Browse all practice questions for the Cybercrime Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Hack the Cybercrime Test 2026 – Unleash Your Inner Cyber Sleuth! course image
All questions

These questions are part of the practice quiz. Start practicing

  • In cybercrime investigations, why is MLAT important?
  • Differences between IP and MAC addresses?
  • Which practice most directly supports evidence integrity in digital forensics?
  • What is NOT a category of threats to information systems?
  • NOT be considered part of a formal risk analysis?
  • According to the data, what percentage of local police agencies experienced a measurable increase in reporting computer and electronic crimes?
  • Which layer corresponds to 'user' in the described layer scheme?
  • The term describing the growing inability of federal law enforcement to collect evidence from electronic communications over the Web is called what?
  • The best source for technical information needed in a network investigation is:
  • IC3 is operated in partnership with which federal agency?
  • Which statement about MAC addresses is correct?
  • Which of the following would NOT be considered one of the three commonly cited malware types in this material?
  • Describe a basic ransomware lifecycle from initial access to recovery options.
  • The most important critical need among local law enforcement agencies is which of the following?
  • Who is the chief law enforcement officer of the U.S. federal government?
  • What is zero-day vulnerability?
  • CCIP collaborates with which department in the prosecution of computer crimes?
  • Which layer is described as 'Provides checkpoint, fall back, and encryption services (e.g., SSL)'?
  • In forensics, what is the purpose of image verification?
  • In the future, terrorists will likely use all of the following tactics, except:
  • If an investigator finds a computer that is turned off during a search with a warrant, what should be done?
  • Which statement accurately contrasts defense in depth with a single point of failure in security architecture?
  • When collecting data during a live incident, which data type should be prioritized due to volatility?
  • Which OSI layer is responsible for establishing, managing, and terminating connections between applications across a network?
  • The disparity in equipment between federal and local cyber cops is most clearly seen in the inability of most local agencies to do what?
  • Which crime scene is the most complex to investigate?
  • Which statement correctly describes training in computer crime for patrol personnel in local agencies?
  • Name a standard forensic principle for ensuring evidence reliability.
  • Which OSI layer is primarily concerned with encoding and modulation of signals on the transmission medium?
  • DNS tunneling is used for what purpose in cybercrime?
  • What is the evolution in IT technology often referred to as the next generation of firewall technology?
  • Which statement best describes the FBI's public sector partnerships?
  • Which statement best distinguishes authentication from authorization?
  • Which term describes a private network that uses TCP/IP and is restricted to members of an organization?
  • Based on the material, which statement best captures the overall projected trend in cybercrime?
  • Which of the following is the largest computer crime problem affecting local law enforcement with the largest number of victims?
  • Which statement best describes ransomware?
  • The most pressing computer crimes enforced by local law enforcement agencies appear to be those related to which category?
  • Which statement best describes the evidence of disparity between federal and local equipment?
  • Terrorist groups will likely use computers and networks for all of the following except:
  • What is a cryptographic hash and why is it used in digital forensics?
  • NOT a limitation in risk analysis for early computing?
  • Approximately ___% of the population is covered by NIBRS reporting.
  • Memory forensics focuses on analyzing volatile memory. Which artifacts can RAM reveal?
  • Which statement about sources of federal contact information for local investigators is accurate?
  • Regarding current organized crime groups, which statement is true?
  • Which statement best reflects online privacy and harassment?
  • What is GDPR and one major principle it enforces?
  • What term describes devices or software that act as a checkpoint between the network and individual users?
  • Name three common sources of digital evidence in a corporate investigation.
  • The National Cyber Response Coordination Group is composed of how many federal agencies that respond to cyber-attacks?
  • ___________________ are the most important security measure a company or individual can take.
  • Which artifact is most useful for establishing who accessed a system and when?
  • Which layer is described as 'Provides direct interaction with the user (e.g., Explorer, Firefox, Chrome)'?
  • Which term describes the disparity in equipment between federal and local cyber personnel?
  • The largest and primary investigative arm of the U.S. Department of Homeland Security is which agency?
  • Which social engineering technique involves creating a fabricated scenario to obtain information?
