Total Marks: 100
Duration: 2 Hours
Student Name: ________________________________
Student ID: _________________________________
Class: ______________________________________
Date: _______________________________________
Instructor: _________________________________
1. Digital Forensics is the process of:
2. Which of the following is digital evidence?
3. Which memory loses data when power is switched off?
4. Which tool is commonly used to create a forensic image?
5. Hash values are used to:
6. A Chain of Custody is:
7. Which of the following is volatile evidence?
8. Which device is commonly examined during a digital forensic investigation?
9. A forensic image is:
10. Which file system is commonly used by Microsoft Windows?
11. Metadata is:
12. Which stage follows evidence collection?
13. The first priority at a digital crime scene is to:
14. A write blocker is used to:
15. Which professional conducts digital forensic investigations?
16. Which of the following is a cybercrime?
17. Which storage device permanently stores data?
18. Which of the following is a source of digital evidence?
19. Evidence integrity means:
20. The final stage of a digital forensic investigation is:
Answer the following using ONE WORD ONLY.
1. The process of creating an exact copy of a storage device. ________________________
2. Memory that loses data when power is removed. ________________________
3. A unique digital fingerprint of a file. ________________________
4. Data that describes other data. ________________________
5. A person who investigates digital crimes. ________________________
6. A document used to record evidence handling. ________________________
7. Device used to prevent changes to storage media. ________________________
8. Portable storage device commonly used to transfer files. ________________________
9. The examination of digital evidence is called ________________________
10. The process of recovering deleted information. ________________________
Answer ALL questions.
1. Define Digital Forensics. (4 Marks)
2. Explain the importance of preserving digital evidence. (4 Marks)
3. Differentiate between volatile evidence and non-volatile evidence. (4 Marks)
4. Explain the importance of hashing in a digital forensic investigation. (4 Marks)
5. Describe the responsibilities of a Digital Forensic Investigator. (4 Marks)
Instructions:
A company has discovered that confidential business documents were copied onto a USB flash drive without authorization before an employee resigned.
a) Identify five (5) pieces of digital evidence you would collect during the investigation. (5 Marks)
b) Explain the forensic investigation process you would follow from the time the incident is reported until the final report is produced. (10 Marks)
c) Explain why maintaining the Chain of Custody is important during this investigation. (5 Marks)
A university student reports that someone gained unauthorized access to their email account and used it to send fraudulent emails to lecturers and classmates.
a) Explain how you would investigate the incident. (10 Marks)
b) Identify five (5) sources of digital evidence you would collect. (5 Marks)
c) Recommend five (5) security measures that could prevent similar incidents. (5 Marks)
An employee intentionally deleted important company financial records before leaving the organization.
a) Explain how you would recover and analyse the deleted files. (10 Marks)
b) State five (5) possible sources of digital evidence. (5 Marks)
c) Explain why forensic imaging should be performed before analysing the storage device. (5 Marks)
Police recover a suspect's smartphone believed to contain evidence linked to cybercrime.
a) Explain how you would preserve and examine the smartphone without altering the evidence. (10 Marks)
b) Identify five (5) types of digital evidence that may be recovered from the smartphone. (5 Marks)
c) Explain why evidence integrity is important in court proceedings. (5 Marks)
A hospital has suffered a ransomware attack that encrypted patient records and disrupted normal operations.
a) Describe the steps you would take to investigate the ransomware attack. (10 Marks)
b) Identify five (5) sources of digital evidence you would examine. (5 Marks)
c) Recommend five (5) cybersecurity measures that the hospital should implement to prevent future ransomware attacks. (5 Marks)