power Supply. Mentioned as a
UPS
physical activity risk factor for cyber crime threats.

IV. Technical/Protocol

Source
Abbreviation Explanation
Context
Directorate General of Civil Aviation. The regulatory
DGCA body in India responsible for setting guidelines for
developing and importing Drones/UAVs.
Multimedia Messaging Service. Used in the context of
MMS sending/receiving text and video clippings in cyber
stalking.
Operating System. The system software mentioned in
O/S
the context of security controls and logging user activity.
Simple Mail Transfer Protocol. The protocol used in
SMPS
email servers, primarily for sending mail.
Short Message Service. Used for text message
SMS
communication in cyber stalking.
Secure Socket Layer. Used along with TLS and PGP
SSL
for communication security.
Transport Layer Security. Used along with SSL for
TLS
communication security.
Secure Hash Algorithm. Used in hashing functions for
SHA
digital signature integrity.
PGP Pretty Good Privacy. Used for communication security.
Radio Frequency Identification. A widely used
RFID
technology for hardware monitoring and asset tracking.

This response provides conceptual clarity and examples for the key topics covering
Cyber Crimes, Computer Fraud Protection, and Incident Management, based
entirely on the information provided in the sources.
I. Cyber Crime and Fraud Fundamentals

1. What is Fraud and Computer Fraud?

Fraud is characterized by the criminal intent of the mind, known as "mens rea,"
which is the essence of fraud. Fraud involves any activity done fraudulently with
an intent to deceive and cheat others. Other concepts similar in meaning to fraud
include cheating, dishonesty, wrongful gain, abuse, and misuse.

 Example for Fraud/Mens Rea: If funds are misappropriated in a bank, this


action might involve fraudulent activities such as making false entries in the
accounts or wrongfully encashing instruments, all driven by the criminal
intent (mens rea).

Computer Fraud is defined as any fraudulent activity accomplished with the


assistance of a computer or an electronic device, done with an intent to defraud
others.

White Collar Crime is a crime committed using the brain and technology as the
primary tools, rather than physical weapons. Computer frauds can often be
classified under the generalized name of "White Collar crimes".

2. The Fraud Triangle

Crime, including cyber crime, is commonly linked to three factors, often referred
to as the Fraud Triangle:

1. Pressure or Need/Greed: The motivation or incentive for the person to


commit the fraud.
2. Opportunity: The chance or weakness in the system that allows the crime
to occur.
3. Rationalization: The criminal justifies their activity in their mind (e.g.,
feeling they deserve the money).

 Example for Fraud Triangle: An employee facing financial pressure


identifies a flaw (or opportunity) in the system's access controls, and
rationalizes the theft by believing they are underpaid.

3. Definition and Channels of Cyber Crime


Cyber Crime refers to any illegal activity or crime that is committed with the help
of a computer or an electronic gadget or equipment using microprocessors. The
fundamental difference between a conventional crime and a cyber crime is that a
computer or electronic device is used in the latter.

Channels of Cyber Crimes refer to the path or tool through which a crime is
committed. Cyber crimes can be classified based on victims (targeting an
individual, property, or a nation/group) or based on the modus operandi.

 Cyber Crime Channels/Targets (Victim-based):


o Targeting the individual (e.g., cyber stalking).
o Targeting the physical assets and property.
o Targeting the society or a nation or a group of persons (e.g., cyber
terrorism).

II. Cyber Crime Methods and Techniques

1. Threat Mapping

 Threat Vector: This is the tool or path through which an attack


materializes, resulting in a risk that impacts the security of the asset.
 Threat Landscape: This term denotes the overall view of the threat, which
is crucial for threat management.

2. Network-Based Techniques

 IP Spoofing: A technique where the IP address of the sending system is


changed dynamically so that it appears to the receiver as something else.
 Fast Flux: A network technology used by criminals to constantly change the
IP address of the system sending messages to hide the sender's details.
 Proxy Server: A front-end server used in the network that hides the IP
address or domain name in a front-end address.

3. Malware and Attack Types

Malware (Malicious Software) is any software written with a malicious intention


that causes a malicious impact or effect on the system.

Concept Explanation Example


A piece of software code Programs that copy themselves
Virus
designed to corrupt data or onto other systems and affect
interrupt the computer's information.
functioning.
A piece of software that can
spread automatically and
Spreading across a network to
Worm replicate itself quickly
consume resources and bandwidth.
through networks and
systems.
Malicious software that hides
Zeus virus (Trojan horse malware)
itself within a seemingly
is used to steal banking and user-
Trojan Horse genuine program to secretly
related information, often spread
steal information or
via email or phishing.
resources.
A network of computers
A home PC user who is unaware
infected with malware that
that their machine is compromised
Botnet/Zombie are controlled by a central
and being used to send malicious
system without the owner's
emails or transfer data.
knowledge.
Registering or occupying an
Internet domain name with Registering "[Link]" for e-
Cyber
the illegal intention of using commerce when it infringes upon
Squatting
someone else's business or the trademark of an existing entity.
trademark.
Obtaining something under
threat, often by gaining A criminal takes control of a user's
Cyber control of information confidential asset and threatens to
Extortion resources illegally (like data make data public if a ransom is not
or a website) and demanding paid.
payment (ransomware).
Stuxnet was reported to be the
world's first cyber weapon,
A criminal attack targeting a
targeting SCADA (Supervisory
Cyber nation or group, primarily
Control and Data Acquisition)
Warfare aimed at attacking critical
systems used in critical industries
systems.
like power generation or oil and gas
supply.
Phishing is obtaining Phishing: A fraudulent email asks a
Phishing /
confidential information (like customer to click a link to update
Vishing
passwords) using a fake bank account details on a deceptive
website. Vishing is Phishing website. Vishing: A fraudster calls,
combined with a voice call, claiming to be a bank
where the fraudster pretends representative, and requests the
to be a bank employee to gain user's OTP or card data over the
data. phone.
Causing irritation, nuisance,
Sending harassing SMS or text
or harassment through a
Cyber Stalking messages or using mobile phones
computer or electronic
for surveillance.
device.

III. Pillars of Information Security

Information security is conventionally defined by core attributes, with the primary


ones forming the CIA triad.

Example / Means of
Pillar Definition
Maintenance
The quality of secrecy
associated with data, ensuring Using Encryption to code a
Confidentiality information is shared and message so only the intended
disclosed only to authorized recipient can read it.
persons.
The state of data remaining in Using a Message
the same format, without Authentication Code to verify
Integrity
allowing tampering except the data's authenticity and
through an authorized process. integrity.
Data must be accessible to users This pillar is threatened by
Availability at all times, as required by the attacks like DoS or DDoS, which
system. make the system unavailable.
Using Digital Signatures or
Not allowing the sender of a
Non- hash values to confirm the
communication to deny having
Repudiation sender's identity and prove the
sent the data.
document's authenticity.
Two-Factor Authentication
The process of confirming that
(2FA) at an ATM, where the
someone or something is
Authentication user must swipe the card
actually the person or entity
(physical possession) and enter a
they claim to be.
PIN/password.
The process that allows a user
Access Privileges are controls
access privileges (commands,
ensuring a user is allowed only
Authorization activities, access to resources)
the necessary access required for
after they have been
their role.
authenticated.

IV. Controls and Protection Measures (CH 6)

Controls are safeguards or countermeasures deployed to detect, avoid, and


minimize security risk and the impact of an attack.

1. Types of Controls (By Nature)

Controls are broadly classified into three categories based on their technical nature:

Type Description Example/Application


Bar-coding or RFID tags affixed to
Hardware Controls related to equipment for inventory management, asset
and Physical the physical assets tracking, and identification. Intrusion
Controls themselves. prevention via biometric devices or physical
security posting at the entrance.
Controls
Software and User level controls (e.g., proper password
implemented within
Logical usage, using anti-virus). Operating System
the software or
Controls controls (monitoring logs, file access).
logical framework.
Controls applied to Using VLAN equipment, firewalls, and
Network
data in transit UTM (Unified Threat Management) servers
Controls
across the network. to manage and monitor network security.

2. Types of Controls (By Function)

Controls are also classified by what they achieve:

 Prevention Controls: Controls that prevent an attack from occurring or


external attackers from meeting the vulnerability.
o Example: Running anti-virus software, using effective password
management, and establishing an Information Security Policy.
o Intrusion Prevention: An effective control to prevent unauthorized
access to a computer's software or hardware, which can be done
through security arrangements like swiping a smart card or tapping a
card.
 Detection Controls: Controls that are post-incident, put in place to check
for material risk or information loss. They primarily detect a failure, isolate
the fault, and recover.
o Example: Reconciliation, logs management, review meetings, and
audits.
 Mitigation Controls (Compensating Controls): Controls designed to
minimize the damage or impact after an attack.
o Example: Cyber Risk Insurance, which transfers the risk from the
organization to a third-party insurer.

3. Application Controls and Database Controls

Application Controls are specialized controls within application development to


ensure the security of data going into, processing, and outputting data.

 Example for Validation Checks: Rejecting an input field if it receives text


when only a number is expected (front-end validation).
 Example for Output Control: In a bank, taking one copy of print-outs of
fixed deposit receipts or security papers like drafts and bankers cheques is a
serious crime area, requiring careful security measures.

Database Controls are built on features of the particular RDBMS (Relational


Database Management System).

 Schema: The description of the structure of the database in a formal manner


and language.
 DDL (Data Definition Language): Used to CREATE, ALTER, or DROP
objects in a database.
 DML (Data Manipulation Language): Used to retrieve, insert, modify, or
delete data within the database.

V. Hacking and Unauthorized Access

1. Types of Hacking and Criminality

Hacking means unauthorized access into someone else’s computer or its resource.
If hacking is done for ethical purposes, the activity is sometimes called Ethical
Hacking; if done for illegal or unethical purposes, the word used is often
Cracking.
Hacker
Description Example
Type
An employee hired by a
White
Find vulnerabilities in systems with the company to test its
Hat
owner's knowledge or permission. security or find and repair
Hackers
patches.
A hacker gaining
Black Hat Access systems without permission for an unauthorized access to
Hackers unlawful act, often motivated by money. steal corporate data to sell
to competitors.
Operate somewhere between the White Hat Finding a vulnerability in
and Black Hat; they may look for a system and then
Grey Hat
vulnerabilities without permission but may notifying the owner,
Hackers
offer to help the owner repair the patches offering to fix it for
for a professional fee. money.
Using readily available
Youngsters without thorough knowledge of
Script Root kits or basic hacking
hacking, engaging in hacking with the help
Kiddie tools downloaded from the
of tools developed by others.
internet.
A person or party involved in testing A third party hired by a
Blue Hat software or hardware to find bugs and software vendor to
Hacker vulnerabilities, typically prior to or conduct testing activity
immediately following the launch. and report bugs.

