Skip to content
Digital ForensicseasyFree

Digital Forensics: Foundations and Core Vocabulary

Published:

Reviewed by Sourabh · 19 May 2026

Questions

30

Duration

30 min

Faculty-reviewed

30

Updated

27 Apr 2026

Score, per-question explanations and topic breakdown shown right after you submit.

About this mock

This mock covers the foundational concepts and vocabulary every digital forensics student must know — the building blocks of every later course, every exam paper, and every real investigation. Thirty questions across storage and memory, the order of volatility, write blockers, forensic imaging, hashing for integrity, file systems (NTFS, ext4, APFS, FAT), chain of custody, first-responder procedures, Faraday bags, and the routine artefacts (Windows Registry, event logs, browser cache, email headers) that turn raw devices into evidence.

It is pitched at BSc and first-year MSc cyber forensics students at NFSU, LNJN-NICFS and other Indian universities, and at FACT or UGC-NET aspirants who need the introductory layer locked in before tackling case law, tool-specific procedure, and reconstruction. If you can pass this mock comfortably, you have the vocabulary for every advanced cyber-forensics topic that follows.

Topics covered:

  • Volatile vs non-volatile memory and the order of volatility (RFC 3227)
  • Write blockers and why they matter for evidence integrity
  • Forensic imaging, hashing (MD5, SHA-256), and the EnCase E01 format
  • Chain of custody — what it is, what breaks it
  • First-responder priorities and the Faraday-bag rule for mobile devices
  • File system fundamentals: NTFS, FAT, ext4, APFS — what each is used for
  • Slack space, unallocated space, and what deleted-file recovery actually does
  • The everyday artefacts: Windows Registry, event logs, browser cache, cookies, email headers
  • Mobile basics: IMEI vs IMSI, logical vs physical acquisition

Each question has a detailed explanation citing the relevant RFC, NIST publication, vendor documentation or standard textbook (Carrier, Casey, Nelson). Allow 30 minutes when you take the timed version. The explanations are long enough to use as study notes by themselves; even if you skip the timed run, reading through them once is a complete refresher.

Sources & references

Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.

  • ACPO Good Practice Guide for Digital Evidence

    Section on Mobile Device Seizure

    cited in 3 questions
  • Carrier, Brian — File System Forensic Analysis

    Chapter 2: Computer Foundations

    cited in 3 questions
  • RFC 3227 — Guidelines for Evidence Collection and Archiving

    Section 2.1: Order of Volatility

    Open source
    cited in 2 questions
  • NIJ Electronic Crime Scene Investigation: A Guide for First Responders

    Section 3: Securing and Evaluating the Scene

    cited in 2 questions
  • Nelson, Phillips, Steuart — Guide to Computer Forensics and Investigations

    Chapter 4: Data Acquisition (write blocker section)

    cited in 2 questions
  • Casey, Eoghan — Digital Evidence and Computer Crime

    3rd Edition, Chapter 1 (definition and scope)

    cited in 2 questions
  • NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response

    Section 4.2.2: Validating Data Integrity

    cited in 2 questions
  • The Linux Programming Interface — Michael Kerrisk

    Chapter 18: Directories and Links (filename conventions)

    cited in 1 question
  • Apple Developer Documentation — Apple File System Reference

    Concepts and Terminology

    Open source
    cited in 1 question
  • 3GPP TS 23.003 — Numbering, addressing and identification

    Section 6: International Mobile Equipment Identity (IMEI)

    cited in 1 question
  • NIST SP 800-101 Rev. 1 — Guidelines on Mobile Device Forensics

    Section 5: Forensic Tool Classification System (logical vs physical)

    Open source
    cited in 1 question
  • Carvey, Harlan — Windows Registry Forensics

    Chapter 1: Registry Analysis (overview and structure)

    cited in 1 question
  • Microsoft Documentation — Windows Event Logging

    Event log architecture and EVTX format

    cited in 1 question
  • RFC 6265 — HTTP State Management Mechanism

    Section 1: Introduction (cookie purpose and structure)

    Open source
    cited in 1 question
  • RFC 5322 — Internet Message Format

    Section 3.6.7: Trace Fields

    Open source
    cited in 1 question
  • libewf — Expert Witness Format Specification

    EWF format reference

    Open source
    cited in 1 question
  • Linux Kernel Documentation — ext4 Filesystem

    Documentation/filesystems/ext4.rst

    Open source
    cited in 1 question
  • UEFI Specification, version 2.10

    Chapter 2: Overview (boot manager workflow)

    Open source
    cited in 1 question
  • Microsoft Documentation — NTFS Overview

    NTFS file system technical reference

    cited in 1 question
  • Volatility Foundation Documentation

    Memory acquisition file formats

    Open source
    cited in 1 question
  • NIST FIPS PUB 180-4 — Secure Hash Standard

    Section 6: SHA-256 specification

    Open source
    cited in 1 question

How our mocks are built

Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.

Common questions

What does the Digital Forensics: Foundations and Core Vocabulary mock cover?+

This mock covers the foundational concepts and vocabulary every digital forensics student must know — the building blocks of every later course, every exam paper, and every real investigation. Thirty questions across storage and memory, the order of volatility, write blockers, forensic imaging, hashing for integrity, file systems (NTFS, ext4, APFS, FAT), chain of custody, first-responder procedures, Faraday bags, and the routine artefacts (Windows Registry, event logs, browser cache, email heade

How many questions and how long is the test?+

30 multiple-choice questions, 30 minutes total. Difficulty: easy. Tier: Free.

Who is this mock for?+

Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Digital Forensics, NET. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.

Are the questions reviewed?+

Yes — 30 of 30 questions are faculty-reviewed. Each question carries a verified source citation.

Do I need an account to take this mock?+

Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.

Browse more mocks

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.