  • The entity that provides victims of Internet fraud with a mechanism to report suspicious online activities is known as which?
  • Which of the following is a widely used authentication technology?
  • A sector-by-sector copy preserves what aspect of data that a simple file copy might not?
  • Which of the following is a logging best practice for incident detection?
  • Which entity is described as responsible for the storage of evidence until the time of trial?
  • What is the data minimization principle in GDPR and why does it matter in cybercrime investigations?
  • What is phishing and how does spear phishing differ from general phishing?
  • Which statement about joint investigations involving the U.S. Postal Service is accurate?
  • Which agency coordinates federal emergency management and is associated with the DHS?
  • Which of the following is not a division of the Bureau of Consumer Protection within the FTC?
  • The most effective tool for dealing with Internet fraud is:
  • Bitcoins are not an anonymous form of electronic payment.
  • Threats to ______________ are threats that actually alter data.
  • Which statement best characterizes the modern trend among organized crime groups with respect to technology?
  • When storing computer evidence, which of the following should be recorded?
  • Which of the following is an Indicator of Compromise (IOC)?
  • Which address type is used to uniquely identify a device on the local network?
  • IC3 is operated in partnership with which federal agency?
  • Define zero trust security and its core principle.
  • What factors have limited the ability of local law enforcement to respond to the growing threat of computer crime?
  • What is "log retention policy" and its role in cybercrime investigations?
  • Which statement is LEAST true about online harassment and privacy?
  • Which layer is described as 'Provides unique addressing for transmission across different networks (e.g., IP)'?
  • What is log correlation?
  • Which OSI layer is described as providing a path for the transmission of bits over cables, fiber, and radio waves?
  • Which statement best describes the primary purpose of a log retention policy?
  • HIPAA primarily governs which type of data?
  • Which security technology works to scramble computer messages and/or data?
  • Which OSI layer is responsible for assembling bits into frames, performing error detection, and handling flow control in Ethernet networks?
  • Explain the concept of time stamping in digital investigations and its importance.
  • Which of the following is not a critical infrastructure component?
  • Which statement best differentiates incident response from disaster recovery in organizational cybersecurity planning?
  • Which technology allows a firewall to block traffic from a known bad location?
  • What portion of the population is not covered by NIBRS reporting, given that 29% are covered?
  • What is malware staging in cyberattacks?
  • Which of the following is NOT a method to secure wireless networks?
  • Threat intelligence plays what role in cybercrime prevention?
  • Which agency is associated with cryptology and signals intelligence in the U.S. government?
  • Which of the following is not a role of the FBI in fighting computer crime?
  • Which OSI layer is primarily responsible for end-to-end reliability and flow control between applications?
  • Which GDPR principle emphasizes collecting only data that is necessary for a stated purpose?
  • The facets of the hacker culture are likely to:
  • Which statement about the U.S. Department of Energy's focus is accurate?
  • Which layer is described as 'The rules, policies, and management controls that govern the actions of users'?
  • A multi-scene crime involves multiple locations.
  • Which statement best describes the Postal Service's role in fighting computer-generated crimes since the creation of DHS?
  • Virtual crimes against persons such as stalking and harassment are facilitated by:
  • Which statement describes the size and impact of e-commerce on the economy?
  • Local law enforcement agencies' most important critical need to improve cybercrime response is which of the following?
  • The DHS subsumed the Federal Emergency Management Agency.
  • BYOD stands for Bring Your Own Device. What cybersecurity concern does it raise?
  • Which statement is true about the trend in reported cyber crimes?
  • Which OSI layer sits directly above the Physical layer and handles framing and MAC addressing in Ethernet networks?
  • Which layer corresponds to 'presentation' in the described layer scheme?
  • Which layer is described as 'Allows multiple simultaneous operations across a single network connection (e.g., TCP)'?
  • After 'Assess and evaluate' which step is next?
  • According to the survey data, what percentage of local police agencies reported a measurable increase in reporting computer and electronic crimes?
  • According to surveys, what percentage of local law enforcement agencies do not have adequate capabilities to read encrypted evidence?
  • A WAN that uses a common addressing and transfer protocol suite called Transfer Control Protocol/Internet Protocol is called a(n) ________.