2. Hacking Techniques and Risks

 Back-end Access: Directly accessing the database using commands (like


SQL) rather than through the normal front-end application. This access is
risky because, unless properly logged, the system will not register the action,
potentially leading to breaches of data integrity.
 Tailgating and Masquerading: Methods for gaining illegal entry to
physical or information resources. Tailgating occurs when an unauthorized
person follows an authorized person through a secured entry point (e.g.,
swiping a smart card) before the door closes. Masquerading is when a
group or person takes a common user ID or a fictitious name (e.g., sysadmin,
cashier) to access the system.

VI. Incident Management and Cyber Forensics


An Incident is an event that is unusual or unwelcome, resulting in an impact, such
as diminishing the value of an information asset or leading to a contravention of
law.

1. Incident Management Life Cycle

Incident Management is a continuous process that deals with the scope from
recognizing the incident until the review and follow-up action is taken. The overall
process is similar to the PDCA (Plan, Do, Check, Act) cycle and typically
comprises four logical stages:

1. Stage I (Reporting): The incident occurs and is reported using a procedure


(e.g., automatic ticketing system).
2. Stage II (Classification): The report is classified (based on criticality) and
escalated, and necessary actions are identified.
3. Stage III (Action): Action is initiated, authority is given, and logs and trails
are created for forensics.
4. Stage IV (Verification/Review): Actions are verified, lessons are learned,
and the entire process is reviewed periodically.

2. Digital Evidence and Collection

Digital Evidence is any available body of facts or information stored or


transmitted electronically that indicates whether a belief or proposition is true or
valid.

 Characteristics of Digital Evidence: Unlike physical evidence, digital


evidence cannot be 'seen' or seized physically, and it can be easily duplicated
or transmitted over a network.
 Volatile Memory (Volatile Log): Memory data that will be obliterated
when the system is switched off. Preserving volatile memory is crucial for
investigation purposes.
 Locard's Exchange Principle: This principle states that every fraudster
takes something from the crime scene or leaves some trail there. In cyber
crime, this principle applies because the perpetrator always leaves behind a
trace or log in the server, system, or personal device.
 Chain of Custody: The essential legal procedure of maintaining a
chronological record and documentation for keeping evidence secure from
the time it is seized until it is produced in court.
 Cyber Forensics: The science concerned with the processes of
identification, seizure, acquisition, authentication, analysis, documentation,
and preservation of digital evidence, ensuring the evidence maintains its
integrity.
 C-DAC (Centre for Development of Advanced Computing): The primary
research and development organization in India engaged in cyber forensics
and associated technology development.
 Example for Evidence Tracking: In the context of mobile devices, the
IMEI (International Mobile Equipment Identity) is the unique number used
for identification, and CDR (Call Detail Records) are logs generated by
mobile towers that contain valuable data like the time, duration, and
completion status of communication.

This response provides conceptual clarity with examples drawn from the sources
regarding key concepts in computer fraud protection and cyber incident
management. Due to the constraint of using only the provided excerpts, it is not
possible to generate 500 multiple-choice questions (MCQs) with answers. The
sources contain a limited number of short questions and corresponding answers
(approximately 60-80 total).

Conceptual Clarity and Examples

1. Fundamentals of Fraud and Computer Fraud

Fraud is characterized by criminal intent, known as "mens rea," and any activity
done fraudulently with an intent to defraud others. The focus is on the intent to
deceive and cheat, often encompassing similar words like cheating, dishonesty,
wrongful gain, abuse, and misuse.

Computer Fraud is any fraud accomplished with the assistance of a computer or


an electronic device. When a crime is committed using the brain and technology as
the tools, and not physical weapons, it is known as a White Collar crime.

Concept Explanation Example


Misappropriation of funds in a
Fraudulent
The essential element of fraud is bank might involve making false
Intent (Mens
the criminal intent to defraud. entries in accounts or fraudulently
Rea)
encashing instruments.
An illegal activity or crime
committed with the help of a Cyber Stalking involves causing
computer or an electronic gadget irritation, nuisance, or harassment
Cyber Crime
or equipment using through a computer or electronic
microprocessors that can be device.
called a computer.
A person facing financial
Crime, including cyber crime, is
pressure identifies an opportunity
The Fraud often linked to three factors:
to commit computer fraud and
Triangle Pressure/Need, Opportunity,
rationalizes the act by thinking
and Rationalization.
they deserve the money.

2. Pillars of Information Security

Information security is conventionally defined by the CIA triad—Confidentiality,


Integrity, and Availability. Other attributes like Non-Repudiation, Authorization,
and Authentication are also considered pillars of information security.

Pillar Explanation Example


The quality of secrecy associated
Using Encryption to code
with data and the state of keeping
information so that only the
Confidentiality an information asset secret and
authorized receiver can
disclosing to authorized persons
understand it.
only.
The state of the data remaining in
A Message Authentication
the same format and allowing for
Code is a significant data
no tampering, otherwise than
Integrity which is used to authenticate a
through an authorized process of
message and ensure its
creation and resultant data
integrity and authenticity.
manipulation.
A Distributed Denial of
Data must be accessible at all Service (DDoS) attack targets
Availability times to the users, as per the this pillar by making the
requirements from the System. system unavailable to
legitimate users.
The process of confirming Using Two-Factor
whether someone or something is Authentication (2FA) at an
Authentication
actually the person or entity that ATM where the card swipe and
he/she or it claims to be. PIN/password are needed for
the transaction.

3. Types of Controls for Protection

Controls are safeguards or countermeasures deployed to detect, avoid, and


minimize security risk and the impact of an attack. Controls are broadly classified
into four categories:

1. Hardware and Physical Controls: Controls related to the physical asset


itself.
o Example: Bar-coding is important for recording and inventory
management of hardware assets. Intrusion prevention through
physical security measures like smart cards or biometric guards.
2. Software and Logical Controls: Controls implemented within the software
or logical framework.
o Example: Application controls which ensure the security of data in
the application and include validation checks (e.g., rejecting an input
if it is not a number when only a number is expected).
3. Network Controls for Data in Transit: Controls focused on protecting
data moving across the network.
o Example: Using VLAN equipment, firewalls, and UTM (Unified
Threat Management) servers to manage and monitor network
security.
4. Other Controls: Controls that do not fall under the other three categories.

Controls can also be categorized by function:

 Prevention Controls: Controls that prevent an attack from occurring (e.g.,


strong password management, Intrusion prevention).
 Detection Controls: Controls that are post-incident and check for material
risk or information loss (e.g., reconciliation, audits, review meetings, logs
management).
 Mitigation Controls: Controls that minimize the damage or impact after an
attack, often referred to as compensating controls (e.g., Cyber Risk
Insurance, segregation of duties).

4. Cyber Crime Methods

Methods used by cyber criminals are diverse and constantly evolving.


Method Description Example
A fraudulent email purporting to
Soliciting or obtaining information
be from a reputable company
called for in a fake website, often of
Phishing asking the recipient to click a link
a bank, in which the customer is
to update their bank account
induced to enter login credentials.
details.
Phishing combined with a voice
call; the fraudster may obtain the A phone call asking a user to
target's email/phone and call, provide an OTP received on their
Vishing
introducing himself as a bank mobile to verify an urgent bank
employee to gain confidential data transaction.
(passwords, card data).
Registering or occupying an Registering a domain name that is
Cyber Internet domain name with the slightly misspelled version of a
Squatting illegal intention of using someone famous company's name
else’s business or trade mark. (typosquatting) to divert traffic.
Zeus viruses (Trojan horse
malware) are sophisticated
Malicious software intended to
programs used to steal banking
Malware cause a malicious impact or cause a
and other user-related
malicious effect on the system.
information, often spread via
emails or phishing.
A Black Hat hacker gaining
unauthorized access to a company
Unauthorized access into someone
Hacking network to steal data without
else’s computer or its resource.
permission, which is an unlawful
act.

5. Cyber Crime Incident Management

An Incident is an event that is either unusual or unwelcome, often resulting in an


impact, such as diminishing the value of an information asset or leading to a
contravention of law. Incident Management is a continuous process that deals with
the gamut from recognizing the incident until the review and follow-up action is
taken.

The Incident Management Life Cycle follows an overall process similar to the
PDCA cycle (Plan, Do, Check, Act). A common framework involves four logical
stages:
1. Stage I (Reporting): Incident occurrence, reported using a procedure (like
an automatic ticketing system or manual report), resulting in the receipt of
the report.
2. Stage II (Classification): Classification of the report and escalation,
identification of necessary direction, and determination of actions to be
taken.
3. Stage III (Action): Action initiated based on authority, creation of logs, and
trails for forensics.
4. Stage IV (Verification/Review): Verification of actions taken, lessons
learned, and review of the entire process.

Digital Evidence is any available body of facts or information indicating whether


a belief is true or valid, stored or transmitted electronically. In cyber crime, there is
no physical "scene of crime" or "place of crime," making the network or devices
involved crucial for evidence gathering.

Available Questions and Answers from Sources

As requested, the following tables contain a compilation of the questions/fill-in-


the-blanks and their corresponding answers available in the source material
chapters.

Chapter 6: Computer Fraud Protection Questions

Q.
Question Answer
No.
A statement used to create, alter, drop objects in a Data Definition
1.
database is called ______. Language.
Encryption and decryption done in the same manner Symmetric
2.
using the same key is called ______. encryption.
Fault detection, isolation and recovery are closely
3. Detection.
associated with ______ control.
Installation of Biometric devices to check unauthorised
4. Physical.
entry is ______ control.
Front-end validation checks for the software is part of
5. Application.
______ control.
6. A simple methodology to ensure hardware monitoring is RFID.
the use of ______ tags.
Description of structure in a formal manner and language
7. Schema.
as part of the particular DBM S is called ______.
Mostly in legal circles, criminal intent of mind is
8. Mens rea.
described as ______.
A crime committed with brain and technology as the tools White Collar
9.
and not physical weapons is known as ______. offence.
Keeping proper track of print-outs like monitoring them
10. Output control.
and ensuring their security is called ______ controls.

