Digital Evidence
File Systems
Memory & Malware
Network Forensics
Tools & Investigation
100

What is Chain of Custody?

This process ensures digital evidence remains unaltered from collection to presentation.

100

This is the default Windows file system

What is NTFS?

100

This type of memory loses its contents when power is removed

What is RAM?

100

This protocol translates domain names into IP addresses.

What is DNS?

100

This commercial tool is widely used for digital forensic investigations.

What is EnCase?

200

What are hash values (MD5, SHA-1, SHA-256)?

These cryptographic values verify that evidence has not changed

200

Deleted file information can often remain in this area until overwritten

What is unallocated space?

200

This forensic technique captures volatile memory before shutdown.

What is memory acquisition?

200

This protocol is commonly used to capture web traffic.

What is HTTP?

200

This open-source suite developed by Sleuth Kit provides forensic analysis.

Question: What is Autopsy?

300

What is a forensic image?

This is an exact bit-for-bit copy of a storage device

300

The NTFS database containing file metadata.

What is the Master File Table (MFT)?

300

This framework is commonly used to analyze RAM dumps

What is Volatility?

300

This tool is widely used for packet capture and analysis.

What is Wireshark?

300

This command-line Linux utility creates forensic disk images.

What is dd?

400

This hardware device prevents writes to the original storage media during acquisition.

What is a write blocker?

400

This NTFS file records filesystem changes for recovery purposes.

What is the USN Journal?

400

Malware that hides its presence by modifying operating system behavior is called this

What is a rootkit?

400

This protocol securely encrypts web communications.

What is HTTPS (TLS)?

400

This file format is commonly used to store memory dumps in Windows.

What is .dmp?

500

This legal principle requires evidence to be collected in a manner that preserves admissibility in court.

What is forensic soundness?

500

Slack space refers to this unused portion of a storage allocation unit.

What is the unused space between the end of a file and the end of its allocated cluster?

500

This malware technique injects malicious code into legitimate processes to evade detection.

What is process injection?

500

The three steps of the TCP connection setup are SYN, SYN-ACK, and this.

What is ACK?

500

This investigative methodology reconstructs events based on timestamps from multiple sources.

What is timeline analysis?

M
e
n
u