  • Which federal agency collaborates with the Computer Incident Advisory Capability (CIAC)?
  • In what year was the FBI established?
  • Explain the concept of "order of volatility" in data collection.
  • Which layer corresponds to 'policies' in the described layer scheme?
  • CCIPS attorneys conduct hundreds of training seminars every year for other federal attorneys.
  • In the early era of computer security intruders, the majority of intruders came from which source?
  • Which option illustrates a key capability local agencies lack when handling cyber evidence?
  • Which of the following best describes data at rest versus data in transit and a typical protection for each?
  • The National Computer Security Survey found that ____% of the businesses sampled experience at least one cybercrime in 2005.
  • Which tool is designed primarily to log network traffic and examine it for known attack patterns?
  • GDPR and HIPAA domains: what type of data does each primarily govern?
  • Which layer is described as 'The human being using the computer and network'?
  • The single greatest problem in computer security is:
  • Which of the following is another typical digital evidence artifact encountered in investigations?
  • Which statement describes a NOT common cybercrime reporting channel for individuals or organizations?
  • Which trend is described as a significant threat to global networks due to hacking?
  • What is credential stuffing?
  • BYOD concerns include which of the following?
  • What is described as the most fundamental skill set of an electronic crimes investigator?
  • Why is data minimization emphasized in GDPR during cybercrime investigations?
  • Which layer is described as 'Standardizes data transmission formats (e.g., JPEG)'?
  • Which layer's responsibilities include framing, error detection, and flow control in LAN technologies such as Ethernet?
  • In a ransomware incident, what typically happens after encryption of files?
  • Experts believe computer hackers in developing countries will be increasingly motivated by which of the following?
  • Which of the following best describes data in transit protection?
  • Which activity would be considered 'exceeding authorized access' under the CFAA?
  • A U.S. Department of Defense study on emerging threats to national security observed that the field of battle is increasingly moving toward:
  • The CSSS arrests and prosecutes the sale and distribution of counterfeit pharmaceuticals and controlled substances over the Internet through which operation?
  • Which category of threat is associated with unauthorized disclosure of information?
  • What ensures consistent timestamps across logs in incident detection?
  • What best defines data exfiltration?
  • IP addressing operates at which OSI layer?
  • What is the primary distinction between cybercrime and conventional crime?
  • Which OSI layer handles end-to-end communication and reliable data transfer between applications?
  • Which agency is the lead for monitoring and protecting all federal government computer networks from cyberterrorism?
  • Which of the following is a characteristic of the black market?
  • The most popular password generator is:
  • Which basic step in risk analysis should be performed second?
  • Which security property is encryption primarily intended to protect?
  • Which statement about USPS involvement in interagency cybercrime work is most accurate?
  • Which agency is known as the nation's preeminent cryptological organization?
  • Which offense is most likely to touch the largest number of community members in the near future?
  • Minimization means:
  • Which of the following is a high-level method attackers use to exfiltrate data?
  • Which of the following is NOT a form of telecommunications fraud?
  • Why is hash verification important after imaging a drive in forensics?
  • The Bureau of Consumer Protection operates under which U.S. government agency?
  • Which layer corresponds to 'network' in the described layer scheme?
  • Active versus passive network defense techniques: which statement is accurate?
  • Which of the following is a form of new technology of user identification?
  • Define volatile data and its relevance in live digital investigations.
  • Which agency leads investigations into access device fraud?
  • Which term describes an evolution of firewall capabilities that inspects data packets at deeper levels?
  • Which of the following is a typical digital evidence artifact encountered in investigations?
  • Which basic step in risk analysis should be performed last?
  • Which of the following is a cybercrime reporting channel designed for nationwide coordination?
  • Which statement best captures the observed disparity between federal and local cyber cops?
  • Which list represents the five or six steps of an incident response lifecycle commonly referenced in frameworks?
  • Which of the following is NOT a form of telecommunications fraud?
  • Which OSI layer handles data representation, encryption, and compression for communication between applications?
  • In digital forensics, what is the primary reason to maintain a chain of custody?