Chapter 7: Incident Management Questions

Q.
Question Answer
No.
The chronological order and documentation for keeping
1. Chain of Custody.
an evidence is called ______.
The device used to serve in a part of the body with
Wearable
2. facility to track, record with some embedded chips is
technology.
associated with ______.
‘Every fraudster always takes something from the crime
3. scene or leaves some trail there’ is normally known as Locard.
______ principle.
______ is an R & D wing of the Dept. of Electronics
4. engaged in cyber forensics and development of C-DAC.
technologies associated with it.
The technology that integrates various gadgets in a
network consisting of the data, not just from a computer
5. Internet of Things.
system but any other device with chip and storage is
called ______.
The Digital Forensic Laboratory of the Government of
6. Hyderabad.
India is located in ______.
This type of hackers normally serve the purpose of
7. giving the first report as part of Incident Management Blue hat hackers.
______.
The memory that will evaporate when the system is
8. Volatile memory.
switched off is called ______.
9. The protocol that is used to determine the time of Network Time
communication especially in an international Protocol.
communication where the time zones differ is called
______.
A major issue to be handled after capturing digital
Non Tamperability
10. evidence at the time of preserving it and up the
ensuring integrity.
production of the same in a court of law is ______.

Chapter 1: Introduction to Cyber Crimes Questions

Q.
Question Answer
No.
Cyber crime is a criminal activity
1. Computer or such an electronic device.
using a ______.
The fundamental difference
between a cyber crime and a
2. Computer or such an electronic device.
traditional crime is that in cyber
crime a ______ is used.
The three aspects to a crime
Need/Greed/Pressure, Opportunity,
3. commonly called a Fraud Triangle
Rationalisation.
are: ______, ______, & ______.
In India, punishments for offences
are dealt with elaborately in the I.T.
4. Indian Penal Code.
Act which is sometimes read with
the relevant sections of ______.
One who wants to be a hacker but
does not have thorough technical
5. knowledge and does it in a child- Script Kiddie.
like manner writing the code, is
called ______.
In the case of hacking or writing a
virus program as a cyber crime, the Technological supremacy or knowledge
6.
motive most often was to show as against the owner of the system.
one’s ______.
Cyber Stalking can be classified as
7. a cyber crime targeted against Persons or Individuals.
______.
Cyber crimes targeted against a
8. Cyber Terrorism.
nation or a group or a particular
sect is often called ______.
False (It is not strictly defined, rather it is
Cyber Crime is defined in the
classified as any offence which is
9. Indian Information Technology Act
committed with the help of a computer or
(True/False).
an electronic device).
In India all cyber crimes are dealt
with elaborately in the I.T. Act
10. False.
2000 and the IT Amendment Act,
2008. (True/False).

Chapter 3: Cyber Crime Methods Questions

Q.
Question Answer
No.
Deceiving a person to part with confidential account details
1. Phishing.
by presenting a fake website is ______.
Cyber terrorism has been specifically included in the IT Act
2. 66F.
in Section ______.
The international agency engaged in domain name
3. ICANN.
registration located in the US is called ______.
Disputes related to cyber squatting in India are being settled
4. INDRP.
by the agency known as ______.
Zeus was considered to be a deadly virus targeted mainly Banking and
5.
against the ______ sector. Financial.
______ was generally reported to be the first cyber weapon in
6. Stuxnet.
the world.
Taking control of the information resource illegally and
Cyber
7. demanding money from the victim to return the data or
Extortion.
resource is called ______.
Critical systems like gas supply, metro rail etc. heavily
8. SCADA.
depending upon automation are normally called ______.
9. ______ is normally of four parts separated by dots. IP Address.
A front end server which hides the IP address or the domain
10. Proxy Server.
name in a front-end address in the network is called ______.

Chapter 4: Computer Insecurity Questions


Q.
Question Answer
No.
The non-tamperable quality of data otherwise than
1. Integrity.
through an authorised process of access is called ______.
Not allowing the sender of a communication, to deny
2. Non Repudiation.
having sent the same is called ______.
The process of confirming that the user is the one who
3. Authentication.
he/she claims to be is called ______.
Allowing only the particular access to an information
4. resources as may be required for the particular user is Access Privileges.
called ______.
To confirm that the system is being accessed only by
5. human beings and not by a robot, the technique used is CAPTCHA.
called ______.
The process of coding a message in such a way that it is
6. read and understood only by the intended recipient and Encryption.
not by others is called ______.
Bring Your Own
7. BYOD stands for ______.
Device.
The process of getting authentication from a process
8. other than user name and password is commonly known 2FA.
as ______.
______ is said to contain features like anti-virus and web
9. Firewall.
filtering, URL filtering etc.
Unified Threat
10. UTM stands for ______.
Management.

Chapter 5: Computer Hackers Questions

Q.
Question Answer
No.
Trying to steal the information of other computer systems
1. Hacking.
is called ______.
The person who takes the information from a computer
White Hat
2. with the owner’s knowledge other than through a normal
hacker.
login process is called ______.
3. Unless properly logged, straightaway accessing the Back-end Access.
database through a SQL call should always be avoided
______.
International gangs operating in the area of hacking
4. exchanging hacking related information are loosely known Anonymous.
as ______.
If hacking can be taken to mean for ethical purposes, the
5. word used for unethical and illegal purposes would be Cracking.
______.
The Information Technology Act, 2008 describes the
6. activity of hacking as a criminal activity in its Section No. 66.
______.
The system of effectively taking care of URL filtering, web
Unified Threat
7. filtering, anti-virus, as an all-in-one solution is normally
Management.
referred to as ______.
Normally youngsters without much knowledge of hacking
8. tools, engaging in hacking with the help of tools developed Script Kiddie.
by others are called ______.
In September 2015, these two nations signed an agreement
9. with a view to discouraging corporate stealing of data and U.S. and China.
as a hacking preventing measure: ______ and ______.
______ kind of hacking is always a crime, mostly done as
10. Black Hat.
an illegal assignment for money or other consideration.

Chapter 2: Channels of Cyber Crimes Questions

Q.
Question Answer
No.
Technology of changing the address of
the system in a network that sends
1. messages so frequently in order to hide Fast Flux.
the sending system’s details is called
______.
The technology in which the IP address
of the sending system can be changed
2. IP Spoofing.
dynamically to look like something else
for the receiver is called ______.
In the case of cyber terrorism, the crime Anything from where the evidence
3.
scene can be fixed as ______. can be taken, irrespective of the
network since there is nothing like
a crime scene in a cyber crime.
The path or the tool through which an
4. attack came to the system is called Threat Vector.
______.
Getting a complete overview of the
5. threat, as part of Threat Management is Threat Landscape.
called ______.

Note on MCQs: The provided sources do not contain 500 MCQs. The questions
listed above are extracted directly from the "Questions" and "Answers" sections
available in the source documents. These questions are mostly in a short answer,
true/false, or fill-in-the-blank format, not higher-level MCQs

### Conceptual Clarity on Chapter 6: Computer Fraud Protection

This chapter provides a comprehensive overview of computer frauds (also known


as cyber frauds) and the controls organizations can implement to prevent, detect,
and mitigate them. Below is a structured summary to clarify the key concepts,
drawing from the document's content. I'll explain each major section conceptually,
highlighting definitions, importance, examples, and interconnections, to build a
deeper understanding. The focus is on practical application in information security,
especially in contexts like banking, where technology penetration increases fraud
risks.

#### 1. **Objective of the Chapter**

- **Concept**: The chapter emphasizes preventing computer frauds amid rising


cyber threats due to technology's growth in daily life. It covers fraud definitions,
types of controls, and strategies for implementation.

- **Clarity**: Fraud prevention is proactive (stopping incidents) and reactive


(detecting and mitigating). Controls are layered safeguards that protect information
assets (hardware, software, data). In real-world scenarios, like banking, poor
controls (e.g., weak passwords) lead to breaches, so organizations must integrate
administrative, technical, and physical measures.

- **Importance**: With cyber frauds evolving (e.g., via networks or devices),


understanding controls ensures compliance with laws like the Indian Penal Code
(IPC) and reduces losses.

#### 2. **What is Fraud?**

- **Concept**: Fraud is an intentional act ("mens rea" or criminal intent) to


defraud, causing wrongful gain or loss. It's distinguished from accidents.
Synonyms include cheating, dishonesty, abuse, misuse. Per IPC Section 25, it's
done "fraudulently" with intent to defraud.

- **Clarity**: Intent is key—e.g., accidentally leaking data isn't fraud, but


deliberately hacking for gain is. In cyber contexts, it's tied to IPC Section 415
(cheating). Fraud isn't defined in IPC but in the Indian Contract Act (Section 17) as
misrepresentation or concealment.

- **Importance**: Differentiates fraud from mere cyber crimes (e.g., accidental


data loss vs. intentional theft). Society's treatment evolves with technology,
culture, and law.

- **Example**: Sharing passwords intentionally to enable unauthorized access is


fraud; forgetting to log out isn't, unless intent is proven.

#### 3. **Computer Frauds**

- **Concept**: Any fraud using a computer, network, or electronic device.


Includes cheating, theft, breach of trust if involving tech. It's similar to cyber crime
but requires fraudulent intent (mens rea). Victims and fraudsters are key parties.

- **Clarity**: Cyber crime may lack intent (e.g., regulatory breach), but
computer fraud always has it. White-collar crimes (e.g., tax evasion via computers)
overlap. Related to corporate espionage, hacking.
- **Importance**: In digital eras, most non-physical crimes (e.g., money
laundering) become computer frauds if tech-enabled. Prevention focuses on intent
detection.

- **Example**: Phishing via email (intent to steal data) is fraud; accidental virus
spread isn't.

#### 4. **Meaning of Controls**

- **Concept**: Controls are safeguards/countermeasures to detect, avoid, or


minimize security risks to assets. They mitigate threats by reducing impact, often
in sequence: detect → avoid → minimize → prevent recurrence.

- **Clarity**: Controls are administrative (policies) or technological (tools).


Success depends on adequacy, efficiency, and implementation. They protect
physical (hardware) and intangible (data) assets.

- **Importance**: Core to information security policy. Without controls, threats


exploit vulnerabilities, leading to losses.

- **Example**: An antivirus detects malware (detection), firewalls avoid entry


(prevention), backups minimize data loss (mitigation).

#### 5. **Types of Controls**

- **Concept**: Broadly categorized into:

- **Hardware/Physical**: Protect physical assets (e.g., inventory, bar-coding,


RFID for tracking). Involves identification, recording, classification, monitoring.

- **Software/Logical**: User-level (e.g., antivirus), Application


(input/processing/output validations), Database (schema, locks, integrity checks),
OS (logs, root access).

- **Network**: For data in transit (e.g., encryption).

- **Others**: Third-party (e.g., audits).


