Skip to content
Cyber Forensicshard Premium

Cyber Forensics: File Systems, Artifacts and Timeline Analysis

Published:

Reviewed by Bismith B · 11 Jun 2026

Questions

30

Duration

30 min

Faculty-reviewed

0

Updated

09 Jun 2026

Score, per-question explanations and topic breakdown shown right after you submit.

About this mock

This test covers the internals of FAT, NTFS and ext file systems as they apply to digital investigations: how metadata structures record file activity, how deleted files survive for recovery, and the mechanics of file carving and slack space analysis. It then turns to the rich artifact ecosystem on Windows systems, including the registry, prefetch files, the Master File Table, LNK files, browser history databases, and email storage formats. The final section addresses timeline construction and super-timeline analysis, the tools used to correlate artifacts across sources, and the anti-forensic techniques investigators routinely encounter. Questions are framed as applied scenarios and comparisons, requiring you to reason about what evidence survives, why it survives, and how an investigator would interpret it. A working knowledge of file-system data structures and forensic tooling is assumed throughout.

Sources & references

Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.

  • File System Forensic Analysis

    Brian Carrier, Chapter 14: Ext2 and Ext3 Concepts

    cited in 11 questions
  • Windows Forensic Analysis Toolkit

    Harlan Carvey, Chapter on AmCache and Program Execution

    cited in 6 questions
  • Digital Forensics with Open Source Tools

    Altheide and Carvey, Chapter on Internet and Browser Forensics

    cited in 6 questions
  • Windows Registry Forensics

    Harlan Carvey, Chapter on User Activity

    cited in 5 questions
  • Handbook of Digital Forensics and Investigation

    Eoghan Casey (ed.), Chapter on Anti-Forensics and Steganography

    cited in 2 questions

How our mocks are built

Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.

Common questions

What does the Cyber Forensics: File Systems, Artifacts and Timeline Analysis mock cover?+

This test covers the internals of FAT, NTFS and ext file systems as they apply to digital investigations: how metadata structures record file activity, how deleted files survive for recovery, and the mechanics of file carving and slack space analysis. It then turns to the rich artifact ecosystem on Windows systems, including the registry, prefetch files, the Master File Table, LNK files, browser history databases, and email storage formats. The final section addresses timeline construction and s

How many questions and how long is the test?+

30 multiple-choice questions, 30 minutes total. Difficulty: hard. Tier: Premium.

Who is this mock for?+

Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Cyber Forensics. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.

Are the questions reviewed?+

Each question carries a verified source citation. Faculty review for individual questions is in progress.

Do I need an account to take this mock?+

Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.