1.
What is the First Step required in preparing a computer for forensics investigation?
2.
Network forensics can be defined as the sniffing, recording, acquisition and analysis of the network traffic and event logs in order to investigate a network security incident.
3.
Which of the following commands shows you the names of all open shared files on a server and number of file locks on each file?
4.
Email archiving is a systematic approach to save and protect the data contained in emails so that it can be accessed fast at a later date. There are two main archive types, namely Local Archive and Server Storage Archive. Which of the following statements is correct while dealing with local archives?
5.
Which of the following email headers specifies an address for mailer-generated errors, like no such user bounce messages, to go to (instead of the sender's address)?
6.
Which of the following commands shows you all of the network services running on Windows- based servers?

 
7.
Email archiving is a systematic approach to save and protect the data contained in emails so that it can tie easily accessed at a later date.
8.
Windows Security Accounts Manager (SAM) is a registry file which stores passwords in a hashed format. SAM file in Windows is located at:
9.
FAT32 is a 32-bit version of FAT file system using smaller clusters and results in efficient storage capacity. What is the maximum drive size supported?
10.
In which step of the computer forensics investigation methodology would you run MD5 checksum on the evidence?