- **Clarity**: Assets combine hardware (value + data efforts). Tiny devices
(e.g., SD cards) need strong tracking (bar-coding vs. RFID: bar-coding cheaper,
RFID for distance). Software controls layer from user to OS. Application controls
ensure data accuracy (e.g., front-end validations save bandwidth).

- **Importance**: Converging all types provides best security. E.g., Database


schema integrates access controls; OS logs monitor root actions.

- **Example**: Bar-coding at procurement prevents theft; RFID tracks


employee movement. In databases, DDL (create/alter) vs. DML (manipulate data)
must be controlled to avoid escalation.

#### 6. **Prevention Controls**

- **Concept**: Proactive measures to stop attacks before impact. Physical


(guards, fences, UTM boxes); Software (policies, AV, passwords, user
management).

- **Clarity**: Focus on vulnerabilities like weak passwords (common in 1990s


banking). Intrusion prevention stops unauthorized access (e.g., smart cards vs.
tailgating/masquerading).

- **Importance**: Prevents losses; e.g., password policies evolved from sharing


to mandatory uniqueness.

- **Example**: Biometric doors prevent tailgating; UTM detects/prevents


intrusions.

#### 7. **Detection Controls**

- **Concept**: Post-incident checks for material risks/errors. Includes audits,


logs, reconciliations, HR verifications. Involves fault detection, isolation, recovery.

- **Clarity**: Detection risk is auditor-accepted error possibility. Steps: Identify


fault → Isolate asset → Recover. Part of fraud management.
- **Importance**: Learns from incidents; e.g., logs review daily to spot
anomalies.

- **Example**: Exception reports flag unusual transactions; audits confirm no


errors.

#### 8. **Mitigation Controls**

- **Concept**: Compensating/alternate controls to reduce impact (e.g.,


segregation of duties, maker-checker). Includes cyber insurance (risk transfer).

- **Clarity**: Fixes control deficiencies; e.g., insurance covers losses. In India,


nascent except card policies; RBI recommended in 2011 but slow adoption.

- **Importance**: Avoids escalation; e.g., in banks, duties segregation prevents


single-person fraud.

- **Example**: Insurance mitigates financial loss from breaches.

#### 9. **Encryption/Decryption**

- **Concept**: Scrambling data so only authorized can read (encryption);


reversing it (decryption). Symmetric (same key); Asymmetric (public/private keys,
hash for integrity, used in digital signatures).

- **Clarity**: Historical (e.g., Kautilya's Arthashastra). Strong cryptography


uses one-time pads. Factors: Network type, data criticality.

- **Importance**: Protects data in transit/storage; e.g., HTTPS vs. HTTP.

- **Example**: Symmetric for simple sharing; Asymmetric for secure emails.

#### 10. **Summary and Key Terms**

- **Concept**: Fraud needs intent; controls are multi-layered


(preventive/detective). Cryptography enhances security.
- **Clarity**: Effective security balances all controls based on risk, regulations.

- **Key Terms**: Mens rea, White-collar crimes, Schema, RFID, DDL/DML,


Asymmetric encryption.

This clarity builds a foundation: Fraud is intent-driven; controls are multi-faceted


shields. For higher-level understanding, apply to scenarios like banking breaches
or policy design.

### 80 Higher-Level MCQs with Answers

These MCQs are designed at a higher level (Bloom's Taxonomy: Application,


Analysis, Evaluation). They require applying concepts to scenarios, analyzing
implications, or evaluating strategies. Each has 4 options; correct answer explained
briefly.

1. **In a banking scenario where a senior official shares their password with a
junior due to perceived tech-savviness, this violates which control principle,
leading to potential fraud?**

- A) Detection control

- B) Mitigation control

- C) Prevention control (password policy)

- D) Database schema design

**Answer: C** (Analysis: This is a preventive breach, as password sharing


enables intrusion, common in 1990s banking per the chapter.)
2. **Evaluate why mens rea is crucial in distinguishing computer fraud from cyber
crime: If data loss occurs due to a non-intentional regulatory breach, it is classified
as?**

- A) Computer fraud

- B) White-collar crime

- C) Cyber crime without fraud

- D) Physical control failure

**Answer: C** (Evaluation: Mens rea (intent) is essence of fraud; absence


makes it mere cyber crime.)

3. **Apply the concept of controls to a scenario: An organization uses RFID for


tracking miniature devices like SD cards. What vulnerability does this share with
bar-coding, requiring additional network checks?**

- A) High cost

- B) Spoofing and cable disconnection

- C) Low traceability

- D) Incompatibility with VLANs

**Answer: B** (Application: Both are vulnerable to physical bypassing, like


removing cables.)

4. **Analyze the impact if an application lacks front-end validation: Data travels to


the database before rejection, consuming resources. This primarily affects which
control type?**

- A) Output control

- B) Input control
- C) OS log management

- D) Hardware inventory

**Answer: B** (Analysis: Front-end validations are input controls to save


bandwidth/processing.)

5. **In evaluating database controls, why is schema design critical for access
privileges in a Big Data environment?**

- A) It enables row-level locking without escalation

- B) It integrates ownership chaining for compliance

- C) It reduces hardware costs

- D) It eliminates the need for OS logs

**Answer: B** (Evaluation: Schema builds hierarchy for securables, preventing


insider attacks.)

6. **Apply intrusion prevention: In a metro station using contactless smart cards,


how does it mitigate tailgating?**

- A) By allowing group logins

- B) Through bio-metric integration for individual entry

- C) Via generic user IDs

- D) Ignoring logs

**Answer: B** (Application: Prevents unauthorized entry post-swipe.)

7. **Analyze why detection controls like logs are non-editable and compulsory: In
an OS environment, this ensures?**
- A) Root access for all users

- B) Audit trail integrity against tampering

- C) Symmetric encryption

- D) Hardware bar-coding

**Answer: B** (Analysis: Prevents deletion, aiding reviews.)

8. **Evaluate mitigation controls in banking: Maker-checker principle


compensates for what risk?**

- A) Password sharing

- B) Single-person control over critical transactions

- C) Antivirus failure

- D) RFID spoofing

**Answer: B** (Evaluation: Segregation of duties reduces fraud risk.)

9. **Apply asymmetric encryption: In digital signatures, how does it confirm


message integrity?**

- A) Using the same key for both ends

- B) Generating hash values with public/private keys

- C) One-time pads only

- D) Without third-party authority

**Answer: B** (Application: Hash verifies no tampering.)

10. **Analyze white-collar crimes' relation to computer frauds: Tax evasion via
networked software is fraud because?**
- A) It lacks intent

- B) It uses computers for non-physical gain

- C) It's always accidental

- D) No victim involved

**Answer: B** (Analysis: Overlaps if tech-enabled with intent.)

11. **Evaluate the sequence of efficient controls: Why detect → avoid →


minimize?**

- A) To escalate risks

- B) To counteract threats in order of impact reduction

- C) To ignore prevention

- D) For hardware only

**Answer: B** (Evaluation: Logical risk mitigation flow.)

12. **Apply hardware controls: For tiny chips storing GBs, why is bar-coding
preferred over RFID initially?**

- A) Higher security

- B) Lower cost and ease of re-application

- C) Better distance reading

- D) No vulnerability

**Answer: B** (Application: Cost-effective for inventory.)

13. **Analyze software controls' convergence: The best security point is where?**
- A) User level only

- B) All four (user, app, DB, OS) overlap

- C) Network transit

- D) Physical guards

**Answer: B** (Analysis: Collective presence ensures compliance.)

14. **Evaluate prevention vs. detection: Password policy is preventive, but logs
review is?**

- A) Mitigation

- B) Detection

- C) Encryption

- D) Hardware

**Answer: B** (Evaluation: Post-incident check.)

15. **Apply DDL vs. DML: In Oracle, DDL for schema alteration requires
controls to prevent?**

- A) Data retrieval

- B) Unauthorized structure changes

- C) Output printing

- D) User logging

**Answer: B** (Application: DDL creates/alters objects.)

16. **Analyze why cyber insurance is nascent in India: Banks fear it may lead
to?**
- A) Stricter regulations

- B) User carelessness in security

- C) Higher premiums only

- D) No techno-legal issues

**Answer: B** (Analysis: Comfort factor reduces precautions.)

17. **Evaluate fault detection steps: After identification, isolation prevents?**

- A) Recovery

- B) Spread to other assets

- C) Logging

- D) Encryption

**Answer: B** (Evaluation: Contains impact.)

18. **Apply output controls: In banking, tracking printouts of drafts prevents?**

- A) Input errors

- B) Duplicate fraudulent copies

- C) Database locks

- D) OS root access

**Answer: B** (Application: Ensures security of outputs.)

19. **Analyze UTM boxes: They combine hardware/software for?**

- A) Detection only

- B) Unified threat prevention


- C) Bar-coding

- D) Schema design

**Answer: B** (Analysis: Multi-feature intrusion control.)

20. **Evaluate symmetric vs. asymmetric: Asymmetric is advanced because?**

- A) Same key risks exposure

- B) Dual keys with hash for integrity

- C) No need for keys

- D) One-time use only

**Answer: B** (Evaluation: Enhances security in PKI.)

21. **Apply masquerading: Using a generic ID like 'admin' enables?**

- A) Traceable actions

- B) Unidentifiable fraud

- C) Better logging

- D) Prevention

**Answer: B** (Application: Hides user identity.)

22. **Analyze database features: Row-level locking in Oracle avoids?**

- A) Escalation in big data

- B) User management

- C) Output validation

- D) Hardware tracking
**Answer: A** (Analysis: Manages internally without limits.)