  • What is a hash collision and why does it matter in forensics?
  • What is the purpose of chain of custody in digital evidence handling?
  • Which OSI layer provides logical addressing and path determination between networks?
  • Distinguish credential stuffing vs phishing.
  • The IP address is associated with which layer of the OSI model?
  • Which statement is MOST true about the globalization of hacking?
  • Which organization is described as the largest and primary investigative arm of the Department of Homeland Security?
  • Which statistic reflects cybercrime prevalence across businesses in 2005?
  • What is a forensic image and why is it important to create a bit-for-bit copy?
  • Which OSI layer would be most associated with routing packets through a network?
  • Cyber-based attacks and high technology crimes are of low priority for the FBI.
  • Biometrics are commonly used as a form of which security function?
  • Script Kiddies best described as?
  • The greatest number of Internet users are in which combination of regions?
  • NOT a characteristic of intruders during the first era of computer security?
  • The facets of the hacker culture are likely to increase the odds that some groups will become organized criminal enterprises.
  • Which statement about overall cybersecurity enforcement is most accurate?
  • What is a CSIRT and how does it differ from a CERT?
  • Which statement about the FBI's public sector partnerships is correct?
  • CCIP works in close collaboration with which entity in the prosecution of computer crimes?
  • The chief law enforcement officer of the federal government is the director of Homeland Security.
  • Name two core offenses defined by the CFAA in the United States.
  • Encryption is used to protect data by performing which action on the data?
  • Which of the following is a characteristic of the black market?
  • Which statement best describes the role of IP addresses?
  • Explain the concept of social engineering in cybercrime and name two common techniques.
  • What is the primary purpose of a risk assessment in cybersecurity?
  • What is the difference between a sector-by-sector copy and a file-level copy in forensics?
  • Name two common legal concepts relevant to digital evidence admissibility.
  • Which statement best reflects the relationship between state laws and technology pace?
  • Which statement describes a defense-in-depth approach?
  • Which agency has primary jurisdiction in cases involving access device fraud?
  • Which statement reflects the capacity of local officers to handle computer crimes?
  • What is "encryption at rest" and "encryption in transit," and why both matter?
  • Which classic element of computer security is generally not required for an encryption scheme?
  • Which statement best describes the role of 'Identify threats' in risk analysis?
  • What is a botnet and how do attackers typically control infected machines?
  • The character of espionage is expected to broaden into which of the following arenas?
  • Which basic step in risk analysis should be performed first?
  • Which federal agency houses CCIPS?
  • What is the purpose of write-blockers in forensic collection?
  • What is an Indicator of Compromise (IOC) and give two examples.
  • Which factor is NOT listed as a limiting factor for local law enforcement in responding to computer crime?
  • Define a digital footprint and its relevance to cybercrime investigations.
  • Name a major challenge in cloud forensics.
  • Which federal agency houses the Customs Cyber Smuggling Center (3C)?
  • The claim that the NSA has provided code-breaking capabilities since the Civil War is historically accurate.
  • Which statement best describes local officers' capacity for computer crime investigations?
  • In the OSI model, which layer is mainly concerned with the raw transmission of bits over a physical medium?
  • Which OSI layer is typically associated with MAC addressing and Ethernet frames?
  • The trio of regions with the largest Internet user base includes which regions?
  • How is a geographically compact crime scene under the administrative control of a single entity classified?
  • Which OSI layer handles frames rather than packets or segments?
  • This security technology can involve biometrics.
  • Which option correctly pairs a malware type with its defining characteristic?
  • What does MLAT stand for in cybercrime investigations?
  • Which layer corresponds to 'application' in the described layer scheme?
  • Which federal agency is primarily responsible for protecting consumers against computer-generated commercial fraud?
  • Which statement about the relationship between drug trafficking and cybercrime trait profiles is supported by the material?
  • Ethernet operates at which OSI layer for its basic data handling features such as framing and error detection?
  • The profiles of individuals at the higher levels of drug trafficking and cybercrime share common personality traits.
  • Unless a computer system holds a particular interest, the most likely threat comes from:
  • Which center is the primary channel for submitting Internet crime complaints to federal authorities?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy