IT INTERNATIONAL ACADEMY

ASSESSMENT 1

Programme: Cyber Security

Course: Digital Forensics

Total Marks: 100

Duration: 2 Hours

Student Name: ________________________________

Student ID: _________________________________

Class: ______________________________________

Date: _______________________________________

Instructor: _________________________________

INSTRUCTIONS
SECTION A
Multiple Choice Questions (20 Marks)

1. Digital Forensics is the process of:

A. Developing Software

B. Investigating and analysing digital evidence

C. Installing Operating Systems

D. Designing Websites

2. Which of the following is digital evidence?

A. Notebook

B. USB Flash Drive

C. Pen

D. Calculator

3. Which memory loses data when power is switched off?

A. SSD

B. RAM

C. Hard Disk

D. DVD

4. Which tool is commonly used to create a forensic image?

A. Microsoft Word

B. FTK Imager

C. Paint

D. Excel

5. Hash values are used to:

A. Delete files

B. Verify evidence integrity

C. Compress files

D. Encrypt folders

6. A Chain of Custody is:

A. Antivirus Software

B. Evidence handling record

C. Password Manager

D. Firewall

7. Which of the following is volatile evidence?

A. RAM

B. Hard Disk

C. DVD

D. USB Drive

8. Which device is commonly examined during a digital forensic investigation?

A. Smartphone

B. Laptop

C. USB Flash Drive

D. All of the above

9. A forensic image is:

A. A screenshot

B. A bit-by-bit copy of storage media

C. A photograph

D. A scanned document

10. Which file system is commonly used by Microsoft Windows?

A. EXT4

B. APFS

C. NTFS

D. HFS+

11. Metadata is:

A. Data about data

B. Deleted data

C. Malware

D. Passwords

12. Which stage follows evidence collection?

A. Formatting

B. Analysis

C. Printing

D. Installation

13. The first priority at a digital crime scene is to:

A. Restart the computer

B. Preserve the evidence

C. Delete suspicious files

D. Install antivirus software

14. A write blocker is used to:

A. Prevent modification of evidence

B. Speed up the computer

C. Install software

D. Remove viruses

15. Which professional conducts digital forensic investigations?

A. Accountant

B. Teacher

C. Digital Forensic Investigator

D. Electrician

16. Which of the following is a cybercrime?

A. Phishing

B. Hacking

C. Identity Theft

D. All of the above

17. Which storage device permanently stores data?

A. RAM

B. Hard Disk

C. Cache Memory

D. CPU

18. Which of the following is a source of digital evidence?

A. CCTV System

B. Smartphone

C. Computer

D. All of the above

19. Evidence integrity means:

A. Evidence has not been altered

B. Evidence has been deleted

C. Evidence has been compressed

D. Evidence has been encrypted

20. The final stage of a digital forensic investigation is:

A. Reporting

B. Imaging

C. Collection

D. Preservation

SECTION B
ONE WORD ANSWERS (20 Marks)

Answer the following using ONE WORD ONLY.

1. The process of creating an exact copy of a storage device. ________________________

2. Memory that loses data when power is removed. ________________________

3. A unique digital fingerprint of a file. ________________________

4. Data that describes other data. ________________________

5. A person who investigates digital crimes. ________________________

6. A document used to record evidence handling. ________________________

7. Device used to prevent changes to storage media. ________________________

8. Portable storage device commonly used to transfer files. ________________________

9. The examination of digital evidence is called ________________________

10. The process of recovering deleted information. ________________________

SECTION C
SHORT ESSAY QUESTIONS (20 Marks)

Answer ALL questions.

1. Define Digital Forensics. (4 Marks)


2. Explain the importance of preserving digital evidence. (4 Marks)


3. Differentiate between volatile evidence and non-volatile evidence. (4 Marks)


4. Explain the importance of hashing in a digital forensic investigation. (4 Marks)


5. Describe the responsibilities of a Digital Forensic Investigator. (4 Marks)

SECTION D
SCENARIO-BASED QUESTIONS (40 Marks)

Instructions:

QUESTION 1 (COMPULSORY) – 20 Marks

A company has discovered that confidential business documents were copied onto a USB flash drive without authorization before an employee resigned.


a) Identify five (5) pieces of digital evidence you would collect during the investigation. (5 Marks)


b) Explain the forensic investigation process you would follow from the time the incident is reported until the final report is produced. (10 Marks)


c) Explain why maintaining the Chain of Custody is important during this investigation. (5 Marks)

QUESTION 2 – 20 Marks

A university student reports that someone gained unauthorized access to their email account and used it to send fraudulent emails to lecturers and classmates.


a) Explain how you would investigate the incident. (10 Marks)


b) Identify five (5) sources of digital evidence you would collect. (5 Marks)


c) Recommend five (5) security measures that could prevent similar incidents. (5 Marks)

QUESTION 3 – 20 Marks

An employee intentionally deleted important company financial records before leaving the organization.


a) Explain how you would recover and analyse the deleted files. (10 Marks)


b) State five (5) possible sources of digital evidence. (5 Marks)


c) Explain why forensic imaging should be performed before analysing the storage device. (5 Marks)

QUESTION 4 – 20 Marks

Police recover a suspect's smartphone believed to contain evidence linked to cybercrime.


a) Explain how you would preserve and examine the smartphone without altering the evidence. (10 Marks)


b) Identify five (5) types of digital evidence that may be recovered from the smartphone. (5 Marks)


c) Explain why evidence integrity is important in court proceedings. (5 Marks)

QUESTION 5 – 20 Marks

A hospital has suffered a ransomware attack that encrypted patient records and disrupted normal operations.


a) Describe the steps you would take to investigate the ransomware attack. (10 Marks)


b) Identify five (5) sources of digital evidence you would examine. (5 Marks)


c) Recommend five (5) cybersecurity measures that the hospital should implement to prevent future ransomware attacks. (5 Marks)

IT INTERNATIONAL ACADEMY

Programme: Cyber Security
Course: Digital Forensics
Assessment 1

***** END OF QUESTION PAPER *****