23. **Evaluate controls' dependency: Success relies on?**

- A) Hardware cost alone

- B) Adequacy and implementation efficiency

- C) Ignoring regulations

- D) Single-layer only

**Answer: B** (Evaluation: Multi-factor.)

24. **Apply 2D bar-coding: It stores more info than linear, useful for?**

- A) Security descriptions

- B) Cost reduction only

- C) Distance reading

- D) Spoofing prevention

**Answer: A** (Application: Price, quality, etc.)

25. **Analyze OS controls: In Unix, root permission ensures?**

- A) Group users dominate

- B) Only system manager accesses critically

- C) Editable logs

- D) Anonymous entries

**Answer: B** (Analysis: Prevents unauthorized changes.)


26. **Evaluate mitigation via insurance: It's a form of?**

- A) Risk avoidance

- B) Risk transfer

- C) Detection

- D) Encryption

**Answer: B** (Evaluation: Shifts to insurer.)

27. **Apply workflow controls: Notifying users of pending actions helps?**

- A) Data accuracy

- B) Process efficiency

- C) Hardware inventory

- D) RFID reading

**Answer: B** (Application: Awaits action in apps.)

28. **Analyze inherent vs. configurable controls: Inherent are?**

- A) Added post-config

- B) Built-in, no addition needed

- C) User-defined only

- D) Reporting-focused

**Answer: B** (Analysis: Delivered with app.)

29. **Evaluate detection risk: Auditor accepts it as?**

- A) No errors exist
- B) Possible material errors undetected

- C) Full prevention

- D) Mitigation failure

**Answer: B** (Evaluation: Lets some risk exist.)

30. **Apply strong cryptography: Uses one-time pads for?**

- A) Government secure comms

- B) Simple emails

- C) Hardware tracking

- D) OS logs

**Answer: A** (Application: Advanced, random keys.)

31. **Analyze tailgating in software: Occurs when?**

- A) Session left open

- B) Encrypted data sent

- C) Bar-code scanned

- D) Database locked

**Answer: A** (Analysis: Unauthorized use post-login.)

32. **Evaluate controls for data in transit: Primarily involves?**

- A) Hardware inventory

- B) Network controls like encryption

- C) User level only


- D) Output printing

**Answer: B** (Evaluation: Protects movement.)

33. **Apply securables in DB: Regulates access to?**

- A) Resources via authorization

- B) Physical hardware

- C) OS events

- D) Bar-codes

**Answer: A** (Application: DB engine scope.)

34. **Analyze why controls depend on RDBMS version: For?**

- A) Customization of security features

- B) Ignoring maintenance

- C) Reducing bandwidth

- D) Eliminating users

**Answer: A** (Analysis: Enables built-in controls.)

35. **Evaluate prevention in physical: Barbed wire is?**

- A) Detection

- B) Preventive barrier

- C) Mitigation

- D) Encryption

**Answer: B** (Evaluation: Stops entry.)


36. **Apply exception reports: As detection, they flag?**

- A) Normal activities

- B) Unusual anomalies

- C) Hardware moves

- D) Symmetric keys

**Answer: B** (Application: Post-incident review.)

37. **Analyze asset value: Includes hardware cost plus?**

- A) Data efforts and criticality

- B) Only monetary

- C) No intangibles

- D) Bar-code price

**Answer: A** (Analysis: Holistic valuation.)

38. **Evaluate asymmetric in PKI: Involves?**

- A) Single key

- B) Public/private with certifying authority

- C) No hash

- D) Symmetric alternative

**Answer: B** (Evaluation: For authenticity.)

39. **Apply HR management: As detection, includes?**


- A) Antecedent checking

- B) Encryption keys

- C) RFID costs

- D) Schema alteration

**Answer: A** (Application: Verifies employees.)

40. **Analyze why output controls track printouts: To ensure?**

- A) Completeness and accuracy

- B) Input validation

- C) Database integrity

- D) OS root

**Answer: A** (Analysis: Prevents errors like checksum.)

41. **Evaluate controls' upgradability: Considered for?**

- A) Future security levels

- B) Ignoring regulations

- C) Hardware only

- D) No customization

**Answer: A** (Evaluation: Based on needs.)

42. **Apply VLANs in security: Checks for?**

- A) Connectivity vulnerabilities in RFID/bar-coding

- B) Data manipulation
- C) User profiles

- D) Symmetric encryption

**Answer: A** (Application: Prevents bypassing.)

43. **Analyze fault recovery: After isolation, focuses on?**

- A) Spreading risk

- B) Restoring assets

- C) Deleting logs

- D) Sharing passwords

**Answer: B** (Analysis: Post-detection action.)

44. **Evaluate cyber warfare: Classified as computer fraud if?**

- A) Accidental

- B) Intentional with tech

- C) No network

- D) Physical only

**Answer: B** (Evaluation: Organized hacking.)

45. **Apply configurable controls: Defined during?**

- A) System configuration

- B) Post-attack

- C) Hardware procurement

- D) Encryption
**Answer: A** (Application: Automated setup.)

46. **Analyze reconciliation: As detection, it?**

- A) Prevents entry

- B) Confirms no discrepancies

- C) Encrypts data

- D) Tracks hardware

**Answer: B** (Analysis: Post-transaction check.)

47. **Evaluate one-time pads: In strong cryptography for?**

- A) Random, secure govt. use

- B) Simple symmetric

- C) Bar-coding

- D) OS logs

**Answer: A** (Evaluation: Advanced variant.)

48. **Apply user management in DB: Restricts?**

- A) Back-end access

- B) Physical guards

- C) Output prints

- D) RFID range

**Answer: A** (Application: Based on roles.)


49. **Analyze why controls minimize impact: Efficient ones?**

- A) Ignore threats

- B) Provide countermeasures

- C) Increase risks

- D) Delete assets

**Answer: B** (Analysis: Reduce damage.)

50. **Evaluate IPC's role: Defines fraudulently but not fraud, referencing?**

- A) Contract Act

- B) No definition

- C) Only cheating

- D) White-collar only

**Answer: A** (Evaluation: Section 17.)

51. **Apply process controls: Reference DB for?**

- A) Validations like balance checks

- B) Hardware inventory

- C) Encryption keys

- D) Guards posting

**Answer: A** (Application: After input.)

52. **Analyze detection in audits: Confirms?**

- A) Material errors absent


- B) Full risks

- C) No logs

- D) Symmetric use

**Answer: A** (Analysis: Though risk exists.)

53. **Evaluate segregation of duties: Mitigates?**

- A) Control deficiencies

- B) Prevention only

- C) Hardware theft

- D) Schema

**Answer: A** (Evaluation: Compensating.)

54. **Apply Kautilya's reference: Historical encryption for?**

- A) Secure state comms

- B) Modern banking

- C) RFID

- D) OS controls

**Answer: A** (Application: Ancient methodology.)

55. **Analyze event logs in Windows: For?**

- A) System manager review

- B) User encryption

- C) Bar-code reading
- D) No purpose

**Answer: A** (Analysis: With Active Directory.)

56. **Evaluate intrusion detection: Part of UTM, it?**

- A) Alerts on attacks

- B) Prevents only

- C) Encrypts

- D) Inventories

**Answer: A** (Evaluation: Complements prevention.)

57. **Apply consistency check in DB: Ensures?**

- A) Data reliability

- B) Physical security

- C) Output copies

- D) Password sharing

**Answer: A** (Application: Built-in RDBMS.)

58. **Analyze why controls are regulatory: For?**

- A) Mandatory security levels

- B) Optional use

- C) Ignoring bandwidth

- D) No upgradability

**Answer: A** (Analysis: Compliance-driven.)


59. **Evaluate hash in asymmetric: Confirms?**

- A) Integrity

- B) Cost

- C) Hardware value

- D) Logs deletion

**Answer: A** (Evaluation: No tampering.)

60. **Apply internal controls: Include?**

- A) Employee verification

- B) External attacks only

- C) Symmetric keys

- D) Barbed wire

**Answer: A** (Application: Detection via HR.)

61. **Analyze maker-checker: In critical transactions for?**

- A) Risk shifting

- B) Single control

- C) No segregation

- D) Detection only

**Answer: A** (Analysis: Mitigation via duties.)

62. **Evaluate RBI's 2011 recommendation: For?**


- A) Cyber risk insurance

- B) No insurance

- C) Password sharing

- D) Hardware only

**Answer: A** (Evaluation: Yet nascent.)

63. **Apply decryption: Requires?**

- A) Authorized key

- B) No assistance

- C) Public exposure

- D) Accidental access

**Answer: A** (Application: Unscrambling.)

64. **Analyze white-collar: Non-physical, brain/tech-based, like?**

- A) Money laundering via computers

- B) Assault

- C) No intent

- D) Physical guards

**Answer: A** (Analysis: Overlaps fraud.)

65. **Evaluate bar-code readers: Types include?**

- A) Pen, laser, camera

- B) Encryption only
- C) DB schema

- D) OS root

**Answer: A** (Evaluation: For hardware control.)

66. **Apply validation checks: Prevent?**

- A) Typos/misclassifications

- B) Hardware movement

- C) Insurance claims

- D) Mens rea

**Answer: A** (Application: Assure accuracy.)

67. **Analyze o/s logs: Non-technical ones like?**

- A) User profiles, events

- B) Encryption formulas

- C) RFID costs

- D) No review

**Answer: A** (Analysis: Daily monitoring.)

68. **Evaluate controls for cloud: Database controls act as?**

- A) Second-line defense

- B) Primary hardware

- C) No role

- D) Symmetric only
**Answer: A** (Evaluation: Vs. SQL injection.)

69. **Apply reporting controls: Rely on?**

- A) App reports

- B) Physical fences

- C) Key generation

- D) Tailgating

**Answer: A** (Application: Standard/ad-hoc.)

70. **Analyze why intent is key: Accidental wrongful gain?**

- A) Not fraud

- B) Always fraud

- C) White-collar

- D) Detection only

**Answer: A** (Analysis: Lacks mens rea.)

71. **Evaluate network bandwidth in DB controls: Influences?**

- A) Security level decisions

- B) Ignoring features

- C) Hardware bar-coding

- D) No impact

**Answer: A** (Evaluation: Customization factor.)


72. **Apply principals in DB: Include?**

- A) Users, roles, groups

- B) Physical assets

- C) Output prints

- D) Insurance

**Answer: A** (Application: Hierarchy with securables.)

73. **Analyze mitigation in audits: Catches?**

- A) Uncorrected misstatements

- B) Prevention failures

- C) Encryption errors

- D) RFID swaps

**Answer: A** (Analysis: Avoids loss.)

74. **Evaluate historical encryption: In Arthashastra for?**

- A) Intelligible only to receiver

- B) Public sharing

- C) No scrambling

- D) Accidental

**Answer: A** (Evaluation: Time-tested.)

75. **Apply lock management: In Oracle, no limit on?**

- A) Row-level locks
- B) Table alterations

- C) User groups

- D) Hardware

**Answer: A** (Application: Internal management.)

76. **Analyze why controls are countermeasures: Against?**

- A) Non-availability or impact

- B) Full availability

- C) No threats

- D) Only physical

**Answer: A** (Analysis: Guard assets.)

77. **Evaluate asset tracking apps: Blessing for?**

- A) Security managers locating transit assets

- B) Ignoring movement

- C) Cost increase

- D) No bar-coding

**Answer: A** (Evaluation: Mobile integration.)

78. **Apply DML: Used for?**

- A) Data manipulation (insert, delete)

- B) Schema creation only

- C) Hardware control
- D) Prevention guards

**Answer: A** (Application: Vs. DDL for definitions.)

79. **Analyze RBI's slow insurance adoption: Due to?**

- A) Techno-legal ramifications

- B) Full evolution

- C) No recommendations

- D) Physical focus

**Answer: A** (Analysis: Niche area.)

80. **Evaluate overall security: Depends on?**

- A) Combination of all controls layered

- B) Single type only

- C) Ignoring intent

- D) No policies

**Answer: A** (Evaluation: For efficiency.)


### Conceptual Clarity on Chapter 7: Incident Management

This chapter provides a comprehensive overview of incident management in the


context of cyber crimes, emphasizing its role in cybersecurity, forensics, and risk
mitigation. Below, I'll break down the key concepts into structured sections for
clarity, drawing from the full chapter content. The explanations aim to connect
theoretical ideas with practical implications, highlighting how incident
management bridges technology, law, and organizational processes.

#### 1. **Objective and Scope**

- The chapter's goal is to explore cyber crime incidents from detection to


resolution, including reporting, investigation, forensics, and risk management. It
focuses on cyber-specific aspects like the absence of physical crime scenes, trans-
border nature of crimes, and the integration of digital evidence. Unlike physical
crimes, cyber incidents lack geographical boundaries, making management more
complex but critical for preventing recurrence.

- Key takeaway: Incident management is not just reactive (handling breaches)


but proactive (lessons learned to strengthen systems). It encompasses threats,
vulnerabilities, and risks, treating incidents as opportunities for improvement.
#### 2. **Meaning and Definition of Cyber Crime Incident**

- An "incident" is an unusual or unpleasant event contravening cyber norms, such


as data loss, unauthorized access, or system failure. It can range from minor (e.g.,
spam emails) to severe (e.g., data breaches like the 2014 Sony hack).

- Cyber incidents are unique: They are borderless, lack a physical scene, and can
be triggered remotely. Incident management covers the full lifecycle—from
detection to prevention—integrating organizational controls like ticketing systems.

- Conceptual link: Incidents are precursors to crimes; early identification


preserves information assets' value and mitigates adverse impacts.

#### 3. **Cyber Crimes Incident Management Process**

- Every incident follows a four-stage lifecycle (similar to PDCA cycle: Plan-Do-


Check-Act):

- **Stage I**: Occurrence, reporting (automatic/manual), receipt.

- **Stage II**: Classification (least/moderately/most critical), escalation, action


assignment.

- **Stage III**: Action initiation, resource allocation, completion with forensic


logs.

- **Stage IV**: Verification, lessons learned, corrective/preventive measures,


management review.

- ITIL phases include occurrence, detection, diagnostics, repair, recovery,


restoration, and closure.

- Practical insight: In banks, incidents align with RBI guidelines (e.g., fraud
classification under IPC sections like misappropriation or forgery). Fraud
management is a subset of incident management.

#### 4. **Types of Incidents**


- Classified by criticality (based on asset impact, industry type): Least (e.g.,
spam), moderate (e.g., small data leak), most (e.g., system failure or major breach
like Sony's).

- Influenced by asset classification (from Chapter 3). Monetary impacts are


handled via departments like Fraud Containment or Vigilance.

- RBI-specific: Frauds categorized (e.g., cheating, negligence); reporting


thresholds (e.g., <₹1 lakh, ₹1-25 lakh, >₹25 lakh).

- Higher-level note: Classification evolves; initial minor incidents can escalate


after impact analysis, requiring dynamic re-evaluation.

#### 5. **Reporting of an Incident**

- Critical first step: Uses ticketing systems for automation, generating logs for
forensics.

- Key details: Reporter's identity/capacity, timing, affected asset, how detected,


suggested remedies.

- Reporters can be employees, customers, observers, or "blue hat hackers"


(ethical hackers spotting vulnerabilities).

- Importance: Immediate reporting enables live data collection (e.g.,


host/network logs, volatile memory). Delays risk evidence loss.

- Conceptual nuance: In internet banking, reporter identity may be secondary to


breach severity; focuses on non-recurrence.

#### 6. **Investigation of an Incident**

- Systematic examination to uncover root causes (Root Cause Analysis). Involves


logs from OS, applications, users, networks.

- Art vs. Science: Science (process-driven, e.g., analyzing trails); Art (intuitive,
psychology-based, considering fraud triangle: need, opportunity, rationalization).
- Prerequisites: Knowledge of environment (OS logs, volatile/non-volatile
memory). Volatile data (in RAM) must be captured live.

- Network-based: Analyze NTP for timestamps, router/switch configs; challenges


with encryption, Trojans, DDoS.

- Advanced insight: Combines tech (tools like EnCase) with law (procedural
compliance) and psychology (fraudster rationalization).

#### 7. **Incident Management Life Cycle**

- Iterative PDCA-based: Plan (event prep), Do (action), Check (verify), Act


(adjust). Applies to every incident for continuous improvement.

- Aligns with ITIL: Focuses on restoring services post-disruption.

#### 8. **Digital Evidence**

- Probative info stored/transmitted electronically (e.g., files, audio, video).


Differs from physical: Easily duplicated, volatile, no visible "scene."

- Legal recognition in India: IT Act 2000 amends Evidence Act, IPC; accepts
digital records.

- Types: Active (user-shared), Passive (unintentional footprints like IP traces).

- Collection: From suspect/victim/third-party devices (e.g., CDRs, IMSI/IMEI


from mobiles). Follows Locard's Principle (perpetrator leaves/takes traces).

- Tools: EnCase (for imaging, hashing); C-DAC indigenous tools.

- Comparison with physical: Digital is intangible, requires experts for analysis;


risks like volatility demand immediate action.

#### 9. **Cyber Forensics**


- Science of identifying, seizing, authenticating, analyzing, documenting,
preserving digital evidence for court.

- Goal: Structured investigation with chain of custody to reconstruct events.

- Challenges: Nascent field, lacks standardization; mobile/wearable/IoT devices


complicate (diverse OS like Android, iOS).

- India-specific: CFSL Hyderabad handles govt. cases; C-DAC develops tools


(e.g., biometrics, honeynets).

- Higher-level: Integrates with incident response; used in non-judicial contexts


(e.g., HR behavior analysis).

#### 10. **Evidence Collection and Chain of Custody**

- No "scene"; evidence from circumstances (e.g., logs, live sessions).

- Chain of Custody: Chronological documentation ensuring integrity (e.g., hash


values to prevent tampering).

- Methods: Forensic imaging (bit-by-bit copies); handle volatiles first.

- Risks: Tamperability, loss during preservation/production.

#### 11. **Cyber Crime Risk Management**

- Risk = Threat × Vulnerability × Impact. Incidents highlight risks; management


involves aggregation of tools, processes, training.

- Threats in evidence: Reporter credibility, inadequacy, fraud misreporting,


preservation issues.

- Proactive: Improve detection, accelerate remediation (SANS guidelines).


Costs: Avg. data breach $3.79M (2015).

- Link to incidents: Reporting identifies risks before materialization.


#### 12. **Summary and Broader Implications**

- Incident management is essential for cyber crime prevention, forensics, and


legal compliance. It evolves with tech (e.g., IoT, wearables), requiring techno-legal
expertise.

- Key terms: Volatile memory, NTP, Blue Hat Hacking, Chain of Custody,
Locard's Principle, etc.

- Practical application: In banking/RBI contexts, aligns with fraud reporting;


globally, tools like EnCase ensure irrefutability.

This summary provides a holistic understanding, emphasizing interconnections


(e.g., forensics as subset of incident management). For deeper insight, the chapter
stresses real-world examples like Sony breach and RBI circulars.

### 80 Higher-Level MCQs with Answers

These MCQs are designed at a higher level, focusing on analysis, application,


evaluation, and synthesis rather than rote recall. They require understanding
concepts in context, comparing ideas, or applying to scenarios. Each has 4 options
(A-D); correct answer and brief explanation follow.

1. **In evaluating the trans-border nature of cyber incidents, how does the absence
of a physical crime scene challenge traditional investigative paradigms?**

A) It simplifies jurisdiction by limiting to digital logs.

B) It necessitates reliance on international treaties for evidence sharing.

C) It shifts focus from physical traces to network-based volatile data.


D) It eliminates the need for chain of custody.

**Answer: C**

*Explanation: Without a scene, investigation pivots to digital trails like NTP-


timed logs, challenging physical paradigms by emphasizing volatility and remote
access (analysis/application).*

2. **Synthesize how the PDCA cycle integrates with the four stages of incident
management to prevent recurrence in a banking fraud scenario.**

A) PDCA replaces stages, focusing solely on action.

B) Plan aligns with reporting, Do with action, Check with verification, Act with
preventive measures.

C) It ignores classification for faster escalation.

D) PDCA is irrelevant to cyber incidents.

**Answer: B**

*Explanation: In banking (e.g., RBI frauds), PDCA iterates: Planning reports,


Doing initiates, Checking verifies, Acting prevents, ensuring non-recurrence
(synthesis).*

3. **Analyze why initial classification of an incident as 'minor' might escalate,


using the Sony breach as an example.**

A) Due to immediate monetary loss assessment.

B) Post-impact study reveals broader involvement (e.g., staff/foreign hackers).

C) RBI guidelines mandate automatic escalation.

D) Volatile memory loss forces reclassification.

**Answer: B**
*Explanation: Sony started minor but escalated via detailed impact analysis,
highlighting dynamic classification based on root causes (analysis).*

4. **Evaluate the role of RBI master circulars in harmonizing incident reporting


with IPC offenses in private banks.**

A) They override bank policies entirely.

B) Provide classification (e.g., misappropriation) while allowing internal


guidelines.

C) Limit to public sector banks only.

D) Ignore cyber-specific incidents.

**Answer: B**

*Explanation: Circulars (e.g., 2015-16) classify frauds under IPC but permit
bank-customized procedures, ensuring compliance (evaluation).*

5. **Apply the concept of 'knee-jerk reaction' to a scenario where an eyewitness


reports a minor spam incident as a disaster.**

A) It leads to under-escalation.

B) Triggers over-reaction, misallocating resources.

C) Ensures immediate forensics.

D) Aligns with blue hat hacking.

**Answer: B**

*Explanation: Poor reporting formats cause exaggerated responses, wasting


resources on non-critical incidents (application).*
6. **Synthesize the importance of recording reporter details in internet banking
breaches, considering blue hat hackers.**

A) Reporter identity always determines credibility.

B) Focus on breach severity over reporter, but details aid forensics.

C) Ignores third-party reports.

D) Limits to employee reports.

**Answer: B**

*Explanation: Blue hat reports prioritize vulnerability; details like network


address enhance trails without over-relying on identity (synthesis).*

7. **Analyze why immediate reporting is crucial for volatile logs in a live system
during investigation.**

A) They persist post-shutdown.

B) Captures memory-based data before evaporation.

C) Simplifies non-volatile analysis.

D) Replaces root cause analysis.

**Answer: B**

*Explanation: Volatile data (RAM) is lost on shutdown, making timely capture


essential for forensics (analysis).*

8. **Evaluate investigation as 'art or science' in a fraud triangle scenario involving


rationalization.**

A) Pure science, ignoring psychology.

B) Art when intuition probes rationalization beyond logs.


C) Irrelevant to cyber crimes.

D) Science only for network incidents.

**Answer: B**

*Explanation: While process-driven (science), out-of-box thinking on fraudster


psychology makes it artistic (evaluation).*

9. **Apply NTP in investigating a network-based incident across time zones.**

A) Encrypts traffic for security.

B) Synchronizes timestamps for accurate access timing.

C) Replaces chain of custody.

D) Detects Trojans directly.

**Answer: B**

*Explanation: NTP ensures precise timing in remote accesses, aiding correlation


in trans-border crimes (application).*

10. **Synthesize challenges of encrypted traffic in network investigations


involving unlawful objectives.**

A) Encryption is always criminal.

B) Hinders decryption without keys, complicating evidence despite legality.

C) Simplifies DDoS detection.

D) Eliminates need for tools.

**Answer: B**

*Explanation: Legal encryption turns criminal if withheld, requiring tech-law


balance (synthesis).*
11. **Analyze how ITIL phases (e.g., diagnostics, repair) align with cyber incident
lifecycle.**

A) Focus only on restoration.

B) Diagnostics identifies characteristics; repair reconfigures attacked items.

C) Ignore occurrence.

D) Replace PDCA entirely.

**Answer: B**

*Explanation: ITIL complements lifecycle by emphasizing service restoration


post-disruption (analysis).*

12. **Evaluate digital evidence as 'probative information' in Indian courts post-IT


Act 2000.**

A) Still rejected due to volatility.

B) Gained recognition, amending Evidence Act for electronic records.

C) Limited to physical devices.

D) Requires US certification.

**Answer: B**

*Explanation: IT Act enables acceptance, overcoming initial reluctance with


enhanced awareness (evaluation).*

13. **Apply passive vs. active digital footprints in tracking a cyber stalker.**

A) Active: Shared emails; Passive: Unintentional IP logs.

B) Both require user consent.


C) Passive is always volatile.

D) Active eliminates trails.

**Answer: A**

*Explanation: Passive (unknown collection) aids covert tracking without


alerting stalker (application).*

14. **Synthesize role of CFSL Hyderabad in digital forensics for court cases.**

A) Handles only mobile evidence.

B) Analyzes storage devices, providing recorded views as irrefutable evidence.

C) Develops tools like EnCase.

D) Focuses on physical crimes.

**Answer: B**

*Explanation: As govt. lab, it processes hard disks/logs for judicial acceptance


(synthesis).*

15. **Analyze EnCase features for ensuring evidence integrity.**

A) Allows tampering for analysis.

B) Bit-by-bit imaging, time-stamping, non-tamperability.

C) Limited to mobiles.

D) Replaces legal procedures.

**Answer: B**

*Explanation: Features like hashing preserve originality, making it court-


acceptable (analysis).*
16. **Evaluate differences between physical and digital evidence in volatility.**

A) Physical is always volatile.

B) Digital (e.g., logs) evaporates quickly, requiring live capture.

C) Both duplicate easily.

D) Digital needs no experts.

**Answer: B**

*Explanation: Digital's volatility demands immediate action, unlike stable


physical objects (evaluation).*

17. **Apply Locard's Exchange Principle to a phishing attack investigation.**

A) Perpetrator leaves no digital traces.

B) Leaves logs (e.g., IP) or takes data, serving as evidence.

C) Applies only to physical scenes.

D) Ignores network access.

**Answer: B**

*Explanation: Principle extends to digital: Traces in victim/server logs


(application).*

18. **Synthesize evidence sources in cyber crimes beyond suspect/victim


devices.**

A) Limited to hardware.

B) Third-party (e.g., ISP logs, CDRs from mobile towers).

C) Exclude service providers.

D) Focus on volatiles only.


**Answer: B**

*Explanation: Intermediaries like towers provide IMSI/IMEI for comprehensive


trails (synthesis).*

19. **Analyze IMEI's role in mobile forensics.**

A) Identifies subscribers.

B) Unique handset ID, like vehicle registration, for tracing lost devices.

C) Stores data like SIM.

D) Synchronizes time.

**Answer: B**

*Explanation: Aids law enforcement in identifying hardware, complementing


IMSI (analysis).*

20. **Evaluate CDR utility in international cyber investigations.**

A) Limited to local calls.

B) Logs time, route, status for evidentiary correlation.

C) Volatile only.

D) Replaces NTP.

**Answer: B**

*Explanation: Provides detailed call metadata, crucial for trans-border timing


(evaluation).*

21. **Apply method of collecting digital evidence to preserve finger prints on


devices.**
A) Irrelevant, as focus is logical access.

B) Wrap in polythene, but prioritize network trails.

C) Destroy for analysis.

D) Use for volatiles only.

**Answer: B**

*Explanation: Physical handling preserves prints, but cyber emphasizes digital


integrity (application).*

22. **Synthesize C-DAC's contributions to Indian cyber forensics.**

A) Foreign tool imports.

B) Indigenous tools for biometrics, honeynets, mobile security.

C) Limited to academics.

D) Focus on physical evidence.

**Answer: B**

*Explanation: Develops end-point solutions, enhancing national capabilities


(synthesis).*

23. **Analyze challenges of evidence from spy devices in sting operations.**

A) Easily standardized.

B) Miniature, diverse OS; techno-legal complexity in extraction.

C) Always active footprints.

D) No chain of custody needed.

**Answer: B**
*Explanation: Devices like pen-cams complicate preservation due to non-
uniform tech (analysis).*

24. **Evaluate cyber forensics as nascent science in India.**

A) Fully standardized with certifications.

B) Lacks guidelines; driven by penal laws, academic courses theoretical.

C) Ignores mobiles.

D) US-based only.

**Answer: B**

*Explanation: Still developing, with tools like C-DAC filling gaps (evaluation).*

25. **Apply wearable technology in future cyber forensics scenarios.**

A) Irrelevant to IoT.

B) Embedded sensors store data for extraction in networked crimes.

C) Non-volatile only.

D) Simplifies evidence.

**Answer: B**

*Explanation: IoT integration means evidence from wearables like trackers


(application).*

26. **Synthesize chain of custody's role in digital vs. physical evidence.**

A) Identical processes.

B) Digital requires hashing for integrity, chronological logs.


C) Physical ignores documentation.

D) Digital omits access records.

**Answer: B**

*Explanation: Ensures non-tamperability through tech like SHA, facing cross-


examination (synthesis).*

27. **Analyze risks in evidence preservation for court production.**

A) Low due to duplication.

B) Tamperability, chain breaks; needs irrefutable hashing.

C) Ignores volatility.

D) Limited to reporting.

**Answer: B**

*Explanation: Risks run through lifecycle, mitigated by documentation


(analysis).*

28. **Evaluate proactive incident response per SANS guidelines.**

A) Reactive only.

B) Improves detection, containment to minimize damage.

C) Ignores HR training.

D) Focuses on costs alone.

**Answer: B**

*Explanation: Aggregates tools/processes for maturity, reducing breach costs


(evaluation).*
29. **Apply risk aggregation (threat × vulnerability × impact) to a DDoS
incident.**

A) Ignores impact.

B) Threat (attack tool), vulnerability (weak config), impact (downtime).

C) Excludes forensics.

D) Simplifies classification.

**Answer: B**

*Explanation: Identifies risks early in reporting for mitigation (application).*

30. **Synthesize how fraud management subsets incident management in banks.**

A) Frauds are unrelated.

B) All frauds start as incidents, but not vice versa; aligns with RBI.

C) Ignores vigilance.

D) Limits to minor incidents.

**Answer: B**

*Explanation: Broader incident process encompasses fraud containment


(synthesis).*

31. **Analyze why non-volatile memory gains importance in forensics.**

A) Always volatile.

B) Long-term storage for persistent evidence post-shutdown.

C) Replaces volatiles.

D) Limited to networks.
**Answer: B**

*Explanation: Preserves data unlike RAM, aiding retrieval (analysis).*

32. **Evaluate blue hat hacking's contribution to incident reporting.**

A) Malicious intent.

B) Ethical vulnerability spotting, triggering preventive action.

C) Ignores severity.

D) Replaces investigation.

**Answer: B**

*Explanation: Serves as third-party alarm, enhancing management


(evaluation).*

33. **Apply root cause analysis in a system failure incident.**

A) Ignores logs.

B) Examines trails to identify exact trigger for problem-solving.

C) Post-verification only.

D) Replaces classification.

**Answer: B**

*Explanation: Core of investigation, preventing recurrence (application).*

34. **Synthesize techno-legal issues in network-based incidents.**

A) Tech only.

B) Tools (Trojans) + law (unlawful deployment) complicate decryption.


C) Ignore encryption.

D) Simplify DDoS.

**Answer: B**

*Explanation: Deployment intent turns tools criminal (synthesis).*

35. **Analyze digital footprints in offline mode.**

A) Always active.

B) Stored in files for expert analysis (e.g., keyloggers).

C) No traces possible.

D) Volatile only.

**Answer: B**

*Explanation: Passive collection aids investigation without online access


(analysis).*

36. **Evaluate Indian courts' evolving acceptance of digital evidence.**

A) Total rejection.

B) Increased with IT Act, but needs irrefutability.

C) US standards required.

D) Physical preferred.

**Answer: B**

*Explanation: Waning reluctance, especially in higher courts (evaluation).*

37. **Apply telephonic instructions as evidence in disputes.**


A) Always binding without recording.

B) Recorded calls need irrefutable presentation for validity.

C) Ignore cross-examination.

D) Replace digital records.

**Answer: B**

*Explanation: Common in banks, but legal scrutiny demands chain of custody


(application).*

38. **Synthesize main features distinguishing digital from physical evidence.**

A) Identical volatility.

B) Digital: Duplicable, needs experts; Physical: Visible, stable.

C) Both non-scene based.

D) Digital ignores preservation.

**Answer: B**

*Explanation: Table in chapter highlights intangibility, requiring specialized


handling (synthesis).*

39. **Analyze why no 'place of crime' in cyber incidents complicates evidence


gathering.**

A) Simplifies to one location.

B) Evidence from circumstances, not spots (e.g., global servers).

C) Limits to victims.

D) Ignores third parties.

**Answer: B**
*Explanation: Shifts to contextual sources like CDRs (analysis).*

40. **Evaluate live evidence collection in DoS attacks.**

A) Post-shutdown only.

B) Crucial during active session for reliable trails.

C) Replaces documentation.

D) Volatile irrelevant.

**Answer: B**

*Explanation: Captures flowing traffic, enhancing judicial value (evaluation).*

41. **Apply procedural laws in seizing electronic documents via EnCase.**

A) No witnessing needed.

B) Document, witness, record for compliance.

C) Ignore hashing.

D) Physical only.

**Answer: B**

*Explanation: Ensures legal acceptability in India (application).*

42. **Synthesize C-DAC's role in national cyber security.**

A) Academic only.

B) Develops tools for intrusion detection, cloud security.

C) Imports from US.

D) Focus on physical.
**Answer: B**

*Explanation: Indigenous R&D under DeitY, addressing forensics gaps


(synthesis).*

43. **Analyze challenges of mobile forensics.**

A) Uniform OS.

B) Diverse OS (Android, iOS), complicating extraction.

C) No IMEI need.

D) Simpler than PC.

**Answer: B**

*Explanation: Variants require specialized tools (analysis).*

44. **Evaluate IoT's impact on future forensics.**

A) Reduces complexity.

B) Interconnects devices, expanding evidence sources but increasing risks.

C) Limits to wearables.

D) Ignores storage.

**Answer: B**

*Explanation: Data from diverse chips demands advanced methods


(evaluation).*

45. **Apply hash algorithms in chain of custody.**

A) Allow tampering.
B) Authenticate copies, retain integrity on viewing.

C) Volatile only.

D) Replace logs.

**Answer: B**

*Explanation: Ensures non-alteration for court (application).*

46. **Synthesize risks in cyber crime management lifecycle.**

A) Reporting only.

B) From credibility to production, including downtime/IP loss.

C) Ignore financials.

D) Low in banks.

**Answer: B**

*Explanation: Aggregates threats across stages, per Ponemon costs (synthesis).*

47. **Analyze proactive vs. reactive incident response.**

A) Reactive accelerates damage.

B) Proactive (tools/training) minimizes via early containment.

C) Identical.

D) Reactive ignores SANS.

**Answer: B**

*Explanation: SANS emphasizes detection for maturity (analysis).*

48. **Evaluate average data breach costs in risk context.**


A) Decreasing.

B) $3.79M (2015), highlighting need for preventive action.

C) Irrelevant to incidents.

D) Per record $1.

**Answer: B**

*Explanation: Drives proactive systems to reduce impact (evaluation).*

49. **Apply corrective/preventive action in stage IV.**

A) Ignores lessons.

B) Ensures non-recurrence via reviews.

C) Reporting only.

D) Replaces investigation.

**Answer: B**

*Explanation: Post-verification, aligns with PDCA Act (application).*

50. **Synthesize fraud classification under RBI as subset of incidents.**

A) All incidents are frauds.

B) Frauds (e.g., cheating) are incidents, but incidents include non-frauds like
spam.

C) Ignore IPC.

D) Public banks only.

**Answer: B**

*Explanation: Broader management encompasses containment (synthesis).*


51. **Analyze why ticketing systems are vital in reporting.**

A) Manual only.

B) Automate logs, aid efficiency checks/forensics.

C) Ignore details.

D) Replace escalation.

**Answer: B**

*Explanation: Creates trails for management review (analysis).*

52. **Evaluate OS logs in Unix servers for critical incidents.**

A) Irrelevant.

B) Login/user files crucial for root cause.

C) Volatile only.

D) Network ignore.

**Answer: B**

*Explanation: Environment knowledge essential for finesse (evaluation).*

53. **Apply steganography tools in investigations.**

A) Always legal.

B) Unlawful if hiding data; requires decryption knowledge.

C) Simplify evidence.

D) Physical only.

**Answer: B**
*Explanation: Intent determines criminality (application).*

54. **Synthesize digital forensics as superset of evidence management.**

A) Subset.

B) Encompasses uncovering/interpreting for reconstruction.

C) Ignore judicial.

D) Physical focus.

**Answer: B**

*Explanation: Broader science including preservation (synthesis).*

55. **Analyze NIST's role in forensic standards.**

A) Indian only.

B) Publications like integration guides for responses.

C) Rejects digital.

D) Tools development.

**Answer: B**

*Explanation: Efforts for irrefutability, influencing global practices (analysis).*

56. **Evaluate telephonic records as binding evidence.**

A) Without dispute.

B) Need irrefutable presentation/cross-exam.

C) Ignore recording.

D) Replace emails.
**Answer: B**

*Explanation: Common but scrutinized legally (evaluation).*

57. **Apply keyloggers in passive footprinting.**

A) Active only.

B) Capture unintentional data for analysis.

C) No files.

D) Online only.

**Answer: B**

*Explanation: Stores offline for experts (application).*

58. **Synthesize EnCase's mobile module.**

A) PC only.

B) Separate for device evidence extraction.

C) Ignores hashing.

D) Physical prints.

**Answer: B**

*Explanation: Complements hard-disk forensics (synthesis).*

59. **Analyze why digital evidence duplication is advantageous yet challenging.**

A) Distinguishes originals.

B) Easy spread, but copies indistinguishable from originals.

C) Reduces volatility.
D) Ignores networks.

**Answer: B**

*Explanation: Aids transmission but complicates authenticity (analysis).*

60. **Evaluate expert assistance in digital vs. physical evidence.**

A) Physical needs more.

B) Digital requires for systemic logs understanding.

C) Both none.

D) Digital simplifies.

**Answer: B**

*Explanation: Technical nature demands specialists (evaluation).*

61. **Apply no 'scene' concept to email hacking scenario.**

A) Limit to victim's PC.

B) Evidence from servers, providers, not physical spots.

C) Ignore circumstances.

D) Simplify jurisdiction.

**Answer: B**

*Explanation: Contextual gathering (application).*

62. **Synthesize live evidence value in DDoS.**

A) Post-attack only.

B) Captures session for reliable, legal trails.


C) Volatile ignore.

D) Replaces CDRs.

**Answer: B**

*Explanation: Enhances evidentiary mechanism (synthesis).*

63. **Analyze C-DAC's honeynet systems.**

A) Physical security.

B) Distributed for intelligence on attacks.

C) Academic only.

D) Ignore cloud.

**Answer: B**

*Explanation: Critical for intrusion gathering (analysis).*

64. **Evaluate wearable tech in IoT forensics.**

A) Standalone.

B) Interconnected data sources complicate but enrich evidence.

C) No sensors.

D) Reduce popularity.

**Answer: B**

*Explanation: Future complexity in extraction (evaluation).*

65. **Apply hashing in evidence viewing.**

A) Permits changes.
B) Records access without alteration.

C) Volatile only.

D) Ignores integrity.

**Answer: B**

*Explanation: Maintains chain for multiple views (application).*

66. **Synthesize reporter credibility as risk in management.**

A) Ignore in reporting.

B) Part of threats turning to risks if unreliable.

C) Low impact.

D) Physical only.

**Answer: B**

*Explanation: Aggregates with inadequacy for lifecycle (synthesis).*

67. **Analyze SANS white paper on incident maturity.**

A) Financial only.

B) Detection, containment, minimization ingredients.

C) Reactive focus.

D) Ignore tools.

**Answer: B**

*Explanation: Proactive approach summary (analysis).*

68. **Evaluate breach cost rise (23% to $3.79M in 2015).**


A) Decreasing records.

B) Underscores need for remediation backups.

C) Ignore IP loss.

D) Per record $154 irrelevant.

**Answer: B**

*Explanation: Highlights economic risks (evaluation).*

69. **Apply preventive action in disaster incidents.**

A) Post only.

B) Triggers recovery procedures to avoid repeats.

C) Ignore reviews.

D) Classification omit.

**Answer: B**

*Explanation: Stage IV ensures (application).*

70. **Synthesize cyber crime as trans-border in incident context.**

A) Physical barriers.

B) No scene, remote triggering complicates reporting.

C) Local only.

D) Ignore NTP.

**Answer: B**

*Explanation: Unique nature demands global tools (synthesis).*


71. **Analyze fraud triangle in artistic investigation.**

A) Science ignore.

B) Probes rationalization intuitively.

C) Opportunity only.

D) Replaces logs.

**Answer: B**

*Explanation: Beyond systematic, psychological (analysis).*

72. **Evaluate NIST guide in incident responses.**

A) Rejection.

B) Integrates forensics techniques.

C) Indian only.

D) Physical focus.

**Answer: B**

*Explanation: Standards for irrefutability (evaluation).*

73. **Apply active footprints in sharing scenarios.**

A) Unintentional.

B) User-released for purpose, aiding traces.

C) No IP.

D) Offline only.

**Answer: B**

*Explanation: Intentional data for investigation (application).*


74. **Synthesize CFSL's views in courts.**

A) Rejected.

B) Recorded as expert on devices.

C) Tools only.

D) Academic.

**Answer: B**

*Explanation: Govt. lab for judicial (synthesis).*

75. **Analyze bit-by-bit extraction in EnCase.**

A) Alters original.

B) Creates forensic images without impact.

C) Mobiles ignore.

D) No stamping.

**Answer: B**

*Explanation: Preserves integrity (analysis).*

76. **Evaluate expert need in systemic logs.**

A) Layperson sufficient.

B) For understanding/generated data.

C) Physical equal.

D) Reduce in digital.

**Answer: B**
*Explanation: Complexity demands (evaluation).*

77. **Apply circumstantial evidence in no-scene crimes.**

A) Ignore.

B) Guides to sources like providers.

C) Physical only.

D) Simplify.

**Answer: B**

*Explanation: Contextual for gathering (application).*

78. **Synthesize mobile tower logs (CDRs) in evidence.**

A) Local only.

B) Vital metadata for routes/status.

C) Volatile.

D) Replace IMEI.

**Answer: B**

*Explanation: Complements IMSI for trails (synthesis).*

79. **Analyze spy devices' forensic challenges.**

A) Large size.

B) Miniature, audio/video complicate legal extraction.

C) Uniform.

D) No sting.
**Answer: B**

*Explanation: Diverse, procedural (analysis).*

80. **Evaluate IoT's forensic complexity.**

A) Simplifies.

B) Diverse devices/OS increase evidence but risks.

C) Wearables ignore.

D) Reduce popularity.

**Answer: B**

*Explanation: Future demands advanced tools (evaluation).*

You might also like